Bitcoin Forum

Other => Meta => Topic started by: chaser_alt on November 11, 2021, 07:10:29 PM



Title: Badly need your help your guys.
Post by: chaser_alt on November 11, 2021, 07:10:29 PM
My main forum account is chaser15 (https://bitcointalk.org/index.php?action=profile;u=523501) and still shocked at what happened in my account just now. It got banned. Here's the story:

- I logged in at the forum
- Do my usual habit of posting. My first post for this day: https://bitcointalk.org/index.php?topic=1220979.msg58407216#msg58407216
- After posting, I've noticed that my signature (I'm part of the Stake signature campaign) is empty. Thinking it's just a bug I check my Profile Settings and to my surprise, my signature space is really empty.
- I immediately copy the signature at the Stake Campaign and update my profile.
- After that, I checked my Post History, and to my surprise, I have a post there that I didn't do! The thread is here: https://bitcointalk.org/index.php?topic=2647654.0

There's also a merited post by me that I didn't do (check the archive page). After I checked the unauthorized post, I immediately archived the page (https://archive.md/krFZm) at the archive.is website but unfortunately, while the archive is ongoing, I immediately deleted the unauthorized post thinking the page was already a snapshot. Now I don't have the copy of that unauthorized post but it's all about an update.

I changed my password immediately but after confirming, boom my account got banned. Is changing the password not allowed for now?
https://i.postimg.cc/J4PJhLHz/banchaser.png

- Is someone talented and skilled here can able to know the deleted post so that I can show the post I'm referring to?
- Is there a chance of unbanning accounts these days? I can provide all the information and proof needed to verify that I'm the original owner.

I don't understand how someone is able to know my password. As a forum Legendary rank and long-time internet geek, I'm not new to this security so I got shocked at what happened.

Many and big Thanks to those who will share their thoughts, views, opinions, etc. about this. :(


Title: Re: Badly need your help your guys.
Post by: hosseinimr93 on November 11, 2021, 07:40:48 PM
Are you sure your account has been banned?
There is no record in modlog (https://bitcointalk.org/modlog.php). Maybe, you have been banned temporarily?

Most probably, some one hacked your account and made that post.
Click here (https://bitcointalk.org/myips.php) to see your IP logs in the past 30 days.
Do you see any strange IP address there?


Title: Re: Badly need your help your guys.
Post by: isaac_clarke22 on November 11, 2021, 07:43:03 PM
User LogitechMouse encountered the similar issue back in September, which was also about this Phoenix Mining stuffs in this thread (https://bitcointalk.org/index.php?topic=5361595.0).
Your best shot is signing a message from your staked address in here.

Credits to LoyceV
I saw the post you're referring to from one of the scraped post from LoyceV's Search Tool, but I am not going to directly refer it in here as it contains the direct download link from Github. It's basically the changelog of the software, if this was indeed what you're referring to.
Quote
The  new  version  is  finally  ready.  You  can  download  PhoenixMiner  5.8c  from  here:

-
-

Changes in version 5.8c :
Full LHR disable mode -lhrdis <n>  1 - yes (default), 0 - no
Added lock core clock
Fixed an issue causing crashing with some RTX 3060/3080/3090 cards
Implemented new "turbo" kernels (-clkernel 3) for AMD Polaris cards that can work with the current DAG sizes over 4 GB. Note that -clkernel 3 uses double the VRAM and will
provide slightly faster hashrate with slightly higher power consumption. You can use the -rvram command-line parameter to specify how much VRAM to be left unused
Increased the maximum supported DAG epoch to 600 (i.e. until about Sep 2023)
Implemented full hardware control for AMD RX6900/6800/6700 cards under Linux. Note that with these cards under Linux you need to specify relative core voltage: e.g. -
cclock -50 will set the core voltage to be 50 mV under the default value
Added ROCr kernels for Vega, Radeon VII and Navi cards. With these kernels you will be able to run these cards with Linux drivers 20.45 and later but the performance will
be lower than with the older PAL drivers and kernels. We recommend using AMD Linux driver 20.30 for all cards except RX6900/6800/6700
Fixed an issue causing crashing with some RX6900/6800/6700 cards under Linux (there is no need to run these cards with -clkernel 0 anymore)
Added support for AMD Windows drivers up to 21.8.1. Note that Radeon VII cards will not work with drivers 21.6.1 or higher - you need to use older drivers for proper
operation of these cards
Added support for AMD Linux drivers up to 21.20 (use older drivers for Vega or Radeon VII cards as they will not work with 21.20). Note that the latest 21.30 drivers are
not supported (and the initial testing shows that even the older Polars cards are not working properly with them, so avoid 21.30 for now)
Numerous other fixes and small improvements

