Bitcoin Forum
October 31, 2024, 01:18:56 PM *
News: Bitcoin Pumpkin Carving Contest
 
   Home   Help Search Login Register More  
Pages: « 1 ... 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 [609] 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761597 times)
PaulyC
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile WWW
January 02, 2014, 02:00:00 AM
 #12161

Yea i saw that.. that hurts man, mine was a total loss of 7808, hurt a lot, i bought slowly over time since Dec. 21st. but I still love this currency!

Doge Mars Landing Foundation
(founder) Coined the phrase, "Doge to the Mars" and "Check that Hash!". Discoverer of the 2013 NXT nefarious wallet.  Admin. FameMom [FAMOM]
S3MKi
Legendary
*
Offline Offline

Activity: 1540
Merit: 1016



View Profile
January 02, 2014, 02:00:35 AM
 #12162

What to do if other users have false client?
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 02, 2014, 02:01:37 AM
 #12163

Ok here are the two zip files in one file.
The bigger one is the one I DLed from Nextcoin.org and used when my NXT were stolen. the smaller one I believe was the one posted on the front page?

DO NOT USE THIS FILE FOR NXT:
https://mega.co.nz/#!lZQBXQqK!EpQQbx9uBy9gcQe7-vc8smWDwHcM7LBODbtoCpKNXNo

Got it. The bogus client is in the link. Can someone check where is the modification ?

You have got to be absolutely fricking kidding me.  I have downloaded from mega.co.nz on Tues and walked it over to my nice sterile laptop....  

Excuse me while I go do an emergency client download from a trusted source and move my NXT to a new account with a zillion character new passcode....

And when this all settles down I'm going to bring up again a few more dozen times the idea of implementing a withdrawal freeze code....
newcn
Full Member
***
Offline Offline

Activity: 143
Merit: 100


View Profile
January 02, 2014, 02:02:36 AM
 #12164

PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history,  
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

162.243.246.223 looks like it is "epicdices.com" (http://domain-kb.com/www/epicdices.com)
Owner of epicdices - EpicThomas - is a member of this topic:
https://bitcointalk.org/index.php?action=profile;u=172850;sa=showPosts

Thank you very much for the information!

BTC:1NzzfeHCgN8fF6mSG1UeBFCVd2cxKbGyHk
NXT:13187911577562526278
PaulyC
Member
**
Offline Offline

Activity: 82
Merit: 10


View Profile WWW
January 02, 2014, 02:02:40 AM
 #12165

How about just renaming the *correct client, posting it on Page 1, and saying don't use 4.8 at all? or is that too drastic?

Doge Mars Landing Foundation
(founder) Coined the phrase, "Doge to the Mars" and "Check that Hash!". Discoverer of the 2013 NXT nefarious wallet.  Admin. FameMom [FAMOM]
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 02, 2014, 02:05:11 AM
 #12166

Now that we seem to have figured out this breach, we need to warn anybody that downloaded that version, but I guess we can't broadcast message yet...

P.S. also maybe a bounty to PaulyC of 7808 NXT for finding this?

I made a pact with Intel to publish news at http://info.nxtcrypto.org/, and this is news.  I will be typing something up for submission ASAP.  If you want to keep a lid on it, good luck with that.

Absolutely PaulyC should be made whole via bounty fund.
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:06:25 AM
 #12167

There is not so much information in the internet about evildave + bitcoin. I found something interesting, some evildave speaking dutch used the service "www.happycoins.nl" to buy bitcoins. He paid using paypal.

Here is the quote from his feedback (translated from dutch):

http://www.trustpilot.gr/review/www.happycoins.nl?page=3

Quote
I am very satisfied with the services of Happy Coins, definitely recommended.
They are one of the few mogelikheiden to buy via PayPal, and my experience with a fairly large purchase Bitcoin Bitcoin their was just okay.

Only downside was that it took a little longer to get nearly 90 minutes, the Bitcoins on my wallet, but that was a very busy period.

