Bitcoin Forum
June 25, 2024, 02:27:50 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 ... 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 [117] 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 »
2321  Bitcoin / Project Development / Re: Secure Bitcoin Using Existing "tanJack" Device for Online Banking! on: August 17, 2011, 05:20:01 PM
Why don't we as the bitcoin community group invest in bio-metric scanning devices for bitcoin clients Cheesy then mass produce. Everyone that was involved in the project gets a piece Cheesy
2322  Bitcoin / Project Development / Re: Secure Bitcoin Using Existing "tanJack" Device for Online Banking! on: August 17, 2011, 04:14:39 PM
lol at first I was like wtf does flashing boxes and typing in the code help security but I read a little bit more and yes if we have a way for bitcoin clients to be set so nothing is sent with out an external device. I would probubly buy into this actually. This sounds very safe.
2323  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] Hack my site Aug, 17th on: August 17, 2011, 04:10:25 PM
Okay everything should be operational doing some last minute touches on product reviews and rating system. Hack-A-Thon will begin at 12PST and I'll PM everyone when its ready to start

*Edit: I meant to put everything should be operation except for the forgot password because it involved mail and getting mail to send and receive is like the devil trying to get to heaven(It can happen but its going to take a lot of work! PUN INTENDED)

*Update:
I will be setting the cost of all the products to about .01 BTC this way testers can try out the shopping cart system and see if there are any vulnerabilities in that.
There is a Store Credit section in the account details if you want your BTC back just type in your return address and press the "Request Refund" button and I'll send you your "Store Credit" back. It will tell you "Please allow 2-3 days for your refund." This won't be true during testing times I'll send it back to you as soon as I see the request but shouldn't be a big deal how soon you receive it since were dealing with .01BTC's here.

Tip:Looking for security flaws and bugs.


(It willl be another 2 more hours from 12:31PM PST I just realized i didn't patch up somthing)
2324  Economy / Services / Re: 1BTC to assist me with sending/recieving email on my ubuntu server on: August 16, 2011, 11:35:59 PM
Thanks Imma try all your responses and see what happens.

And yea defiantly not running off my home computer it is a Cloud Hosting type server
2325  Economy / Speculation / Re: Are we about to witness something epic? on: August 16, 2011, 11:05:58 PM
I wouldn't mind a gradual increase of $1/week in the price. Keeps things running smoothly. The difficulty drop may be the harbinger of future price increases - based on the last time that happened.

Watching the charts...
A $1 every 2 weeks would be even better. Slow and steady is the way to go if we ever want this "experiment" to work, and turn into a viable currency.

if it did go up slow and steady, after a while It would start to look like a safe investment, and the speculators would be all over it, driving the price up , which would cause panic buying Grin then eventually the surge runs out of steam... oh no!  SELL! SELL! SELL!

is that pattern even avoidable?

Afraid not, bitcoin follows the swings generated by it's milestones good and bad. We haven't even reached V1 yet of the client, so there's a lot to happen yet. Also a few million is very little of a unit to have in circulation, any relatively small movement on an international scale can have a massive impact on price. It will be a long, long while until the price settles in to an equilibrium if ever, as bitcoin has behaved more like a commodity than a currency due to it's scarceness. Currencies fluctuate mildly(on the macro scale at least) just on the basis of their vast quantities in circulation.
Thank you for explaining this as I have been trying to tell my friends for weeks why Bitcoin is going to have a hard time catching on as a "currency". Regardless it's an awesome commodity which does have it's own value.
We all know Gold was a commodity when they first found that stuff Wink
2326  Economy / Services / Re: 1BTC to assist me with sending/recieving email on my ubuntu server on: August 16, 2011, 09:22:57 PM
Post fix is the issue. I don't understand why it won't pick up on my domain name. All my emails get sent back to me.
2327  Economy / Services / [CLOSED] 1BTC to assist me with sending/recieving email on my ubuntu server on: August 16, 2011, 08:18:31 PM
1BTC if you can assist me in installing sending and receiving emails when somebody sends an email to my domain name.
Not through SSH just give me the steps through skype or something instant. I've attempted my self many times and failed.
I have squirrel mail installed and I'd like to get that working with it as well I believe I read that there is an extra step for that I'll pay 0.5BTC to help get squirrel mail installed.
2328  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] Hack my site Aug, 17th on: August 16, 2011, 07:54:04 PM
Forgotten password won't be available for testing tomorrow. I'm still trying to figure out how to get mail to send correctly. As well as set up the receiving end
2329  Other / Off-topic / Re: What game should i point my miner to? on: August 15, 2011, 05:19:22 PM
Black Ops or MAss Effect 1/2/3

