Bitcoin Forum
November 06, 2024, 07:21:13 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: LTCMine hacking, change your passwords now (Pool ops, check the suspect list)  (Read 1458 times)
tacotime (OP)
Legendary
*
Offline Offline

Activity: 1484
Merit: 1005



View Profile
April 20, 2013, 04:53:17 PM
Last edit: April 21, 2013, 12:40:30 AM by tacotime
 #1

List of LTCmine accounts compromised:
https://bitcointalk.org/index.php?topic=92522.msg1892862#msg1892862

This occurred after Balthazar banned a known botnet operator from his pool

It appears the attacker got the users/passwords from another pool by SQL injection, possibly coinotron:
pool-x.eu
litecoinpool.org
Burnside's pool (ltc.kattare.com)
give-me-ltc.com
NuKingsMiningCo

https://bitcointalk.org/index.php?topic=92522.msg1893276#msg1893276

Users are urged to change their passwords for all pools and lock their deposit addresses where they can.

edit:
List of attacker addresses
Litecoin
LZ799S7zBUwuj68MqSXqHudgGEgBvB2sKD

Bitcoin
1Mh9uHViV9MhBiW3tACQj5PB4JRx7tcJQx
1FxvLMD4nigvDi6ynaJpfsMxpWKcbtJeQL
1DxmLunbUVbkoXe7LTs1TM5Lftrz7ujccP
1JS6iyDne5DvwxwzCFyHZkUMYvpsCtL3uG

Code:
XMR: 44GBHzv6ZyQdJkjqZje6KLZ3xSyN1hBSFAnLP6EAqJtCRVzMzZmeXTC2AHKDS9aEDTRKmo6a6o9r9j86pYfhCWDkKjbtcns
coinotron
Legendary
*
Offline Offline

Activity: 1182
Merit: 1000


View Profile
April 20, 2013, 08:44:49 PM
 #2


I checked out today's payouts. There were no payouts to attacker addresses.
I didn't find any suspicious withdrawals or significant brute force attacks in last few days.


If those passwords were get from another pool, it certainly wasn't Coinotron.

tacotime (OP)
Legendary
*
Offline Offline

Activity: 1484
Merit: 1005



View Profile
April 20, 2013, 08:46:13 PM
 #3

Okay, thanks for the information.

Code:
XMR: 44GBHzv6ZyQdJkjqZje6KLZ3xSyN1hBSFAnLP6EAqJtCRVzMzZmeXTC2AHKDS9aEDTRKmo6a6o9r9j86pYfhCWDkKjbtcns
milly6
Legendary
*
Offline Offline

Activity: 1632
Merit: 1010



View Profile WWW
April 20, 2013, 08:50:36 PM
 #4

thanks for the info. +1 for info gathering

Eyes open, No Fear. Be Safe! Trinity: Currency Without Bias
mr_random
Legendary
*
Offline Offline

Activity: 1344
Merit: 1001



View Profile
April 20, 2013, 08:57:46 PM
 #5

+2 thanks for the info

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
coinotron
Legendary
*
Offline Offline

Activity: 1182
Merit: 1000


View Profile
April 20, 2013, 09:05:50 PM
 #6

Just in case I disabled payouts for all users with account names from LTCMine list of hacked accounts:


a-bolt,imsaguy,MinerG,drjunk,pushyk,nikola,csandr,mutano,aili,Nabi,dextro,Tenechek,metal,skoomskoom,46d938,witcher,Goga43,

Enzo,Alekse777,Acidd,Sinner3232,scorpy,yanes,alexx,drozd,boroda,NTWII,a102030b,ttls,yuren,xefirot,mladen811,228,alexchel,zullus000,

stasson4ik,norman14,fujifotoguy,vatten,Happyendl,bogdan0410,dpushkarev,mining,forgaill,riv2013,NigikGmen,thor,rain,blindas,ekvelibriym,

dimadsp,superbrain,simcity44,calabass

EDIT
Only two of those accounts have some withdrawals today.

g2x3k
Full Member
***
Offline Offline

Activity: 147
Merit: 100

PooL-X.eu


View Profile WWW
August 28, 2013, 01:56:25 AM
Last edit: August 28, 2013, 12:11:31 PM by g2x3k
 #7

still floating some around i think but thats to be expected had one user getting his account compromised

http://PooL-X.eu/ join the crew, bring your slaves
http://wallet.it.cx/ Instant LTC Wallet service
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!