Bitcoin Forum
May 14, 2024, 05:05:17 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Request] Regarding the recent hack.  (Read 643 times)
kougsa (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
June 24, 2015, 12:00:06 AM
 #1

I would like to ask theymos to introduce a field in the profile panel where we could check all the information that got leaked during the hack.

I 'm mostly concerned about registration and last ip address used because it could be used to associate alt accounts.
Many of us use alt accounts for participating in signature giveaways (people often auto-ignore those who use ads in their sigs), or just to be able to express some thoughts more freely (no one wants an angry mob against him just because he called a scam-coin... scam-coin  Tongue ).

The hacker now has more information about my accounts than me and this makes me feel very uncomfortable.

Thank you.

Ps. For obvious reasons i'm using a new account for this post.  Cheesy
In order to achieve higher forum ranks, you need both activity points and merit points.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715663117
Hero Member
*
Offline Offline

Posts: 1715663117

View Profile Personal Message (Offline)

Ignore
1715663117
Reply with quote  #2

1715663117
Report to moderator
1715663117
Hero Member
*
Offline Offline

Posts: 1715663117

View Profile Personal Message (Offline)

Ignore
1715663117
Reply with quote  #2

1715663117
Report to moderator
--Encrypted--
Copper Member
Legendary
*
Offline Offline

Activity: 924
Merit: 1007

hee-ho.


View Profile
June 24, 2015, 12:14:04 AM
 #2

I would like to ask theymos to introduce a field in the profile panel where we could check all the information that got leaked during the hack.

I 'm mostly concerned about registration and last ip address used because it could be used to associate alt accounts.
Many of us use alt accounts for participating in signature giveaways (people often auto-ignore those who use ads in their sigs), or just to be able to express some thoughts more freely (no one wants an angry mob against him just because he called a scam-coin... scam-coin  Tongue ).

The hacker now has more information about my accounts than me and this makes me feel very uncomfortable.

Thank you.

Ps. For obvious reasons i'm using a new account for this post.  Cheesy

why would you need that when you already know what got leaked?

On May 22 at 00:56 UTC, an attacker gained root access to the forum's server. He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server. In the intervening time, it seems that he was able to collect some or all of the "members" table. You should assume that the following information about your account was leaked:
- Email address
- Password hash (see below)
- Last-used IP address and registration IP address
- Secret question and a basic (not brute-force-resistant) hash of your secret answer
- Various settings

full post here
https://bitcointalk.org/index.php?topic=1067985.msg11445725#msg11445725

change everything and you're as good as new. no need to change your email address if it is secure enough and if you don't mind spams. but change it anyway if you want to be sure
kougsa (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
June 24, 2015, 12:25:37 AM
 #3

why would you need that when you already know what got leaked?

I know that ip addresses got leaked in general. I have to know the exact ip addresses to tell if the hacker can associate my accounts or not.
--Encrypted--
Copper Member
Legendary
*
Offline Offline

Activity: 924
Merit: 1007

hee-ho.


View Profile
June 24, 2015, 01:21:49 AM
 #4

why would you need that when you already know what got leaked?

I know that ip addresses got leaked in general. I have to know the exact ip addresses to tell if the hacker can associate my accounts or not.

you can always PM theymos and ask him. that would be easier than what you suggest. tho I'm really not sure if he'll be able to tell exactly which address that got leaked.
dogie
Legendary
*
Offline Offline

Activity: 1666
Merit: 1183


dogiecoin.com


View Profile WWW
June 24, 2015, 01:37:19 AM
 #5

I would like to ask theymos to introduce a field in the profile panel where we could check all the information that got leaked during the hack.

I 'm mostly concerned about registration and last ip address used because it could be used to associate alt accounts.
Many of us use alt accounts for participating in signature giveaways (people often auto-ignore those who use ads in their sigs), or just to be able to express some thoughts more freely (no one wants an angry mob against him just because he called a scam-coin... scam-coin  Tongue ).

The hacker now has more information about my accounts than me and this makes me feel very uncomfortable.

Thank you.

Ps. For obvious reasons i'm using a new account for this post.  Cheesy

Isn't this a theoretical worry, on the database coming into public hands? Which doesn't seem to have yet, probably still floating around some hacker forum.

kougsa (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
June 24, 2015, 03:45:06 AM
 #6

you can always PM theymos and ask him. that would be easier than what you suggest.

Well, i'll do if it's difficult for him to implement it although i think a lot of people would find such a feature helpful.
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5194
Merit: 12985


View Profile
June 24, 2015, 05:01:11 AM
 #7

I don't have that data on hand. I could tell you the IP you used a day before the hack, but I don't have the immediate-post-hack DB backup loaded anywhere.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
Saruvn
Newbie
*
Offline Offline

Activity: 21
Merit: 0


View Profile
June 24, 2015, 08:36:17 AM
 #8

Yes , PM theymos or badbear , and they will generally help you with this.

Edit: Havent checked that theymos have already replied here  Grin
UnrealBeast
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
June 25, 2015, 04:52:43 PM
 #9

I don't have that data on hand. I could tell you the IP you used a day before the hack, but I don't have the immediate-post-hack DB backup loaded anywhere.
theymos check u pm about something important
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!