Mass Effect 3 is out? Are you from the future?

Speakaing of mass effect... I still need to beat 1 as when i actually owned the game(I lost it) i only got up to a few chapters in until my old video card froze up at this one part Sad Man i have alot of catching up to do.....

How can you have played Mass Effect 2 without having finished Mass Effect 1? That must be punishable by law or something. I like importing my character from ME1 into ME2 and following the history. In ME2 they were kind of limited on the paths available because it was the middle of the trilogy, but they have said in ME3 the decissions you took in ME1 and ME2 will have a big impact in how the game ends.

I haven't played ME2 yet i was just saying i need to catch up becuase im soo behind
2330  Other / Off-topic / Re: What game should i point my miner to? on: August 15, 2011, 06:16:29 AM
Black Ops or MAss Effect 1/2/3

Mass Effect 3 is out? Are you from the future?

Speakaing of mass effect... I still need to beat 1 as when i actually owned the game(I lost it) i only got up to a few chapters in until my old video card froze up at this one part Sad Man i have alot of catching up to do.....
2331  Other / Off-topic / Re: What game should i point my miner to? on: August 15, 2011, 04:10:12 AM
BORDERLANDS!
That reminds me i still need to beat that game.... darn scally-wags (aka scags)
2332  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] I <3 lamp! on: August 14, 2011, 05:18:10 PM
Edited OP for payment details I've decided.
2333  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 14, 2011, 05:09:55 PM
Start Date: August 17th
12 in the afternoon PST.

Use this thread to report bugs. Smiley
2334  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 14, 2011, 12:52:11 PM
Thanks for the bounty!  Glad I could help!

Send me another PM if you need some more help with this....but once you understand it, it's simple to fix...albeit tedious since you have to examine and fix every form post and action URL your users have access to.

Thankfully I only have a few forms most of which everything required a #id number so they were semi safe if the attacker could guess the #id number of the shopping cart they wanted to control but I did have to do some token work on account details so packages won't get shipped in the wrong place Wink
2335  Bitcoin / Bitcoin Discussion / Re: How helpfull would it be to shoot a bitcoin block chain up into deep space? on: August 13, 2011, 08:01:24 PM
You have no idea how much your answers have helped Cheesy thank you all Wink
2336  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 13, 2011, 04:11:51 PM
The link not necessarily has to be on your site...because we all use these forums, I could put a link on the forum..and if someone is logged into your site when they click the link I post here...they can get goxed if your site isn't xsrf safe..

Or, I could post an image here...but the image isnt an image, but a URL instead.  The image will look broken, but as soon as the person's browser tries to fetch it, they trigger the URL with the xsrf...no need to click on a link at all.

That's why its dangerous....cuz the attack doesn't have to come from your site...the user just needs to be logged in to your site.





wow!? This is a crazy type of attack, I must get back to work Wink
2337  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 13, 2011, 03:24:11 PM
And that's why XSRF is so dangerous because it's it's not intuitive how they work.

You will have to take special care to avoid them.

If a user is logged into my site and your site at the same time, I can get your user to perform any action I want if you're not protected.

A common way to prevent this type of attack is to include a hidden form field in your forms that includes a random token.  Also save this token as a HttpOnly cookie.  When you process the POST response, check that the hidden form field token equals the token set in the user's cookie.  You can also save the token in a database instead of a cookie if you prefer that route.

