Bitcoin Forum

Economy => Marketplace => Topic started by: mineriapepe on December 24, 2011, 09:42:04 PM



Title: Victim of pishing in MtGox
Post by: mineriapepe on December 24, 2011, 09:42:04 PM
Hello. Lamentably I was a victim of pishing from Mtgix.tk. , asking me for a MtGox verification. >:( All my funds are gone. I send a mail to MtGox to abort the transactions. Do it work???

Thanks. 


Title: Re: Victim of pishing in MtGox
Post by: btc_artist on December 24, 2011, 09:44:11 PM
Bitcoin transactions cannot be aborted.


Title: Re: Victim of pishing in MtGox
Post by: JusticeForYou on December 24, 2011, 09:46:20 PM
You clicked the link...  :-\

The site is was not very accurate, was missing the CA...,

You can, I guess, fill out a ticket and see... but I doubt it.

Use the real site http://support.mtgox.com  this time.

Sorry to here it.


Title: Re: Victim of pishing in MtGox
Post by: mineriapepe on December 24, 2011, 09:56:39 PM
You clicked the link...  :-\

The site is was not very accurate, was missing the CA...,

You can, I guess, fill out a ticket and see... but I doubt it.

Use the real site http://support.mtgox.com  this time.

Sorry to here it.

Thanks, I send the tickets already in the correct place ;)

The green dot of the start of .tk domains, confused me.  :-[


Title: Re: Victim of pishing in MtGox
Post by: Otoh on December 28, 2011, 01:48:35 PM
I received this phishing email in the last 24 hours (my email was on the original leaked list - surprised that they took this long to get around to it), forwarded it to Mt.Gox

from:    info@mtgox.com via de1.imhoster.net
sender time: redacted
reply-to:    info@mtgox.com
to:    redacted
date:    27 December 2011
subject:    [Mt.Gox] Your account is currently pending review.
mailed-by:    de1.imhoster.net

Dear Mt.Gox user,

Your account is currently pending review, please visit https://mtgox.com/forms/verification
For those users who have had their accounts marked for review, an explanation of why were are implementing these security measures can be found here:

Security Measures Explained

“Verified” Accounts are eligible for monthly/daily transaction limits of up to 5 times the monthly limit and 10 times the daily limit.

In order to apply for the “Verified” account status please attach a copy of the following documents:
- Your government issued photo ID (passport, permanent residence card or driver’s license) and
- A scan of either your monthly utility bill (power, phone, TV, gas, water, etc.) or a certificate of residency issued by your local government.

Thanks,
The Mt.Gox team

...these were the dodgy links in it going to:

http://www.mtgkx.tk/forms/verification
http://www.mtgkx.tk/entries/20471711-security-measures-explained

Genuine Mt.Gox reply:

Hello Redacted,

Thank you, this is indeed a phishing attempt. We will never send you an email asking you to log in anywhere, although we may occasionally send emails pointing you to the support page for information updates.

The email you provided has been documented, and will be used in our efforts to prevent phishers from continuing to target our users.

Kind regards,

Mt.Gox Support


Title: Re: Victim of pishing in MtGox
Post by: DeathAndTaxes on December 28, 2011, 02:01:27 PM
I have wondered why Mt. Gox doesn't implement an optional irrevocable timer.

User sets a 1 hour to 48 hour delay timer.  Once set this timer can't be removed or reduced without waiting timeout period.

1) User (or attacker makes withdraw attempt)
2) User email (and possible SMS) is notified.
3) Timer engages.  If user set a 24 hour delay then funds will transfer in 24 hours.
4) If transfer is valid then user does nothing and in 24 hours funds will transfer.
5) If transfer if bogus then user aborts the transfer.

Making other "high security" changes would also require notification and delay timer period.
* changing email address
* adding new bank account for wire transfers


Yeah it would be less convenient is user wants to move funds rapidly but it would be user optional.  Users can each choose the compromise between security and convenience.


Title: Re: Victim of pishing in MtGox
Post by: finway on December 28, 2011, 03:17:03 PM
I think put some private "welcome message" hilighted -- like LibertyReserve does -- would somehow help.


Title: Re: Victim of pishing in MtGox
Post by: mc_lovin on December 28, 2011, 07:06:45 PM
I have wondered why Mt. Gox doesn't implement an optional irrevocable timer.

User sets a 1 hour to 48 hour delay timer.  Once set this timer can't be removed or reduced without waiting timeout period.

1) User (or attacker makes withdraw attempt)
2) User email (and possible SMS) is notified.
3) Timer engages.  If user set a 24 hour delay then funds will transfer in 24 hours.
4) If transfer is valid then user does nothing and in 24 hours funds will transfer.
5) If transfer if bogus then user aborts the transfer.

