Bitcoin Forum
June 21, 2024, 09:55:58 PM *
News: Voting for pizza day contest
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Bitcoin / Bitcoin Technical Support / Re: OMG help! Wtf? on: July 04, 2011, 12:41:01 AM
Relaunch client. If not better, use only 1 bitcoin client at the same time on the same internet line (NAT port forwarding and uPnP related, sometime it fails with 2+ running bitcoin clients)
2  Bitcoin / Bitcoin Discussion / Re: Good News: Mt.Gox has a new logo!! on: June 21, 2011, 11:41:36 PM
Is this logo done with FLOSS ? Gonna ask Mark by phone. Won't be able to sleep until I know.
Anyway, do like.
3  Bitcoin / Bitcoin Discussion / Re: TradeHill - Stance on spam / removing users referral codes on: June 21, 2011, 10:57:56 PM
I ask TradeHill to totally deactivate referral codes for now, since this is an incentive to spam and scam. And you won't be able to manually deactivate every infringing account one by one, it isn't worth the pain. Let the situation calm down, until the referral codes are used for fair uses.

ps: got 2 spams:

"Mt Gox has been hacked"
?r=TH-R15683
Received: from goemitar by bonecrusher.gulfsouthmedia.com (envelope-from <goemitar@bonecrusher.gulfsouthmedia.com>)
Last remote: 209.223.236.66 (bonecrusher.gulfsouthmedia.com)
http://network-tools.com/default.asp?prog=express&host=209.223.236.66

"Important message to Bitcoin traders!"
?r=TH-R15977
Received: from server ([46.5.146.44]) by home  [s15389739.onlinehome-server.info]
Last remote: 87.106.62.244 (s15389739.onlinehome-server.info)
http://network-tools.com/default.asp?prog=express&host=87.106.62.244

Enjoy your spam reports.
4  Bitcoin / Bitcoin Discussion / Re: Mt.gox claims page is up on: June 21, 2011, 10:54:15 PM
Maybe they should just rent Microsoft's update servers for a few hours, they are quite good load-ready  Cheesy
Stop smashing the F5 button, they may run nginx on a special "DDoS protection service provider", too much is just too much.
5  Bitcoin / Bitcoin Discussion / Re: Newest Mt.Gox update status, on: June 21, 2011, 10:47:39 PM
Have a clock set on JST. Right now: 7:41 am.
Also, I don't think they want to hire someone who's job is to blablabla senseless press releases and so on, we want facts and not empty words.

GeniuSxBoY: Good luck cracking very strong passwords SHA-512 multi-iteration salt-hashed :p Implying you even get access to the hashes, now that these things happened.
6  Bitcoin / Bitcoin Discussion / Re: Making it public: I have moved the disputed 643.2771 BTC into an escrow account on: June 21, 2011, 10:27:30 PM
Oh look, it's THIS thread again. Gonna repeat myself.

-> accident (account intrusion)
-> abnormal market (all open bids fulfilled by selling of the stolen coins)
-> transactions not legit
-> hand the withdrawed coins back
7  Bitcoin / Bitcoin Discussion / Re: MtGox claim site is up! Everyone who claimed say haaaay ... on: June 21, 2011, 09:08:04 PM
The claim site is overloaded.
True.

PING claim.mtgox.com (72.52.5.67) 56(84) bytes of data.
64 bytes from unknown.prolexic.com (72.52.5.67): icmp_req=1 ttl=246 time=24.4 ms

httping -g claim.mtgox.com -p 443 -c 3 -s -l
PING claim.mtgox.com:443 (claim.mtgox.com):
error receiving reply from host

prolexic.com ->
Quote
Distributed Denial of Service (DDoS) attacks have become a commonplace threat to online businesses. With over 50,000 distinct attacks per week, DDoS attacks have become highly visible and costly forms of cyber-crime, and are increasingly being proactively addressed by online businesses to avoid devastating costs of DDoS-related downtime.

In response, Prolexic Technologies provides class-leading global DDoS mitigation service that protects Internet operations from the debilitating service disruptions caused by DDoS attacks.

Oops, service provider #fail.

