Bitcoin Forum
April 27, 2024, 07:18:52 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 [15] 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 »
  Print  
Author Topic: [1423GH] ABCPool PPS - Proxy Pool For High & Steady Mining Rewards  (Read 151534 times)
bitlane
Internet detective
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


I heart thebaron


View Profile
November 04, 2011, 02:03:21 AM
 #281

It is the address with which I registered and it is the actual address from the control panel. I did not change anything. They sent the payment to the wrong address.
Looks like someone got access to your account and changed your wallet address. Do you have a weak password ? or does this have to do with teh fact that ABC does not have https setup and someone just packaet sniffed all they needed..... ?

Look in your control panel and see what the address is now, as your default. Did they change it back to your old one ?

1714202332
Hero Member
*
Offline Offline

Posts: 1714202332

View Profile Personal Message (Offline)

Ignore
1714202332
Reply with quote  #2

1714202332
Report to moderator
1714202332
Hero Member
*
Offline Offline

Posts: 1714202332

View Profile Personal Message (Offline)

Ignore
1714202332
Reply with quote  #2

1714202332
Report to moderator
1714202332
Hero Member
*
Offline Offline

Posts: 1714202332

View Profile Personal Message (Offline)

Ignore
1714202332
Reply with quote  #2

1714202332
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714202332
Hero Member
*
Offline Offline

Posts: 1714202332

View Profile Personal Message (Offline)

Ignore
1714202332
Reply with quote  #2

1714202332
Report to moderator
ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:04:36 AM
 #282

It is not an easy password. The address is not changed in the control panel. Beside the adress they should have guess also the PIN.
I believe it is a bug in the automated payment module.

bitlane
Internet detective
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


I heart thebaron


View Profile
November 04, 2011, 02:06:10 AM
 #283

It is not an easy password. The address is not changed in the control panel.
Well, looks like the pool OP owes you 25 BTC Wink

bitlane
Internet detective
Sr. Member
****
Offline Offline

Activity: 462
Merit: 250


I heart thebaron


View Profile
November 04, 2011, 02:07:55 AM
 #284

Those are decent payouts. What is your GH/s mining rate ?

ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:08:55 AM
 #285

We will see after they check their logs. Do not use the automatic payment feature until this is checked out.

It is not an easy password. The address is not changed in the control panel.
Well, looks like the pool OP owes you 25 BTC Wink

ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:09:54 AM
 #286

Around 12GH/s.

Those are decent payouts. What is your GH/s mining rate ?

MintCondition (OP)
Legendary
*
Offline Offline

Activity: 1147
Merit: 1007



View Profile
November 04, 2011, 02:21:00 AM
 #287

Hello there,

There is a problem with the automatic payment.
I had an automatic payment of 25 bitcoins which went to a different address which is not mine.
Here is a pic:
The top address is not mine and the actual address in the account is still 1ATRa5im91QsuNDYL81BpvhENuJWE78Ets.
Please advise!
Hi Ciuciu,

That's a pretty serious amount; We've immediately halted all payments while we investigate this matter to avoid additional losses. It could very well be that someone has gained unauthorized access to our systems.

I'm investigating the matter now, and will keep you posted as I learn more.

Eveofwar
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250


View Profile
November 04, 2011, 02:28:48 AM
 #288

Hello there,

There is a problem with the automatic payment.
I had an automatic payment of 25 bitcoins which went to a different address which is not mine.
Here is a pic:
The top address is not mine and the actual address in the account is still 1ATRa5im91QsuNDYL81BpvhENuJWE78Ets.
Please advise!
Hi Ciuciu,

That's a pretty serious amount; We've immediately halted all payments while we investigate this matter to avoid additional losses. It could very well be that someone has gained unauthorized access to our systems.

I'm investigating the matter now, and will keep you posted as I learn more.

Sounds like he got compromised...simple google search of "ciuciu bitcoin" reveals some user/password lists that the name is listed on:

http://www.google.com/search?btnG=1&pws=0&q=ciuciu+bitcoin

ciuciu:albastru   <---- I hope this wasn't your ABCPool.co password.
ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:29:04 AM
 #289

Hi,
I checked with the block exporer, but I do not understand the output.
http://blockexplorer.com/tx/17048250d465f25243fc7a09b24379989302b19f9176acd5fc63ac51a48ea561#o1
I will try a manual payment  to see if it is working.
Thanks.

ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:31:29 AM
 #290

That was leaked by MtGox. I use a different user and password.

Hello there,

There is a problem with the automatic payment.
I had an automatic payment of 25 bitcoins which went to a different address which is not mine.
Here is a pic:
The top address is not mine and the actual address in the account is still 1ATRa5im91QsuNDYL81BpvhENuJWE78Ets.
Please advise!
Hi Ciuciu,

That's a pretty serious amount; We've immediately halted all payments while we investigate this matter to avoid additional losses. It could very well be that someone has gained unauthorized access to our systems.

I'm investigating the matter now, and will keep you posted as I learn more.

Sounds like he got compromised...simple google search of "ciuciu bitcoin" reveals some user/password lists that the name is listed on:

http://www.google.com/search?btnG=1&pws=0&q=ciuciu+bitcoin

ciuciu:albastru   <---- I hope this wasn't your ABCPool.co password.


chunglam
Donator
Full Member
*
Offline Offline

Activity: 229
Merit: 106



View Profile
November 04, 2011, 02:33:20 AM
 #291

That address is exactly same as the address stole my 2 BTC Sad. I believe either your account and my account hacked by the same person or ABC system compromised by hacker.
Eveofwar
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250


View Profile
November 04, 2011, 02:34:19 AM
 #292

Well, that's somewhat promising then...but there have been other password leaks around the Bitcoin community.  Hope the best for you !

