Bitcoin Forum
June 20, 2024, 12:34:20 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they believe that the creator of this topic displays some red flags which make them high-risk. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 ... 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 [1428] 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 »
  Print  
Author Topic: FreeBitco.in-$200 FreeBTC⭐Win Lambo🔥0.2BTC DailyJackpot🏆$32,500 Wager Contest  (Read 532662 times)
ID482015
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
April 09, 2024, 02:44:09 PM
 #28541

Hi,
Today, I was playing Muli-BTC as usual and then after some time my account has been locked.
I have only one account, I was not using any VPN and I was not using any bots.
I'm highroller and premium user since the beginning of this program. I'm active FBC user.
As normal I was just using built-in feature "auto-bet" and that's all.
In my history I made a lot of deposits and withdrawals and I've never had a problem.
 
Now when I'm logged in, I have just a blank page with a message:
"Your account is locked. Please contact @hallohap_1 on telegram or fellowyun@proton.me email. Failure to comply will result to a lost of funds."

After some time, e-mail address has changed and at present it is:
Your account is locked. Please contact @hallohap_1 on telegram or bellera12@proton.me email. Failure to comply will result to a lost of funds

https://www.talkimg.com/images/2024/04/09/VeLqf.png

That's very disturbing.


I've just got a response from this email.
"Your browser is hacked. Send 0.5 btc to bc1qhrdvuxrealra5xm7qsu9tyh06k3frcrzuvsms7 to unlock it. Why trust me? I cant withdraw your money because it needs otp and email. Ill wait 1hr before I drain it"

https://www.talkimg.com/images/2024/04/09/Ve7Sw.png

What the heck?

 don t send nothing,   you need an new device  that you dont used on your internet, and try open your account on other device out of your internet provider. , if they have your email address, , i think you need care of too, open your email on another device out of your internet provider, and cahnge your passs keys, enable 2fa in your email, wrote the key of 2fa on paper, and disable phone recovery of your accounts...dont send any bit for anyone.

Yeah, I know. Like I said before I managed to withdraw all BTC funds from my account.
I have also some quite big bag of FUN token there, but it's locked. I will try to use them when FUN savings matured.

Now, fbc page is working as normal, but in case that my account can be compromised I will not use it anymore.
Pity, because I have unlocked all premium benefits and I will have to start over again.

Anyway, it could have ended much worse.

I checked this on different clean device which was never used for fbc (different OS, different browser, different DNS servers) and still my session was somehow hijacked.
It's also possible that my router is compromised but it's highly unlikely.
From my point of view.. I know it's hard to believe and even I have doubts, but it looks like fbc had some security breach or some 3rd party service they were using. Attackers were targeting only some small group of users (including me) and they managed do inject malicious script only for some accounts.
For a week or so I was also getting notifications about change in deposit address (change to P2SH segwit addresses started with 3...), but I ignored that because I didn't plan to make deposits.
Everything was looking legitimate. This message was looking exactly the same as any other notification on fbc site. Same fonts, same colors, etc.

Now everything works as usual, so I guess I will never know what happened.



That's the message I was getting about thr deposit addresses.....


Hmmm
ID482015
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
April 09, 2024, 03:15:08 PM
Last edit: April 09, 2024, 03:32:02 PM by ID482015
Merited by decodx (1)
 #28542

In logs I saw loading a strange js sript so I blocked it with browser plugin and then I managed to withdraw my funds.
+
Now everything works as usual, so I guess I will never know what happened.

- You are unable to understand the "js sript" that you have sucessfully "blocked"? Around here there are people who can help you.

