Bitcoin Forum
May 27, 2024, 06:48:32 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 »  All
  Print  
Author Topic: About the recent server compromise  (Read 15325 times)
monbux
Legendary
*
Offline Offline

Activity: 1736
Merit: 1029



View Profile WWW
May 25, 2015, 09:18:10 PM
 #141

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?

Yes. I also have a database snapshot from a little before the attack which I can use to verify people by email if necessary.
I'm sorry, but has theymos actually confirmed his forum identity after the attack yet?  And also, is it just me or is the forum currently loading slower than normal?
alani123
Legendary
*
Offline Offline

Activity: 2408
Merit: 1440


Leading Crypto Sports Betting & Casino Platform


View Profile
May 25, 2015, 09:20:15 PM
 #142

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?

Yes. I also have a database snapshot from a little before the attack which I can use to verify people by email if necessary.
I'm sorry, but has theymos actually confirmed his forum identity after the attack yet?  And also, is it just me or is the forum currently loading slower than normal?

It's also loading slower for me, although I'm confident that this will improve throughout the day.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 25, 2015, 09:28:06 PM
 #143

I don't think he stated or insinuated that, just that people should consider using them.

Have others received an email from the forum? I took a quick peek. Just want to verify if isn't something fishy.

Yes, they were sent out by theymos en masse, though that doesn't mean you might not have recieved a phishing mail. I'm sure the hacker will try something with our emails.
Well yes, I do agree on that. People should consider using one and using Protonmail (or a similar service) with Bitcointalk. Using that email only for Bitcointalk is also recommended.
I'm pretty sure that individuals will receive emails in the future; whoever uses the same email for other services too will receive a taste of social engineering.

I recall theymos saying that deleted PMs and posts are kept in the db? This is a concern (especially PMs) in situations like these. Hopefully PMs have not been compromised.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
fronti
Legendary
*
Offline Offline

Activity: 2909
Merit: 1308



View Profile
May 25, 2015, 09:32:15 PM
 #144


After he got KVM access, the attacker convinced the ISP NFOrce that he was me (using his KVM access as part of his evidence) and said that he had locked himself out of the server. So NFOrce reset the server's root password for him, giving him complete access to the server and bypassing most of our carefully-designed security measures. I originally assumed that the attacker gained access entirely via social engineering, but later investigation showed that this was probably only part of the overall attack. As far as I know, NFOrce's overall security practices are no worse than average.


To reduce downtime and avoid temporarily-broken features, I was originally going to stay in NFOrce's data center. However, some things made me suspicious and I moved everything elsewhere. That's where the extra day+ of downtime came from after a short period of uptime. No additional data was leaked.


please do so!

If you like to give me a tip:  bc1q8ht32j5hj42us5qfptvu08ug9zeqgvxuhwznzk

"Bankraub ist eine Unternehmung von Dilettanten. Wahre Profis gründen eine Bank." Bertolt Brecht
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3822
Merit: 2633


Join the world-leading crypto sportsbook NOW!


View Profile
May 25, 2015, 09:44:17 PM
 #145

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?

Yes. I also have a database snapshot from a little before the attack which I can use to verify people by email if necessary.
I'm sorry, but has theymos actually confirmed his forum identity after the attack yet?  And also, is it just me or is the forum currently loading slower than normal?

Was running ok earlier but it's got a bit sluggish now, but that's to be expected as everyone tries logging on and resetting their passwords etc. Wouldn't surprise me if the forum will get ddosed as well.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Mt.Gox Support
VIP
Sr. Member
*
Offline Offline

Activity: 308
Merit: 250



View Profile
May 25, 2015, 09:47:25 PM
 #146

If our account still gets compromised, are you still able to revert permissions back with a PGP btc address to confirm user?

Yes. I also have a database snapshot from a little before the attack which I can use to verify people by email if necessary.
I'm sorry, but has theymos actually confirmed his forum identity after the attack yet?  And also, is it just me or is the forum currently loading slower than normal?

Was running ok earlier but it's got a bit sluggish now, but that's to be expected as everyone tries logging on and resetting their passwords etc. Wouldn't surprise me if the forum will get ddosed as well.

ddosbtc is fucking around with his annoying booter.

Mt.Gox : The Leading International Bitcoin Exchange.
Mt.Gox Merchant Solutions : https://mtgox.com/merchant
cinnamon_carter
Legendary
*
Offline Offline

Activity: 1148
Merit: 1018


It's about time -- All merrit accepted !!!


View Profile WWW
May 25, 2015, 10:12:43 PM
 #147

Did he confirm his identity ??

check the pgp signature in the e mail you would have got.

that confirms it

----------

Thanks for these details.

Also the people running this board CANNOT control if someone social eng. the employee's working or the isp.
This hack is not on them.

Furthermore I would suggest to everyone to do what i do regarding forums or anything else you 'sign up for' ....

