Bitcoin Forum
May 24, 2024, 09:16:54 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: AllCrypt Out?  (Read 1534 times)
BlindMayorBitcorn (OP)
Legendary
*
Offline Offline

Activity: 1260
Merit: 1115



View Profile
March 16, 2015, 11:25:54 PM
Last edit: March 17, 2015, 02:08:00 AM by BlindMayorBitcorn
 #1

"AllCrypt.com is down for a bit

"Update:
Spent the last 16 hours scouring logs. I believe I know what happened and how. I'll post full details as soon as I know more. The site is down, for now, completely, until I can assess the damage done. I'm not even sure there is anything to bring back up.

"Older notice:
Well, due to some apparent exploit in wordpress, someone, somehow, got into the server tonight, installed some files, and managed to empty the goddamned BTC wallet. Best I can tell it was something with that worthless pile of shit software wordpress.

"I'm fucking done. I run a site, spend thousands of hours of time, thousands of dollars of my OWN money to run it, decide to shut down, and somehow, through ways I cannot even figure the hell out, someone gets in, uploads files to the server, somehow finds the goddamned BTC wallet on the network, and it appears that they slammed it with withdraw requests. Of course, the wallet is locked - but it unlocks when a withdraw is legitimately made through the site. I THINK they made a real wd on the site, and then slammed the backdoor to get the other funds out.

"We had 42 BTC in the wallet. 12 was the sites. 30 was users BTC. I'm fucking done with crypto. I'll post details when I sort this fucking mess out. Not that it will matter, because no one ever actually gives a shit when something like this happens."



Emphasis and .gif added by OP.





Forgive my petulance and oft-times, I fear, ill-founded criticisms, and forgive me that I have, by this time, made your eyes and head ache with my long letter. But I cannot forgo hastily the pleasure and pride of thus conversing with you.
mutha
Sr. Member
****
Offline Offline

Activity: 430
Merit: 250


AS8UDRR8Dc4wTyZkMT7Z5vaXtiWK9zh5Hb


View Profile
March 17, 2015, 02:47:26 AM
 #2

Wow that sux another BTC hit and run... see if it was a Zero Day iframe exploit. This link has some of the details and code you can look for on the logs

Hope this helps. 

https://www.cryptobells.com/fancybox-for-wordpress-zero-day-and-broken-patch/
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!