Bitcoin Forum
November 17, 2024, 04:45:20 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 6 7 »  All
  Print  
Author Topic: [ANN][STABLECOIN][POOL][PPLNS][STRATUM][1% FEE] Silverwolf's StableCoin Pool  (Read 8274 times)
nearmiss
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250



View Profile
June 09, 2013, 04:00:31 AM
 #41

I am increasing mine to 5% donation.  Have you fixed the issue that allowed the individual to do that?

I'm pretty sure he used some kind of software or plugin to submit the post data for a manual withdrawal several times in rapid succession (all within the same second), this resulted in multiple payouts being started before the first payout was completed and his balance was reset to 0.

Automatic withdrawals are not subject to this vulnerability because they are run by the cron job.  They cannot be triggered manually.

Manual Withdraws have been disabled completely.  Automatic Withdraws are working normally.

I will not re-enable Manual Withdraws until I'm certain the issue has been fixed.  So we are safe from this happening again, we just won't be able to do manual withdrawals until I can figure it out.



probably want to consider wrapping the process in a transaction, doing the db updates first (update balance, insert into ledger), then the coin send (if the previous sql succeeded), and if the coin send succeeds commit, otherwise rollback.

Just a suggestion.

That might still be vulnerable to the same kind of attack, I'm not sure.  

What I'm thinking is I'm going to separate the actual send function from the front end completely.

Like this :

1. The user hits the withdrawal button and a flag is set in the database.
2. 1 minute later when the cron job runs again it will send the payment, adjust the balance and ledger, and reset the flag.

That way, no matter what you can't trigger multiple payments, you'd just be setting the flag over and over again.  It wouldn't have any effect.

It would mean a short delay (up to 1 minute) in sending manual payments, but that's a pretty small inconvenience.


Yeah, more or less the 'every 60s approach'.  It mimics the safety of the auto-withdraws, which is good.  Good luck with it.  Nothing worse than someone cheating the system.

Profit-Switching Pool w/ Vardiff -> http://hashco.ws  Optionally keep the alts we mine or auto-trade for BTC. In addition can be paid out in any of: 365, AC, BC,  BTC, C2, CINNI, COMM, FAC, HBN, MINT, PMC, QRK, RDD, WC, XBC
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:05:48 AM
Last edit: June 09, 2013, 04:22:45 AM by the1silverwolf
 #42

I am increasing mine to 5% donation.  Have you fixed the issue that allowed the individual to do that?

Thank You for helping !

I'm pretty sure he used some kind of software or plugin to submit the post data for a manual withdrawal several times in rapid succession (all within the same second), this resulted in multiple payouts being started before the first payout was completed and his balance was reset to 0.

Automatic withdrawals are not subject to this vulnerability because they are run by the cron job.  They cannot be triggered manually.

Manual Withdraws have been disabled completely.  Automatic Withdraws are working normally.

I will not re-enable Manual Withdraws until I'm certain the issue has been fixed.  So we are safe from this happening again, we just won't be able to do manual withdrawals until I can figure it out.




Hey, about you delete that post...for obvious reasons.

Well... I don't know about that.  Transparency is important.  This attack is out there and being used regardless if I leave this post up. Other pool owners need to be aware of this attack so they can modify their pools to prevent it.

Leaving it in the dark only helps the people doing the thieving in my opinion.  A more careful thief might have been able to continue doing this without being discovered.  I'm certain it's happening right now to other pools based upon the same or similar mmcFE code.

Does anyone else have an opinion about leaving this data up or taking it down ?  I would consider taking it down if I'm the only one who thinks leaving it up is a good idea.

If I had a way to make it available to only the pool operators or the developer than I would, but I don't.  This same code has been forked a dozen times and is being used by tons and tons of pools.

--
the1silverwolf
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:07:10 AM
 #43


Yeah, more or less the 'every 60s approach'.  It mimics the safety of the auto-withdraws, which is good.  Good luck with it.  Nothing worse than someone cheating the system.

Agreed. and thank you.

--
the1silverwolf
FiiNALiZE
Hero Member
*****
Offline Offline

Activity: 868
Merit: 500

CryptoTalk.Org - Get Paid for every Post!


View Profile
June 09, 2013, 04:24:57 AM
 #44

What a faggot.

He deserves to have his IP DoS'd

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:31:48 AM
 #45

What a faggot.

He deserves to have his IP DoS'd

I don’t disagree with that assessment, lol.

We will recover, it's just a matter of time.

--
the1silverwolf
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:39:12 AM
 #46

I would like to give a shout out to "noble" who is donating 100% of his mining income.  I'm assuming it's to help us recover.  I haven't spoken with him I just noticed him on the PPLNS status list right next to me, at the bottom, lol.

Thank You.

I will remember your assistance and once the pool is back in the black I will make it up to you!


--
the1silverwolf
FiiNALiZE
Hero Member
*****
Offline Offline

Activity: 868
Merit: 500

CryptoTalk.Org - Get Paid for every Post!


View Profile
June 09, 2013, 04:47:19 AM
 #47

What a faggot.

He deserves to have his IP DoS'd

I don’t disagree with that assessment, lol.

We will recover, it's just a matter of time.

Well I finally transferred my rig into a plastic crate.

I'll donate 100% for 12 hours. That should help a bit.

All other pool operators should ban his IP.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:50:30 AM
 #48

What a faggot.