Original
 
Quote
HappyCoins: bijna perfecte ervaring met Bitcoins kopen

Ik ben zeer tevreden met de dienstverlening van HappyCoins, zeker een aanrader.
Ze zijn een van de weinig mogelikheiden om Bitcoin in te kopen via iDeal, en mijn ervaring met een vrij grote Bitcoin aankoop bij hun was gewoon goed.

Enige minpunt was dat het heeft wat langer geduurd om de Bitcoins op mijn wallet te krijgen, bijna 90 minuten, maar dat was wel in een hele drukke periode.

So, it's worth to contact with happycoins.nl and get his data.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 02:06:51 AM
 #12168

PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history, 
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

please check your browser history to find which page you used for the download - where did you find a link?
jl777
Legendary
*
Offline Offline

Activity: 1176
Merit: 1134


View Profile WWW
January 02, 2014, 02:07:11 AM
 #12169

rickyjames,

I wasn't saying we should cover it up, I was saying that the feature to broadcast messages to all NXT clients is not there yet.

James

http://www.digitalcatallaxy.com/report2015.html
100+ page annual report for SuperNET
mnightwaffle
Hero Member
*****
Offline Offline

Activity: 1022
Merit: 506



View Profile
January 02, 2014, 02:08:04 AM
 #12170

Ok here are the two zip files in one file.
The bigger one is the one I DLed from Nextcoin.org and used when my NXT were stolen. the smaller one I believe was the one posted on the front page?

DO NOT USE THIS FILE FOR NXT:
https://mega.co.nz/#!lZQBXQqK!EpQQbx9uBy9gcQe7-vc8smWDwHcM7LBODbtoCpKNXNo

Got it. The bogus client is in the link. Can someone check where is the modification ?

You have got to be absolutely fricking kidding me.  I have downloaded from mega.co.nz on Tues and walked it over to my nice sterile laptop....  

Excuse me while I go do an emergency client download from a trusted source and move my NXT to a new account with a zillion character new passcode....

And when this all settles down I'm going to bring up again a few more dozen times the idea of implementing a withdrawal freeze code....
excellent! me too.

How do you check the sha?
joefox
Full Member
***
Offline Offline

Activity: 210
Merit: 100


View Profile WWW
January 02, 2014, 02:08:46 AM
 #12171

Download pages on the wiki have all been locked down.

I admin the Nxt Wiki at http://wiki.nxtcrypto.org/ Please support my work by donating to Nxt account #1234567740944417915
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 02, 2014, 02:11:43 AM
 #12172

rickyjames,

I wasn't saying we should cover it up, I was saying that the feature to broadcast messages to all NXT clients is not there yet.

James

Ah, sorry.  I'm a little agitated at the moment and my paranoia needle has broken off the peg over in the red zone.  My apologies.

We still see  eye to eye on security, dude.
newcn
Full Member
***
Offline Offline

Activity: 143
Merit: 100


View Profile
January 02, 2014, 02:12:19 AM
 #12173

PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history, 
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

please check your browser history to find which page you used for the download - where did you find a link?

how to find it from Chrome?
I just find the link, not the webpage the link was in,
there should be some ways to find that!

BTC:1NzzfeHCgN8fF6mSG1UeBFCVd2cxKbGyHk
NXT:13187911577562526278
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:15:49 AM
 #12174

People, the malware is being hosted on 162.243.246.223, it is digital ocean, a lot of people here have VPS here.

Contact their support asap and notify that the IP 162.243.246.223 is running a listening backdoor / passlogger.

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
xyzzyx
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


I don't really come from outer space.


View Profile
January 02, 2014, 02:16:50 AM
 #12175


How do you check the sha?


https://bitcointalk.org/index.php?topic=345619.msg4259260#msg4259260

"An awful lot of code is being written ... in languages that aren't very good by people who don't know what they're doing." -- Barbara Liskov
EvilDave
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1001



View Profile
January 02, 2014, 02:17:51 AM
 #12176

There is not so much information in the internet about evildave + bitcoin. I found something interesting, some evildave speaking dutch used the service "www.happycoins.nl" to buy bitcoins. He paid using paypal.

