Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: AtlasONo on May 17, 2011, 08:13:03 PM



Title: Stealing Bitcoins
Post by: AtlasONo on May 17, 2011, 08:13:03 PM
http://evilpacket.net/2011/may/17/stealing-bitcoins/  

Quote
As you can see from the video, exploiting an unsuspecting Mt Gox user into giving up their (hard earned?) bitcoins wouldn't be that difficult. This is just the tip of the iceberg and I'm sure we will see many more attacks against bitcoin itself and supporting sites.

Just be aware and be alert.


Title: Re: Stealing Bitcoins
Post by: Nesetalis on May 17, 2011, 08:17:59 PM
just another point towards non-centralized economy. I hope Mt catches this thread.


Title: Re: Stealing Bitcoins
Post by: kiba on May 17, 2011, 08:20:06 PM
just another point towards non-centralized economy. I hope Mt catches this thread.

Um. Email the owner of mtgox, now.

Also, decentralizing the economy doesn't do much if security vulnerabilities exist on many bitcoin sites rather than just one big site.


Title: Re: Stealing Bitcoins
Post by: gigabytecoin on May 17, 2011, 08:34:47 PM
So this "hack" relies on the victim opening up a compromised webpage that will steal/copy their keystrokes...? Or a compromised webpage in general?

Yes, that "tactic" can be used to steal anything from anyone, this is not bitcoin centric imho.


Title: Re: Stealing Bitcoins
Post by: Littleshop on May 17, 2011, 08:48:24 PM
Thanks for the good information.  This is something to watch out for but not anything unique to mtgox.com especially since they enabled SSL.  If it is not an SSL connection to mtgox then there is a PROBLEM! 

Cool song too, I think I will search out that group. 


Title: Re: Stealing Bitcoins
Post by: BitcoinStars.com on May 17, 2011, 08:53:16 PM
the bitcoin community needs more of this monitoring and info sharing to help avoid future issues


Title: Re: Stealing Bitcoins
Post by: kiba on May 17, 2011, 08:55:55 PM
the bitcoin community needs more of this monitoring and info sharing to help avoid future issues
I wrote an article for bitcoin security long ago:

http://bitcoinweekly.com/articles/security-in-bitcoin


Title: Re: Stealing Bitcoins
Post by: Nesetalis on May 17, 2011, 08:59:45 PM
XSS is a big problem for sites all over the web and there is no easy solution.