Bitcoin Forum
April 30, 2024, 12:26:20 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 »  All
  Print  
Author Topic: About the recent server compromise  (Read 15323 times)
squall1066
Copper Member
Legendary
*
Offline Offline

Activity: 2310
Merit: 1032


View Profile
May 25, 2015, 04:37:30 PM
 #81

Thanks for the info,

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?
1714479980
Hero Member
*
Offline Offline

Posts: 1714479980

View Profile Personal Message (Offline)

Ignore
1714479980
Reply with quote  #2

1714479980
Report to moderator
Even if you use Bitcoin through Tor, the way transactions are handled by the network makes anonymity difficult to achieve. Do not expect your transactions to be anonymous unless you really know what you're doing.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
dogie
Legendary
*
Offline Offline

Activity: 1666
Merit: 1183


dogiecoin.com


View Profile WWW
May 25, 2015, 04:38:10 PM
 #82

Glad that it's back, but as previously said it's fairly unacceptable that a forum with such a security aura can still be compromised by attackers.
When will the new forum be happening? It's been in speculation for at least a year, if not longer now. It cannot take this long to code a forum software.

Yeah, DDOS you out of digital existence.
Do you think that they would bother? Surely to take down as many people as it would be worth here it would take more resources than what the attacker could get back.

Yes because a) people are malicious and b) it costs them nothing. There are plenty of "stress test your website" sites that use botnets to do evil things when asked to, either for free or a small fee. The attacker gets nothing other than "winning" the argument.

marcotheminer
Legendary
*
Offline Offline

Activity: 2072
Merit: 1049


┴puoʎǝq ʞool┴


View Profile
May 25, 2015, 04:39:14 PM
 #83

Hey guys!

One more thing: DON'T FORGET TO CHECK YOUR WALLET ADDRESS, TOO!!! IN YOUR PROFILE.

This is most important for users already participating in campaigns (FOR AUTOMATED PAID campaigns like bitmixer etc)

Hacker would easily check the participants accounts and just change the payment address to his own, in order to receive the payments.

 Wink

A hacker after small change.  Grin
Good joke. Smiley

Over 5 BTC a week wouldn't be that tiny.
sgk
Legendary
*
Offline Offline

Activity: 1470
Merit: 1002


!! HODL !!


View Profile
May 25, 2015, 04:41:20 PM
 #84

It is possible the attacker is selling the stolen email address database to spammers to make quick bucks.

ahh, I really don't wanna start any drama. maybe it was just spam in "wrong time" and it is not related at all. just reporting..Smiley

This doesn't look like the average email spam hack to me.

It definitely isn't. The hacker was downloading the complete members table which allows him to compromise many user accounts on this forum as well as other sites.

Selling email addresses might be a side income for him with no extra effort until he brute-forces the passwords.
theymos (OP)
Administrator
Legendary
*
Offline Offline

Activity: 5180
Merit: 12900


View Profile
May 25, 2015, 04:43:38 PM
 #85

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?

Yes. I also have a database snapshot from a little before the attack which I can use to verify people by email if necessary.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
timk225
Hero Member
*****
Offline Offline

Activity: 955
Merit: 1004


View Profile
May 25, 2015, 04:46:50 PM
 #86

15 XAU....how much is that in US Dollars?  If it isn't enough for me I will not tell what I know about the attack.  Hint -- it came from China.  They are trying to counterfeit and steal everything in the world, and it seems like no one tries to stop them.

My password was a single keyboard character repeated 10 times, maybe I should change it?

And no amount of security in the world will stop this if some dumbass at the data center believes what someone on the phone tells him and resets the access password.
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3794
Merit: 2615


Join the world-leading crypto sportsbook NOW!


View Profile
May 25, 2015, 04:49:22 PM
 #87

15 XAU....how much is that in US Dollars? 

http://www.xe.com/currency/xau-gold-ounce

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Xialla
Legendary
*
Offline Offline

Activity: 1036
Merit: 1000


/dev/null


View Profile
May 25, 2015, 04:50:38 PM
 #88

15 XAU....how much is that in US Dollars?  If it isn't enough for me I will not tell what I know about the attack.  Hint -- it came from China.  They are trying to counterfeit and steal everything in the world, and it seems like no one tries to stop them.

My password was a single keyboard character repeated 10 times, maybe I should change it?

And no amount of security in the world will stop this if some dumbass at the data center believes what someone on the phone tells him and resets the access password.

1 XAU = ~ 1200USD

rest of post is just bullshit, sorry.
nor9865
Hero Member
*****
Offline Offline

Activity: 700
Merit: 500


If you think you know me.. Think again


View Profile
May 25, 2015, 04:53:11 PM
 #89

15 XAU....how much is that in US Dollars?  If it isn't enough for me I will not tell what I know about the attack.  Hint -- it came from China.  They are trying to counterfeit and steal everything in the world, and it seems like no one tries to stop them.

My password was a single keyboard character repeated 10 times, maybe I should change it?

And no amount of security in the world will stop this if some dumbass at the data center believes what someone on the phone tells him and resets the access password.


