Bitcoin Forum
June 30, 2024, 02:03:01 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: WARNING TO COMMUNITY  (Read 970 times)
elambert (OP)
Legendary
*
Offline Offline

Activity: 1696
Merit: 1008



View Profile
August 23, 2013, 09:08:28 AM
Last edit: August 23, 2013, 09:26:41 AM by elambert
 #1

Hello all,
I have seen someone try to do this with CGB a month ago and now I see it occurred with Krugercoin. The CGB occurrence went unnoticed fortunately and no damage was done, but I see the Krugercoin one took off and is creating issues.

Please be extremely cautious of where you are downloading updates! Either get them direct from github or take the time to confirm that the updates are from the development team (can be identified by tracking down the original ANN thread and seeing who posted it). One can only reason that we will see more of this, so please be cautious!

Any creative ideas should be thrown into the mix in order to create some kind of safeguard (signature or other) so the trusted sources can be confirmed.


FYI - From what I have seen, this issue occurs with a junior profile that is named after the coin. This should be an indicator to you to beware!
tyrion70
Legendary
*
Offline Offline

Activity: 934
Merit: 1000



View Profile
August 23, 2013, 09:15:09 AM
 #2

Hey,

Just an idea on signing.. What I did with some QT builds I created is the following:
- create a md5 hash of the files created
- sign the md5 hashes with my wallet address thats in my signature
- include a text file with binaries that contain those hashes and signing strings
- include the github address of the commit used to create the build

That way everyone can verify that the files are actually coming from the person owning that address. For fancyness you could use a vanity address containing the name of the coin Smiley

HTH,
Cheers

digitalindustry
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


‘Try to be nice’


View Profile WWW
August 23, 2013, 09:16:49 AM
 #3

great work tyrion70

recently Nybble lost its Client (it was only updated to Google drive)

i certainly suspected something like this .

- Twitter @Kolin_Quark
GoldBit89
Hero Member
*****
Offline Offline

Activity: 526
Merit: 500


Its all about the Gold


View Profile
August 23, 2013, 09:24:54 AM
 #4

got to wonder what other alternate crypto coins are effected.

FTC  6nvzqqaCEizThvgMeC86MGzhAxGzKEtNH8 |WDC WckDxipCes2eBmxrUYEhrUfNNRZexKuYjR  |BQC bSDm3XvauqWWnqrxfimw5wdHVDQDp2U8XU
BOT EjcroqeMpZT4hphY4xYDzTQakwutpnufQR |BTG geLUGuJkhnvuft77ND6VrMvc8vxySKZBUz |LTC  LhXbJMzCqLEzGBKgB2n73oce448BxX1dc4
BTC 1JPzHugtBtPwXgwMqt9rtdwRxxWyaZvk61  |ETH 0xA6cCD2Fb3AC2450646F8D8ebeb14f084F392ACFf
Lethn
Legendary
*
Offline Offline

Activity: 1540
Merit: 1000



View Profile WWW
August 23, 2013, 09:25:54 AM
 #5

This should be standard practice for all software people download, never ever download from untrustworthy sources and best practice if you can be bothered is to get some kind of virus scanner that works on download links before you get them but I'll admit I don't know much about that kind of software because I'm just using what comes with Windows 7.
cryptocoinsnews
Sr. Member
****
Offline Offline

Activity: 299
Merit: 250


View Profile WWW
August 23, 2013, 09:34:28 AM
 #6

http://www.cryptocoinsnews.com/2013/08/23/warning-to-community/

/David Parker, Director of CCN
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
August 23, 2013, 01:12:40 PM
 #7

Thank you for warning everyone.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
minerapia
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 23, 2013, 01:18:39 PM
 #8

Hey,

Just an idea on signing.. What I did with some QT builds I created is the following:
- create a md5 hash of the files created
- sign the md5 hashes with my wallet address thats in my signature
- include a text file with binaries that contain those hashes and signing strings
- include the github address of the commit used to create the build

That way everyone can verify that the files are actually coming from the person owning that address. For fancyness you could use a vanity address containing the name of the coin Smiley

HTH,
Cheers

This doesnt actually help much on the krugercoin case since malicious client was not redirected or anything. But it was just some forum post which offered completly new link to client.

donations -> btc: 1M6yf45NskQxWXknkMTzQ8o6wShQcSY4EC
                   ltc: LeTpCd6cQL26Q1vjc9kJrTjjFMrPhrpv6j
digitalindustry
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000


‘Try to be nice’


View Profile WWW
August 23, 2013, 01:31:32 PM
 #9

Hey,

Just an idea on signing.. What I did with some QT builds I created is the following:
- create a md5 hash of the files created
- sign the md5 hashes with my wallet address thats in my signature
- include a text file with binaries that contain those hashes and signing strings
- include the github address of the commit used to create the build

That way everyone can verify that the files are actually coming from the person owning that address. For fancyness you could use a vanity address containing the name of the coin Smiley

HTH,
Cheers

This doesnt actually help much on the krugercoin case since malicious client was not redirected or anything. But it was just some forum post which offered completly new link to client.

In which case don't download from Devs you don't know with no forum account reputation, i'd call that evolution more than anything.

If Developers do not look after or care about a development then obviously its going to go that way , where users don't know who controls it or who is up-keeping it.

Most of that is the effect of a saturated market of pre-mined and insta-scammed crypto-"currency".

all things being equal.

- Twitter @Kolin_Quark
minerapia
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
August 23, 2013, 02:25:04 PM
 #10

Quote
In which case don't download from Devs you don't know with no forum account reputation, i'd call that evolution more than anything.
If Developers do not look after or care about a development then obviously its going to go that way , where users don't know who controls it or who is up-keeping it.
Most of that is the effect of a saturated market of pre-mined and insta-scammed crypto-"currency".
all things being equal.

Deal was that someone created new account named "Krugercoin", then posted "Krugecoin, mandatory update" post which had the malicious client. Real dev of krugercoin (Nibiru) had nothing to do with it.

Well, its like oldest scam in the internet. send email to gazillion ppl which states:
'BankNameHere' wants youre feedback, win an iPAD !
then the link goes to BankNameHere.easyurls.com and steals credentials. Easy as pie.

Lesson pretty much is, allways check what you click allways check what u download.

donations -> btc: 1M6yf45NskQxWXknkMTzQ8o6wShQcSY4EC
                   ltc: LeTpCd6cQL26Q1vjc9kJrTjjFMrPhrpv6j
Snail2
Legendary
*
Offline Offline

Activity: 1512
Merit: 1000



View Profile
August 23, 2013, 02:42:15 PM
 #11

This is why I like using Cryptsy, Coins-e, Bter, and BTC-e as wallets for a part of my altcoins Smiley. I know this is also a dangerous practice but a distributed coin store as well.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!