Note to MintCondition: I attempted to login to the account about 5 minutes ago using the credentials provided (which failed), don't kill me Smiley
ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:34:42 AM
 #293

When this happened?

That address is exactly same as the address stole my 2 BTC Sad. I believe either your account and my account hacked by the same person or ABC system compromised by hacker.

Eveofwar
Sr. Member
****
Offline Offline

Activity: 406
Merit: 250


View Profile
November 04, 2011, 02:35:32 AM
 #294

When this happened?

That address is exactly same as the address stole my 2 BTC Sad. I believe either your account and my account hacked by the same person or ABC system compromised by hacker.

http://blockexplorer.com/address/13Sv8joH75nUPufd4fEqjAhum9kdnUexgm

You can see your transaction in there, and the one previous...presumably his.
MintCondition (OP)
Legendary
*
Offline Offline

Activity: 1147
Merit: 1007



View Profile
November 04, 2011, 02:37:32 AM
 #295

Hi,
I checked with the block exporer, but I do not understand the output.
http://blockexplorer.com/tx/17048250d465f25243fc7a09b24379989302b19f9176acd5fc63ac51a48ea561#o1
I will try a manual payment  to see if it is working.
Thanks.
'not yet redeemed' means that the receiver of your BTC has not yet spent it.
FYI: All payments, both manual and automatic, have been disabled while we're investigating how this happened.
MC

ciuciu
Donator
Hero Member
*
Offline Offline

Activity: 588
Merit: 500


View Profile
November 04, 2011, 02:39:42 AM
 #296

Got it.
Let me know if you need more info.

Hi,
I checked with the block exporer, but I do not understand the output.
http://blockexplorer.com/tx/17048250d465f25243fc7a09b24379989302b19f9176acd5fc63ac51a48ea561#o1
I will try a manual payment  to see if it is working.
Thanks.
'not yet redeemed' means that the receiver of your BTC has not yet spent it.
FYI: All payments, both manual and automatic, have been disabled while we're investigating how this happened.
MC

chunglam
Donator
Full Member
*
Offline Offline

Activity: 229
Merit: 106



View Profile
November 04, 2011, 03:15:48 AM
 #297

When this happened?

That address is exactly same as the address stole my 2 BTC Sad. I believe either your account and my account hacked by the same person or ABC system compromised by hacker.

Yesterday morning.
plastic.elastic
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 04, 2011, 06:42:49 AM
 #298

damn this is not cool.
 Angry

Tips gladly accepted: 1LPaxHPvpzN3FbaGBaZShov3EFafxJDG42
MintCondition (OP)
Legendary
*
Offline Offline

Activity: 1147
Merit: 1007



View Profile
November 04, 2011, 08:56:24 AM
 #299

I had an automatic payment of 25 bitcoins which went to a different address which is not mine.
..
Please advise!
.. We've immediately halted all payments while we investigate this matter to avoid additional losses. It could very well be that someone has gained unauthorized access to our systems.

I'm investigating the matter now, and will keep you posted as I learn more.
An update on the investigation: The traces left in our logs indicate that the transaction has almost certainly been initiated through the web interface (possibly scripted to guess the PIN numbers). A SQL-Injection is highly unlikely because it would have left a different pattern of traces. In addition, a code re-review did not reveal any open SQL-injection vectors.

The attacker probably did not have access to all accounts, otherwise he could have just as easily taken a lot more while he remained undetected.

In the mean time, we advise everybody to make sure they are not reusing their passwords for other pools or services at ABCPool; please choose a new & difficult password if that's the case. It's easy to guess usernames based on the MtGox list and the forum accounts, and the Bitcoin community isn't that big.

We'll leave the payout disabled for at least another day until we can introduce additional measures to protect our miners from any unwanted withdrawals. For example, enabling you to permanently lock the payout address will surely help.

Now it's time for me to get some sleep!

plastic.elastic
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
November 04, 2011, 09:36:13 AM
 #300

I had an automatic payment of 25 bitcoins which went to a different address which is not mine.
..
Please advise!
.. We've immediately halted all payments while we investigate this matter to avoid additional losses. It could very well be that someone has gained unauthorized access to our systems.

I'm investigating the matter now, and will keep you posted as I learn more.
An update on the investigation: The traces left in our logs indicate that the transaction has almost certainly been initiated through the web interface (possibly scripted to guess the PIN numbers). A SQL-Injection is highly unlikely because it would have left a different pattern of traces. In addition, a code re-review did not reveal any open SQL-injection vectors.

The attacker probably did not have access to all accounts, otherwise he could have just as easily taken a lot more while he remained undetected.

In the mean time, we advise everybody to make sure they are not reusing their passwords for other pools or services at ABCPool; please choose a new & difficult password if that's the case. It's easy to guess usernames based on the MtGox list and the forum accounts, and the Bitcoin community isn't that big.

We'll leave the payout disabled for at least another day until we can introduce additional measures to protect our miners from any unwanted withdrawals. For example, enabling you to permanently lock the payout address will surely help.

Now it's time for me to get some sleep!

Why dont you use browser activation? When a user log into ABC pool from a non-activated browser, an email will be sent to the user's email address to activate that browser. This will help tremendously assuming ppl do use have great password for their email addresses. Only one browser can be activated at any time. So when a user log in from another browser, they will have to re do the process.

Its tedious  but its very effective against remote access hacking.

If the user's computer is hacked then its already game over.

Tips gladly accepted: 1LPaxHPvpzN3FbaGBaZShov3EFafxJDG42
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 [15] 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!