Bitcoin Forum
April 26, 2024, 04:33:48 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 3 4 [All]
  Print  
Author Topic: http://ecrypto.net/ is down - No surprises  (Read 4688 times)
dez82 (OP)
Member
**
Offline Offline

Activity: 123
Merit: 10


View Profile
December 26, 2013, 08:23:00 AM
 #1

No wallets, poor load times, no contact info.

Poor prick couldn't even prop up his own scam

EverGreenCoin faucet! Get some free EverGreenCoin!

http://Coin-Faucet.com/EGC/?r=384
1714149228
Hero Member
*
Offline Offline

Posts: 1714149228

View Profile Personal Message (Offline)

Ignore
1714149228
Reply with quote  #2

1714149228
Report to moderator
1714149228
Hero Member
*
Offline Offline

Posts: 1714149228

View Profile Personal Message (Offline)

Ignore
1714149228
Reply with quote  #2

1714149228
Report to moderator
The forum was founded in 2009 by Satoshi and Sirius. It replaced a SourceForge forum.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714149228
Hero Member
*
Offline Offline

Posts: 1714149228

View Profile Personal Message (Offline)

Ignore
1714149228
Reply with quote  #2

1714149228
Report to moderator
1714149228
Hero Member
*
Offline Offline

Posts: 1714149228

View Profile Personal Message (Offline)

Ignore
1714149228
Reply with quote  #2

1714149228
Report to moderator
1714149228
Hero Member
*
Offline Offline

Posts: 1714149228

View Profile Personal Message (Offline)

Ignore
1714149228
Reply with quote  #2

1714149228
Report to moderator
Shadey
Full Member
***
Offline Offline

Activity: 193
Merit: 100


View Profile
December 26, 2013, 08:31:51 AM
 #2

Give it time, they're a brand new site aren't they?

New sites have bugs sometimes, especially when they don't expect to get the volume of new people signing up like they are getting lol

DRK - Xq5o7AGBau1bL59fDuJpgcU6XQ6Fr6iHRm
BTC - 182pCAyuawff3ANB6FdifKBLcq5a7abFTh
LTC - LcpDzdX8v9s1JB2bHnb8bCoCKEckyxL9JU
The Golden Egg game Sponsor: https://thegoldenegg.co/users/Shadey?d27de3572
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
December 26, 2013, 08:33:27 AM
 #3

Its working ok here albeit its a bit slow. Apparently he had a huge influx of new signups today so the site is experiencing a bit of downtime. There's a message on the site advises he's added extra RAM to the server to help with the load but work is ongoing.

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
Ardolafat
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


View Profile
December 26, 2013, 08:35:22 AM
 #4

I got mine back without withdrawal fee, it still loads sometimes  Cool
BrewCrewFan
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile
December 26, 2013, 08:36:51 AM
 #5

No wallets, poor load times, no contact info.

Poor prick couldn't even prop up his own scam

With many people looking for an out of the unnamed site, there most likely was a huge influx of people. Being the first day I do not think that was expected. Pretty hard to judge on the first day IMO, I still would only put small sums of BTC in, but other wise, lets just do a wait and see.

Free SIGNs giving everyday. Be part, do not miss!.
SqMe5ceYfdcGsRyVpgvpYb6bRLS9j8omvB

XChat : Addy : XYuZESQpeMtZ2wit8nVVnXKGytfiaTBCo6 PubKey : eteshLzeq8Bh54BRjGSunMTc6Ytxtk7HYaSmDYMQn61z
Ardolafat
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


View Profile
December 26, 2013, 08:41:39 AM
 #6

btw deposits and withdrawals are much faster than on craptsy  Cheesy
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
December 26, 2013, 01:43:57 PM
 #7

i cannot withdraw my btc... the "send" button remains red and is followed by an "X". anyone have the same issue?

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
December 26, 2013, 01:48:18 PM
 #8

It amazes me how quickly people put faith in such a new and untested website.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
hvezdasmrti
Sr. Member
****
Offline Offline

Activity: 797
Merit: 251


View Profile
December 26, 2013, 01:49:02 PM
 #9

for someone it was working only in internet explorer, try this

In Pump and Dump we trust.
Equate
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


View Profile
December 26, 2013, 02:08:18 PM
 #10

not a new thing for new exchange.
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
December 26, 2013, 02:14:57 PM
 #11

for someone it was working only in internet explorer, try this

Also with explorer, seems impossible to me to withdraw right now

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
December 26, 2013, 05:16:19 PM
 #12

Finally i got an email confirmation using safari, but it didn't work... and now the site is again offline

 Sad

dudes, you're not doing it right

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
CryptoMine
Member
**
Offline Offline

Activity: 112
Merit: 10


View Profile
December 26, 2013, 05:22:18 PM
 #13

ERROR: Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (2)

Absolute pro..
BrewCrewFan
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile
December 26, 2013, 06:02:34 PM
 #14

No wallets, poor load times, no contact info.

