Bitcoin Forum
May 04, 2024, 07:25:08 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 [629] 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 ... 2557 »
  Print  
Author Topic: NXT :: descendant of Bitcoin - Updated Information  (Read 2761529 times)
opticalcarrier
Full Member
***
Offline Offline

Activity: 238
Merit: 100



View Profile
January 02, 2014, 03:36:43 PM
 #12561

I have just read the last 50 pages of this topic and wow this is crazy.

First of all yes the client was posted by me and I added some code that would send the secrets to my server.
A week ago there were all the ddos issues and billions created which led to a lot of client updates.
During these updates I noticed a lot of those clients had different hashes which made me wondering how easy it would be to modify the client and get it circulated.
So that is what I did. I quoted the official post made by jean-luc on 31/12 and changed the url. Setting this all up took less then an hour.
The server was only online for about an hour and I decided to shut it down after I had gotten access to about 10 accounts.

Now here is what is odd. Yes I got access to some accounts but not those people here who are claiming they got hacked.
The accounts that I got access to never had more then 1000 nxt in them and I never had the intention of taking it.
To the people who got hacked before 0.4.8 I can say that it was definetly not me who could have stolen your coins.

Normally at this point I was going to post details about how easy it is to steal nxt and how people have to be aware about where they download their client instead if only focussing only on their pass strength.
That point has been made very clear now in an unfortunate way.

To be honest if I had found an account containing a 50 million next I would have probably taken it and diseappeared but that was not the case. I am human after all.

I know there are other modified clients around whether they use the same type of attack I don't know.
Digitalocean has also contacted me that people here have sent complaints and that different IP's have logged in on my account.
Whether someone else had access to my vps, people downloaded a different infected client or someone is playing it smart letting me take the blame I do not know. 

People are angry and ofcourse I can understand that but the only thing I can do is tell my story and hope a correct explanation for these thefts will appear.


wow and so now you take us for idiots?
1714807508
Hero Member
*
Offline Offline

Posts: 1714807508

View Profile Personal Message (Offline)

Ignore
1714807508
Reply with quote  #2

1714807508
Report to moderator
The block chain is the main innovation of Bitcoin. It is the first distributed timestamping system.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714807508
Hero Member
*
Offline Offline

Posts: 1714807508

View Profile Personal Message (Offline)

Ignore
1714807508
Reply with quote  #2

1714807508
Report to moderator
1714807508
Hero Member
*
Offline Offline

Posts: 1714807508

View Profile Personal Message (Offline)

Ignore
1714807508
Reply with quote  #2

1714807508
Report to moderator
EvilDave
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1001



View Profile
January 02, 2014, 03:38:24 PM
 #12562

Now this is gonna get interesting....

Nulli Dei, nulli Reges, solum NXT
Love your money: www.nxt.org  www.ardorplatform.org
www.nxter.org  www.nxtfoundation.org
Jimmy2011
Hero Member
*****
Offline Offline

Activity: 589
Merit: 500



View Profile
January 02, 2014, 03:38:26 PM
 #12563

Let's see... 0.4.8 was more stable than 0.4.7e, even on 512 Mb. If 0.4.9e is even better, then we're getting where it should be.

The goal is to run NRS on 64 KiB devices. Wink

Yeah, Bill Gates said he will join in Nxt.
plasticAiredale
Full Member
***
Offline Offline

Activity: 207
Merit: 120



View Profile
January 02, 2014, 03:38:58 PM
 #12564

I have just read the last 50 pages of this topic and wow this is crazy.

First of all yes the client was posted by me and I added some code that would send the secrets to my server.
A week ago there were all the ddos issues and billions created which led to a lot of client updates.
During these updates I noticed a lot of those clients had different hashes which made me wondering how easy it would be to modify the client and get it circulated.
So that is what I did. I quoted the official post made by jean-luc on 31/12 and changed the url. Setting this all up took less then an hour.
The server was only online for about an hour and I decided to shut it down after I had gotten access to about 10 accounts.

Now here is what is odd. Yes I got access to some accounts but not those people here who are claiming they got hacked.
The accounts that I got access to never had more then 1000 nxt in them and I never had the intention of taking it.
To the people who got hacked before 0.4.8 I can say that it was definetly not me who could have stolen your coins.