Please let us know if you have any problems or questions related to PhoenixMiner 5.8c


Title: Re: Badly need your help your guys.
Post by: chaser_alt on November 11, 2021, 08:00:18 PM
User LogitechMouse encountered the similar issue back in September, which was also about this Phoenix Mining stuffs in this thread (https://bitcointalk.org/index.php?topic=5361595.0).
Your best shot is signing a message from your staked address in here.

I saw the post you're referring to from one of the scraped post from LoyceV's Search Tool, but I am not sure if I should refer it in here as it contains the direct download link from Github. It's basically the changelog of the software, if that was indeed what you're referring to.

Big thanks for this! Yes, it's the same case that happened to me a while ago. The unauthorized post that Logitechmouse did (https://archive.fo/8Xb0A) is identical to what I remember on the post I deleted. I already sent an email to the email address provided at the ban noticed. I hope I will get an update.

I can provide a signed message in ETH. The address I always used when asking loan for DarkStar. I hope it will consider as enough and strong proof.



Are you sure your account has been banned?
There is no record in modlog (https://bitcointalk.org/modlog.php). Maybe, you have been banned temporarily?

Most probably, some one hacked your account and made that post.
Click here (https://bitcointalk.org/myips.php) to see your IP logs in the past 30 days.
Do you see any strange IP address there?

Yes, I'm 100% sure that everything is fine at my end. Referring to the post of @isaac_clark22 looks like a sort of program can breach anyone's account. I don't know how's that possible. Thanks for the response!


Title: Re: Badly need your help your guys.
Post by: mprep on November 11, 2021, 08:13:59 PM
  • Read through the entire ban message you've screenshotted carefully. Follow the (rather simple) instructions in it.
  • Have you installed anything dodgy or even a bit suspect recently? Hell, have you ran any executables on your PC recently? If so, your PC may be compromised and changing your passwords (Bitcointalk or otherwise) on that PC is (probably) useless.
  • Have you reused your previous password on other websites? Is your password just a few words (with maybe a few numbers added at the end or start, some random capitalization and maybe a few replaced letters)? Is your password short (less than 8 characters)? If you answered to any of these with "yes" (especially the first one), there's a possibility the attacker might've just managed to guess it.
  • Have you recently been redirected to a Bitcointalk login screen (or at least what looks like it) via a link in a Bitcointalk PM you've received? If so, someone might've phished you out of your Bitcointalk password.


Title: Re: Badly need your help your guys.
Post by: hosseinimr93 on November 11, 2021, 08:25:35 PM
-------
Why the ban hasn't been reported in the modlog (https://bitcointalk.org/modlog.php)?
As far as I know, the modlog doesn't report the ban only if that's temporarily.
According to the rules, since chaser15 (the hacker) has shared a malware, the ban should be permanent. So, it should be displayed in the modlog. It's weird.


Title: Re: Badly need your help your guys.
Post by: khaled0111 on November 11, 2021, 08:30:55 PM
Your account is not banned but, as the ban message says, it has been locked for security reasons.
Send a message to the email address which appears on the ban message and make sure to sign it with one of your stacked addresses to prove ownership of the account.
In the meantime, try to figure out how your account got compromised and take the appropriate actions.


Title: Re: Badly need your help your guys.
Post by: JeromeTash on November 11, 2021, 08:31:10 PM
Cases of hackers hijacking high ranking accounts and then using them to post malware are quite common this days. The hackers nolonger change the passwords or emails as they know that they will be locked out and won't be able to use your account to post their malicious links.

What they do, they just keep logging in and posting when you don't know and before you realise it, you account is already flagged for sharing malware and even banned.

Mine got hacked too but the cause was using the same log in credentials on different sites. One site's security was breached and the passwords got leaked.


Title: Re: Badly need your help your guys.
Post by: chaser_alt on November 11, 2021, 08:38:53 PM
The hackers nolonger change the passwords or emails as they know that they will be locked out and won't be able to use your account to post their malicious links.

