Bitcoin Forum
April 28, 2024, 06:33:46 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: My Bitcoin Forum account has been compromised!!  (Read 829 times)
Sword Smith (OP)
Sr. Member
****
Offline Offline

Activity: 406
Merit: 286


Neptune, Scalable Privacy


View Profile WWW
June 07, 2013, 10:21:54 AM
 #1

This account seems to have been hacked. Please quote this in another thread so that the attacker cannot

I will update this thread if the attacker does not delete it :/

Do not make any deals with this account until I sign a message saying everything i OK.

1714329226
Hero Member
*
Offline Offline

Posts: 1714329226

View Profile Personal Message (Offline)

Ignore
1714329226
Reply with quote  #2

1714329226
Report to moderator
You can see the statistics of your reports to moderators on the "Report to moderator" pages.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714329226
Hero Member
*
Offline Offline

Posts: 1714329226

View Profile Personal Message (Offline)

Ignore
1714329226
Reply with quote  #2

1714329226
Report to moderator
1714329226
Hero Member
*
Offline Offline

Posts: 1714329226

View Profile Personal Message (Offline)

Ignore
1714329226
Reply with quote  #2

1714329226
Report to moderator
Sword Smith (OP)
Sr. Member
****
Offline Offline

Activity: 406
Merit: 286


Neptune, Scalable Privacy


View Profile WWW
June 07, 2013, 10:29:55 AM
 #2

This account seems to have been hacked. Please quote this in another thread so that the attacker cannot

I will update this thread if the attacker does not delete it :/

Do not make any deals with this account until I sign a message saying everything i OK.

WOW a lot of bitcointalk accounts are getting compromised. Theymos 2FA is need!
I got some emails from Yahoo saying my email had been accessed from Russia. And later I got some info about a verified btc-e transaction. All clues point to btc-e imho. Please quote OP in another thread Smiley

John (John K.)
Global Troll-buster and
Legendary
*
Offline Offline

Activity: 1288
Merit: 1225


Away on an extended break


View Profile
June 07, 2013, 10:34:41 AM
 #3

I banned OP for the time being to stop the spam. I'll ask theymos to look into this, in the meantime CHANGE ALL YOUR PASSWORDS GODDAMNIT.
theymos
Administrator
Legendary
*
Offline Offline

Activity: 5180
Merit: 12900


View Profile
June 07, 2013, 07:43:29 PM
 #4

WOW a lot of bitcointalk accounts are getting compromised. Theymos 2FA is need!

I think that this attack involves stealing cookies using some weakness in Java, so two-factor authentication wouldn't help here.

1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
Mike Christ
aka snapsunny
Legendary
*
Offline Offline

Activity: 1078
Merit: 1003



View Profile
June 07, 2013, 07:45:49 PM
 #5

Java seems to be the center of all hacking attempts related to Bitcoin.

So from now on, words to live by: just don't run Java on any website related to Bitcoin.

The 4ner
aka newbitcoinqtuser
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500


R.I.P Silk Road 1.0


View Profile
June 07, 2013, 07:53:14 PM
 #6

I have a 50 char password and only ever log in through encrypted VPN's. Hopefully that's enough protectiong.
01BTC10
VIP
Hero Member
*
Offline Offline

Activity: 756
Merit: 503



View Profile
June 07, 2013, 07:58:02 PM
 #7

I have a 50 char password and only ever log in through encrypted VPN's. Hopefully that's enough protectiong.
Useless against cookie stealing. Don't click any forum link.
pekv2
Hero Member
*****
Offline Offline

Activity: 770
Merit: 502



View Profile
June 07, 2013, 10:15:45 PM
 #8

WOW a lot of bitcointalk accounts are getting compromised. Theymos 2FA is need!

I think that this attack involves stealing cookies using some weakness in Java, so two-factor authentication wouldn't help here.

Ekk, if this is the case, by damned people need to start locking down their browsers. Easy way for mozilla is cookie monster.

https://addons.mozilla.org/en-US/firefox/addon/cookie-monster/

I'm not being self centered, but my browser is a fortress. Nothing normally that usually gets through a default browser, mine is setup to block. Tons of about:config settings, cookies, noscript,requestpolicy,mvps hosts,adblock with malware blocking list and others, I've got a ton of crap to long to list in here and be ot. [edit]btw, as noted in the other thread, I've got java uninstalled too[/edit]

Need to get a point across to new comers & even old timers about browser security, some how. A browser can be a double doorway to your computer, letting things roll in then out.

Block cookies and only allow cookies you trust for a certain time.

Edit:
Seriously, need a security section here  Smiley
The 4ner
aka newbitcoinqtuser
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500


R.I.P Silk Road 1.0


View Profile
June 08, 2013, 01:02:55 AM
 #9

Damn. Well I do use Ghostery as well and have an app called cookie that also blocks cookies and deletes cookies every 5 minutes while browsing.
MysteryMiner
Legendary
*
Offline Offline

Activity: 1470
Merit: 1029


Show middle finger to system and then destroy it!


View Profile
June 08, 2013, 03:02:10 AM
 #10

I have a 50 char password and only ever log in through encrypted VPN's. Hopefully that's enough protectiong.
VPN will make MITM attack easier by VPN operator. Bitcointalk already uses SSL to protect the contents of communication to Bitcointalk server, including specific urls and cookies.

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
Maged
Legendary
*
Offline Offline

Activity: 1204
Merit: 1015


View Profile
June 08, 2013, 06:06:47 AM
 #11

Say, does the session cookie need to be accessible through JavaScript? If not, we could make the cookies HttpOnly.

D35TR0Y3R
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 08, 2013, 06:10:39 AM
 #12

Say, does the session cookie need to be accessible through JavaScript? If not, we could make the cookies HttpOnly.
Java malware will steal the cookies through the browser's storage directories.

Update: Hi everyone, just to let you guys know that I hacked this account and removed all the negative trust, I've dealt with that scumbag hacker-wannabe extortionist I rooted his fucking machine and stole every last bitcent. I will be in contact with those that he has defrauded and you will be reimbursed fully BM-2D8oHJRsGqH82FDAC2eTEtVmeN7TAVmNBP the1 trojan
MysteryMiner
Legendary
*
Offline Offline

Activity: 1470
Merit: 1029


Show middle finger to system and then destroy it!


View Profile
June 08, 2013, 08:04:18 PM
 #13

Say, does the session cookie need to be accessible through JavaScript? If not, we could make the cookies HttpOnly.
Java malware will steal the cookies through the browser's storage directories.
Malware can do anything. Don't run malware on your computer. Period.

Specify time to stay logged in when logging in. Log out your forum profile when leaving forum. Useless cookie is not delicious.

bc1q59y5jp2rrwgxuekc8kjk6s8k2es73uawprre4j
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!