Bitcoin Forum
May 25, 2024, 05:45:07 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Captain obvious: "Change your mybitcoin passwords"  (Read 1512 times)
AngstHase (OP)
Newbie
*
Offline Offline

Activity: 39
Merit: 0


View Profile
June 21, 2011, 09:33:58 AM
 #1

One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.


Definitely the attacker got some more accounts cashed out.
http://blockexplorer.com/address/1MAazCWMydsQB5ynYXqSGQDjNQMN3HFmEu
foo
Sr. Member
****
Offline Offline

Activity: 409
Merit: 250



View Profile
June 21, 2011, 11:25:31 AM
 #2

One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.
*facepalm* No, the salt is right there in the file, next to the hash. What the salt does is make it impractical to use precomputed tables, you have to brute force the password. If the password is very weak this does not take long.

I know this because Tyler knows this.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!