Bitcoin Forum
May 10, 2024, 07:16:36 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: BitcoinTalk server was compromised  (Read 1455 times)
BitCoinDream (OP)
Legendary
*
Offline Offline

Activity: 2324
Merit: 1204

The revolution will be digital


View Profile
May 25, 2015, 10:05:52 PM
Last edit: May 25, 2015, 10:16:04 PM by BitCoinDream
 #1

As some of you already know, BitcoinTalk server was compromised through Social Engineering and the attacker got access to the DataBase, partially or completely. The most dangerous part of the incident is that the DataBase dump is available in the public domain. If you are intersted in the details of the attack, check the post by the BitcoinTalk admin: https://bitcointalk.org/index.php?topic=1067985.0.


As an immediate measure, it is highly recommended to...

1. Change your password.

2. Not to have trade with a trusted forum member without verifying his identity.


We have already noticed that a few old accounts have suddenly become active in the forum.

The Bitcoin software, network, and concept is called "Bitcoin" with a capitalized "B". Bitcoin currency units are called "bitcoins" with a lowercase "b" -- this is often abbreviated BTC.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Fernandez
Legendary
*
Offline Offline

Activity: 1008
Merit: 1000



View Profile
May 26, 2015, 08:49:31 AM
 #2

Not to have trade with a trusted forum member without verifying his identity.

This always applies, and goes for any escrow too. They should always give a signed message.






██████████████████████████████████████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████████████████████████████
███████████████████████████████████████████████████████████████████████▄▄▄███████████████████████
███████████████████████████████████████████████████████████████████████▀▀▀████████████████████████
██████████████████████████████████████████████████████████████████████████████████████████████████
█████████████████████████████████████████████████████████████████████████████████████████████████





...INTRODUCING WAVES........
...ULTIMATE ASSET/CUSTOM TOKEN BLOCKCHAIN PLATFORM...






thebitcoinquiz.com
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250



View Profile
May 27, 2015, 02:11:27 PM
 #3

The most dangerous part of the incident is that the DataBase dump is available in the public domain.
In the public domain? But where?
I failed to fined any such database dump(or a mention that the dump is available to everyone).  The link you provided also doesn't talk of the dump being available in public? Would you like to throw some more light upon it?

Stay hungry. Stay foolish.
vennali
Legendary
*
Offline Offline

Activity: 2338
Merit: 1081


#SWGT CERTIK Audited


View Profile
May 27, 2015, 10:26:55 PM
 #4

The most dangerous part of the incident is that the DataBase dump is available in the public domain.
In the public domain? But where?
I failed to fined any such database dump(or a mention that the dump is available to everyone).  The link you provided also doesn't talk of the dump being available in public? Would you like to throw some more light upon it?
I don't think the data was dumped out in the public, theymost only said "He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server" 

pandher
Legendary
*
Offline Offline

Activity: 952
Merit: 1000


Stagnation is Death


View Profile WWW
May 28, 2015, 08:16:55 AM
 #5

Compromises have become a joke now, get that millionaire board up already
Rotten Egg
Member
**
Offline Offline

Activity: 172
Merit: 22


View Profile
May 30, 2015, 10:54:53 AM
 #6

The most dangerous part of the incident is that the DataBase dump is available in the public domain.
In the public domain? But where?
I failed to fined any such database dump(or a mention that the dump is available to everyone).  The link you provided also doesn't talk of the dump being available in public? Would you like to throw some more light upon it?
I don't think the data was dumped out in the public, theymost only said "He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server" 

Nopes. It seems that the data is out in the public: http://satoshibox.com/5568fdd512fb6d98558b462d

And we are already witnessing adverse effects of that...

Example 1: https://bitcointalk.org/index.php?topic=1074180.0

Example 2: https://bitcointalk.org/index.php?topic=1074232.0

Cleaning BitcoinTalk community since 2014.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
May 30, 2015, 10:58:33 AM
 #7


Nopes. It seems that the data is out in the public: http://satoshibox.com/5568fdd512fb6d98558b462d


If you seriously believe that it's the real dump not a fake file, please pay 0.2 BTC and download it then spread links here and there.
It's a fake file which is being used by some new scamming accounts.
Rotten Egg
Member
**
Offline Offline

Activity: 172
Merit: 22


View Profile
May 30, 2015, 11:04:07 AM
 #8


Nopes. It seems that the data is out in the public: http://satoshibox.com/5568fdd512fb6d98558b462d


If you seriously believe that it's the real dump not a fake file, please pay 0.2 BTC and download it then spread links here and there.
It's a fake file which is being used by some new scamming accounts.

I have nothing to do with the forum database. So, I'm not going to waste around Rs. 2965. But, if it is fake, how the account hacks are happening ? Few old accounts like Mt. Gox support got active in the forum recently after almost 2 years of non-activity.

Cleaning BitcoinTalk community since 2014.
escrow.ms
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
May 30, 2015, 11:49:35 AM
 #9

I have nothing to do with the forum database. So, I'm not going to waste around Rs. 2965. But, if it is fake, how the account hacks are happening ? Few old accounts like Mt. Gox support got active in the forum recently after almost 2 years of non-activity.

Those account were not related to recent database hack, you can check both threads. As for Activity they might came back here to change passwords as theymos did mass mailing to warn all users about hacking. But it's possible that some accounts will get hacked or got hacked.
maheshmahi
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
May 30, 2015, 06:18:36 PM
 #10

Theymos has already warned all of them.
But the group "the hole seekers" who hacked bitcointalk tweeted that they will not gonna stop this.
Amitabh S
Legendary
*
Offline Offline

Activity: 1001
Merit: 1003


View Profile
May 31, 2015, 05:21:47 AM
 #11

https://www.cryptocoinsnews.com/bitcoin-mining-figure-joshua-zipkin-responsible-bitcointalk-hack/

"Is Bitcoin Mining Figure Joshua Zipkin Responsible for the Bitcointalk Hack?"

The circumstantial evidence presented is very strong that he is responsible for the attack.

Probably he hired someone.


Coinsecure referral ID: https://coinsecure.in/signup/refamit (use this link to signup)
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!