U1TRA_L0RD
Full Member
Offline
Activity: 126
Merit: 100
CAUTION: Angry Man with Attitude.
|
|
February 02, 2014, 08:41:34 PM |
|
Hmm, Java script ? Exploits,
|
|
|
|
tkbx
|
|
March 13, 2014, 12:41:29 PM |
|
Do you release information about vulnerabilities once they're fixed, or is obscurity safer in this case?
|
|
|
|
rero2
Member
Offline
Activity: 66
Merit: 10
|
|
March 22, 2014, 12:25:12 PM |
|
if I find anything I will surely tell you about it. Goodluck and hopefully there arent many vulnerabilities
|
|
|
|
bluefirecorp
Legendary
Offline
Activity: 882
Merit: 1000
|
|
May 24, 2014, 04:50:54 AM |
|
This is epic. I've actually started actively looking for vulnerabilities now that I JUST found this bug bounty program
|
|
|
|
NLNico
Legendary
Offline
Activity: 1876
Merit: 1295
DiceSites.com owner
|
|
May 25, 2014, 04:12:30 AM |
|
This is epic. I've actually started actively looking for vulnerabilities now that I JUST found this bug bounty program If you are finished with this bug bounty program, you can have a look at the 30+ other bug bounty programs that pay Bitcoins Overview of Bug Bounty Programs for Bitcoins > https://bitcointalk.org/index.php?topic=483195.0
|
|
|
|
bluefirecorp
Legendary
Offline
Activity: 882
Merit: 1000
|
|
May 25, 2014, 08:04:54 PM |
|
This is epic. I've actually started actively looking for vulnerabilities now that I JUST found this bug bounty program If you are finished with this bug bounty program, you can have a look at the 30+ other bug bounty programs that pay Bitcoins Overview of Bug Bounty Programs for Bitcoins > https://bitcointalk.org/index.php?topic=483195.0Neat. Thanks a lot for the link. I'll get a few of my netsec friends to take a look at the list and see if they can find anything. Everything at bitcointalk seems pretty secure from what I've tried so far.
|
|
|
|
e1ghtSpace
Legendary
Offline
Activity: 1540
Merit: 1001
Crypto since 2014
|
|
August 12, 2014, 10:42:00 AM Last edit: August 12, 2014, 08:13:11 PM by e1ghtSpace |
|
Does this count as an exploit?
<----- it has nothing to do with security but still... Edit: it got fixed. Got 0.03 btc for it.
|
|
|
|
MakeBelieve
|
|
August 12, 2014, 08:31:34 PM |
|
So should we test this on this actual website or should I test for vulnerabilities on a local host and the contact admin if I find any vulnerabilities on the same version? I don't want to risk getting into trouble testing on this forum just in case I do get into something I'm not suppose to unless it's allowed as long as you report it.
|
On a mission to make Bitcointalk.org Marketplace a safer place to Buy/Sell/Trade
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
|
September 08, 2014, 09:53:06 AM |
|
Does this count as an exploit?
<----- it has nothing to do with security but still... Edit: it got fixed. Got 0.03 btc for it.
what was it? unicode control codes?
|
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
|
September 08, 2014, 09:54:04 AM |
|
Does changing your display name, or registering a new username with prohibited strings (e.g. Satoshi) count as something that would receive a bounty?
|
|
|
|
theymos (OP)
Administrator
Legendary
Offline
Activity: 5376
Merit: 13407
|
|
September 08, 2014, 08:54:54 PM |
|
Does changing your display name, or registering a new username with prohibited strings (e.g. Satoshi) count as something that would receive a bounty?
It's not covered in this bounty, but I'd probably pay a little for info about some bugs of that sort. Some things (like various ways to visually defeat prohibited strings) are known bugs that aren't likely to be fixed.
|
1NXYoJ5xU91Jp83XfVMHwwTUyZFK64BoAD
|
|
|
Cyrus
Ninja
Administrator
Legendary
Offline
Activity: 3948
Merit: 3152
|
|
September 08, 2014, 09:48:01 PM Last edit: September 08, 2014, 10:01:55 PM by Cyrus |
|
I was meaning to raise awareness about people using different characters to make their usernames visually similar to some trustworthy members on bitcointalk. Example: ṣatoshi, theymoṣ, ṫheymos etc.* Why not limit the charset to UTF-8, and maybe some non-visually interfering symbols?
*As of yet, there aren't any usernames containing the characters ṣ and ṫ, but I could compile a list of such characters just to show how easy it is to try and register such a username.
|
|
|
|
cakir
Legendary
Offline
Activity: 1274
Merit: 1000
★ BitClave ICO: 15/09/17 ★
|
|
September 10, 2014, 11:29:46 PM |
|
I've sent a pm to theymos, I hope he doesn't miss it (it's not a code hack etc.)
|
|
|
|
| ,'#██+: ,█████████████' +██████████████████ ;██████████████████████ ███████: .███████` ██████ ;█████' `█████ #████# ████+ `████+ ████: ████, ████: .# █ ████ ;███+ ██ ███ ████ ████ ███' ███. '███, +███ #████ ,████ ████ ████ █████ .+██████: █████+ `███. ,███ ███████████████████████ ████ ████ ███████████████████████' :███ ███: +████████████████████████ ███` ███ █████████████████████████` ███+ ,███ ██████████████████████████ #███ '███ '██████████████████████████ ;███ #███ ███████████████████████████ ,███ ████ ███████████████████████████. .███ ████ ███████████████████████████' .███ +███ ███████████████████████████+ :███ :███ ███████████████████████████' +███ ███ ███████████████████████████. ███# ███. #██████████████████████████ ███, ████ █████████████████████████+ `███ '███ '████████████████████████ ████ ███; ███████████████████████ ███; ████ #████████████████████ ████ ███# .██████████████████ `███+ ████` ;██████████████ ████ ████ '███████#. ████. .████ █████ '████ █████ #████' █████ +█████` ██████ ,██████: `███████ ████████#;,..:+████████. ,███████████████████+ .███████████████; `+███████#,
| |
|
|
|
IceTurk
Member
Offline
Activity: 84
Merit: 10
|
|
November 16, 2014, 04:36:31 PM |
|
The only major flaw in this forum that I can see is that you are using SMF as your forum software. Can't wait until the new platform arrives.
