Bitcoin Forum
May 25, 2024, 10:04:32 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 7 8 9 10 11 [12] 13 14 15 »
221  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] Tamagucci | Nostalgia | Scrypt |4 days POW | Proof Of Care rewards! on: July 05, 2015, 03:41:10 PM
can everyone get on to ccex to fix there wallet please

Same, waiting for 2 days for my deposit about 8k. Opened support ticket but no response from support.
222  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: July 05, 2015, 08:14:54 AM
Are they sold?

Hello,

they are reserved to buyer which wan't to come to pick them up. I will update the thread if any change...

Edit:

All 5 miners are Sold.

Thank You
nyo

223  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] AppleBytes - the cryptocurrency for the arts! on: July 02, 2015, 06:42:27 PM
is there no github for these?

no source released
224  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] Tamagucci | Nostalgia | Scrypt | ICO OVER | POW | Proof Of Care rewards! on: July 02, 2015, 03:34:11 PM
Huh

Code:
Total coins supply: 5.000.000
a 3.000.000 premine has taken place in the first 10 blocks.

source:
Code:
        if(nHeight == 1)
{
        nSubsidy = 30000000 * COIN; // 0.5 billion coins, that all pow coins
}

You are 100% CORRECT


This is a stupid typo, overlooked by me, OC and others that went trough the source.

Now, i already set this straight by burning 26.700.000 TAM to proven unspendable address T9yD14Nj9j7xAB4dbGeiX9h8unkKHxuWwb
See Earlz topic about this address. http://earlz.net/view/2014/10/22/0340/provably-spendable-altcoin-burn-addresses

It wont alter current supply in the source, but at least you know it's safe and burned!

TX id: c5842d66a5252f75297a44cda30122201799a4f65d8f4440816dd7f7ad8c1301

Remaining coins from premine:

750.000 Promo
1.500.000 PoC
1.050.000 ICO that is locked up for the next 7 days and will be burned to the same address.


Edit: Thanks for pointing that out. That's why open source exists.
Whoever found this typo, please PM your address, i'll give you a nice bounty for it.


Edit2



Thx, for burning them...
I'm still mining the coin.
Good Luck
225  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] Tamagucci | Nostalgia | Scrypt | ICO OVER | POW | Proof Of Care rewards! on: July 02, 2015, 02:54:27 PM
Huh

Code:
Total coins supply: 5.000.000
a 3.000.000 premine has taken place in the first 10 blocks.

source:
Code:
        if(nHeight == 1)
{
        nSubsidy = 30000000 * COIN; // 0.5 billion coins, that all pow coins
}
226  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: July 01, 2015, 09:41:10 PM
All 5 miners are reserved...

Thank You
nyo
227  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: July 01, 2015, 12:24:27 PM
How about shipping to Russia? I would consider to buy one...

Shipping to Russia by EMS 86Eur + You will pay tax in your country. Delivery time 7-10 days.
228  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN] Pharma [XPH] | Scrypt | Masternodes | Real team | Online store on: July 01, 2015, 10:34:45 AM
I was going to give exchanges a bit more time to react, but I don't want to sit on this longer than needed.

Link for the report at https://gist.githubusercontent.com/Earlz/41c5c18113210d3c36f9/raw/4d14022e3c75a6a10c653bd98831fd3bbded79a1/gistfile1.txt

TL;DR; Exploit, blockchain is completely ruined and unsalvageable. Devs used exploit to amplify their hashrate and mine all the blocks

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Exploit report:

Written by Jordan Earls (earlz, earlz.net), June 30th 2015, 9:20pm
Verify this message's signature by going to https://keybase.io/earlz

KNOWN COINS AFFECTED: Pharmacoin, Hexxcoin, MasterDOGE
(Note, just because a coin is affected does not mean the developer had any knowledge of this)

Pharma and thus all of it's forks have a LIVE EXPLOIT. Investigation continues as to what source code is responsible,
However. I can point to the side-effects of this exploit:

The PoW hash in Pharma is "distorted" to appear to be more powerful than it actually is.
It appears that the scrypt hash is generated correctly, but then modified seemingly unintentionally.
The end result is that this mangled hash is a higher difficulty than it actually is, thus making the entire
coin network have a higher difficulty than it really does.

