Bitcoin Forum
June 21, 2024, 03:05:14 PM *
News: Voting for pizza day contest
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1] 2 3 »
1  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 11, 2014, 02:47:16 AM
I did finally find a test that points out there could be an issue.   https://lastpass.com/heartbleed/?h=btc-arbs.com    Recommended that you don't change your password until it is patched.    
Glad to hear that you found that.  Now you see that we're not just "whipping up the fear".  Cheesy

You don't even know if they had any version of openSSL 1.01 ... most sites don't.
I think I read that 59% of sites use OpenSSL, but I don't know about 1.01.  I hope that it hasn't been exploited this whole time.

EDIT: according to Wikipedia, 17% of secure servers are/were vulnerable.  That's a lot.
2  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 10, 2014, 11:45:54 PM
That page says "btc-arbs.com IS VULNERABLE. " ?

No it is fine.  That test can give a false positive when load is high.
What are you talking about? It gives part of the memory as proof :s


Just to be clear: anyone using BTC-arbs last few days should be very careful. An attacker can steal user's cookies/password as long as btc-arbs.com has this OpenSSL vulnerability. I recommend to not use this site until this vulnerability is fixed.

And well, obviously I recommend to not use them at all since months already but yeh. Will be perfect end for ponzi too "ah shit, got hacked".

What?  Now you are just spreading FUD!  
Why? With this vulnerability attackers can get ~64KB of random data from the memory, and an attacker can keep doing this to get more memory data. In the memory data there can be sessions IDs of users so the attacker can take over their session and for example do a BTC withdrawal. This is widely documented already, for example: https://www.mattslifebytes.com/?p=533 , https://www.michael-p-davis.com/using-heartbleed-for-hijacking-user-sessions/ , etc. and the scripts for it are pretty easy to find too.

Do you really enjoy people losing their money or something? I am just trying to warn people for a serious security vulnerability :\

Where is your proof that BTC-arbs is open to this vulnerability?    The test site used early in this thread cleared the site.   This is only a problem with unpatched openSSL 1.01.   In the meantime you are just whipping up the fear you have been trying since the beginning of this thread.   


Heartbleed could end up having a HUGE IMPACT on the internet.  And it's not just 1.01, it's 1.01-1.01f.  This has been around for about two years, and it could have been exploited during that whole time.  64kb of data times many requests can get you a lot of info. 

If you don't know anything about Heartbleed, you should read about it at http://heartbleed.com/.  The worst case scenario is not hackers just stealing usernames and passwords, but acquiring the encryption keys and being able to read ALL the traffic between the server and users (including in the past) and being able to impersonate the server at will. 

I checked BTC Arbs on http://filippo.io/Heartbleed/ and with Chromebleed Checker at the time of my post about it, and they both said it was vulnerable.  Rechecking now says that it's okay, so BTC Arbs must have fixed it.  Although BTC Arbs mentioned Heartbleed in the reports, they didn't say anything about their own vulnerability.  They are just reminding everyone about 2FA (isn't that vulnerable to Heartbleed anyway?). 

It doesn't look like they revoked the certificate, so they haven't gone that far in patching the vulnerability.
3  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 10, 2014, 02:55:41 AM
Does someone else want to ask them about fixing Heartbleed?  I'd do it, but I don't know how to properly keep track of the certs and see how/if they would fix it. 
4  Economy / Gambling / Re: XBTcontracts.org - Speculate to accumilate. on: April 09, 2014, 01:27:40 AM
EDIT : one more thing to fix - log in will be enabled once I have made the fix and i will remove this edit.
And you're still fixing this?
5  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 09, 2014, 01:13:40 AM
It looks like BTC Arbs is vulnerable to Heartbleed, let's watch if they fix this or not. 
6  Economy / Gambling / Re: SATOSHIGEM.COM | Real-time puzzle multiplayer | 10000% JACKPOTS | LARGE BETS on: April 09, 2014, 01:01:47 AM
I was going to check if you guys are vulnerable to Heartbleed, but then realized that you don't have encryption.  That is something you should defiantly have, especially with logins and for withdrawing. 


Maybe some kind of referral link program would be good?
I agree.  Maybe some of the house edge from their games?
7  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 07, 2014, 03:13:14 AM
Friend tried to do a withdrawal and site would not allow her in...any scamming yet?

Just logged in without a problem, however the yield over the last 3 days has been less than what I'm making from mining.   :-(


I logged in and initiated a withdrawal successfully.  It hasn't come through yet, but it usually takes a while.
8  Economy / Gambling / Re: XBTcontracts.org - Speculate to accumilate. on: April 06, 2014, 05:31:50 PM
Okay, the counter is fixed, but now the going to the login page gives an error.

EDIT: it is working now.
9  Economy / Gambling / Re: What are YOUR Most Loved Gambling Sites? on: April 06, 2014, 02:23:20 AM
My favorite now is SatoshiGem.  It's not really gambling, it's a skill (and luck) based game with pvp.  You can play against others for btc.
10  Economy / Trading Discussion / Re: [ANN] [UPDATED] coins.ml Free market prediction service on: April 06, 2014, 01:02:50 AM
Site not working for me either, Chrome takes a long time and then gives me "Oops! Google Chrome could not connect to coins.ml". 
11  Economy / Gambling / Re: XBTcontracts.org - Speculate to accumilate. on: April 06, 2014, 12:56:04 AM
Something is wrong:

Quote
-760,013.8606 BTC until Contract 0 Completes.