I see. I'm not aware that changing emails or passwords will lead to account locked. But regardless, I'm glad now that my account got locked as it might post more malicious links without my consent.

I already sent an email provided on the ban notice and waiting for the instructions. I also reached out to Logitechmouse to share with me some details on his former case and what steps he did in retrieving his account.

Thanks for everyone's response. I truly appreciate it. Your shared information is feeding my mind and if the same case in the future happened to anyone, this thread can serve as a reference.


Title: Re: Badly need your help your guys.
Post by: mprep on November 11, 2021, 09:11:20 PM
-------
Why the ban hasn't been reported in the modlog (https://bitcointalk.org/modlog.php)?
As far as I know, the modlog doesn't report the ban only if that's temporarily.
According to the rules, since chaser15 (the hacker) has shared a malware, the ban should be permanent. So, it should be displayed in the modlog. It's weird.
Check OP's screenshot - the account wasn't permanently banned, it was locked (there's a difference). Also, not all permanent bans show up in the modlog:

Autoban is permanent, unless manually removed/modified. Nuke bans and removes all of a user's posts (spambots usually).  Manually applied bans won't show up in the modlog, those are usually temporary, but not always.



The hackers nolonger change the passwords or emails as they know that they will be locked out and won't be able to use your account to post their malicious links.

I see. I'm not aware that changing emails or passwords will lead to account locked.
It doesn't. However, IIRC it does notify you via email if your password's been changed (alerting you that someone unauthorized has access to your account). Also, if the hacker changed your email address, an email with a an account lock link (that's valid for 14 days IIRC) is sent to your old email address. While neither of these factoids are really relevant to this situation, I just wanted to clear up the misconception.


Title: Re: Badly need your help your guys.
Post by: Findingnemo on November 11, 2021, 10:19:59 PM
Already mprep have you an explanation about the ban and lock, its just locked via the link sent to your email which is linked to your forum account so it means literally you clicked the link when someone accessed your account by somehow so all you have to do is to just follow the instructions which is signing in a message from one of the address you posted in an unedited post in the past and let the recovery team to do the remaining work hope it will take maximum of 1 week to get back.


Title: Re: Badly need your help your guys.
Post by: The Sceptical Chymist on November 11, 2021, 10:50:52 PM
Cases of hackers hijacking high ranking accounts and then using them to post malware are quite common this days. The hackers nolonger change the passwords or emails as they know that they will be locked out and won't be able to use your account to post their malicious links.
Yikes.  I do remember LogitechMouse's case from a while back, and it does sound like that's exactly what happened here.  I don't know diddly squat about hacking techniques, but that's kind of scary.  I think after this post I'm going to change my password to something a lot stronger (though I couldn't tell you off the top of my head what my current one is). 

The good news is that OP shouldn't have much of a problem getting his account back, since it's pretty clear he wasn't the one who posted that malicious link.  Could have been a lot worse, though it sucks that it happened in the first place--and a few years ago if a hacker got ahold of your account, there wasn't much you could do about it.



Title: Re: Badly need your help your guys.
Post by: Peanutswar on November 11, 2021, 11:57:51 PM
I guess your account is not banned base on the record of bpip.org it doesn't have a cancel icon that reflects as a banned user. I guess it's just a locked account because of some suspicious activity with your account that forum detects it and lock i guess moderators can answer that questions and wait for their actions as long as you provide the info for verification theres no problem.

https://i.imgur.com/yZGiTM5.png

https://i.imgur.com/46BZSlV.png


Title: Re: Badly need your help your guys.
Post by: Lafu on November 12, 2021, 03:12:34 AM
Your Account got hacked and it was reported in my thread for posting the Fake Miner software download link with malware !
Thats why i try to write down there as much as possible the Accounts that got catched or posting this Links.
Mostly the Accounts got hacked , and its making things a bit easier to see why the Accounts got locked or banned.

URGENT

ITS BACK or still live fake PhoenixMiner github

https://github.com/PhoenixMain


chaser15 posted fake PhoenixMiner here: https://bitcointalk.org/index.php?topic=2647654.msg58406832#msg58406832


using a impressive account: https://bitcointalk.org/index.php?action=profile;u=523501


Just wanted to let you know , if you got your Account back please write in the thread and i will remove the negative Feedback.


