Bitcoin Forum

Economy => Trading Discussion => Topic started by: bitrain on February 26, 2012, 01:51:29 PM



Title: Attention Phishing (Mtgox)
Post by: bitrain on February 26, 2012, 01:51:29 PM
 Just received an e-mail:

Quote
Dear Mt.Gox user,

Your account is currently pending review, please visit  htps://mtgox.com/forms/verification (fake link)
For those users who have had their accounts marked for review, an explanation of why were are implementing these security measures can be found here:

Security Measures Explained

“Verified” Accounts are eligible for monthly/daily transaction limits of up to 5 times the monthly limit and 10 times the daily limit.

In order to apply for the “Verified” account status please attach a copy of the following documents:
- Your government issued photo ID (passport, permanent residence card or driver’s license) and
- A scan of either your monthly utility bill (power, phone, TV, gas, water, etc.) or a certificate of residency issued by your local government.

Thanks,
The Mt.Gox team

 Typical phishing. Don't play with it.
 All links drives to http://yhhr4.tmweb.ru . Message sent from Ukraine.


Title: Re: Attention Phishing (Mtgox)
Post by: ineededausername on February 26, 2012, 02:35:19 PM
I went and gave them this:
Username: fuck
Password: you
;D


Title: Re: Attention Phishing (Mtgox)
Post by: jake262144 on February 26, 2012, 02:47:25 PM
I went and gave them this:
Username: fuck
Password: you
;D
Not prudent - you can't tell what browser exploits the fake site might have been enriched with.
While your act of defiance is duly noted, never actually touching the attacking server is the way to go.

And *PLEASE* don't tell me that running <your_favourite_antivirus> justifies this attitude.


Title: Re: Attention Phishing (Mtgox)
Post by: marked on February 26, 2012, 02:56:49 PM
Not prudent - you can't tell what browser exploits the fake site might have been enriched with.
While your act of defiance is duly noted, never actually touching the attacking server is the way to go.

And *PLEASE* don't tell me that running <your_favourite_antivirus> justifies this attitude.

ha, they can't exploit my lynx running from my atari st that's running MiNT....  :)

marked, now wondering what gui browser is available.


Title: Re: Attention Phishing (Mtgox)
Post by: cypherdoc on February 26, 2012, 03:05:56 PM
I went and gave them this:
Username: fuck
Password: you
;D

why didn't you use your former avatar?  aka The Bird.


Title: Re: Attention Phishing (Mtgox)
Post by: cbeast on February 26, 2012, 04:49:25 PM
Let's compare notes. Did anyone contact anyone in the bitcoin community by email shortly before getting this phishing email? Or did anyone post in a particular section or thread? I'm not asking for names, I'm simply looking for a pattern.


Title: Re: Attention Phishing (Mtgox)
Post by: grue on February 26, 2012, 04:59:02 PM
I went and gave them this:
Username: fuck
Password: you
;D
Not prudent - you can't tell what browser exploits the fake site might have been enriched with.
While your act of defiance is duly noted, never actually touching the attacking server is the way to go.

And *PLEASE* don't tell me that running <your_favourite_antivirus> justifies this attitude.
i got noscript. problem?


Title: Re: Attention Phishing (Mtgox)
Post by: jake262144 on February 26, 2012, 05:19:06 PM
i got noscript. problem?
That makes at least two of us...  :D
That "fuck you" attitude needed some sort of comment lest we see newbs catching up the idea and getting zapped. A week later "I lost my bitcoins" posts will crop up like a bad rash on one's behind.

Also, don't fall into the delusion of invulnerabillity. There have been exploits aplenty targeting various bugs in html parsing, completely orthogonal to JavaScript.
NoScript makes you a less desirable/expected target but it can't mitigate all attack vectors.


Title: Re: Attention Phishing (Mtgox)
Post by: dub0matic on February 26, 2012, 08:23:26 PM
haha thats exactly why i came here today to make sure. lastweek i got it and width-drew all my my coins i would never verify my account mtgox anyway


Title: Re: Attention Phishing (Mtgox)
Post by: stick_theman on February 27, 2012, 05:50:13 AM
I wonder how successful these phising emails are, giving the btc community is a lot more tech savvy.


Title: Re: Attention Phishing (Mtgox)
Post by: drakahn on February 27, 2012, 05:53:26 AM
i wonder what site the people that got it are all a member of


Title: Re: Attention Phishing (Mtgox)
Post by: sveetsnelda on February 27, 2012, 07:10:52 AM
i wonder what site the people that got it are all a member of

That's the real question. What membership are they drawing from and how did they get that access?

When MTGox was hacked months ago, the user database was leaked.  I'm sure it's still from that database.


Title: Re: Attention Phishing (Mtgox)
Post by: cbeast on February 27, 2012, 07:39:01 AM
Besides MT Gox, I have only given my email address to Matthew. I hope his system isn't compromised. Although the mods/admins may have access to it as well.


Title: Re: Attention Phishing (Mtgox)
Post by: Bro on February 27, 2012, 09:52:45 AM
i wonder what site the people that got it are all a member of

That's the real question. What membership are they drawing from and how did they get that access?

When MTGox was hacked months ago, the user database was leaked.  I'm sure it's still from that database.

nope, I haven't receive any phishing attempt


Title: Re: Attention Phishing (Mtgox)
Post by: Kluge on February 27, 2012, 10:16:03 AM
i wonder what site the people that got it are all a member of

That's the real question. What membership are they drawing from and how did they get that access?

When MTGox was hacked months ago, the user database was leaked.  I'm sure it's still from that database.

my account was formed since then :/  i got the phishing stuff too. it is really why i do not want to deal with gox via email. on the forum or irc is the safest way.
Opposite, here, though same point implied. I had account prior to hack but did not get the phishing email (checked spam folder) - also subscribed to BTC Mag.

Not sure what other large BTC-related services remain which hold email.


Title: Re: Attention Phishing (Mtgox)
Post by: zer0 on February 27, 2012, 05:42:51 PM
I gave up on tracking gox phishing scams ever since one of my old emails was leaked I must get around a dozen per week of various pathetic nigerian attempts


Title: Re: Attention Phishing (Mtgox)
Post by: deslok on February 27, 2012, 10:41:39 PM
I got my phishing stuff about a month ago, at least before Matthew had my address. I doubt that is the source.

Goat is there any need to implicate Matthew beyond some form of unreasonable animosity?


Title: Re: Attention Phishing (Mtgox)
Post by: Kluge on February 27, 2012, 10:43:05 PM
I got my phishing stuff about a month ago, at least before Matthew had my address. I doubt that is the source.

Goat is there any need to implicate Matthew beyond some form of unreasonable animosity?
Ciphercoin brought him up, not Goat, who actually implied it was not Matt. (unless I misinterpreted it)


Title: Re: Attention Phishing (Mtgox)
Post by: deslok on February 27, 2012, 10:44:52 PM
I got my phishing stuff about a month ago, at least before Matthew had my address. I doubt that is the source.

Goat is there any need to implicate Matthew beyond some form of unreasonable animosity?
Ciphercoin brought him up, not Goat, who actually implied it was not Matt. (unless I misinterpreted it)

Valid point, well we know gox has been comprimised before them selling our emails wouldnt suprise me