Bitcoin Forum
May 11, 2024, 09:27:59 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: BTC Guild Security Warning!  (Read 1932 times)
terminator (OP)
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
June 28, 2011, 04:28:00 PM
 #1

Recently BTC guild replaced all the secure https links on the menu with http links.
Also the site now has google ads which load javascript from insecure http.

This allows man in the middle attacks on your accounts.
An attacker can hijack the insecure request to google and inject javascript into btc guild pages to steal cookies/money, even if your on a https page.
If you click any of the links in the menu, your login cookies are sent over plain text http.
I sent an email to them about this and got no response.

If you use Tor to access btc guild, you are especially vulnerable to this.
1715462879
Hero Member
*
Offline Offline

Posts: 1715462879

View Profile Personal Message (Offline)

Ignore
1715462879
Reply with quote  #2

1715462879
Report to moderator
1715462879
Hero Member
*
Offline Offline

Posts: 1715462879

View Profile Personal Message (Offline)

Ignore
1715462879
Reply with quote  #2

1715462879
Report to moderator
1715462879
Hero Member
*
Offline Offline

Posts: 1715462879

View Profile Personal Message (Offline)

Ignore
1715462879
Reply with quote  #2

1715462879
Report to moderator
"This isn't the kind of software where we can leave so many unresolved bugs that we need a tracker for them." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715462879
Hero Member
*
Offline Offline

Posts: 1715462879

View Profile Personal Message (Offline)

Ignore
1715462879
Reply with quote  #2

1715462879
Report to moderator
TurdHurdur
Full Member
***
Offline Offline

Activity: 216
Merit: 100


View Profile
June 28, 2011, 05:26:32 PM
 #2

Good work getting the BTCGuild thread deleted. Tongue
mike85123
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
June 28, 2011, 05:30:36 PM
 #3

I posted to the thread (where did it go btw?) asking if he could deliver ads via ssl and never got a response. Started donating to remove ads and there is still a warning from Chrome that there are still some items not being delivered over ssl. Would be nice to just have everything run over ssl.
TurdHurdur
Full Member
***
Offline Offline

Activity: 216
Merit: 100


View Profile
June 28, 2011, 05:34:23 PM
 #4

Try QuietUrl, add
^http://www\.btcguild\.com/(.*) https://www.btcguild.com/$1
and make sure enabled is checked.
Clipse
Hero Member
*****
Offline Offline

Activity: 504
Merit: 502


View Profile
June 28, 2011, 05:35:27 PM
 #5

wtf who deleted the btcguild thread?

...In the land of the stale, the man with one share is king... >> Clipse

We pay miners at 130% PPS | Signup here : Bonus PPS Pool (Please read OP to understand the current process)
hart
Newbie
*
Offline Offline

Activity: 14
Merit: 0



View Profile WWW
June 28, 2011, 05:36:07 PM
Last edit: June 29, 2011, 01:17:06 PM by hart
 #6

I posted to the thread (where did it go btw?) asking if he could deliver ads via ssl and never got a response. Started donating to remove ads and there is still a warning from Chrome that there are still some items not being delivered over ssl. Would be nice to just have everything run over ssl.

AdSense doesn't support SSL (yet, anyway). Source.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!