Normally at this point I was going to post details about how easy it is to steal nxt and how people have to be aware about where they download their client instead if only focussing only on their pass strength.
That point has been made very clear now in an unfortunate way.

To be honest if I had found an account containing a 50 million next I would have probably taken it and diseappeared but that was not the case. I am human after all.

I know there are other modified clients around whether they use the same type of attack I don't know.
Digitalocean has also contacted me that people here have sent complaints and that different IP's have logged in on my account.
Whether someone else had access to my vps, people downloaded a different infected client or someone is playing it smart letting me take the blame I do not know. 

People are angry and ofcourse I can understand that but the only thing I can do is tell my story and hope a correct explanation for these thefts will appear.

Wow. Just Wow.
Kodoka
Member
**
Offline Offline

Activity: 63
Merit: 10


View Profile
January 02, 2014, 03:39:15 PM
 #12565


The fact is that the stolen NXT from all five of these guys is sitting stuck in the five thief accounts and it can't get converted to BTC without going thru Dgex.   That ain't gonna happen.

This is a major crime in the tens of thousands of dollars range and we know who did it.  People go to prison for years for this kind of crap.
  
(Are you reading this, EpicThomas?  I know you are.)  

You know, if the NXT were somehow to be magically transferred back into the accounts where it is supposed to be, maybe just maybe I won't personally make it my mission to find your home address and phone number, post it right here on this forum, and call the police in your local town or city.

Do you feel lucky, punk?

A MESSAGE TO EPIC THOMAS:


Dude, I'm coming for you.  You had better put back the NXT where it belongs before I find out who you are and go to the police.  I will stop if you repay the NXT you have taken from others.  Once I find out a name and address and turn it over to law enforcement, things are out of my hands.  Until that time you can save yourself.  Do it.

My email to customer service at Digital Ocean:

Can you identify the real name, email address, mailing address, and telephone number of the user renting a cloud server from you at 162.243.246.233 for the past several days?  This person is involved in illegal activities and has stolen over $23,000 that we know of so far through  unauthorized transfers of assets.  When you have obtained this information, please let me know the name and location of the representative who may be contacted by local law enforcement.  

This is not a prank or joke.   My name is X.  I am a resident of X and you can contact me at my cell number of X if needed.  Thank you, and I look forward to your prompt response.
I understand your enthusiasm. I'd be pissed if my Nxt was stolen, too. Theft of crypto-currency is tricky, though.

rickyjames
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
January 02, 2014, 03:41:09 PM
 #12566


The fact is that the stolen NXT from all five of these guys is sitting stuck in the five thief accounts and it can't get converted to BTC without going thru Dgex.   That ain't gonna happen.

This is a major crime in the tens of thousands of dollars range and we know who did it.  People go to prison for years for this kind of crap.
  
(Are you reading this, EpicThomas?  I know you are.)  

You know, if the NXT were somehow to be magically transferred back into the accounts where it is supposed to be, maybe just maybe I won't personally make it my mission to find your home address and phone number, post it right here on this forum, and call the police in your local town or city.

Do you feel lucky, punk?

A MESSAGE TO EPIC THOMAS:


Dude, I'm coming for you.  You had better put back the NXT where it belongs before I find out who you are and go to the police.  I will stop if you repay the NXT you have taken from others.  Once I find out a name and address and turn it over to law enforcement, things are out of my hands.  Until that time you can save yourself.  Do it.

My email to customer service at Digital Ocean:

Can you identify the real name, email address, mailing address, and telephone number of the user renting a cloud server from you at 162.243.246.233 for the past several days?  This person is involved in illegal activities and has stolen over $23,000 that we know of so far through  unauthorized transfers of assets.  When you have obtained this information, please let me know the name and location of the representative who may be contacted by local law enforcement.  

This is not a prank or joke.   My name is X.  I am a resident of X and you can contact me at my cell number of X if needed.  Thank you, and I look forward to your prompt response.
I understand your enthusiasm. I'd be pissed if my Nxt was stolen, too. Theft of crypto-currency is tricky, though.



Hell, I'm not out to convict him.  I'm out to bankrupt him through lawyer fees to defend his sorry ass.  A conviction would just be icing on the cake.
wesleyh
Sr. Member
****
Offline Offline

Activity: 308
Merit: 250


View Profile
January 02, 2014, 03:41:17 PM
 #12567

I have just read the last 50 pages of this topic and wow this is crazy.