Always use different e mail addresses and long difficult passwords, (also login names if possible)

If the information in the op is correct my password is good for several million years at present technology although I did change it as recommended.

Another item to remember.  If you use the e mail for this forum for other 'accounts' , for example twitter, or a coin exchange.....  remember for many places your e mail address is as good as your log in name.....

Therefore it may make it MUCH easier for someone to attack you someplace else unless you use only e mail addresses for one place. 

Anyone who uses the same password for more than one thing in life is just a sitting duck in cyberspace waiting to be taken out.

Personally what I am most curious about is why someone would go to such trouble to hack this forum ?

As most here are going to be way above average in security habits the chance of getting a password to something else is almost nil (and they were not stored in plaintext although I guess the attacker may have hoped they would be) . 

Was it an enemy of bitcoin ??

Was it a teenager hoping to be a famous hacker ?? (doubtful no one claimed respnsibility or  posted information to pastebin proving they pulled this off)

Was it some curious person wondering if they could figure out who Satoshi is ??

Was it a wealthy jealous spouse that paid a private investigator a lot of money to 'sniff out' all their spouses online activity ?

Was it a team of scammers hoping to steal bitcoin ??

I wonder....


When hacks take place they remind everyone how important it is to practice good secure methods on everything.  I guess now we wait and watch........ see what happens next.

   

Check out my coin Photon
Merge Mine 5 other Blake 256 coins - 6x your hash power  https://www.blakecoin.org/

The obvious choice is not always the best choice.

LOOK DEEPER - Look into the Blake 256 Family -- CC
kolloh
Legendary
*
Offline Offline

Activity: 1736
Merit: 1023


View Profile
May 25, 2015, 10:29:32 PM
 #148

Thanks for the info and hope you are able to figure out exactly how it happened.
Gervais
Sr. Member
****
Offline Offline

Activity: 366
Merit: 250



View Profile
May 25, 2015, 10:30:46 PM
 #149

Personally what I am most curious about is why someone would go to such trouble to hack this forum ?

As most here are going to be way above average in security habits the chance of getting a password to something else is almost nil (and they were not stored in plaintext although I guess the attacker may have hoped they would be) . 

Was it an enemy of bitcoin ??

   

You'd be surprised at how many people will reuse emails and passwords. I'm sure many do the same with their blockchain.info accounts too. Regardless of that, the infodump of all this forum's users emails would be very valuable to advertisers or scammers/spammers but maybe whoever hacked it did it just because he could. Some people just like finding security holes though I'm sure the person will try get some money out of the info he has.
LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3542
Merit: 9687


#1 VIP Crypto Casino


View Profile
May 25, 2015, 10:40:58 PM
 #150

If it happens again I'm going to stop posting on here & find somewhere else.
It's ridiculous that with 1.5 million USD donated they can't stop attacks like this happening.
Imagine if people had wallet back ups in their emails, bank details etc.
I think it's disgraceful.

.
.BITCASINO.. 
.
#1 VIP CRYPTO CASINO

▄██████████████▄
█▄████████████▄▀▄▄▄
█████████████████▄▄▄
█████▄▄▄▄▄▄██████████████▄
███████████████████████████████
████▀█████████████▄▄██████████
██████▀██████████████████████
████████████████▀██████▌████
███████████████▀▀▄█▄▀▀█████▀
███████████████████▀▀█████▀
 ▀▀▀▀▀▀▀██████████████
          ▀▀▀████████
                ▀▀▀███

.
......PLAY......
Gervais
Sr. Member
****
Offline Offline

Activity: 366
Merit: 250



View Profile
May 25, 2015, 10:50:37 PM
 #151

If it happens again I'm going to stop posting on here & find somewhere else.
It's ridiculous that with 1.5 million USD donated they can't stop attacks like this happening.
Imagine if people had wallet back ups in their emails, bank details etc.
I think it's disgraceful.


It wasn't the forum's fault but the hosting. The new forum is being made now but that wouldn't have stopped this either and its being tested to make sure there are no holes or ways to exploit it. And people shouldn't keep their bank details or back ups of their wallets in their emails especially if they can't keep it secure.
LFC_Bitcoin
Legendary
*
Offline Offline

Activity: 3542
Merit: 9687


#1 VIP Crypto Casino


View Profile
May 25, 2015, 10:58:31 PM
 #152

If it happens again I'm going to stop posting on here & find somewhere else.
It's ridiculous that with 1.5 million USD donated they can't stop attacks like this happening.
Imagine if people had wallet back ups in their emails, bank details etc.
I think it's disgraceful.


It wasn't the forum's fault but the hosting. The new forum is being made now but that wouldn't have stopped this either and its being tested to make sure there are no holes or ways to exploit it. And people shouldn't keep their bank details or back ups of their wallets in their emails especially if they can't keep it secure.

Hopefully nobody has been badly effected by all of this.
Hopefully the culprit was just somebody that thought it'd be funny to make the site get taken down, a troll or something.
Wouldn't be nice if it was somebody who wanted to try & do it for monetary reasons.

