Bitcoin Forum
May 14, 2024, 10:08:50 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: monero exploit reveal ip of nodes  (Read 301 times)
babo (OP)
Legendary
*
Offline Offline

Activity: 3598
Merit: 4146



View Profile WWW
October 22, 2017, 10:13:39 AM
 #1

https://bitsonline.com/monero-exploit-threatens-privacy/

in github proof of concept of attack

we wait a fix Smiley

open source regnat

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
1715681330
Hero Member
*
Offline Offline

Posts: 1715681330

View Profile Personal Message (Offline)

Ignore
1715681330
Reply with quote  #2

1715681330
Report to moderator
1715681330
Hero Member
*
Offline Offline

Posts: 1715681330

View Profile Personal Message (Offline)

Ignore
1715681330
Reply with quote  #2

1715681330
Report to moderator
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715681330
Hero Member
*
Offline Offline

Posts: 1715681330

View Profile Personal Message (Offline)

Ignore
1715681330
Reply with quote  #2

1715681330
Report to moderator
1715681330
Hero Member
*
Offline Offline

Posts: 1715681330

View Profile Personal Message (Offline)

Ignore
1715681330
Reply with quote  #2

1715681330
Report to moderator
Smokey Bob
Member
**
Offline Offline

Activity: 106
Merit: 100


View Profile
October 22, 2017, 11:08:37 AM
 #2

Well that sucks for Monero. A successfull attack like that should scare the people who use Monero. Not like it doesn't have any competitors one could use.

★ ★ ★ ★ ★   DeepOnion  ✔  Anonymous and Untraceable Cryptocurrency  ✔  TOR INTEGRATED & SECURED   ★ ★ ★ ★ ★
› › › › ›  JOIN THE NEW AIRDROP ✈️    ★    ✔ VERIFIED WITH DEEPVAULT  ‹ ‹ ‹ ‹ ‹
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬   ANN  WHITEPAPER  FACEBOOK  TWITTER  YOUTUBE  FORUM   ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
babo (OP)
Legendary
*
Offline Offline

Activity: 3598
Merit: 4146



View Profile WWW
October 22, 2017, 02:21:33 PM
 #3

Well that sucks for Monero. A successfull attack like that should scare the people who use Monero. Not like it doesn't have any competitors one could use.

opensource code can be fixed Smiley
for this reason i wrote "open source regnat"

Wink and monero being more secure

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
wordspavovv
Full Member
***
Offline Offline

Activity: 139
Merit: 100



View Profile
October 22, 2017, 02:27:49 PM
 #4

Well, this is very bad... But world of cryptos is very new and new technologies have problems. It is a good thing that we know about this bug now and not later.

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
DIW ◈    DIWtoken.com    ▐   WHITEPAPERANN THREADTELEGRAM   ▌    SECURITY DECENTRALIZED
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
Febo
Legendary
*
Offline Offline

Activity: 2730
Merit: 1288



View Profile
October 22, 2017, 02:41:13 PM
Last edit: October 22, 2017, 02:57:29 PM by Febo
 #5

https://bitsonline.com/monero-exploit-threatens-privacy/

in github proof of concept of attack

we wait a fix Smiley

open source regnat

Hiding IP is not an exploit!
Those that want to hide their IP they do. Most people that used Monero on darkmarkets uses Tor. Also to access dark market itself.  When Kovri will be added to Monero it will be like everyone uses Tor. That should happen in 2018.


Eh. Is obvious Verge FUG. I see they immediately shill article as it was posted. They will post here also. Probabyl also on Twitter and reddit. When you dont have much to show you attack others, that was mastered by DASH and now Verge greatly use it.
Heye
Member
**
Offline Offline

Activity: 72
Merit: 10


View Profile
October 22, 2017, 02:47:12 PM
 #6

Sounds like the exploit only reveals IP addresses that use monero, but can they link the IP with a monero address or a transaction? sorry but I don't get what the big deal is I never assumed that monero was hidding your IP.

One of the comment says "Some of them had web servers running open to path traversal so you could get their wallets because you know where to look for." can someone explain what this means.
De Selby
Full Member
***
Offline Offline

Activity: 136
Merit: 100


View Profile
October 22, 2017, 03:04:31 PM
 #7

Yeah, because tax evaders and money launderers are all fucking retarded.

So, so dumb that they broadcast their illegal activities on their clear without recourse to Tor or I2P.

I hear that's how Alexandre Cazes of Alphabay bought his Lambo Aventador.
Moved his XMR straight from Alphabay and into a Poloniex account registered under his real name! $900k. Just like that! Easy peasy.</s>
vv181
Legendary
*
Offline Offline

Activity: 1932
Merit: 1273


View Profile
October 22, 2017, 03:23:41 PM
 #8

This is major concern for monero development teams, because most of  us, who use connections straight away is in danger, although if you want  privacy should use tor and combining it with trustworthy VPN provider
eaLiTy
Hero Member
*****
Offline Offline

Activity: 2814
Merit: 911

Have Fun )@@( Stay Safe


View Profile
October 22, 2017, 03:45:19 PM
 #9

This is major concern for monero development teams, because most of  us, who use connections straight away is in danger, although if you want  privacy should use tor and combining it with trustworthy VPN provider
It is really sad to see that there is an exploit in the network but this was a known exploit that it leaked IP address but it does not correlate to any transactions or the time the transaction is done,so it cannot be connected to any transactions what so ever,but a lot of random IP has being leaked ,but none of the transactions that are made are not in danger and that is what i understood with the situation.
beachbummer
Full Member
***
Offline Offline

Activity: 251
Merit: 100


View Profile
October 22, 2017, 03:49:38 PM
 #10

One of the comment says "Some of them had web servers running open to path traversal so you could get their wallets because you know where to look for." can someone explain what this means.

That means that the web server allows you to specify a path to follow from the http document's home directory. Let's say that your web server was set up to serve pages from c:\webpages. You may normally see the file at c:\webpages\index.html (e.g. mywebpage.com/index.html) being served as the home page, but a web server with a very bad configuration may allow you to go to c:\webpages\..\monero_wallet\wallet.file (e.g. mywebpage.com/../monero_wallet/wallet.file).

Thus you have access to the wallet file, but do note this is just a very simplified explanation just for quick understanding
vv181
Legendary
*
Offline Offline

Activity: 1932
Merit: 1273


View Profile
October 22, 2017, 05:09:35 PM
 #11

This is major concern for monero development teams, because most of  us, who use connections straight away is in danger, although if you want  privacy should use tor and combining it with trustworthy VPN provider
It is really sad to see that there is an exploit in the network but this was a known exploit that it leaked IP address but it does not correlate to any transactions or the time the transaction is done,so it cannot be connected to any transactions what so ever,but a lot of random IP has being leaked ,but none of the transactions that are made are not in danger and that is what i understood with the situation.
Well it is a good thing that it only leaked the IP address. But maybe, if the monero team did not fix it fast enough,it could open more possibilities of exploit that can be exploited to gain that information
mR.k0fka
Member
**
Offline Offline

Activity: 210
Merit: 10


View Profile
October 22, 2017, 05:18:52 PM
 #12

it will keep happening with other coins too
a war begins haha
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!