A miner MUST take this into account when generating blocks on this network. A legit mining pool's blocks
will still be considered valid. However, a malicious miner can use this advantage and mine blocks that are much weaker,
and thus can basically have their hashrate amplified by a significant amount.

You can prove that a pool knowingly took part in this by taking it's PoW hash of a block it solved, shifting it left by 1 byte
and confirming that the block's PoW hash does not match the difficulty required for the network at that time

You can verify this by using this program: https://github.com/Earlz/hashchecker

See below for in-progress exploit details

litecoin:
Data used: 020000008F49E5FD7EF50DB9A2A1BFF5D3E93717A096329A8AC802A248463EF366CEEA1099B1FD0 D
B4CE8F4728251711F759081D0B5B4DA015FB78421D8FFBFDA1105A2ABDA1DB521B64101B00E60CD 0

true result:   000000000009183C881DEBBEAD806241A2467EB42BF4FBBFC988DC4045E91A46
wallet result: 000000000009183c881debbead806241a2467eb42bf4fbbfc988dc4045e91a46

pharma:
Data used: 07000000C29AB087984FC66B1333D0E7BFA44C901171CF8B609E8450C9C27C2F082BDBFD83D0919 A
75A7DB8E2DE73944F8C67B999014BD82EDDF3EB52FF1C28FEC4AB444B6B97655C261221BA9C0560 6

true result:   00000000203B7BC14DF5A74C09045BDC127C90FF7ED73C0C84C2AE4C21AC9A9B
wallet result: 0000000000203b7bc14df5a74c09045bdc127c90ff7ed73c0c84c2ae4c21ac9a


block info for relevant blocks used:

