Bitcoin Forum
May 06, 2024, 10:31:22 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Who is fuzzing blockchain.info users? [HACK ATTEMP]  (Read 1214 times)
btctalk (OP)
Full Member
***
Offline Offline

Activity: 137
Merit: 112



View Profile WWW
September 25, 2013, 06:48:32 AM
Last edit: September 25, 2013, 07:20:08 AM by btctalk
 #1

I had this in mind a while ago but I guess someone finally did this.

Today I received an email saying:

Quote
Authorize log-in attempt

An attempt to login to your blockchain.info wallet was made from an unknown browser. Please confirm the following details are correct:

Time: 2013-09-25 03:16:43
IP Address: 23.29.121.166 (United States)
User Agent: Python-urllib/2.7

It's a while that I haven't used my blockchain.info wallet in any forms (chrome plugin, mobile app, etc)
As the Python-urllib says, it's a script doing this login from a probably proxy with the specified ip.

something fishy is going on in shirt! secure your accounts Wink

Persian Blockchain Podcast: https://shiryakhat.net
Super Bitcoiner Club http://superbitcoiner.com
Persian Blockchain Community - http://coiniran.com - http://fb.com/IranBitcoin
If you want to be a moderator, report many posts with accuracy. You will be noticed.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
pajak666
Hero Member
*****
Offline Offline

Activity: 746
Merit: 502


Looking for advertising deal


View Profile
September 25, 2013, 10:13:13 AM
 #2

my friend has 0.56 btc stolen from his account today
with this transaction
https://blockchain.info/pl/tx/79adb6e96a6a34017bbd02b4e521ec2a052e219a376210bfc04cf4598cd3c40a
bitcoin44me
Full Member
***
Offline Offline

Activity: 252
Merit: 100


MARKETPLACE FOR PAID ADVICE LIVE BROADCASTS


View Profile
September 25, 2013, 11:08:35 AM
 #3

That could be a bot, or anyone in the world. Just do not click on the link and remove it from your mailbox.

btctalk (OP)
Full Member
***
Offline Offline

Activity: 137
Merit: 112



View Profile WWW
September 27, 2013, 10:45:08 PM
 #4

That could be a bot, or anyone in the world. Just do not click on the link and remove it from your mailbox.

either it's a bot or anyone it is trying to login in my account. and the useragent shows that it's by python so it's probably a large scale hack attempt.


I got another one last night too

Quote
Time: 2013-09-27 07:09:21
IP Address: 96.44.189.101 (United States)
User Agent: Python-urllib/2.7

Persian Blockchain Podcast: https://shiryakhat.net
Super Bitcoiner Club http://superbitcoiner.com
Persian Blockchain Community - http://coiniran.com - http://fb.com/IranBitcoin
DobZombie
Hero Member
*****
Offline Offline

Activity: 896
Merit: 532


Former curator of The Bitcoin Museum


View Profile
September 28, 2013, 02:08:11 PM
 #5

me too!

Quote
Time: 2013-09-28 13:00:14
IP Address: 74.120.13.132 (Anonymous Proxy)
User Agent: Python-urllib/2.7

Tip Me if believe BTC1 will hit $1 Million by 2030
1DobZomBiE2gngvy6zDFKY5b76yvDbqRra
marcovaldo
Sr. Member
****
Offline Offline

Activity: 350
Merit: 250



View Profile
September 28, 2013, 02:22:33 PM
 #6

That could be a bot, or anyone in the world. Just do not click on the link and remove it from your mailbox.

either it's a bot or anyone it is trying to login in my account. and the useragent shows that it's by python so it's probably a large scale hack attempt.


I got another one last night too

Quote
Time: 2013-09-27 07:09:21
IP Address: 96.44.189.101 (United States)
User Agent: Python-urllib/2.7


It does not matter at all, unless your email is compromised and they can click on the link ....

BITEX
            ███     ███     ███
              ███     ███     ███
                ███     ███     ███
                  ███     ███     ███
                    ███     ███     ███
                      ███     ███     ███
                        ███     ███     ███
                          ███     ███     ███
                            ███     ███     ███
                              ███     ███     ███
                            ███     ███     ███
                          ███     ███     ███
                        ███     ███     ███
                      ███     ███     ███
                    ███     ███     ███
                  ███     ███     ███
                ███     ███     ███
              ███     ███     ███
            ███     ███     ███

The First Locally-Embedded, Yet Global, Crypto-Bank
TELEGRAM    FACEBOOK   TWITTER    YOUTUBE    LINE

                  ███     ███     ███
                ███     ███     ███
              ███     ███     ███
            ███     ███     ███
          ███     ███     ███
        ███     ███     ███
      ███     ███     ███
    ███     ███     ███
  ███     ███     ███
███     ███     ███
  ███     ███     ███
    ███     ███     ███
      ███     ███     ███
        ███     ███     ███
          ███     ███     ███
            ███     ███     ███
              ███     ███     ███
               ███     ███     ███
                 ███     ███     ███

WHITEPAPER | ANN
JOIN WHITELIST NOW!
vm1990
Legendary
*
Offline Offline

Activity: 1540
Merit: 1002



View Profile
September 28, 2013, 02:40:01 PM
 #7

this has been going on for a while. someone will be trying top brute force accounts, people with simple passwords like 12345 are pretty screwed or if you password is in a dictionary.. pretty easy to think of a slightly complex password but the hacker only has to get access to 1 or 2 accounts with BTC in them to make it worth his time..

simple rules are
dont be stupid and use a password like Dave or Bob (you use these kinds of passwords then you deserve to get your money taken)
make sure emails arnt scam emails and that you log into the correct site not a clone

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!