Bitcoin Forum
December 03, 2016, 01:44:04 PM *
News: Latest stable version of Bitcoin Core: 0.13.1  [Torrent].
 
   Home   Help Search Donate Login Register  
Pages: [1]
  Print  
Author Topic: Captain obvious: "Change your mybitcoin passwords"  (Read 1248 times)
AngstHase
Jr. Member
*
Offline Offline

Activity: 31


View Profile
June 21, 2011, 09:33:58 AM
 #1

One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.


Definitely the attacker got some more accounts cashed out.
http://blockexplorer.com/address/1MAazCWMydsQB5ynYXqSGQDjNQMN3HFmEu

1480772644
Hero Member
*
Offline Offline

Posts: 1480772644

View Profile Personal Message (Offline)

Ignore
1480772644
Reply with quote  #2

1480772644
Report to moderator
1480772644
Hero Member
*
Offline Offline

Posts: 1480772644

View Profile Personal Message (Offline)

Ignore
1480772644
Reply with quote  #2

1480772644
Report to moderator
1480772644
Hero Member
*
Offline Offline

Posts: 1480772644

View Profile Personal Message (Offline)

Ignore
1480772644
Reply with quote  #2

1480772644
Report to moderator
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1480772644
Hero Member
*
Offline Offline

Posts: 1480772644

View Profile Personal Message (Offline)

Ignore
1480772644
Reply with quote  #2

1480772644
Report to moderator
foo
Sr. Member
****
Offline Offline

Activity: 409



View Profile
June 21, 2011, 11:25:31 AM
 #2

One of my friends got hacked on mybitcoin.com. He used the self username/password combination as on mtgox.

However his password was salt-hashed in the mtgox database, and far as I know its impossible to hack a salted hashvalue without the special salt hash/hex key.
*facepalm* No, the salt is right there in the file, next to the hash. What the salt does is make it impractical to use precomputed tables, you have to brute force the password. If the password is very weak this does not take long.

I know this because Tyler knows this.
Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!