Bitcoin Forum
May 29, 2024, 08:38:55 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Alternate cryptocurrencies / Announcements (Altcoins) / Re: [ANN][DRK] DarkCoin | First Anonymous Coin | First X11 | First DGW | ASIC Resistant on: May 28, 2014, 04:08:22 AM
It appears there is someone that is pulling all the masternodes from the wallet and running scripts on them to hack in.
Is this a surprise?

And in this case they was able to gain access via SSH, so it had nothing to do with problems in the wallet/daemon/masternode itself.
As suspected.

  • The firewall was not running, so all ports were open
  • Root access via SSH was allowed
  • OpenSSL v1.0.1f was installed on the server
  • The password to unlock the wallet was still in bash history command
  • The root password was less than 8 characters
As suspected.

My recommendations:
  • DO NOT allow root ssh access
  • Only open port 9999 in your firewall to the world
  • Only open port 22 (SSH) to a trusted ip
  • Setup SSH to use certificates for logging in
  • Do not run any application on the server that you dont have to
  • Encrypt you wallet
  • Clear your bash history

All common sense... It worries me that a rote list is being handed out. These are things a person should know if they're going to support the network...

If a person doesn't know this much already, they have no business running any server on the internet, much less a masternode. Following some rote guide line by line will only give them a false sense of security and no ability to handle the future.

Frankly, I'd prefer all ports but 9999 and TOR Listen be secured by port knocking. Re-direct all externally accessible services through TOR so that they only listen to localhost and no known .onion exists for those services to anyone but yourself. Since TOR uses renzdezvous points, the TOR port being open grants them access to none of the services passing through it, and no idea what the traffic is, where it goes, what it's for, etc... They can't protscan a port that doesn't exist. SOCKS5 stream for the win. Using TOR for this has massive advantages completely removed from it's anonymity/encryption/obfuscation functions.

I re-route all my SSH through TOR. SSHD doesn't even listen to the NIC, localhost only. Also, the entire SSHD service is port knocked to trigger "service sshd start" on top of not even listening to the NIC... Run knock sequence then ssh through socat .onion... Nobody even knows it's there... Nobody knows the address but me. Logs can't even give me away since I'm coming in through tor... If only DPR had used his head... ;-)

his wallet address is XhGwaKJPMdqEyMU85QBReNNMzVGKDW2EPz

He learned the HARDWAY how not to setup your masternode. I will be putting together a list of things to check and an ISO and AMI for people to use with MOST of the issue addressed, you will still be responsible for checking any think I missed and verify it works for your setup.

His lose WILL help everyone else by showing what you MUST setup so please help him where you can. I will pull some together myself to send.

Pain is an excellent teacher. A smart man learns from his mistakes. A wise man learns from the mistakes of others. If you don't know what you're doing; don't!

It's sad and all, but I'm not sending him any welfare. I want him to learn. Let it hurt... Call me a meany poopie face if you want, but this was super extreme stupid. No excuse at all. If you don't know what youo're doing; don't. There is no guide that can teach you common sense. You MUST understand. There is no substitute.


Thats the way to do it!  Cool
2  Alternate cryptocurrencies / Altcoin Discussion / Re: WTF THIS GUYS ARE STEALING LIKE MOTHERFUCKERS ! on: March 24, 2014, 07:24:50 AM
Serious question to senior members. Mazacoin seems like a good project. Is it possible to do a community takeover of it and block/invalidate the premined addresses?

No
To block/invalidate any addresses goes against the whole idea of "Bitcoin" and related projects.

Interesting concept though. If 50% of the network forced a copy of the wrong blockchain to destroy the early coins or adopted a community driven maza that started with the block right after the premine what would  that do? Like copy the source and start the block count later and have everyone synch with that instaead of the original maza client?
3  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 19, 2014, 07:56:22 AM
11 Million Mazacoin were transferred out of the "Oglala Lakota National MazaCoin Reserve" yesterday. 

Here's the page that lists the address:
http://mazacoin.org/about.html

Here's the block explorer for the National Reserve's address:
http://explorer.mazacoin.org/address/MNG15HKzUQeiT8QmtAghvSKpQwwgzZSFzS


That's for food, education and dental work for 10 Little Indians.   Cheesy

Interesting. I wonder what Payu had to say at the meetup yesterday in Silicon Valley...
http://www.meetup.com/Silicon-Valley-Bitcoin-Users/events/165612122/
4  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 18, 2014, 01:15:49 AM
http://rapidcityjournal.com/news/local/ost-s-brewer-co-chairs-indian-health-service-budget-committee/article_056f12db-30bb-54fd-a679-40e828e7b22b.html

This guy is said to have undermined the project. Look where it got him.
5  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 16, 2014, 12:02:39 PM
@c3ntrx

Fair enough. There is a chance he's legit.

However, how do you explain the FB accusations regarding his previous fundraisers. Other natives have openly called him a scammer. He didn't bother debunking such claims.

Herp, I never said he came off to me as not a scammer, fact I must say he came off as a true hustler (and he even admitted it!). Fact is  right now Payu has the worlds attention. Yes he can do a Bernie Madoff and we will all be out some btc, no big deal...