Hey guys I have found the malicious js script on my end I'll paste in on pastebin

this is how its loaded in..... when I check under network in chrome screen shot is as below

https://i.ibb.co/YLBMyvq/Screenshot-2024-04-10-01-24-48.png

This is the pastebin of it https://pastebin.ai/eo0q78pbuj
ID482015
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
April 09, 2024, 03:50:51 PM
 #28543

seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js
Zibi321
Newbie
*
Offline Offline

Activity: 22
Merit: 1


View Profile
April 09, 2024, 04:01:44 PM
 #28544

When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.
ID482015
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
April 09, 2024, 04:07:17 PM
 #28545

When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.
Zibi321
Newbie
*
Offline Offline

Activity: 22
Merit: 1


View Profile
April 09, 2024, 04:13:54 PM
 #28546

When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.

Oh, that's very interesting finding.
My account has different ID, but I believe that scammers have changed the script few hours ago to attack another active user.
piebeyb
Legendary
*
Offline Offline

Activity: 2338
Merit: 1038


Leading Crypto Sports Betting & Casino Platform


View Profile WWW
April 09, 2024, 04:19:53 PM
 #28547

As far as I know, car prices have skyrocketed in the last few years all over the world.  Is the price of a Lambo actually still only $200,000 in the US? Has FreeBitco adjusted their top prize to account for inflation?  Cheesy

Never dreamed of owning a Lambo let alone hoping to get it from this site by collecting gold tickets, I actually don't know if the price of the car has increased due to inflation, if indeed the price has increased I'm sure this site has taken it into account well or maybe there is a series or the type of Lambo that is currently worth $200k, no one knows and I'm not a car lover and don't know for sure its current value, we don't need to doubt this team either because they have given away Lambos so far up to the current round. I'm sure the lucky people who have gotten it already know that.

The $200k price may also just be an estimate but I think a prize of that size is worth it and perhaps not all winners take their Lambo and just exchange bitcoins from the winnings as it might be difficult to pick up the Lambo and receive it from across the country not to mention there will be tax difficulties too other fees, so people prefer to exchange it for bitcoin rather than Lambo, BTW I forgot what round it is now, isn't it already into round 10, who won? It seems I haven't seen a winner in round 10 until now.  Grin

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
ID482015
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
April 09, 2024, 04:28:52 PM
 #28548

When issue was visible I saw that fbc page was loading and after short period of time it's getting covered by some kind of blockpage.
Like message about locked account is in the foreground and a normal fbc webpage is in the background. I tried to blocked it by adding filter to "ublock" plugin but without success.
Then a tried to check network logs from developer tools built-in browser.
I also saw this suspicious url bitwrecked.
 
Unfortunately I didn't took any usefull screenshots or save any logs.
I know that now it's impossible to proof anything.

At some point when I had these two scripts blocked it started to work
https://www.talkimg.com/images/2024/04/09/Vljab.png

But now even with allowed these two scripts to run, page is loading successfully without any concerns.
It looks and works as usual.

seems they are targeting the winners of the multiply btc list which i am on there.....
I was in the top10 daily jackpot leaderboards for a few days in a row.  It could be it.

It just stops auto-roll when you hit 98>= satoshi profit during your rolling session.
To get bonus balance transferred do you "main balance" you have to wager a specific amount of BTC.

in the script its got a user ID of 31898443 who won yesterdays to lock there account.@zibi its the cash travel script that's doing it.

Oh, that's very interesting finding.
My account has different ID, but I believe that scammers have changed the script few hours ago to attack another active user.

I've reported the sire where thr script is hosted for abuse and the bitwrecken domain
FelErYun
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
April 09, 2024, 05:13:34 PM
 #28549

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.
dwyane36
Legendary
*
Offline Offline

Activity: 2898
Merit: 2065



View Profile WWW
April 09, 2024, 08:13:58 PM
 #28550

As far as I know, car prices have skyrocketed in the last few years all over the world.  Is the price of a Lambo actually still only $200,000 in the US? Has FreeBitco adjusted their top prize to account for inflation?  Cheesy


The price of such a luxury car can vary greatly depending on the trim and options. As far as I know, the price of the Lambo Huracan starts at ~$250k and can go up to ~$350k this year. In any case, I don't think it matters since all previous winners of the Lambo lottery most likely preferred to get the prize in BTC equivalent rather than a car.