Title: Re: Badly need your help your guys.
Post by: LogitechMouse on November 12, 2021, 03:21:04 AM
User LogitechMouse encountered the similar issue back in September, which was also about this Phoenix Mining stuffs in this thread (https://bitcointalk.org/index.php?topic=5361595.0).
Your best shot is signing a message from your staked address in here.

I saw the post you're referring to from one of the scraped post from LoyceV's Search Tool, but I am not sure if I should refer it in here as it contains the direct download link from Github. It's basically the changelog of the software, if that was indeed what you're referring to.

Big thanks for this! Yes, it's the same case that happened to me a while ago. The unauthorized post that Logitechmouse did (https://archive.fo/8Xb0A) is identical to what I remember on the post I deleted. I already sent an email to the email address provided at the ban noticed. I hope I will get an update.

I can provide a signed message in ETH. The address I always used when asking loan for DarkStar. I hope it will consider as enough and strong proof.
I can still remember that time where my account also got hacked by this stupid Phoenix Miner shits. I don't even know what that means or at least I just know that it is a miner that's all.

They've said already the way to retrieve your account and I already sent you a PM into what I've done when I experienced the same thing. Sending a signed and verified message here is the best thing and if you still have that (which is I think you have) then you're good. I still can't forget what I did after seeing the my account got locked. I needed to get my 8 yr old laptop with a broken screen just to recover my signed Bitcoin address there :D.

Just wait for at least 2 weeks I think because that is the number of weeks I waited before I got my account back. You will get yours so no worries :). Thanks again for those who helped me back then :).


Title: Re: Badly need your help your guys.
Post by: PrimeNumber7 on November 12, 2021, 03:24:02 AM
I think there is a strong argument to say that the “ban” message for accounts locked for security purposes, should not say they are “banned”. This creates a lot of confusion, even if someone only needs to read the rest of the message to understand what happened.

It might also be an idea to reconsider blanket account locks when certain actions are taken. For example, if someone resets their password, their account will only get locked if they don’t access the forum from a “new” browser within x time, and access the forum at least y times over x days in w unique days. 


Title: Re: Badly need your help your guys.
Post by: LoyceV on November 12, 2021, 09:03:25 AM
I think after this post I'm going to change my password to something a lot stronger (though I couldn't tell you off the top of my head what my current one is).
I've seen people who use a few different passwords, but don't remember which one they use where. So they just try all of them and see what works.
If that is what you're doing, you're basically sharing all your passwords with different websites, which kinda defeats the purpose of using more than one password.
If you're using a password manager, this doesn't apply to you.

Have you recently been redirected to a Bitcointalk login screen (or at least what looks like it) via a link in a Bitcointalk PM you've received? If so, someone might've phished you out of your Bitcointalk password.
One very simple way to prevent this, is having your browser store your password. If I need to enter my password instead of just clicking the Login button, I know it's not the real site.


Title: Re: Badly need your help your guys.
Post by: UserU on November 12, 2021, 12:42:39 PM
I can still remember that time where my account also got hacked by this stupid Phoenix Miner shits. I don't even know what that means or at least I just know that it is a miner that's all.

They've said already the way to retrieve your account and I already sent you a PM into what I've done when I experienced the same thing. Sending a signed and verified message here is the best thing and if you still have that (which is I think you have) then you're good. I still can't forget what I did after seeing the my account got locked. I needed to get my 8 yr old laptop with a broken screen just to recover my signed Bitcoin address there :D.

Just wait for at least 2 weeks I think because that is the number of weeks I waited before I got my account back. You will get yours so no worries :). Thanks again for those who helped me back then :).

Whenever I see those posts, most come from low-rankers but once in a blue moon would see Legendaries. One spotted earlier today. I'd always be wondering if they would actually be bought over or something because some even bear signatures from previous campaigns.

Did you install any malicious browser extension or had your credentials leaked by any chance? HaveIbeenPwned is a good place to start.


Title: Re: Badly need your help your guys.
Post by: LogitechMouse on November 12, 2021, 03:43:41 PM
I can still remember that time where my account also got hacked by this stupid Phoenix Miner shits. I don't even know what that means or at least I just know that it is a miner that's all.