First of all yes the client was posted by me and I added some code that would send the secrets to my server.
A week ago there were all the ddos issues and billions created which led to a lot of client updates.
During these updates I noticed a lot of those clients had different hashes which made me wondering how easy it would be to modify the client and get it circulated.
So that is what I did. I quoted the official post made by jean-luc on 31/12 and changed the url. Setting this all up took less then an hour.
The server was only online for about an hour and I decided to shut it down after I had gotten access to about 10 accounts.

Now here is what is odd. Yes I got access to some accounts but not those people here who are claiming they got hacked.
The accounts that I got access to never had more then 1000 nxt in them and I never had the intention of taking it.
To the people who got hacked before 0.4.8 I can say that it was definetly not me who could have stolen your coins.

Normally at this point I was going to post details about how easy it is to steal nxt and how people have to be aware about where they download their client instead if only focussing only on their pass strength.
That point has been made very clear now in an unfortunate way.

To be honest if I had found an account containing a 50 million next I would have probably taken it and diseappeared but that was not the case. I am human after all.

I know there are other modified clients around whether they use the same type of attack I don't know.
Digitalocean has also contacted me that people here have sent complaints and that different IP's have logged in on my account.
Whether someone else had access to my vps, people downloaded a different infected client or someone is playing it smart letting me take the blame I do not know. 

People are angry and ofcourse I can understand that but the only thing I can do is tell my story and hope a correct explanation for these thefts will appear.


Heh..

Assuming this were true, where are the clients you've noticed that have different hashes? Please post them here.

gbeirn
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
January 02, 2014, 03:42:42 PM
 #12568

If anyone else wants to contribute anything to helping reimburse those who were affected my account is: 7692313866255280204

I just received 35K NXT from neer.g. Once we get some confirmations on that I will begin sending it out.




I think this is a great effort but I urge you to hold off for a day or two and see if we can get EpicThomas to rethink the wisdom of keeping his ill-gotten gains and put the money back that he stole.

Worth a shot.  And I am 99.99% sure I will have the law on his tail if he doesn't.  I am a persistent fellow once I take up a cause.

You keep up work on that side. I will give this a couple of hours and then distribute what I have. If by some chance we get those coins back we can worry about that then.

Smiley

Thanks, xyzzyx, for the 1K contribution!

NXT VPS Server Donations can be sent here: 6044921191674841550
At the end of each month I will donate some of them back to the community.
This is separate from my main wallet so you can keep track of them. I will keep them in there and only use them for hosting.
instacalm
Hero Member
*****
Offline Offline

Activity: 798
Merit: 500



View Profile
January 02, 2014, 03:43:48 PM
 #12569

EpicThomas, that was a very stupid move of yours
Buratino
Legendary
*
Offline Offline

Activity: 1151
Merit: 1003


View Profile
January 02, 2014, 03:45:57 PM
 #12570

Thus, is it happy end with the theft story?

salsacz
Hero Member
*****
Offline Offline

Activity: 490
Merit: 504


View Profile
January 02, 2014, 03:48:15 PM
 #12571

First identified Nxt hacker

Robbed announcements:
PaulyC
01-01-2014, 14:03:40
https://bitcointalk.org/index.php?topic=345619.msg4253372#msg4253372

sparta_cuss
01-01-2014, 17:05:58
https://bitcointalk.org/index.php?topic=345619.msg4255475#msg4255475

newcn
01:40:33 AM (CET)
https://bitcointalk.org/index.php?topic=345619.msg4262475#msg4262475

plasticAiredale on Today at 13:31:39
https://bitcointalk.org/index.php?topic=345619.msg4269412#msg4269412

Hacker was still posting to the Nxt topic:
Quote
EpicThomas
01-01-2014, 19:18:39
Both bitcoin and nxt generate your address from a 256bit key. The only problem is that bitcoin generates your private key while nxt uses sha256(pass) to get your private key.
https://bitcointalk.org/index.php?topic=345619.msg4257117#msg4257117

Good points:
Come-from-Beyond on 01-01-2014, 20:43:09
Quote
- Someone cracked SHA256 and Curve25519 (why then multi-million accounts not hacked?)
- Someone distributes modified NRS (someone should decompile PaulyC's software)
- Keylogger
- He used online node that records entered passphrases

Patel: 01-01-2014, 20:48:22
Quote
Another possibility is that the global mod that went rogue from the nxtforum, he could have changed the download link to a infected copy of NRS and people who used that link from the forum were using a compromised version

BloodyRookie: 01-01-2014, 21:04:11
Quote
He should calculate the SHA256 Hash of the class files, no need to decompile.

opticalcarrier: 01-01-2014, 21:15:36
Quote
its unforunate that one of the links there is a mega.co server. paulyc please tell us if you downloaded from the mega.co link or not.
in fact, can you please look on your HD and get the zipfile and post it somewhere for us to look at.