I think Mtgox is just going to cash out on this one. Oh wait, they don't even have an exchange to cash out on.
I think you're wrong.
8  Bitcoin / Bitcoin Discussion / Re: MtGox really secure now on: June 21, 2011, 08:54:46 PM
So bad. Why do people still use this site, are they stupid.
They want their money back.  Roll Eyes
That doesn't mean they aren't stupid.
But many of them still want to use Mt.Gox in the future.
That doesn't mean they are stupid.

Just sayin'...
9  Bitcoin / Bitcoin Discussion / Re: MtGox claim site is up! Everyone who claimed say haaaay ... on: June 21, 2011, 07:34:15 PM
Protip:

-launch "base64" in Terminal/Konsole
-let your cat walk on keyboard:  564174kl:mml;jbhçiyhvezf"dm;àiht-de"quté
-Ctrl+D to base64 this: NTY0MTc0a2w6bW1sO2piaMOnaXlodmV6ZiJkbTvDoGlodC1kZSJxdXTDqQo=
-pick a piece of the string: 6bW1sO2piaMOn
-add special chars, for fun: 6b!W1/sO+2piaM*%On
-> strong enough to Mt.Gox, proceed claim.

Also, do this when Mt.Gox successfully blocks incoming UDP (DDoS) and TCP (SYN flood).
10  Bitcoin / Bitcoin Discussion / Re: MtGox really secure now on: June 21, 2011, 07:21:49 PM
Quote
Server: nginx/0.8.53
Date: Tue, 21 Jun 2011 18:55:52 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Status: 200 OK
Etag: "(snip)"
P3P: CP="NOI DSP COR NID ADMa OPTa OUR NOR"
X-Runtime: 12
Set-Cookie: _zendesk_session=(snip); path=/; HttpOnly
Cache-Control: private, max-age=0, must-revalidate
Content-Encoding: gzip

200 OK
Got from support desk.
Oh wow, they do run nginx 0.8.53 while latest is 1.0.4 !! For sure, everybody's computer is infected by trojan software now !!!

Oh look look !!!
Quote
  <!--[if lt IE 9]>
  <script src="https://assets.zendesk.com/javascripts/vendor/html5_shiv.js?1308347461" type="text/javascript"></script>
  <![endif]-->
They actually hotlink javascript from zendesk's website for Internet Explorer users, in plain text in the HTML source code for everyone to see !! I shit in my pants, this is now the end of the world !!!!1

/joke


>copypasta of random "Too many connections" error and feeling 1337 about it
>not showing proper screenshot, unable to understand what problem is
>implying this actually is a vulnerability, server saying "whoops, can't handle this much shitload"
>instead of mail MagicalTux about it and appear stupid to one person -> post in Bitcoin forum and appear stupid to everybody else who actually work with PHP and MySQL
>be marked as troll, for now
11  Bitcoin / Bitcoin Discussion / Re: I'm Kevin, here's my side. on: June 21, 2011, 10:11:23 AM
Phil21 -> well, guess I got some things not right then and the way it developed (nobody knows everything about all this mess anyway) _sorry_.
Still: I stated "if he really did it" in my post, since I've no proof of anything for or against Smiley -and there I am, waiting authority investigations make light on this. Meanwhile, my post applies to all massive bitcoin thieves.
//

Torminalis: be assured that MagicalTux is highly ashamed of himself for not forcing all users to update the password when he acquired Mt.Gox, making the passwords salted at the start. Not even mention the discredit on Mt.Gox and all the other services he's running, many people sure lost faith in his ability to secure websites. As a human, he can only do his best, not guarantee perfection: he may have more technical experience than the average, but he still has 24 hours time per day like everybody. Every expert knows that perfect security in computers is impossible, even the über-safe OpenBSD had 2 remote critical vulnerabilities at standard install in it's history. The internet in it's whole has been hacked and hacked again, making the network stronger everytime (would DNSSEC exist if there weren't any DNS poisoning vulnerabilities ? Buffer protection if there weren't "ping of death" attacks ? Antiviruses if there weren't viruses ?). Bitcoin economy is at experimental state, I prefer Mt.Gox exploited now and reinforce security massively (and anybody else taking lessons) than all markets hacked and coins sucked out while bitcoins are worth 4000 $ each. Preparing good times from the bad times, that's the philosophy.

btw: I'm directly concerned about all this, since I'm hosted on KalyHost and want to pay it with bitcoins - fed up about PayPal/MoneyBookers fees, plus bank tracing. So I really want Bitcoin to go back normal again and stay legal everywhere in the world.
12  Bitcoin / Bitcoin Discussion / Re: I'm Kevin, here's my side. on: June 21, 2011, 08:39:30 AM
+1 Nescio.