[earlz@earlztest2 src]$ ~/coins/litecoin/src/litecoin-cli getblock 65858117fadcff3b591ad4cbd320ecd3b0a63ffda1db9609822cf09ade790aa9
{
    "raw" : "020000008F49E5FD7EF50DB9A2A1BFF5D3E93717A096329A8AC802A248463EF366CEEA1099B1FD0 DB4CE8F4728251711F759081D0B5B4DA015FB78421D8FFBFDA1105A2ABDA1DB521B64101B00E60C D0",
    "powhash" : "000000000009183c881debbead806241a2467eb42bf4fbbfc988dc4045e91a46",
    "hash" : "65858117fadcff3b591ad4cbd320ecd3b0a63ffda1db9609822cf09ade790aa9",
    "confirmations" : 307648,
    "size" : 10184,
    "height" : 500000,
    "version" : 2,
    "merkleroot" : "2a5a10a1fdfb8f1d4278fb15a04d5b0b1d0859f711172528478fceb40dfdb199",
    "tx" : [
        "7290af5dd8bfebda2852c0949742b110cfcf8931c40ff5a5aac18329bcbf0540",
        "9b9047924ce1a690b90d38c922666baf18ea5259d26890193f5b7d3a9921b5a5"
    ],
    "time" : 1390125501,
    "nonce" : 3490506240,
    "bits" : "1b10641b",
    "difficulty" : 3998.22171415,
    "chainwork" : "0000000000000000000000000000000000000000000000000ccc596c88108dfb",
    "previousblockhash" : "10eace66f33e4648a202c88a9a3296a01737e9d3f5bfa1a2b90df57efde5498f",
    "nextblockhash" : "dd7c727ff0f5d825c3ce15d608dd63d48a41647369ba1afa79d5ae9760b8f209"
}
[earlz@earlztest2 src]$ popd
~/coins/pharma/src
[earlz@earlztest2 src]$ ./pharmad getinfo
{
    "version" : "v1.0.1.0-g32a928e",
    "protocolversion" : 60020,
    "walletversion" : 60000,
    "balance" : 0.00000000,
    "newmint" : 0.00000000,
    "stake" : 0.00000000,
    "blocks" : 64466,
    "timeoffset" : 37,
    "moneysupply" : 86631250.00916556,
    "connections" : 83,
    "proxy" : "",
    "ip" : "1XXX",
    "difficulty" : {
        "proof-of-work" : 2501.83885576,
        "proof-of-stake" : 10056110.06951050
    },
    "testnet" : false,
    "keypoololdest" : 1433727007,
    "keypoolsize" : 101,
    "paytxfee" : 0.00001000,
    "mininput" : 0.00000000,
    "errors" : ""
}
[earlz@earlztest2 src]$ ./pharmad getblockbynumber 6793
{
    "raw" : "07000000C29AB087984FC66B1333D0E7BFA44C901171CF8B609E8450C9C27C2F082BDBFD83D0919 A75A7DB8E2DE73944F8C67B999014BD82EDDF3EB52FF1C28FEC4AB444B6B97655C261221BA9C056 06",
    "hash" : "2eeb9ea9e31a3f2b3a4067416fc5a076f655e1bd65c84ca39430daabe9f1c7ab",
    "confirmations" : 57674,
    "size" : 212,
    "height" : 6793,
    "version" : 7,
    "merkleroot" : "44b44aec8fc2f12fb53edfed82bd1490997bc6f84439e72d8edba7759a91d083",
    "mint" : 10000.00000000,
    "time" : 1433844150,
    "nonce" : 106348713,
    "bits" : "1b2261c2",
    "difficulty" : 1906.09198269,
    "blocktrust" : "7721efe4c7a",
    "chaintrust" : "b7ff730dc5620f",
    "previousblockhash" : "fddb2b082f7cc2c950849e608bcf7111904ca4bfe7d033136bc64f9887b09ac2",
    "nextblockhash" : "8938068868ae0fc3eb441ae5ce9286571b17cf2c875b45cf90ec80bfd47887f1",
    "flags" : "proof-of-work",
    "proofhash" : "0000000000203b7bc14df5a74c09045bdc127c90ff7ed73c0c84c2ae4c21ac9a",
    "entropybit" : 1,
    "modifier" : "47d924eb1325e958",
    "tx" : [
        "44b44aec8fc2f12fb53edfed82bd1490997bc6f84439e72d8edba7759a91d083"
    ]
}

Code notes:

The exploit is somewhere in pbkdf2.cpp. Some unintuitive pointer arithmetic is done which appears to malform the resulting PoW hash.

A good comparison is to diff it against the version in Crave. I replaced this file with Crave's version and it compiles fine, but results in the wallet instantly failing because the genesis seed hash is no longer matching.

Output (line breaks added for clarity) when also printing out the genesis hash:

[earlz@earlztest2 src]$ ./pharmad -daemon
hash: 00000102617cecd8aeba57d393e295389b83ff81f223898240282757ad7cdf7e
pharmad: chainparams.cpp:111: CMainParams::CMainParams(): Assertion `hashGenesisBlock == uint256("0x0000000102617cecd8aeba57d393e295389b83ff81f223898240282757ad7cdf")' failed.
Aborted (core dumped)

For reference, here the hashes are aligned to see the obvious difference.
true hash:   0x00000102617cecd8aeba57d393e295389b83ff81f223898240282757ad7cdf7e
wallet hash: 0x0000000102617cecd8aeba57d393e295389b83ff81f223898240282757ad7cdf

How to check for this exploit in other coins:

Replace the pbkdf2.cpp file with Crave's version from https://raw.githubusercontent.com/industrialcoinmagic/crave/master/src/pbkdf2.cpp
If the blockchain syncs completely after doing this, then it should be safe.