.
.BITCASINO.. 
.
#1 VIP CRYPTO CASINO

▄██████████████▄
█▄████████████▄▀▄▄▄
█████████████████▄▄▄
█████▄▄▄▄▄▄██████████████▄
███████████████████████████████
████▀█████████████▄▄██████████
██████▀██████████████████████
████████████████▀██████▌████
███████████████▀▀▄█▄▀▀█████▀
███████████████████▀▀█████▀
 ▀▀▀▀▀▀▀██████████████
          ▀▀▀████████
                ▀▀▀███

.
......PLAY......
Gervais
Sr. Member
****
Offline Offline

Activity: 366
Merit: 250



View Profile
May 25, 2015, 11:13:27 PM
 #153

Well it looks like people have already been badly effected by their info being leaked and I'm sure it will become publicly available at some point. It looks like several accounts have already been hacked and over the next few days I'm sure we'll see people complaining about having other accounts hacked or bitcoin balances cleaned out and so on.
nomad13666
Legendary
*
Offline Offline

Activity: 854
Merit: 1000


View Profile
May 25, 2015, 11:30:56 PM
 #154

All good here. Changed password just in case. Don't use secret question.
Lauda
Legendary
*
Offline Offline

Activity: 2674
Merit: 2965


Terminated.


View Profile WWW
May 26, 2015, 05:11:41 AM
 #155

If it happens again I'm going to stop posting on here & find somewhere else.
It's ridiculous that with 1.5 million USD donated they can't stop attacks like this happening.
Imagine if people had wallet back ups in their emails, bank details etc.
I think it's disgraceful.

Actually no, you're the one being ridiculous. The money is being used to make a new forum, not actively prevent this one from being breached.
You don't even realize how lucky we are that theymos is the man behind the forum. Most of the time when these hacks happen it usually passes some time before detection.
You can blame anyone here. 1.5 million USD is nothing. If you take a look at the recent hacks, millions of people have been completely exposed.
Remember the Sony hack (a multi-million company)? or this:
http://www.usatoday.com/story/tech/2015/02/15/hackers-steal-billion-in-banking-breach/23464913/

Everyone was advised to use VPNs or at least PGP when sharing valuable information.

"The Times 03/Jan/2009 Chancellor on brink of second bailout for banks"
😼 Bitcoin Core (onion)
AGD
Legendary
*
Offline Offline

Activity: 2069
Merit: 1164


Keeper of the Private Key


View Profile
May 26, 2015, 06:07:42 AM
 #156

It wasn't the forum's fault but the hosting.

Theymos claims it was the hosting. That's what you meant to say.
He openly states, in this very thread, that before any of the alleged social engineering took place,
"... The attacker was able to acquire KVM access credentials for the server. The investigation into how this was possible is still ongoing, so I don't know everything ..."

Not sure why everyone is acting like lax DC security is the issue,

The hoster denied beeing attacked with SE. It is still not clear how attacker gained access and why.
 
Possible, that the goal was to extract only a few certain PMs. This attack could be part of another, bigger attack. This also looks so determined to me, that I exclude email spammers, Satoshi seekers and random script kiddies.

Bitcoin is not a bubble, it's the pin!
+++ GPG Public key FFBD756C24B54962E6A772EA1C680D74DB714D40 +++ http://pgp.mit.edu/pks/lookup?op=get&search=0x1C680D74DB714D40
RFDZ
Newbie
*
Offline Offline

Activity: 32
Merit: 0


View Profile
May 26, 2015, 06:31:50 AM
 #157

So when is the next compromise?  Grin

Just kidding. Need to know what happened though.
mishax1
Legendary
*
Offline Offline

Activity: 2898
Merit: 1017


View Profile
May 26, 2015, 08:30:29 AM
 #158

The NSA hacked the forum to link users' information (nicknames, emails, IP's, passwords) with illegal activity made elsewhere..  Roll Eyes
nor9865
Hero Member
*****
Offline Offline

Activity: 700
Merit: 500


If you think you know me.. Think again


View Profile
May 26, 2015, 08:35:35 AM
 #159

have a strong feeling they inserted a backdoor somewhere or a keylogger.

something that would keep them getting access to the forum and retrieve data
Gervais
Sr. Member
****
Offline Offline

Activity: 366
Merit: 250



View Profile
May 26, 2015, 08:53:45 AM
 #160

The NSA hacked the forum to link users' information (nicknames, emails, IP's, passwords) with illegal activity made elsewhere..  Roll Eyes

Why would they need to hack the forum when the NSA likely has access to all this info already?

have a strong feeling they inserted a backdoor somewhere or a keylogger.

something that would keep them getting access to the forum and retrieve data

I'm sure theymos checked for this kind of stuff or would have noticed if this had of happened. Probably why the forum was down for so long.
Pages: « 1 2 3 4 5 6 7 [8] 9 10 11 12 13 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!