He deserves to have his IP DoS'd

I don’t disagree with that assessment, lol.

We will recover, it's just a matter of time.

Well I finally transferred my rig into a plastic crate.

I'll donate 100% for 12 hours. That should help a bit.

All other pool operators should ban his IP.

Thank You !

Hows the crate working for you ?  I've heard that it makes a big difference but haven't tried it yet myself ?

--
the1silverwolf
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:51:30 AM
Last edit: June 09, 2013, 05:10:27 PM by the1silverwolf
 #49

RESERVED FOR DONATORS:

noble - 100%
FiiNALiZE - 100%
peonminer - 100%
ROGGOR - 100%
ManOfKnight - 100%
yonsje - 50%
Ethera - 10%

Thank You guys !

(If I missed anyone, please let me know !!)

--
the1silverwolf
FiiNALiZE
Hero Member
*****
Offline Offline

Activity: 868
Merit: 500

CryptoTalk.Org - Get Paid for every Post!


View Profile
June 09, 2013, 04:52:41 AM
 #50

What a faggot.

He deserves to have his IP DoS'd

I don’t disagree with that assessment, lol.

We will recover, it's just a matter of time.

Well I finally transferred my rig into a plastic crate.

I'll donate 100% for 12 hours. That should help a bit.

All other pool operators should ban his IP.

Thank You !

Hows the crate working for you ?  I've heard that it makes a big difference but haven't tried it yet myself ?


Makes things a lot neater and the airflow is pretty good.

Lol its a pretty ugly setup because I didn't have the right tools to cut out parts of the crate.

I'll finish everything up tomorrow but I'm just glad everything's working right now Smiley

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:53:32 AM
 #51

On a side note, the network hash has increased to the point where we are now less than than 45% so new user registrations have automatically unlocked so there are some slots available.

They will automatically lock again if we exceed the 45% threshold.

--
the1silverwolf
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 04:57:03 AM
 #52


Thank You !

Hows the crate working for you ?  I've heard that it makes a big difference but haven't tried it yet myself ?


Makes things a lot neater and the airflow is pretty good.

Lol its a pretty ugly setup because I didn't have the right tools to cut out parts of the crate.

I'll finish everything up tomorrow but I'm just glad everything's working right now Smiley

Sounds sweet!  You should post a pic!

--
the1silverwolf
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 05:02:57 AM
 #53

On a side note, the network hash has increased to the point where we are now less than than 45% so new user registrations have automatically unlocked so there are some slots available.

They will automatically lock again if we exceed the 45% threshold.

Wow, that didn't take long.  Back up to 46% and registrations properly locked again.

Anyhow, if your interested in an account keep an eye on the network hash.  As it increases our registrations will automatically unlock.

--
the1silverwolf
peonminer
Hero Member
*****
Offline Offline

Activity: 798
Merit: 531


Crypto is King.


View Profile
June 09, 2013, 05:18:20 AM
 #54

Sorry to hear about the attack. I've adjusted to 100% donation for the good of the people. Silverwolf, please let us know in a thread update or PM that we have recovered the pool funding that was compromised.

I vote to leave the information up and well known. We don't need what ever tools the thief is using to become a widespread problem. If the devs and pool operators can be notified, it needs to be done. A sticky thread in the Pools forum should be made ASAP.
the1silverwolf (OP)
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
June 09, 2013, 05:48:39 AM
Last edit: June 09, 2013, 06:02:55 AM by the1silverwolf
 #55

Sorry to hear about the attack. I've adjusted to 100% donation for the good of the people. Silverwolf, please let us know in a thread update or PM that we have recovered the pool funding that was compromised.

I vote to leave the information up and well known. We don't need what ever tools the thief is using to become a widespread problem. If the devs and pool operators can be notified, it needs to be done. A sticky thread in the Pools forum should be made ASAP.

Thank You and I agree :

https://bitcointalk.org/index.php?topic=229767.new#new
https://bitcointalk.org/index.php?topic=229766.0

--
the1silverwolf
yonvanom
Newbie
*
Offline Offline

Activity: 20
Merit: 0


View Profile
June 09, 2013, 10:08:07 AM
 #56

Sorry to hear about the attack. I'm donating 50% (as yonsje).
Ethera
Member
**
Offline Offline

Activity: 69
Merit: 10


View Profile
June 09, 2013, 10:42:14 AM
 #57

Giving 10% for the time being.
ManOfKnight
Full Member
***
Offline Offline

Activity: 243
Merit: 100


View Profile
June 09, 2013, 02:04:17 PM
 #58

Moving to 100% for a few hours...please let us know when you are close to the black again.
ManOfKnight
Full Member
***
Offline Offline

Activity: 243
Merit: 100


View Profile
June 09, 2013, 02:20:23 PM
 #59

Giving 10% for the time being.

What is bad is Ethera giving 10% is actually MORE than me giving 100%   Roll Eyes
Ethera
Member
**
Offline Offline

Activity: 69
Merit: 10


View Profile
June 09, 2013, 02:57:12 PM
 #60

its not bad Cheesy we all have our sympathies for pool op, so we can do what we can (i mean we dont need to fix this insta second!). Within  a day pool will be back operating normaly, we all happy. (I like seeing numbers pop.. you know what i mean).
Pages: « 1 2 [3] 4 5 6 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!