|
|
|
|
soowein
Newbie
Offline
Activity: 42
Merit: 0
|
|
March 25, 2015, 10:40:40 AM |
|
Do you release information about vulnerabilities once they're fixed, or is obscurity safer in this case?
Thanks !
|
|
|
|
🏰 TradeFortress 🏰
Bitcoin Veteran
VIP
Legendary
Offline
Activity: 1316
Merit: 1043
👻
|
|
May 26, 2015, 01:49:39 AM |
|
Time for social engineering to be added as a valid attack?
|
|
|
|
Check-0
|
|
May 26, 2015, 07:09:36 AM |
|
Time for social engineering to be added as a valid attack?
to kill all "social engineers" theymos must host forums in his basement on dedicated server with fat connectivity. Problem solved !
|
He иcкyшaй мeня, ибo нeoбyздaн я в жeлaнияx cвoиx... Xoчeшь я взopвy вce звeзды и Зaвтpa нe нacтyпит никoгдa..?
|
|
|
macsga
Legendary
Offline
Activity: 1484
Merit: 1002
Strange, yet attractive.
|
|
May 27, 2015, 07:19:17 AM |
|
If I may, the main problem with security vulnerabilities is our lack to understand that most of them are based on breaking some very simple rules. For instance, anyone who has the ability to physically access my computer is -in theory- able to retrieve ANY password that I have stored inside my web-browser and/or key-chain. You may be now thinking "oh, this is not possible" but please take some time to use some good UN-delete software together with a web-browser password retriever utility and most probably you will get the job done in less than 10 mins. Brute forcing is another way, but will take more time.
@Theymos: It's been sometime now that I thought about the possible attacks this (and similar) sites will get within the next BTC bubble. I expect this will get much worse. Restricting user access via Tor blocking (I know this will hurt me as well, because I'm using tor from my work to access the site) will definitely rule out some of the most significant attacks. Cloudflare is also a way, but I'd go for a dedicated person(s) service. You can hire one that you trust, most possible near where you live. This would've been the best case scenario I'd choose, if I were you.
Best of luck sorting this out.
|
Chaos could be a form of intelligence we cannot yet understand its complexity.
|
|
|
Check-0
|
|
May 27, 2015, 08:19:21 AM Last edit: May 27, 2015, 08:31:16 AM by Check-0 |
|
of course i was joking about dedicated server in basement. such setup will have issues with load balancing and speed of connection likely. also it will be stil centralised service. If theymos wanna save his income and keep community here, he should : i) invest in decentralised forum software, or some day such forum engine will become reality, but not under his control, written by other guys.Community will switch to it after next couple of hacks here.Theymos must be smart and proactive ii) make sure to have auth of members without passwords ( maybe with bitcoin keys or other virtual identities ). iii) never store hashes and IPs in Internet-hosted DB. take a look : https://unhosted.org/iiii) abolish email usage for passwords' recovery ( there are safer means of communication ). iiiii) drop "security question checking" feature for password recovery. If Bitcointalk will stay centralised, what will happen when next bubble of greater adoption will arrive ?? How many members can bear 1 forum engine ( SMF or Epochtalk ) ?? At least theymos should go to several federated servers for forums... I am not sure what is the year right now for theymos and team ?! Are we really in 2015 ?!
|
He иcкyшaй мeня, ибo нeoбyздaн я в жeлaнияx cвoиx... Xoчeшь я взopвy вce звeзды и Зaвтpa нe нacтyпит никoгдa..?
|
|
|
NLNico
Legendary
Offline
Activity: 1876
Merit: 1295
DiceSites.com owner
|
|
May 27, 2015, 08:43:18 AM |
|
i) invest in decentralised forum software, or some day such forum engine will become reality, but not under his control, written by other guys.Community will switch to it after next couple of hacks here.Theymos must be smart and proactive Performance of decentralized forum software at this point will be very shit AFAIK. And usability probably bad too (gotta download client?) ii) make sure to have auth of members without passwords ( maybe with bitcoin keys or other virtual identities ). You want people to sign a message with a bitcoin address every time they login? Seriously, "don't use passwords" is easier said than done. Login with Trezor Connect would be cool though. And 2FA should obv be option. iii) never store hashes and IPs in Internet-hosted DB. Not storing IPs def will be bad against spam / trolls / etc. iiii) abolish email usage for passwords' recovery ( there are safer means of communication ). Well for some people it's just about usability. But an optional option to only do (automatic, not manual like now) recovery by signing w/ a specific addy would be cool. If Bitcointalk will stay centralised, what will happen when next bubble of greater adoption will arrive ?? How many members can bear 1 forum engine ( SMF or Epochtalk ) ?? Are you telling me decentralization is better for scalability/performance at this point? Def not. Also interesting you are first for keeping IPs private but now you want a P2P forum? Not disagreeing with all points, but some things are easier said than done
|
|
|
|
|