Finale:
PaulyC
Today at 01:43:01
Quote
Has anyone else noticed the 4.8 download zip from nextcoin.org vs. the one from this exact link Nxt 0.4.8 - https://mega.co.nz/#!yV5A1BTR!oi33K7WovgccuEHvP05nzggTnxrkZHJbwFmv5tGeXNI
Are 5 Kb in difference? is that anything to be concerned about?

S3MKi
Today at 01:55:38
Quote
Where did you download your client 0.4.8?

utopianfuture
Today at 02:04:18
Quote
Looks like you downloaded a bogus client.



newcn found the hack:
newcn
Today at 02:21:33
Quote
the 0.4.8 client I used, I forgot where I downloaded it, but from chrome history,  the link was http://162.243.246.223/n...

Salsacz found the hacker's Bitcointalk account:
Salsacz, 02:38:10 AM (CET)
https://bitcointalk.org/index.php?topic=345619.msg4263111#msg4263111

LiQio found a proof in googlecache:
LiQio
Today at 14:16:48
Quote
Thanks for the additional info, seems to point again to EpicThomas
He quoted the original message, but modified the link! And later modified it back!
Check:
https://bitcointalk.org/index.php?topic=345619.msg4237883#msg4237883
BUT in Google cache (Do not use the link found in cache!):
http://webcache.googleusercontent.com/search?q=

+ then I pointed out other posts where could be modified links

---

I am glad so we could find the wrong client and now we exactly know how it happened and how many people got robbed:
https://bitcointalk.org/index.php?topic=345619.msg4271189#msg4271189
- We can still check some other blocks during the time of the hacks, but it looks like we can relax now Smiley
plasticAiredale
Full Member
***
Offline Offline

Activity: 207
Merit: 120



View Profile
January 02, 2014, 03:49:30 PM
 #12572

I have just read the last 50 pages of this topic and wow this is crazy.

First of all yes the client was posted by me and I added some code that would send the secrets to my server.
A week ago there were all the ddos issues and billions created which led to a lot of client updates.
During these updates I noticed a lot of those clients had different hashes which made me wondering how easy it would be to modify the client and get it circulated.
So that is what I did. I quoted the official post made by jean-luc on 31/12 and changed the url. Setting this all up took less then an hour.
The server was only online for about an hour and I decided to shut it down after I had gotten access to about 10 accounts.

Now here is what is odd. Yes I got access to some accounts but not those people here who are claiming they got hacked.
The accounts that I got access to never had more then 1000 nxt in them and I never had the intention of taking it.
To the people who got hacked before 0.4.8 I can say that it was definetly not me who could have stolen your coins.

Normally at this point I was going to post details about how easy it is to steal nxt and how people have to be aware about where they download their client instead if only focussing only on their pass strength.
That point has been made very clear now in an unfortunate way.

To be honest if I had found an account containing a 50 million next I would have probably taken it and diseappeared but that was not the case. I am human after all.

I know there are other modified clients around whether they use the same type of attack I don't know.
Digitalocean has also contacted me that people here have sent complaints and that different IP's have logged in on my account.
Whether someone else had access to my vps, people downloaded a different infected client or someone is playing it smart letting me take the blame I do not know. 

People are angry and ofcourse I can understand that but the only thing I can do is tell my story and hope a correct explanation for these thefts will appear.