Making other "high security" changes would also require notification and delay timer period.
* changing email address
* adding new bank account for wire transfers


Yeah it would be less convenient is user wants to move funds rapidly but it would be user optional.  Users can each choose the compromise between security and convenience.

Thats a damn good idea, you would save so much money from being stolen!


Title: Re: Victim of pishing in MtGox
Post by: DeathAndTaxes on December 29, 2011, 03:29:21 PM
I have wondered why Mt. Gox doesn't implement an optional irrevocable timer.

User sets a 1 hour to 48 hour delay timer.  Once set this timer can't be removed or reduced without waiting timeout period.

1) User (or attacker makes withdraw attempt)
2) User email (and possible SMS) is notified.
3) Timer engages.  If user set a 24 hour delay then funds will transfer in 24 hours.
4) If transfer is valid then user does nothing and in 24 hours funds will transfer.
5) If transfer if bogus then user aborts the transfer.

Making other "high security" changes would also require notification and delay timer period.
* changing email address
* adding new bank account for wire transfers


Yeah it would be less convenient is user wants to move funds rapidly but it would be user optional.  Users can each choose the compromise between security and convenience.

Thats a damn good idea, you would save so much money from being stolen!

I was at 7-11 yesterday.  They have those time lock safes and it made me think of it. 


Title: Re: Victim of pishing in MtGox
Post by: DeathAndTaxes on December 29, 2011, 03:30:51 PM
I have wondered why Mt. Gox doesn't implement an optional irrevocable timer.

User sets a 1 hour to 48 hour delay timer.  Once set this timer can't be removed or reduced without waiting timeout period.

1) User (or attacker makes withdraw attempt)
2) User email (and possible SMS) is notified.
3) Timer engages.  If user set a 24 hour delay then funds will transfer in 24 hours.
4) If transfer is valid then user does nothing and in 24 hours funds will transfer.
5) If transfer if bogus then user aborts the transfer.

Making other "high security" changes would also require notification and delay timer period.
* changing email address
* adding new bank account for wire transfers


Yeah it would be less convenient is user wants to move funds rapidly but it would be user optional.  Users can each choose the compromise between security and convenience.

Thats a damn good idea, you would save so much money from being stolen!

I was at 7-11 yesterday.  They have those time lock safes and it made me think of it.  

Hopefully Mt. Gox understands that layered security is the only real security.  Personally I always look for the Green Address but some people don't.

Green Address
yubikey
strong password requirement
encrypted hashed password table (w/ key hardening)
user education
time locks
etc

all together created a layered defense.


Title: Re: Victim of pishing in MtGox
Post by: btc_artist on December 29, 2011, 04:59:19 PM
encrypted password list
If you're referring to how passwords are stored server-side, then it should be hashed, not encrypted (huge difference).  Also, they should be salted and hashed with something like bcrypt with performs key hardening, not a hash primitive like sha256.


Title: Re: Victim of pishing in MtGox
Post by: DeathAndTaxes on December 29, 2011, 06:31:29 PM
encrypted password list
If you're referring to how passwords are stored server-side, then it should be hashed, not encrypted (huge difference).  Also, they should be salted and hashed with something like bcrypt with performs key hardening, not a hash primitive like sha256.

Yeah I was thinking that just wrote encryption for some reason.  Updated.


Title: Re: Victim of pishing in MtGox
Post by: mc_lovin on December 30, 2011, 06:10:26 AM
I wonder how many BTC's they stole total that day?


Title: Re: Victim of pishing in MtGox
Post by: bitcoinTrader on December 31, 2011, 08:23:27 PM
I also got the same mail, stating that my account is under review.
I was shocked for a moment, since after much struggle I was able to get Verified status.
When I clicked the link, it asked for username and password, resembling the same new mtgox interface.
Then I noticed the last price, which was some $3.xx, which alarmed me, since I had seen the price at 4.6x some 5-10 minutes ago.
After that I noticed the URL and then I was sure this is phishing :)


Title: Re: Victim of pishing in MtGox
Post by: Edward50 on February 19, 2012, 05:26:29 PM
I just got this same phishing E-mail about acounts being verified today.
It looked pretty legit also. But I knew right away it was wierd.




How the hell did they get my E-Mail address to send me this letter?


Title: Re: Victim of pishing in MtGox
Post by: Otoh on February 19, 2012, 06:13:02 PM
assume that your email address wasn't on the original Mt.Gox leaked list or you wouldn't have asked such an obvious question, personally in your case I'd be inclined to suspect Goldilocks (http://en.wikipedia.org/wiki/The_Story_of_the_Three_Bears) on this one  ;D