Aahzman (OP)
|
|
May 11, 2013, 01:00:00 PM |
|
After hearing reports of Yacoin wallet stealers, I decided to investigate my Wireshack logs. My computer has made a connection to 31.170.164.138 which is netne.net, and it's a HTTP post.
My wallet is encrypted, however be careful if you have downloaded Yacoin.
|
|
|
|
xibeijan
Legendary
Offline
Activity: 1232
Merit: 1001
|
|
May 11, 2013, 01:02:41 PM |
|
Your YAC p2p software will be making tons of connections to tons of random peers in the network. What's so special about netne.net?
I suspect either FUD OR someone broke into server hosting the binaries and put a backdoor binary in.
YAC Devs--- You need to investigate and make official response and get clean binaries uploaded.
Let's see some action to these claims.
|
|
|
|
Aahzman (OP)
|
|
May 11, 2013, 01:03:23 PM |
|
That's true, however it should not be making a connection to a free web host that does not allow shell access, nor access my Bitcoin wallet.dat file.
|
|
|
|
Mushoz
|
|
May 11, 2013, 01:04:39 PM |
|
That's true, however it should not be making a connection to a free web host that does not allow shell access, nor access my Bitcoin wallet.dat file.
Can you please give me a SHA-1 or MD5 hash of the infected .exe? Would like to check if I'm using the same one.
|
www.bitbuy.nl - Koop eenvoudig, snel en goedkoop bitcoins bij Bitbuy!
|
|
|
hdclover
|
|
May 11, 2013, 01:05:08 PM |
|
when u all realized it , its all too LATE !!!!
|
Blah blah
|
|
|
Aahzman (OP)
|
|
May 11, 2013, 01:05:21 PM |
|
That's true, however it should not be making a connection to a free web host that does not allow shell access, nor access my Bitcoin wallet.dat file.
Can you please give me a SHA-1 or MD5 hash of the infected .exe? Would like to check if I'm using the same one. Will do, 1 secI have actually deleted it, I downloaded it from mega
|
|
|
|
Boxman90
|
|
May 11, 2013, 01:09:38 PM |
|
FUD until proper proof. Stop making 1000 topics.
|
LTC: LKKy4eDWyVtSrQAJy7Qmmz61RaFY91D9yC BTC: 18fzdnCkuUNthCD8hM36UBGopFa9ij78gG
|
|
|
cwfabc
|
|
May 11, 2013, 01:13:48 PM |
|
realy?
|
|
|
|
bennybong
|
|
May 11, 2013, 01:16:24 PM Last edit: May 11, 2013, 01:56:37 PM by bennybong |
|
[MY ACCOUNT WAS COMPROMISED PLEASE IGNORE]
|
|
|
|
rbdrbd
|
|
May 11, 2013, 01:17:59 PM |
|
I just ran wireshark on the yacoin client I downloaded a few hours after launch. I do not see any connections made to that IP on startup, while running, or on shutdown. Fiddler also shows nothing.
IF this is true, perhaps the file could have been compromised at a later date?
|
|
|
|
GröBkAz
|
|
May 11, 2013, 01:18:09 PM |
|
Just anti YAC propaganda from a hand full people. Where is the proof?
|
|
|
|
bit2124
Member
Offline
Activity: 73
Merit: 10
|
|
May 11, 2013, 03:38:10 PM |
|
what is the MD5 of your client, or where is the screenshot
|
|
|
|
SaltySpitoon
Legendary
Offline
Activity: 2590
Merit: 2156
Welcome to the SaltySpitoon, how Tough are ya?
|
|
June 22, 2013, 03:55:58 AM |
|
If anyone has any hard evidence of a wallet stealer in the Yacoin client, please let me know via pm, or something of the sorts. I've seen this rumor going around for weeks if not months now, and so far everything has been inconclusive. I'm not saying it does or doesn't, I'm just saying that I've seen this sort of thread more than a few times, and have been unable to figure out if its some sort of ongoing joke, or if it is real.
|
|
|
|
forsetifox
|
|
June 22, 2013, 04:31:46 AM |
|
I've run 3 different Yacoin clients and I scan everything with Virustotal or Metascan.
Nothing has been taken from me.
|
|
|
|
HotSwap
|
|
June 22, 2013, 04:36:59 AM |
|
This has all been said before about a month ago. It was some random one put up on mega. Just download from Yacoin.org and your fine.
|
|
|
|
HotSwap
|
|
June 22, 2013, 02:57:19 PM |
|
This has all been said before about a month ago. It was some random one put up on mega. Just download from Yacoin.org and your fine.
A link on MEGA kinda was the official link for a while and I guess someone took advantage of that at that time just to make the download look bad. I believe this as well.
|
|
|
|
|