Did the contract complete?  My level was raised.
12  Economy / Gambling / Re: SATOSHIGEM.COM | Real-time puzzle multiplayer | 10000% JACKPOTS | LARGE BETS on: April 05, 2014, 11:26:12 PM
@Bit-Gods Thanks we do our best  Cheesy

Allright guys, we need feedback on the subject of guest gameplay.

When guest enters the game, we created temporary account (with random username & 2000GEMs). Our aim is to show him the possibilities of SatoshiGem, AI for start and PvP (which is quite unique on the market). Do you think we should allow to play guest with registered users for GEMs? Do you have anything against it? Smiley


I don't see how that could be bad, so it sounds fine to me!  Or it might be better to get them to sign up if they want to play with other people.
13  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 05, 2014, 02:01:08 AM
ok, so you realize btc-arbs is a HYIP? right? have to start there at least.

Maybe it is a HYIP maybe it's Arbitrage. That is what we'r trying to find out here.

BTC Arbs IS a High Yield Investment Program no matter what you think of it - you are promised a LOT of interest for what you put in.  HYIPs can be legit.  What we're talking about is if BTC Arbs really does arbitrage to get profits or is just a ponzi.

This is really a small technicality, but I thought I'd point it out.
14  Economy / Gambling / Re: SATOSHIGEM.COM | Real-time puzzle multiplayer | 10000% JACKPOTS | LARGE BETS on: April 04, 2014, 10:09:03 PM
The Tournaments section isn't working.

EDIT: now it is.  Smiley
15  Economy / Gambling / Re: [ANN] Blockchain-reaction.com | 100% Skill based | Win BTC | Multi-player on: April 04, 2014, 03:19:45 AM
A bit complicated for me today and if I entered the game now I will be slaughtered by experienced players
I don't mean to thread-jack, but as there are other people who think this is too confusing I want to share something I found recently.  There's a new game that you can play with Bitcoin (or Litecoin, Dogecoin, Earthcoin, or just for free) called SatoshiGem.  It's a LOT easier to understand and play than Blockchain-Reaction(it's basically candy crush).

There's multiplayer pvp and tournaments, and the only problem with this site right now is that there aren't enough people.  Let's change that!

The website is www.satoshigem.com and the forum post is at https://bitcointalk.org/index.php?topic=555362.msg6062104#msg6062104
16  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 04, 2014, 03:00:27 AM
---snip---

From   administrator
Sent on   April 02nd 2014
I believe the forgot password function does work, just some people have email accounts that send our messages to their spam folder.

Regardless... this is the Bitcoin industry, if people aren't bright enough to remember their passwords, Bitcoin is something they should probably stay away from.


---snip---

Is that a new letter you got back?  Kind of confusing when you just edit a quote without any other information...
17  Economy / Gambling / Re: XBTcontracts.org - Speculate to accumilate. on: April 04, 2014, 01:53:48 AM
Although I don't comment much in this forum I thought I would come in on this thread to say that I have deposited and withdrawn a profit from XBTcontracts already. Smiley

The thing is that nobody will believe a new user with just 10 posts.  Sorry! 
18  Economy / Gambling / Re: SATOSHIGEM.COM | Real-time puzzle multiplayer | 10000% JACKPOTS | LARGE BETS on: April 04, 2014, 01:22:29 AM
I just want to tell everyone that this website looks and feels fantastic.  It has the promise to be a great site for people to play with each other!  The most important thing for this website right now is MORE PEOPLE.  

Give this a try!  You do have to sign up, but then go to the single game page and do a Pratice game with AI.  If there are other people online, you can play against them!

Now's the best time to start because with so few people, it's easy to place in the free tournaments and earn Gems.
19  Bitcoin / Development & Technical Discussion / Re: [BOUNTY] Help test next major release of Armory! [0.01 BTC per bug!] on: April 03, 2014, 11:16:01 PM
Another thing: I had Armory open when Bitcoin Core was catching up, and Armory was updating the database (or whatever it does).  I got a notification that Armory was online and had finished loading, but when I checked Bitcoin Core there were still 13 hours to catch up on.  After I clicked the close button (or whatever the okay button is called), Armory froze.  It's still frozen now.

EDIT: It unfroze.  Also, in the bottom right, it says "Connected (0 blocks)", if that's any help.

EDIT EDIT: I restarted and it worked fine.
20  Economy / Investor-based games / Re: btc-arbs.com - Daily ROI (0.01-10%) Update: Registration issues + deposits on: April 03, 2014, 08:48:09 PM
-> No correct caclulations. I have "earned" more coins than calculated. Not much more, but theres a deviation. (Other user reports correct working calculations) And i really did correct calculations.

You must have messed up, because it works for me.  Make sure that you're truncating the result with just four decimal points for the interest.  And make sure that you have the deposits and withdrawals marked on the right day (according to BTC Arbs).
Pages: [1] 2 3 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!