Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: AngstHase on June 21, 2011, 09:33:58 AM



Title: Captain obvious: "Change your mybitcoin passwords"
Post by: AngstHase on June 21, 2011, 09:33:58 AM
One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.


Definitely the attacker got some more accounts cashed out.
http://blockexplorer.com/address/1MAazCWMydsQB5ynYXqSGQDjNQMN3HFmEu


Title: Re: Captain obvious: "Change your mybitcoin passwords"
Post by: foo on June 21, 2011, 11:25:31 AM
One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.
*facepalm* No, the salt is right there in the file, next to the hash. What the salt does is make it impractical to use precomputed tables, you have to brute force the password. If the password is very weak this does not take long.