XAU is Gold

Quote
XAU-USD 1,206.9400 Price of 1 XAU in USD
alani123
Legendary
*
Offline Offline

Activity: 2380
Merit: 1411


Leading Crypto Sports Betting & Casino Platform


View Profile
May 25, 2015, 05:07:51 PM
 #90

What's the limit for passwords? I tried using an unreasonably large string as my password and didn't receive any error messages (despite the load time after I press the login button being huge). Were the last characters of the string cut off for it to fit a certain limit?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
matt4054
Legendary
*
Offline Offline

Activity: 1946
Merit: 1035



View Profile
May 25, 2015, 05:09:33 PM
 #91

I'm quoting this for those like me who didn't understand why they couldn't login after changing pwd yesterday

If you changed your password in the short time when the forum was online a little over a day ago, the change didn't stick. You'll have to change it again.
1Referee
Legendary
*
Offline Offline

Activity: 2170
Merit: 1427


View Profile
May 25, 2015, 05:18:41 PM
 #92

As far as I can see no one had access to my account. I have set a stronger password just in case. Better safe than sorry. Credits to theymos for his hard work.
Panthers52
Hero Member
*****
Offline Offline

Activity: 675
Merit: 502


#SuperBowl50 #NFCchamps


View Profile WWW
May 25, 2015, 05:24:33 PM
 #93

I am glad that too much damage wasn't done and that too much personal information wasn't leaked. This is just one more example of the importance of using GPG when sending or receiving any kind of sensitive information.

PGP 827D2A60

Tired of annoying signature ads? Ad block for signatures
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 25, 2015, 05:46:28 PM
 #94

I am glad that too much damage wasn't done and that too much personal information wasn't leaked. This is just one more example of the importance of using GPG when sending or receiving any kind of sensitive information.
Actually there is quite some damage. Passwords are irrelevant,as they can be changed.
A lot of people are going to be targeted due to this
Quote
- Last-used IP address and registration IP address
There are people who sometimes use a VPN, and some that don't use it at all. We will see what happens in the future.
Hopefully the attacker gets found.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
Fernandez
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
May 25, 2015, 05:47:53 PM
 #95

I was using a moderately strong password which I could remember too. Now I will have to come with another system.






██████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████▄▄▄███████████████████████
███████████████████████████████████████████████████████████████████████▀▀▀████████████████████████
██████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████





...INTRODUCING WAVES........
...ULTIMATE ASSET/CUSTOM TOKEN BLOCKCHAIN PLATFORM...






Panthers52
Hero Member
*****
Offline Offline

Activity: 675
Merit: 502


#SuperBowl50 #NFCchamps


View Profile WWW
May 25, 2015, 05:51:05 PM
 #96

I am glad that too much damage wasn't done and that too much personal information wasn't leaked. This is just one more example of the importance of using GPG when sending or receiving any kind of sensitive information.
Actually there is quite some damage. Passwords are irrelevant,as they can be changed.
A lot of people are going to be targeted due to this
Quote
- Last-used IP address and registration IP address
There are people who sometimes use a VPN, and some that don't use it at all. We will see what happens in the future.
Hopefully the attacker gets found.
I am not sure why anyone would consider not using a VPN. They are really not very expensive to use and they provide a lot of added privacy.

PGP 827D2A60

Tired of annoying signature ads? Ad block for signatures
1Referee
Legendary
*
Offline Offline

Activity: 2170
Merit: 1427


View Profile
May 25, 2015, 05:53:33 PM
 #97

I am glad that too much damage wasn't done and that too much personal information wasn't leaked. This is just one more example of the importance of using GPG when sending or receiving any kind of sensitive information.
Actually there is quite some damage. Passwords are irrelevant,as they can be changed.
A lot of people are going to be targeted due to this
Quote
- Last-used IP address and registration IP address
There are people who sometimes use a VPN, and some that don't use it at all. We will see what happens in the future.
Hopefully the attacker gets found.

For most people it doesn't matter if their IP address is now in the hands of the hacker, they will most likely target those with the highest ranks and based on how important that person is in the community.
btcdealer.nl
Full Member
***
Offline Offline

Activity: 235
Merit: 250



View Profile
May 25, 2015, 05:57:39 PM
 #98

9800 Savage Rd
Fort Meade, MD 20755
USA

 Wink
alani123
Legendary
*
Offline Offline

Activity: 2380
Merit: 1411


Leading Crypto Sports Betting & Casino Platform


View Profile
May 25, 2015, 06:02:36 PM
 #99

9800 Savage Rd
Fort Meade, MD 20755
USA

 Wink

What is this?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
btcdealer.nl
Full Member
***
Offline Offline

Activity: 235
Merit: 250



View Profile
May 25, 2015, 06:05:33 PM
 #100

9800 Savage Rd
Fort Meade, MD 20755
USA

 Wink

What is this?

Address of the most loved agency in this world Tongue
Pages: « 1 2 3 4 [5] 6 7 8 9 10 11 12 13 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!