So you admit to stealing account information, but not taking the funds. You admit to creating a hacked client, and poisoning a link from a developer. But coincidentally also say your VPS account was hacked into and someone else used your account to actually do the stealing? So they had about an hour to figure out you poisoned a link, hack your VPS, and replace your hacked client with their hacked client?  Just admit it, you stole the NXT, return it before you dig yourself in deeper. I have in my history the time and path to your VPS server, which "hour" did you have your hacked client on your VPS?
landomata
Legendary
*
Offline Offline

Activity: 2184
Merit: 1000


View Profile WWW
January 02, 2014, 03:50:20 PM
 #12573

WHAT TIME (GMT) WILL THE SOURCE CODE BE RELEASED?....ITS ALREADY JAN 3rd IN JAPAN/AUSTRALIA......CHINA IS COMING UP IN 10 MINUTES.




EpicThomas
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile
January 02, 2014, 03:52:00 PM
 #12574

I realize my story sounds rediculous but it is what it is.

After the dropbox shutdown and the ddos issues a lot of mirrors were created on different sites I am trying to find out if any of these links still exist and if they could have also been infected.
That moment of chaos would have been a perfect time to circulate a client without people noticing it.
EpicThomas
Newbie
*
Offline Offline

Activity: 19
Merit: 0


View Profile
January 02, 2014, 03:53:52 PM
 #12575


So you admit to stealing account information, but not taking the funds. You admit to creating a hacked client, and poisoning a link from a developer. But coincidentally also say your VPS account was hacked into and someone else used your account to actually do the stealing? So they had about an hour to figure out you poisoned a link, hack your VPS, and replace your hacked client with their hacked client?  Just admit it, you stole the NXT, return it before you dig yourself in deeper. I have in my history the time and path to your VPS server, which "hour" did you have your hacked client on your VPS?


I do not claim I got hacked. The only thing I know is that digitalocean asked me if I knew about this because there are different ip logins on my digitalocean account.
coolfish
Full Member
***
Offline Offline

Activity: 121
Merit: 100


View Profile
January 02, 2014, 03:59:50 PM
 #12576

Quote

Shit...! Why are these account balance is negative?

Quote

Why this account was created blocks so fast?

Nxt:17482068461146780755
plasticAiredale
Full Member
***
Offline Offline

Activity: 207
Merit: 120



View Profile
January 02, 2014, 04:00:07 PM
 #12577


So you admit to stealing account information, but not taking the funds. You admit to creating a hacked client, and poisoning a link from a developer. But coincidentally also say your VPS account was hacked into and someone else used your account to actually do the stealing? So they had about an hour to figure out you poisoned a link, hack your VPS, and replace your hacked client with their hacked client?  Just admit it, you stole the NXT, return it before you dig yourself in deeper. I have in my history the time and path to your VPS server, which "hour" did you have your hacked client on your VPS?


I do not claim I got hacked. The only thing I know is that digitalocean asked me if I knew about this because there are different ip logins on my digitalocean account.

Your story sounds ridiculous because it is! I hope you believe your story is enough to keep you safe. I have a timestamp to your VPS along with the file that does the stealing. It should be easy enough to verify which IP put that zip file there. Just do yourself a favor and start sending the NXT back.  Kiss
Jimmy2011
Hero Member
*****
Offline Offline

Activity: 589
Merit: 500



View Profile
January 02, 2014, 04:01:08 PM
 #12578


Thomas, suggest you return back what don't belong to you and shut up!
xyzzyx
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


I don't really come from outer space.


View Profile
January 02, 2014, 04:02:57 PM
 #12579


It's ok.

http://localhost:7874/nxt?requestType=getBalance&account=9433259657262176905
returns:
{"balance":2592169000,"effectiveBalance":2592169000,"unconfirmedBalance":2592169000}

http://localhost:7874/nxt?requestType=getBalance&account=10105875265190846103
returns:
{"balance":543252400,"effectiveBalance":543252400,"unconfirmedBalance":543252400}

Just a little bug in the explorer.  It'll be fine in a while.

"An awful lot of code is being written ... in languages that aren't very good by people who don't know what they're doing." -- Barbara Liskov
EvilDave
Hero Member
*****
Offline Offline

Activity: 854
Merit: 1001



View Profile
January 02, 2014, 04:03:18 PM
 #12580

So to paraphrase EpicThomas:

U admit that u modifed and uploaded the client, but then some bad people took it over and stole the money.

Forgive me for not believing u very much.

Nulli Dei, nulli Reges, solum NXT
Love your money: www.nxt.org  www.ardorplatform.org
www.nxter.org  www.nxtfoundation.org
Pages: « 1 ... 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 [629] 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 ... 2557 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!