They've said already the way to retrieve your account and I already sent you a PM into what I've done when I experienced the same thing. Sending a signed and verified message here is the best thing and if you still have that (which is I think you have) then you're good. I still can't forget what I did after seeing the my account got locked. I needed to get my 8 yr old laptop with a broken screen just to recover my signed Bitcoin address there :D.

Just wait for at least 2 weeks I think because that is the number of weeks I waited before I got my account back. You will get yours so no worries :). Thanks again for those who helped me back then :).

Whenever I see those posts, most come from low-rankers but once in a blue moon would see Legendaries. One spotted earlier today. I'd always be wondering if they would actually be bought over or something because some even bear signatures from previous campaigns.

Did you install any malicious browser extension or had your credentials leaked by any chance? HaveIbeenPwned is a good place to start.
I didn't install any malicious browser extension whatsoever. The mistake that I did is that, I only used one email account in all of my accounts that is related to crypto including my Bitcointalk account. Maybe its because of that mistake I did that lead to my account getting locked.

I just tried putting my email address into HaveIbeenPwned and it seems like there is a problem with my email since this is what appeared.
Quote
Pwned in 3 data breaches and found 3 pastes
Since its my main email account, maybe I saved some of my credentials out there that caused my account to get compromised. Is there a way to remove this breaches and paste that I got from my email account? Thanks for sharing too :).
Right now, I'm not using that email anymore when I'm creating accounts that are related to crypto since I have may emails that I'm using right now. Gladly that I used a different email address in some of my important accounts that are related to crypto.


Title: Re: Badly need your help your guys.
Post by: UserU on November 12, 2021, 04:05:11 PM

Quote
Pwned in 3 data breaches and found 3 pastes
Since its my main email account, maybe I saved some of my credentials out there that caused my account to get compromised. Is there a way to remove this breaches and paste that I got from my email account? Thanks for sharing too :).
Right now, I'm not using that email anymore when I'm creating accounts that are related to crypto since I have may emails that I'm using right now. Gladly that I used a different email address in some of my important accounts that are related to crypto.

Shid, pastes are definitely bad since they usually include the login credentials. Glad you learnt something new :)


Title: Re: Badly need your help your guys.
Post by: chaser15 on November 16, 2021, 12:05:12 AM
Thanks for everyone's help! I finally recover my account. Will be careful next time even I don't know how it happened. Moving forward......

Thanks also to the Bitcointalk team. The process was fast and smooth.

My problem now is how to lock this thread lol. I forgot the password of the alt account I used here because I'm in rush to create that account to post my problem here. Still figuring out what's the password and soon as I remember it, I will lock the thread.


Title: Re: Badly need your help your guys.
Post by: Pmalek on November 16, 2021, 02:54:43 PM
If you don't remember the password for the alt account you used, you can just report the thread and ask the mods to delete it if you think it has served its purpose. I will do it for you if it helps. Additionally, get in touch with Lafu and ask him to remove his negative trust rating since the rightful owner is again in possession of the account.


Title: Re: Badly need your help your guys.
Post by: UserU on November 16, 2021, 03:17:45 PM

My problem now is how to lock this thread lol.


Scroll down to the bottom of the thread, you should see both Close Thread | Move Thread hyperlinks.

https://i.ibb.co/9qh713m/close.png

Hurry up, before the shitposters start entering ;D


Title: Re: Badly need your help your guys.
Post by: hosseinimr93 on November 16, 2021, 03:30:17 PM
Scroll down to the bottom of the thread, you should see both Close Thread | Move Thread hyperlinks.
chaser15 (https://bitcointalk.org/index.php?action=profile;u=523501) account was locked at the time of creating this topic and he used his alt account (https://bitcointalk.org/index.php?action=profile;u=3405820) for creating it.
Now, he doesn't remember the password of the alt account.


To OP:
You should be able to reset the password of your alt account using the email address used at the time of its registration. Just click on "Forgot your password?" option.


Title: Re: Badly need your help your guys.
Post by: UserU on November 16, 2021, 03:58:03 PM

chaser15 (https://bitcointalk.org/index.php?action=profile;u=523501) account was locked at the time of creating this topic and he used his alt account (https://bitcointalk.org/index.php?action=profile;u=3405820) for creating it.
Now, he doesn't remember the password of the alt account.


Ah... my bad.

I've reported the OP so it'd get closed then.