Some say that simply checking the referrer can stop this attack, but referrer can be spoofed and some secure browsing modes don't send a referrer at all.

It's hard to find good information on this topic..most of it just seems too nerdy and unnecessary because this attack isn't used much....but if there is a hole..especially in a bitcoin related site, you can guarantee someone will find it.

This is somewhat of a good article...but even if you read the comments, some people still don't get it....XSRF isn't XSS at all.  http://www.codinghorror.com/blog/2008/09/cross-site-request-forgeries-and-you.html





Thanks for this very informative article, I will be researching it to the line, It's crazy the things people come up with to hack something. Cheesy

Edit so As long as I don't allow any links to other websites I'm thinking I should be good.
2338  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 13, 2011, 01:08:46 PM
Smiley  How's your site coming along anyway?

I just finished patching my XSRF holes Kokjo was kind enough to rub in my face.  Smiley  Don't forget those!  They can be nasty buggers!  Even nastier than a XSS bug because the danger is subtle and may not even be obvious at first.

Wow haven't heard of those attacks yet, I'm not entirely sure I'm covered but the measure I have taken before reading about that kind of attack is this.
I sha512 hash the cookie authentication similar to mining farm except I have removed the annoying 30 minute session limit that was in mining farm you can browse as long as your active for up to an hour of inactivity. I'm hoping that should be enough. I'll give you guys a hint on the frame work for the hashing value.....
Quote
user_ip_address.randomly_generated_secret.user_unhashed_password.auto_updating_ expiration_timestamp

Pseudo code looks something like this
Quote
$CookieIp.$CookieSecret.$Password.$ExpireTimestamp

At the time of writing this, I'm finishing up the last touch and that is user reviews. I hope to start the hack-a-thon on Monday, 15th of August. Cheesy

Edit: all this got me thinking, I'm rewriting the login code to constantly randomly generate a "secret" every-time a page is refreshed just to make it super extra session-hijacking safe

Edit2: I think I'll give some more hints to the people: I have changed my root MySql user name that mysql runs on(wont disclose what the username is) and I have the actual website running through a jailed user, there is no phpMyAdmin(to prevent bruteforce attacks on that), and I've changed my root user name login through SSH. I think I got everything covered as far as securing the actual box, I hope some hackers can prove me wrong Wink
2339  Bitcoin / Project Development / Re: [Scheduled Hack-A-Thon] RSVP Here to have a hack at my upcomming website. on: August 13, 2011, 12:12:47 PM
I'm just waiting for the day I find someone to hack who has one of those 3D printers.  I'd hack it and program it to make a zombie robot and have it attack the guy while he's sleeping and steal his mining rigs and all his bitcoinz!


A glimspse t future hacking endevours....
Hide yo bitcoins,hide yo wife.... Run and tell that, run and tell that, home boy ,'home boy
2340  Bitcoin / Bitcoin Discussion / Re: The most convincing information about Bitcoin to bring in friends on: August 13, 2011, 05:54:48 AM
speaking soley for myself,

i wouldnt try to bring on friends at this point....BTC is, IMO, still waaaaay to risky to try to convince friends and family to sink their hard earned cash into...ive had a couple of friends ask about it (they caught me staring at the charts) and ive explained it to them in round about terms, but thats as far as it goes.

there are better investments for loved ones to put their cash into IMO...i just dont feel safe at this point reccomending BTC to anyone who hasnt done thier due dilligence in research and/or is naive or unaware of the extreme risk involved with investing in BTC....

that said, if someone does do the research and decides to invest, i certainly wouldnt discourage them...but for now, im not trying to bring new people on until BTC's growing pains have settled out a bit.
 

That is a very good point, I've never thought over overly convincing a family member or a friend to have the urge to invest in to it. especially with out knowning the possible consequences of it all
Pages: « 1 ... 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 [117] 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!