Right now Payu is probably the most powerful Indian in his nation. He can step up and become a Leader of his people. I see that in him. I fully support him doing this. I hope he realizes this coin is just a small step in the direction he could take his nation and hope greed does not hinder the height in which things could go.

That being said I am buying some more. Dont let me down Payu, you can make history.

>he appears to be a scammer
>he admits to being a hustler
>i'm buying more!
>5 posts on account

pt barnum's quote needs to be updated. there's a sucker born every second.

My bad. I just have Balls of Steel unlike those that dumped. I'll ride a longshot. I killed it with Doge ;p
6  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 16, 2014, 08:33:42 AM
How many of the Lakota people are actually mining these coins though? The answer to this question is the first and most obvious sign of where this coin is actually heading. A coin can't be the sovereign currency of a tribe if no one in the tribe holds even a single piece.

Who knows,

maybe they will give them out or bankroll a casino.

He stated he wanted to use the coins publicly for the community.

I guess time will show Payu for what he is. Hopefully he can lead his people. Though he told me most of his people lost the ambition to hustle for themselves.
7  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 16, 2014, 06:33:03 AM
@c3ntrx

Fair enough. There is a chance he's legit.

However, how do you explain the FB accusations regarding his previous fundraisers. Other natives have openly called him a scammer. He didn't bother debunking such claims.

Herp, I never said he came off to me as not a scammer, fact I must say he came off as a true hustler (and he even admitted it!). Fact is  right now Payu has the worlds attention. Yes he can do a Bernie Madoff and we will all be out some btc, no big deal...

Right now Payu is probably the most powerful Indian in his nation. He can step up and become a Leader of his people. I see that in him. I fully support him doing this. I hope he realizes this coin is just a small step in the direction he could take his nation and hope greed does not hinder the height in which things could go.

That being said I am buying some more. Dont let me down Payu, you can make history.
8  Alternate cryptocurrencies / Altcoin Discussion / Re: Did Max Keiser Abandon Maxcoin? Explain to me like I'm Five! :p on: March 15, 2014, 02:44:53 PM
I'll admit I got MaxCoin wrong. The lack of Max Keiser saying anything about it for awhile seems pretty clear to me.  Embarrassed

He mentioned it on his twitter 2 hours ago
https://twitter.com/maxkeiser
9  Alternate cryptocurrencies / Announcements (Altcoins) / Re: Mazacoin ** FAKE Sovereign Currency ** on: March 15, 2014, 02:31:05 PM
can we put this scamming pos in jail for life???

I met Payu at Bitcoin Center in New York. He gave me a paper wallet for $100. I went home and couldnt import the keys. The next morning I saw he emailed me. He said anyone with problems importing just send him the last 4 of the public and he'd transfer it to the exchange. I sent him my wallet address and you know what, the man kept his word and next time I checked there were coins.

Yeah I bought a sh*tload more, yeah I lost money - so far.

Payu kept his word which means alot. Whether he pulls this off or not who knows. Ive met alot of con men in my time and yes Payu does have some of those traits (sorry bud) however I have never met a shrewd businessman that didnt have a good game.

He gave me his personal info, phone etc, howevver I will not throw him under the bus or to the wolves here. Fact is I think I may pick up more coin now that its cheap again.

I'm a good judge of character, I do believe Payu has his head in the right place. Worse case scenario you made an indian a millionaire. Didn't he deserve it though, the hustle, the ingenuity? I think a man like that deserves more credibility than you are giving here. This guy is fighting lots of roadblocks and instead of bashing him we should give him the support of the community. I mean lets call a spade a spade, bitcoin would have never taken off unless the shadows gave it momentum.
10  Alternate cryptocurrencies / Altcoin Discussion / Re: The True Value of Auroracoin on: March 05, 2014, 08:14:05 AM
As kennitala (personal identification) is publicly available in Iceland it will take more than submitting this reference to claim your free coins. I really can't grasp how the developers can achieve this. Are they going to accept any IP address from that region that submits a valid kennitala? If so, I will be booking a flight to Iceland soon and will be rich.

I also wonder this, does anyone know? How does the dev guarantee, using a public database, someone is really who they say they are?

They don't care because it is a SCAM!

MAZA is WORSE!

I met the developer for MAZA last night. Yes he was a real Indian. He spoke at Bitcoin Center New York City. Later he sold me a paper wallet of 10,000 coins for $100 cash. Having a hard time transferring the keys to my linux QT wallet he wrote me the next day and I sent him my address and he sent me what was then worth $1000 (cuz it jumped 10x overnight)

Not everyone is in this to scam people. Some of us actually are trying to change the world. If you cant afford the game or cant afford losing once in a while you shouldnt play. Whether or not Aurora is a scam I cannot say. I would like to know as well but in the meantime I choose to play.
11  Other / Beginners & Help / Compiling on Debian Systems....please promote me! on: January 11, 2014, 08:12:56 AM
So Ive managed to compile alot of different wallets and each one has there little tricks. I noticed that the Qt Creator sometimes doesnt do well but after running make -f makefile.unix from the git the qt creator is then able to usually complete the gui build.

Im kinda new to this coin thing but def not a newb. Can someone please promote me!

Lol.

C.E.O.
Centrix Systems
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!