Conclusion:

Honestly, this is the most elaborate exploit I've ever seen in the altcoin world.
The review for Pharma is of course now an invalidated F as well as for Hexxcoin because of this exploit.
I reviewed these coins and found nothing wrong initially because this exploit is so well hidden.
Measures will be taken in the future to verify PoW hashes, but I must remind everyone that my reviews are not 100% guarantees.
My reviews pick out the obvious problems and the simpler exploits. I spend about 1-2 hours per review.
Figuring out this exploit took more than 10 hours all together and I still can't point to the exact line of code that's the problem.
I will continue to strive to review the code in altcoins, but everyone needs to realize that the bad guys have the upper hand here.
-----BEGIN PGP SIGNATURE-----
Version: Keybase OpenPGP v2.0.14
Comment: https://keybase.io/crypto

wsFcBAABCgAGBQJVk5ElAAoJEAKXMK2l7Ra+OrQP+weHqq8m4aRSxnnWP+Hmqdhu
ImHjm2z86bsi8poV7wop5ZRxP0PamevjdnPpzCAWSc1NrnbNDOstN8VNlPpCiD4N
5/fE+pPqlMmy94CPUXgP3UsNsIS2lncQCNnPhou3DqQw5EtfihOiPR+UbPgrwH6t
w14/Avr17+Ceja9v6mbyOVEEKBtqofNQbSsKzUcmO7+1d72sWMc4AJRz/gWH9KOv
bUlBW9/1curZDvRbaiMDV32YTQyNJf6wEUHkhhL1z++Xy05l8pfHuGwMqJ0fGcD8
sk4Y7qD+4N9wfkwuoq8CSBNgkIQwftT0XJLvW22lWwwwY20FXCLChs5v1ZkkxepY
KbjFr/U4uAlDiJgHRNQfdVZrqMO86OLGdT6cFQ3q9N0Nt35acOZFvqw3w76Cgi0m
5IBCh8X2n1PVmwTPI9z3H5Qr2LqqfAkEkCP6Bi4GqtBHuMXoi3i6LWfhlOCVw0QE
slVBhD5sJbrLyt9qzwQczEatmus5PM1JoPeStB3AxkMcyoJnfURBlh0BEsn0YCbd
YCCnukiZagqWlgF+xxBhjeL7aXpggPaL4j9V8A9kVqSe0DHg5Hn7Qx0Srbfal5lF
ChFxjYm3NO5LXpw6kRYaxjz3x00SjGx54r8n+mEYlJ6Cfos4CgPssrV2Vh7H0Iss
V7qjrnEiGynE6+papfXd
=OCRf
-----END PGP SIGNATURE-----

Nice work earlz, thank you for pointing this out and for hashchecker...
229  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: July 01, 2015, 09:24:15 AM
How many KW for 88MHS?
Sorry

The Innosilicon A2 ASIC performance is 1.8MHs (+- 8% variation) per chip with average 13W power consumption. The Innosilicon A2 Terminator Official Miners is about 86.4Mhs (within 8% variation)per Machine with 750W power consumption at the wall in our testing.

If overclocked to ~95MH/s consumption is about 800W.

source:
http://www.innosilicon.com/A2.htm
230  Alternate cryptocurrencies / Altcoin Discussion / Re: [8BIT][Incoming Voting] Call for proposals on: June 30, 2015, 08:17:40 PM
MN COST: 888.00
BLOCK VALUE: 1.2
MN REWARD: random 0.80 to 0.96(if not possible, than 0.88)
231  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: June 30, 2015, 07:21:07 AM
USA Plz. :-)

Zip : 06484

Hello,
The cheapest shipping to USA, which I found is by EMS - 230Eur(per miner 17-18kg, really expensive...), and you need to add taxes to it. I think it's no way to send it to USA in good price.

Sorry about that.
nyo
232  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: June 30, 2015, 04:57:45 AM
Have you checked other shipping alternatives? DHL here is way more expensive than the national postal service (which also delivers across boarders).

