Bitcoin Forum
September 02, 2024, 07:04:38 AM *
News: Latest Bitcoin Core release: 27.1 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Bitcoin / Pools / Re: CEX.IO "hacked"........? on: January 16, 2014, 09:06:36 PM
Was just logged in to cex.io chat and got 2 javascript alerts minutes apart with simply the text "1".

I logged back in a few minutes later to investigate, and discovered this in the "russian" tab of their chat window:

Code:
z66 : 20:25
“><img src="#" onerror="alert(1)"
Ramirez : 20:26
><img src="#" onerror="alert(1)"
Ramirez : 20:26
doesnt work
kickbit : 20:27
xe2x80x9c><img src="#" onerror="alert(1)"
Ramirez : 20:28
-->
Ramirez : 20:29
->

They have been alerted via twitter by others that noticed the problem too:
https://twitter.com/chrisfarms/status/423913046512128001
https://twitter.com/vvedma/status/423920180750610432

As a professional web developer, this is deeply concerning.

I am not sure that this is necessarily related to people having their accounts cleaned out, but it is certainly something to consider regardless as a "possibility".  Anyone who has studied computer information security knows how serious the potential for an XSS attack is, and it certainly should not be taken lightly.

You are free to draw your own conclusions, but personally I withdrew all my BTC from there a while ago.
2  Economy / Service Announcements / Re: BitcoinWisdom.com - Live Bitcoin/LiteCoin Charts on: December 27, 2013, 03:21:38 PM
I understand why you had the Android app removed, but can you please re-enable scripts to work on mobile phones now?  I've used BitcoinWisdom.com in my iPhone's browser for a long time now, and I was disappointed to see that it suddenly stopped working on my phone and I'm guessing it has something to do with this "unauthorized app" stuff because it was working, then I saw a message / warning about "no official apps" and then it just stopped working all together.
3  Bitcoin / Project Development / Price alerts, miners tools, and more: MinersDashboard.com on: December 18, 2013, 01:00:28 AM
I just released a site that I have big plans for, called MinersDashboard.com

Currently, the only real feature is the ability to set low/high alerts on various exchanges (with CEX.io and cloud hashing prices being listed first).  I built the site because I couldn't find a tool that did this specifically with CEX.io, and I figured adding a few more exchanges and features could make it a really useful tool.  I'm open to help if you're interested (currently building the site with Rails 4 + Bootstrap 3 + AngularJS), just send me a message (or BTC - 15j5umUGjhKdqE4QaC5vxhqLauF5rWexz9 ).

Current functionality:

  • Alerts: Click on an exchange to reveal the "alert thresholds" section.  Set your low and high alerts for the exchange, click close, and once your alert is hit, a sound will play to let you know!  (a "ding" for low, a "glass crash" sound for the high alert)  See screenshot for example:


A few things I have planned:

  • Charts: I'm trying not to reinvent the wheel here (hence the reason for embedding bitcoinwisdom in an iframe), but for CEX for example, new / improved charts are needed and bitcoinwisdom doesn't support their data yet.
  • Buy/Sell Tools: I want to create some dead simple "quick sell" tools that both miners and traders can use to do simple things that surprisingly few exchanges do (like a button to populate amount to purchase based on set price and current balance).
  • Offline Alerts Ability to send emails to yourself using current set alerts
  • Wallet Balances Ability to track / view wallet balances quickly in one place
  • Pool/Miner Feeds Aggregate data from pool API to display current works/mining speeds/stats
  • Hardware Providers/Prices Deals and new hardware being released to the market
  • BitCoin News News and views about BitCoin to stay up to date on the news affecting BTC prices
  • Games A tab to play some HTML5 games, because who doesn't want to play games and have a ticker on the top to ensure you never miss out on any of the latest swings!
4  Other / Beginners & Help / Mt. Gox withdrawals. on: November 18, 2013, 01:12:06 AM
Since apparently "new users" are considered second rate citizens, even though there is a perfectly applicable post where it would be pertinent for me to post - https://bitcointalk.org/index.php?topic=324918.0 , I must relegate myself to "noobishly" duplicating a topic that's already been created elsewhere, because yah that makes sense.  Anyways, no guy at the end of that topic, you aren't the only one.  I have a pending BTC withdrawal from Mt. Gox and am absolutely horrified to come across this thread. 
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!