Bitcoin Forum
May 10, 2024, 12:02:36 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: [1]
1  Bitcoin / Bitcoin Discussion / TLS heartbeat read overrun (CVE-2014-0160) on: April 08, 2014, 09:18:41 AM
IIRC, bitcoin-qt uses OpenSSL 1.0.1e.

https://www.openssl.org/news/secadv_20140407.txt
Quote
OpenSSL Security Advisory [07 Apr 2014]
========================================

TLS heartbeat read overrun (CVE-2014-0160)
==========================================

A missing bounds check in the handling of the TLS heartbeat extension can be used to reveal up to 64k of memory to a connected client or server. Only 1.0.1 and 1.0.2-beta releases of OpenSSL are affected including 1.0.1f and 1.0.2-beta1. Thanks for Neel Mehta of Google Security for discovering this bug and to Adam Langley <agl@chromium.org> and Bodo Moeller <bmoeller@acm.org> for preparing the fix. Affected users should upgrade to OpenSSL 1.0.1g. Users unable to immediately upgrade can alternatively recompile OpenSSL with -DOPENSSL_NO_HEARTBEATS. 1.0.2 will be fixed in 1.0.2-beta2.

How does this bug affect us?
2  Economy / Services / Dispute on Bit777 & Peerbet Signature Program on: February 24, 2014, 11:01:00 AM
I have made lots of post for the last month (~2000) after joining the sig program, and I truly believe at least 95% of my posts are informative and helpful to the community.

However, the site owner (indeed the old owner) considered 90% of my posts "pure spam", and decided not to pay me anything.

"Sonny, 90% of your posts are pure spam, so you won't be getting paid for them." quoted from https://bitcointalk.org/index.php?topic=216854.msg5333714#msg5333714.

I want to know if we are having a common definition of "pure spam" here, and I really have no idea if solving other people's problems (from 360 seconds time limit, to cloud mining profitability, to wallet backup problem, to scrypt pool selection, to report spam bot to Badbear, etc) are considered spam here.

So I hereby ask everyone to please take a look at my post history (https://bitcointalk.org/index.php?action=profile;u=157320;sa=showPosts).

Please take a random check on a few pages of my previous posts (from page 1 to page 108), and tell me how much do you think my posts are pure spam.

Thanks everyone in advance.



Updates on Feb 25:

1. Thanks everyone for your replies here, and thanks for your supporting PMs as well.
I have sent casinobitco (https://bitcointalk.org/index.php?action=profile;u=37924) two PMs and two emails to support@casinobitco.in at around 10am UTC yesterday, but I haven't received anything back yet after 21 hours. I have just sent him another PM and email (with a link to this thread), and I hope he can read my points here, but I am not really optimistic about it. I am quite desperate now, and I have no idea what I can/should do.


2. I am still an university student, right now working a part-time job to pay my own tuition. So, that 0.4btc is a lot of money to me. It can cover half of my monthly tuition fee, and I really need it. To be honest, I was very very upset yesterday and can't sleep at all, not only because I was not payed according to the terms, but my works were not recognized and appreciated at all.


3. Before I joined the bit777 signature program, I checked the terms of different programs and eventually chose bit777 over Primedice, simply because I was worried that I would forget to send Stunna a PM on 17th each month. It now seems I have made a terrible and painful mistake.
I have heard a lot of good things about Stunna (sadly, after joining bit777 program), but I guess I will quit all those per-post signature program for now. As I mentioned above, I am not making money for a pair of new shoes, but to pay my university tuition fee. Thus, I really need to be 100% sure I will get the money each month, and I would probably go work a few more hours on my job next week.


4. I don't think leaving a negative trust to bit777 would be useful, as I believe he has already abandoned that forum account. And I don't think it would be fair to leave a negative trust to casinobitco.



(Final) Updates on Feb 28:

1. After all these days, I am still unable to make any contact with forum account bit777, and I have given up on that completely.


2. I have received a response from casinobitco on Feb 25 (slightly more than 1 day after the first PM).
Even though it is not his fault at all, he and his team are willing to pay me 0.25btc out of their own pocket.
I want to give them a big thanks for their help and generosity, and I guess I can call this a happy ending.
I just gave casinobitco a positive trust, and I sincerely wish him and his team all the best.


Thanks very much again for everyone's attention, help and encouragement.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!