Hello,
No problem,  I can check also another shipping methods after request.  About national postal in my country, last time i checked their limit was 10kg per package. (weird i know).  But i can check alternative courriers, just let me know the country guys.
233  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: June 29, 2015, 06:19:14 AM
Too bad these are not in the USA, or I'd be all over them.  Grin

Good luck with the sale.
Yes, too bad :-(... Expensive shipping and taxes.  Anyway good luck with finding miners :-)
234  Economy / Computer hardware / Re: [WTS] [EU Only] 5x A2 Innosilicon Terminator 88MH/s on: June 28, 2015, 06:31:10 PM
bump

since I listed my offer. Miners made for me another $2k - $1,2K to pocket after electr.bill(at todays rates of LTC), so I'm lowering the price to Eur 700, accepting also BTC or LTC.
235  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN]--[GOLDR]--GOLDRUSH COIN [Scrypt] 0% PREMINE COIN LAUNCHED PLEASE JOIN on: June 25, 2015, 12:32:25 PM
And the DOgebc, genesiscoin, peercoindark, uranus, aurum Dev strikes again, as expected:

https://github.com/GoldRushGOLDR/Gold-Rush_GOLDR/blob/master/src/net.cpp#L1159

https://github.com/GENESISCOIN/GENESISCOIN_SCRYPT/blob/master/src/net.cpp#L1159

This time he tried to obfuscate the walletbuilder node by editing this:

https://github.com/GoldRushGOLDR/Gold-Rush_GOLDR/blob/master/src/net.cpp#L1176


But the wallet won't sync without adding any nodes like this, so simply do this in the config:

addnode=node.walletbuilders.com

And you'll see.. the wallet will sync fine..

Nice try !
Ok, I'm out, thx OC Smiley
Good Luck, guys
236  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN]--[GOLDR]--GOLDRUSH COIN [Scrypt] 0% PREMINE Start Tomorrow Please Join on: June 25, 2015, 12:26:51 PM

it is compiled wallet downloaded from link dev posted.
237  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN]--[GOLDR]--GOLDRUSH COIN [Scrypt] 0% PREMINE Start Tomorrow Please Join on: June 25, 2015, 12:18:49 PM
my pool wallet

{
    "version" : 1000005,
    "protocolversion" : 70002,
    "walletversion" : 60000,
    "balance" : 0.00000000,
    "blocks" : 0,
    "timeoffset" : 0,
    "connections" : 0,
    "proxy" : "",
    "difficulty" : 0.00024414,
    "testnet" : false,
    "keypoololdest" : 1435234281,
    "keypoolsize" : 101,
    "paytxfee" : 0.00000000,
    "mininput" : 0.00001000,
    "errors" : ""
}



{
"version" : 1000005,
"protocolversion" : 70002,
"walletversion" : 60000,
"balance" : 0.00000000,
"blocks" : 360,
"timeoffset" : -2,
"connections" : 5,
"proxy" : "",
"difficulty" : 16.00000000,
"testnet" : false,
"keypoololdest" : 1435233994,
"keypoolsize" : 101,
"paytxfee" : 0.00000000,
"mininput" : 0.00001000,
"errors" : ""
}
238  Alternate cryptocurrencies / Altcoin Discussion / Re: [POLL] BitStake Multi-Stake Platform coin lising on: June 23, 2015, 05:10:44 PM
go sigu Smiley
239  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][SLR] SolarCoin | PoW to PoS v. 2.0 | Solar Proof of Generation (§1 = 1MWh) on: June 20, 2015, 05:41:15 AM
This is going to be mega pump :-).  Only 2btc to x10 price
240  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][SLR] SolarCoin | PoW to PoS v. 2.0 | Solar Proof of Generation (§1 = 1MWh) on: June 18, 2015, 07:54:05 PM
Dear All,

Had a couple of good meetings with some solar manufacturers this past week at the InterSolar in Munich, Germany http://www.intersolar.de/en/home.html

These companies could eventually be accepting SLR for payment for their products. Datalogger companies are interested in monitoring the amount of SLR produced from household installations.

Specialised solar Magazines are still dubious of the BitCoin Business Model (?) but are now aware of the existence of SLR...

Keep in mind : 6.000.000 households already have solar panels on their roof across the world : This is our target market.

Regs,

SunnyBoy



Great news, bright future Smiley
Pages: « 1 2 3 4 5 6 7 8 9 10 11 [12] 13 14 15 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!