.
.DuelbitsSPORTS.
▄▄▄███████▄▄▄
▄▄█████████████████▄▄
▄██████████████████████▄
██████████████████████████
███████████████████████████
██████████████████████████████
██████████████████████████████
█████████████████████████████
███████████████████████████
█████████████████████████
▀████████████████████████
▀▀███████████████████
██████████████████████████████
██
██
██
██

██
██
██
██

██
██
██
████████▄▄▄▄██▄▄▄██
███▄█▀▄▄▀███▄█████
█████████████▀▀▀██
██▀ ▀██████████████████
███▄███████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
▀█████████████████████▀
▀▀███████████████▀▀
▀▀▀▀█▀▀▀▀
OFFICIAL EUROPEAN
BETTING PARTNER OF
ASTON VILLA FC
██
██
██
██

██
██
██
██

██
██
██
10%   CASHBACK   
          100%   MULTICHARGER   
decodx
Hero Member
*****
Offline Offline

Activity: 1456
Merit: 935

🇺🇦 Glory to Ukraine!


View Profile
April 09, 2024, 09:03:59 PM
 #28551

seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js

We need to figure out what's injecting that script into the freebitco.in website's HTML. It doesn't seem to be coming from their end, based on what I can see. My HTML source code is clean and free of any suspicious js calls from cashtravel(dot)info domain.
Garmo
Member
**
Offline Offline

Activity: 92
Merit: 36


View Profile
April 09, 2024, 09:44:23 PM
 #28552

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?

Stake.com
Leading Casino: Slots, Blackjack, Roulette, Dice, VIP Club!
Join Now!
Zibi321
Newbie
*
Offline Offline

Activity: 22
Merit: 1


View Profile
April 09, 2024, 09:47:34 PM
Last edit: April 09, 2024, 10:02:06 PM by Zibi321
 #28553

seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js

We need to figure out what's injecting that script into the freebitco.in website's HTML. It doesn't seem to be coming from their end, based on what I can see. My HTML source code is clean and free of any suspicious js calls from cashtravel(dot)info domain.


As far as I can see, malicious code is added to main site document named "?op=home"

Below some screenshots how it looks on my side.
https://www.talkimg.com/images/2024/04/09/j2CCf.png
https://www.talkimg.com/images/2024/04/09/j2QYZ.png
https://www.talkimg.com/images/2024/04/09/j2Gi8.png

Edit:
And also in default index document.
https://www.talkimg.com/images/2024/04/09/j2P49.png
FelErYun
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
April 09, 2024, 11:09:41 PM
 #28554

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.
Garmo
Member
**
Offline Offline

Activity: 92
Merit: 36


View Profile
April 09, 2024, 11:20:36 PM
 #28555

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.

Stake.com
Leading Casino: Slots, Blackjack, Roulette, Dice, VIP Club!
Join Now!
NK345
Newbie
*
Offline Offline

Activity: 22
Merit: 0


View Profile
April 09, 2024, 11:28:33 PM
 #28556

seems they are targeting the winners of the multiply btc list which i am on there.....

I've just blocked the malicous script with adblock add this  to your block list https://cashtravel.info/forum/main.js

i see the same "cashtravel" main.js script in my browser as well.  and i was also in the top 10 before the P2SH message appeared. Sad Sad
FelErYun
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
April 09, 2024, 11:35:21 PM
 #28557

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.

Idk but i saw the xss vulnerability like a year ago. I believe it existed it for alot of years since they added a specific system that i wont mention. there are also multiple other xss that existed for long that hasnt been fixed
Garmo
Member
**
Offline Offline

Activity: 92
Merit: 36


View Profile
April 09, 2024, 11:45:55 PM
 #28558

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.

Idk but i saw the xss vulnerability like a year ago. I believe it existed it for alot of years since they added a specific system that i wont mention. there are also multiple other xss that existed for long that hasnt been fixed

Interesting. So what critical information could you parse with this xss exploit from the victim's FBC account that you could use for monetary gain? Besides, y'know, scaring them shitless with a message telling them to transfer half a BTC or else.

