Bitcoin Forum

Economy => Service Discussion => Topic started by: hellojpg on October 20, 2014, 01:41:49 PM



Title: Warning BTCjam
Post by: hellojpg on October 20, 2014, 01:41:49 PM
Be careful using BTCjam hackers are typing malicious code in the comments section.  I logged in to invest in someone and there were a bunch of script errors on the page.

I scrolled down to see other peoples comments and low and behold it is flooded with code I'm yanking me money outta there ASAP.

I tried to post it here but I get "The message body was left empty."

BTCjam are useless goxxers php wotever u call it things are starting to heat up so I got outta there


Title: Re: Warning BTCjam
Post by: --Encrypted-- on October 20, 2014, 01:50:58 PM
Be careful using BTCjam hackers are typing malicious code in the comments section.  I logged in to invest in someone and there were a bunch of script errors on the page.

I scrolled down to see other peoples comments and low and behold it is flooded with code I'm yanking me money outta there ASAP.

I tried to post it here but I get "The message body was left empty."

BTCjam are useless goxxers php wotever u call it things are starting to heat up so I got outta there


yeah I saw it too.. I dunno if it is malicious tho
I hope it didn't harm my pc in any way


Title: Re: Warning BTCjam
Post by: hellojpg on October 20, 2014, 02:31:31 PM
commentor goes by the name of "h4xx0r5000" with some sort of meme face his profile speaks for himself from ireland apparent   oly.

Here is a snippet I found interesting however i hath no experinced in programming but its obvious wot this is trying to do it is pages and pages long:

//Authentication

$login = "shellci.biz";//login
//DON'T FORGOT ABOUT CHANGE PASSWORD!!!
$pass = "shellci.biz"; //password
$md5_pass = "";//md5-cryped pass. if null, md5($pass)

/*COMMENT IT FOR TURN ON AUTHENTICATION>>>*/$login = false; //turn off authentication



Title: Re: Warning BTCjam
Post by: hellojpg on October 20, 2014, 02:38:40 PM
Here ith the page:

https://btcjam.com/listings/25467-debt-consolidation-loan-%231

wot ith this then php script?  security most be shltty if that can happen in the comment section wot say u?


Title: Re: Warning BTCjam
Post by: sifter on October 20, 2014, 02:44:18 PM
Get devthedev to check what's going on,

There's are/is (a) user(s) on this forum with a similar name(s)

https://bitcointalk.org/index.php?action=profile;u=138858
https://bitcointalk.org/index.php?action=profile;u=228517
https://bitcointalk.org/index.php?action=profile;u=388123


Title: Re: Warning BTCjam
Post by: --Encrypted-- on October 20, 2014, 02:49:52 PM
Here ith the page:

https://btcjam.com/listings/25467-debt-consolidation-loan-%231

wot ith this then php script?  security most be shltty if that can happen in the comment section wot say u?

that's not the only listing that have script comment, looks like it's all over the big loans

I'm not a coder so I don't know much. it's just odd how the script can run from the comment section tho.


Title: Re: Warning BTCjam
Post by: --Encrypted-- on October 20, 2014, 02:52:32 PM
Get devthedev to check what's going on,

There's are/is (a) user(s) on this forum with a similar name(s)

https://bitcointalk.org/index.php?action=profile;u=138858
https://bitcointalk.org/index.php?action=profile;u=228517
https://bitcointalk.org/index.php?action=profile;u=388123

that h4xx0r5000 (same name with the one on btcjam) was just registered hours ago..

edit:
ah crap, sorry for double post