Here is the quote from his feedback (translated from dutch):

http://www.trustpilot.gr/review/www.happycoins.nl?page=3

Quote
I am very satisfied with the services of Happy Coins, definitely recommended.
They are one of the few mogelikheiden to buy via PayPal, and my experience with a fairly large purchase Bitcoin Bitcoin their was just okay.

Only downside was that it took a little longer to get nearly 90 minutes, the Bitcoins on my wallet, but that was a very busy period.

Original
 
Quote
HappyCoins: bijna perfecte ervaring met Bitcoins kopen

Ik ben zeer tevreden met de dienstverlening van HappyCoins, zeker een aanrader.
Ze zijn een van de weinig mogelikheiden om Bitcoin in te kopen via iDeal, en mijn ervaring met een vrij grote Bitcoin aankoop bij hun was gewoon goed.

Enige minpunt was dat het heeft wat langer geduurd om de Bitcoins op mijn wallet te krijgen, bijna 90 minuten, maar dat was wel in een hele drukke periode.

So, it's worth to contact with happycoins.nl and get his data.

Er...wtf?

Am i missing something?

Nulli Dei, nulli Reges, solum NXT
Love your money: www.nxt.org  www.ardorplatform.org
www.nxter.org  www.nxtfoundation.org
Damelon
Legendary
*
Offline Offline

Activity: 1092
Merit: 1010



View Profile
January 02, 2014, 02:17:56 AM
 #12177

So, are most people with the new client boned?

If not, what should you check?

Member of the Nxt Foundation | Donations: NXT-D6K7-MLY6-98FM-FLL5T
Join Nxt Slack! https://nxtchat.herokuapp.com/
Founder of Blockchain Workspace | Personal Site & Blog
jl777
Legendary
*
Offline Offline

Activity: 1176
Merit: 1134


View Profile WWW
January 02, 2014, 02:23:26 AM
 #12178

I think we all agree PaulyC should be made whole as he was the first to report this. Usually bounties are for the first, not sure what the feeling is about newcn's being second. There is value in confirmation, so maybe half credit?

We can't make a policy out of this, but I feel that during this critical time it is important to show the world what the NXT community is.

There are the payment fees that doesn't currently have, nor do I expect will have a team that can make a realistic claim to have added value to that feature. This creates a certain amount of the community fund that would be discretionary. The actual process of collection and disbursement of the community fund has not been completed yet, but as soon as this year gets into full gear I expect that the kinks will be worked out.

Since I seem to be the only one pushing this idea, I guess it is up to me to make discretionary calls, but I want to get people's feedback on the bounty for newcn's confirmation of this hack.

For anybody that wants to directly contribute to the community fund, all donations are welcome. I couldn't get any volunteers to deal with the logistics of all this, so I will coordinate it for now. I will disclose all contributions and disbursements. For now just post your contribution to the community fund and I will confirm receipt or if you want to do it anonymously, PM me your contribution and your contribution will be listed as from anonymous. If you want your contribution to be spread over a period of time, please state the time period.

James

P.S. The more in the community fund, the more people like wesleyh, ferment, nexern, etc. will be rewarded and this in turn will get more and more people improving NXT instead of working OT at their real jobs Smiley

http://www.digitalcatallaxy.com/report2015.html
100+ page annual report for SuperNET
xyzzyx
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


I don't really come from outer space.


View Profile
January 02, 2014, 02:23:35 AM
 #12179

Er...wtf?

Am i missing something?

I think you turned him into a newt, but he got better.

"An awful lot of code is being written ... in languages that aren't very good by people who don't know what they're doing." -- Barbara Liskov
mkmen
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
January 02, 2014, 02:25:47 AM
 #12180

So, are most people with the new client boned?

If not, what should you check?

if the sha256 of your nxt-client-0.4.8.zip is:

ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2

you are fine, if it's:

948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06

you should download legit client and transfer your NXT immediately to another account if it's still there

how to get sha256 hash of your file is explained in this thread (nice windows tool here: http://sourceforge.net/projects/quickhash/)
Pages: « 1 ... 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 [609] 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!