I'm actually pretty impressed they saw through that bullshit message, by the way. Tracked down the malicious js and blocked it, even. How much BTC did you steal with the address switcheroo?

Stake.com
Leading Casino: Slots, Blackjack, Roulette, Dice, VIP Club!
Join Now!
FelErYun
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
April 10, 2024, 12:11:46 AM
 #28559

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.

Idk but i saw the xss vulnerability like a year ago. I believe it existed it for alot of years since they added a specific system that i wont mention. there are also multiple other xss that existed for long that hasnt been fixed

Interesting. So what critical information could you parse with this xss exploit from the victim's FBC account that you could use for monetary gain? Besides, y'know, scaring them shitless with a message telling them to transfer half a BTC or else.

I'm actually pretty impressed they saw through that bullshit message, by the way. Tracked down the malicious js and blocked it, even. How much BTC did you steal with the address switcheroo?

i can setup a convincing login page or a verification page but there is no point, if i cant access their email since email requires additional securities these days. the scare message was my desperate attempt to get my final btc because i got into a debt problem after gambling other users money and decided to deposit my own money and borrowed some after losing it all.
i stole 1.3-1.4 in total. Zibi321 could have gotten 9btc in return from my gambling session since i felt bad for him but he decided to lie and ghost me. His money is still on fbc and if only fbc is kind enough to give it back since i spent his balance there.
Garmo
Member
**
Offline Offline

Activity: 92
Merit: 36


View Profile
April 10, 2024, 12:27:35 AM
 #28560

hi :3 i was the one who did it. funny thing i reported stuffs to freebitcoin previously and they ignored it. actually multiple people knew the exploits and was also reported. i waited time to do this and wonder if they still care. i guess not? if you wonder where is the money of those people, i gambled it for those people and blew it all up. its also funny to see people are depositing on a website that has very high house edge. there are alternatives that you can use that has better edge + better support that actually cares for the people.

No way you orchestrated such a high-profile heist like this just to send a message about FBC's house edge. What's the motivation, really?
i just hate fbc. this wouldnt happen if they actually care for the customers. the website is filled with xss exploits and they know it but they just didnt fix it.

How long would you say the XSS vulnerability was in the site for? Crazy to think it was there all this time until you exploited it proper.

Idk but i saw the xss vulnerability like a year ago. I believe it existed it for alot of years since they added a specific system that i wont mention. there are also multiple other xss that existed for long that hasnt been fixed

Interesting. So what critical information could you parse with this xss exploit from the victim's FBC account that you could use for monetary gain? Besides, y'know, scaring them shitless with a message telling them to transfer half a BTC or else.

I'm actually pretty impressed they saw through that bullshit message, by the way. Tracked down the malicious js and blocked it, even. How much BTC did you steal with the address switcheroo?

i can setup a convincing login page or a verification page but there is no point, if i cant access their email since email requires additional securities these days. the scare message was my desperate attempt to get my final btc because i got into a debt problem after gambling other users money and decided to deposit my own money and borrowed some after losing it all.
i stole 1.3-1.4 in total. Zibi321 could have gotten 9btc in return from my gambling session since i felt bad for him but he decided to lie and ghost me. His money is still on fbc and if only fbc is kind enough to give it back since i spent his balance there.

Lie and ghost you? C'mon. He played you like a damn fiddle from where I'm standing. He says he withdrew his entire balance. Finessed you and got away! And don't get me started on the embarrassing reminder emails you sent him a bunch of times. You didn't have to tell me you were desperate, I could hear your knees clanking all the way out here. Is this your first time heisting?

But anyway, wouldn't you have it in your heart to return the stolen BTC, or are you gonna settle your debts with them?

Stake.com
Leading Casino: Slots, Blackjack, Roulette, Dice, VIP Club!
Join Now!
Pages: « 1 ... 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 [1428] 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!