Ok I just kick in this thread to make some things clear:
You surely know what's about "deal in stolen goods" (dunno if the word "concealment" is right, only know in french it's "recel"). Will you accept getting bitcoins if you suspect someone stole these from another account ? Maybe not, you want to stay safe legally said, since this is more punished than the stealing itself.

Short: lots of people not wanting to deal with "probably stolen" bitcoins, selling them, making the bitcoin's value drop, and so on. Then, 250 000 bitcoins robbed:
- will be worth nothing if nobody want to pay for them
- still is illegal

Mt.Gox did the right thing, Kevin is already tracked down for stealing and possible relation with system intrusion and cracking (if he really did it). It's now your turn: give the stolen bitcoins back where they belong (Mt.Gox) and be less charged, or keep them and face more charges and massive bitcoin crisis of interest and value loss.

You can't fuck around thinking you're safe because it's virtual and looked legit to you, Mt.Gox has to hand over all their logs to the authorities and they will easily go up to you. Legally, they have to hand over everything they know to the authorities, may the community like the FBI sniffing on it, or not. Mt.Gox being a registered society, they have to comply to any law of the countries involved, french because of french bank and admin, american because of technical infrastructure, and japanese because of society establishment and admin home. The point is how hard you will be hit in the end, and what impact this will have on the whole bitcoin economy. And how Bitcoin will be treated by the govs.

TL;DR: give the bitcoins back. For the community, for the future of Bitcoin and for yourself.
inb4 domain names "bitcoin.org", "mtgox.com", "tradehill.com", "sourceforge.net"... get seized by ICE (they can, TLDs managed by american societies)
13  Other / Beginners & Help / Re: If your Mt. Gox account has been compromised, PLEASE READ. on: June 20, 2011, 03:02:34 PM
how does everyone know how much they lost?? I didn't think anyone could access anything.
Nobody lost.
14  Other / Beginners & Help / Re: HOWTO: create a 100% secure wallet on: June 20, 2011, 12:41:24 PM
Best just to but it on a hidden encrypted volume inside a hidden virtual machine that has encrypted archive file that doesn't seem like a archive file Smiley
I've better: LiveCD system accessing physically encrypted volume (external hard drive with fingerprint recognition ?), inside of which there is some trap files plus a TrueCrypt volume named "Pr0n.zip" containing a BtrFS filesystem, inside of which there is a volume with some random porn pics in it "to make sure the kids/woman don't find out" plus a hidden volume with a read-only wallet.dat which name has been changed to Thumbs.db.
15  Other / Beginners & Help / Re: Hosting for bitcoins? on: June 20, 2011, 11:38:17 AM
KalyHost.
Happy with it, so far.
0,27 ฿TC/month, + 5% value added tax. 0,32 for unlimited databases and email accounts.
16  Other / Beginners & Help / Re: HOWTO: create a 100% secure wallet on: June 20, 2011, 11:34:36 AM
some recomendation for encrypticng program in linux? im not linux user. but i know how install and run ubuntu at least. sadly i dont know how install packaged directly only using synaptic.
For GNU/Linux and Windows: TrueCrypt.
You can mix keyfiles and password, against keyloggers. But don't forget to dismount all volumes after use Smiley
17  Other / Beginners & Help / Re: If your Mt. Gox account has been compromised, PLEASE READ. on: June 20, 2011, 10:59:27 AM
Extreme caution for all registered users of Mt.Gox, please.
Plenty of spam, phishing and malware coming. Bitcoin now is serious business to hackers, so at least use standard security (encrypted wallet.dat, 1 password per website, strong passwords, separate email addresses,...)
Since Windows users are especially targeted, we've got to teach the security basics, I fear  Sad
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!