Bitcoin Forum
May 06, 2024, 01:14:38 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ecurrency exchange website hack  (Read 1418 times)
ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 08, 2013, 10:18:50 PM
Last edit: September 11, 2013, 11:37:04 PM by ITsTanked
 #1

Admin not respond so I sell to high bidder.
1715001278
Hero Member
*
Offline Offline

Posts: 1715001278

View Profile Personal Message (Offline)

Ignore
1715001278
Reply with quote  #2

1715001278
Report to moderator
Bitcoin addresses contain a checksum, so it is very unlikely that mistyping an address will cause you to lose money.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715001278
Hero Member
*
Offline Offline

Posts: 1715001278

View Profile Personal Message (Offline)

Ignore
1715001278
Reply with quote  #2

1715001278
Report to moderator
og kush420
Full Member
***
Offline Offline

Activity: 1050
Merit: 110



View Profile
September 09, 2013, 12:17:04 AM
 #2

are passwords in plaintext is what i want to know. not going to buy it, but just curious

ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 09, 2013, 01:43:00 AM
 #3

all are in md5.  I add this to listing
ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 09, 2013, 04:54:47 PM
 #4

5 hour left
ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 10, 2013, 03:10:04 PM
 #5

buyer not pay yet so relist
vesperwillow
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500


View Profile
September 10, 2013, 06:42:19 PM
 #6

So.. has this been proven or is it just using classic sql injection hoping it'll work?

And..... yeah. Quite an interesting thread you have here..

ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 10, 2013, 07:07:41 PM
 #7

So.. has this been proven or is it just using classic sql injection hoping it'll work?

And..... yeah. Quite an interesting thread you have here..

Hope?
I get in and read all 104 tables and see 15k users so it work.
hamburger
Full Member
***
Offline Offline

Activity: 241
Merit: 107



View Profile WWW
September 10, 2013, 11:29:30 PM
 #8

Hi,

Bull Sh..

This is my username Hamburger

You have my permission to publish my registered Full name, LTC balance, email address and password here as prove that it work.

Hamburger

Datacoin : DHZ6H91fsDoBHbdqED3ysCJJ2TUh3zRMZD
Krugercoin : Yz3A9sTMp2yh5QLuAL8YQyvS5PdjHRHkkf
uoyeparannog
Member
**
Offline Offline

Activity: 72
Merit: 10


Drunk Lunatic


View Profile WWW
September 11, 2013, 01:52:39 AM
 #9

Note somewhere that I owe You beer, Hamburger.

Chaos Prediction Center
1ChaosQ9uFudq5Xy8i9tiiECiDhKbtjiJd
ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 11, 2013, 06:05:17 PM
 #10

Admin reply me now finally.  I tell him the flaw for free because it is his site. 
vesperwillow
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500


View Profile
September 11, 2013, 06:36:28 PM
 #11

Hamburger: 1
ITsTanked: 0

uoyeparannog
Member
**
Offline Offline

Activity: 72
Merit: 10


Drunk Lunatic


View Profile WWW
September 11, 2013, 09:15:30 PM
 #12

Of course, vesperwillow.
Anyway, that site is full of shit - FPD, some leaks, index of's and other non-critical issues. I didn't made deep test (I didn't create account even, just 5-minutes browse) so there's small chance for blind sqli, but I REALLY doubt it.

Chaos Prediction Center
1ChaosQ9uFudq5Xy8i9tiiECiDhKbtjiJd
ITsTanked (OP)
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
September 11, 2013, 11:47:24 PM
 #13

I remove link in 1st post now that I am talking to admin.  There is a job put on freelancer.com about this now.

admin contact me and then my conciseness get to me and I realize I should tried harder to get this to admin so I apologize to him and tell him the exact sqli point and how to temporary fix it until the code for this section is fixed.   
joesmoe2012
Hero Member
*****
Offline Offline

Activity: 882
Merit: 501


Ching-Chang;Ding-Dong


View Profile WWW
September 12, 2013, 04:12:16 PM
 #14

    What site was it?     

Check out BitcoinATMTalk - https://bitcoinatmtalk.com
uoyeparannog
Member
**
Offline Offline

Activity: 72
Merit: 10


Drunk Lunatic


View Profile WWW
September 12, 2013, 08:54:18 PM
 #15

goldux.com

Chaos Prediction Center
1ChaosQ9uFudq5Xy8i9tiiECiDhKbtjiJd
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!