Poor prick couldn't even prop up his own scam

So dude thinking it was going to be a modest growth rate, did not expect to see as many people as he did. With as many wanting out of a unnamed exchange, plus carrys a few coins that are not listed there....

Really, a day old and people bitch. These are the same people who bitch when they can not drive up to the driveup window at a fast food place and not get the food handed to them right away as soon as they come to a stop.

Free SIGNs giving everyday. Be part, do not miss!.
SqMe5ceYfdcGsRyVpgvpYb6bRLS9j8omvB

XChat : Addy : XYuZESQpeMtZ2wit8nVVnXKGytfiaTBCo6 PubKey : eteshLzeq8Bh54BRjGSunMTc6Ytxtk7HYaSmDYMQn61z
samesstee
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
December 27, 2013, 12:00:44 AM
 #15

dez... bit harsh! There are no REAL scam reports so far just speculation,  a friend has used it and it was fine - after reading the introduction they clearly have some fresh ideas and for that reason I think these guys will go far.

trade safe!
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
December 27, 2013, 01:40:50 AM
 #16

https://bitcointalk.org/index.php?topic=386604.msg4161431#msg4161431

i feel like they stole my money now... and they have no support!

 Cry Cry Cry Cry Cry Cry

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
Shmollen
Full Member
***
Offline Offline

Activity: 205
Merit: 100


View Profile
December 27, 2013, 12:12:11 PM
Last edit: December 27, 2013, 12:37:26 PM by Shmollen
 #17

I'am blind! Shocked
Where can I deposit/windraw coins on ecrypto???
I dont find/see it! Huh Huh

Is there a direct link like "ecrypto.net/index.php?action=history" for "Trades"?

Plz help! Thx!!!


Okay found it!!!  Grin

★★★ Help me to become a KittehCoin billionaire! Donate MEOW to KNKVoobKxwMB1fEEm1YyApTLFUhYF75x9A ★★★
★★★★★
g0re79
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


I´ve got a picture! Haha!


View Profile WWW
December 28, 2013, 12:04:18 AM
 #18

30+ hours ago I´ve sended there 1000 EAC, traded them for 0.0024 BTC (by some strange flaw it happened 2 times in a row, so I sold 2000 EAC for 0.0047 BTC) and tried to withdraw BTC. First time I´ve clicked on the link in confirmation email it gets me to the front page of exchange site (with no message), second and any further clicks gives me "Transaction Failed 0.0047 was not sent to ....". That 0.0047 BTC was already deducted from my acc, but never hit blockchain. And as far as there is no contact form nor email adress on ecrypto site, I believe its SCAM.

Don´t deal with crappy shitcoins and stop wasting electricity
Support real science instead
[/url]
taufu
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
December 28, 2013, 06:47:22 PM
 #19

Ok, I am seeing my Tips going to a different address:

http://fedorachain.info/tx/611a2ea5dad1cdfa90f219d876448ff2aed1208281bfa36ca22328ef8a8ef868#i9

We've looked up the person behind Ecrypto:

https://www.facebook.com/smagik

More info here:
https://bitcointalk.org/index.php?topic=387786
quarkkid
Full Member
***
Offline Offline

Activity: 210
Merit: 100


View Profile
December 29, 2013, 03:16:54 AM
 #20

Ecrypto's back up!! New front login page aswell...Cant log in to my account tho..

My reputation thread!! ...https://bitcointalk.org/index.php?topic=419456.0
C A Ix > >   CAIx-- Xt7qWX6LTAURHZYzjenTBNfViztCz2z72U
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
December 31, 2013, 12:11:37 PM
 #21

Anyone here living in BC, Canada able to go pay this guy a visit?

I also just saw the "grinning" cow on the website. He wouldn't have posted it, if he were in over his head. Seems to me, he just ran with all the money he collected.

This is very unfortunate for the people who deposited their coins there.

Which exchange do you trust besides Cryptsy?

I trust cn.bter.com and (maybe) vircurex.

P.S.

Name: bruce degrosbois
Organization: sitemagik
Street: 19613-42 ave
City: langley
State/Province: BC
Postal Code: v3a3a3
Country: CA
Phone: +1.6045399527


Experience
Recreation and Tourism Alumni Event Coordinator at Vancouver Island University
Professional Driver at AC Taxi
Coder at Coastal Webmasters (Self-employed)
Assistant Manager at Agape Ministry
Manager at Edmonton Restaurant Slowpitch League, Edmonton, AB
Coder at Coastal Webmasters (Self-employed)



(From Linkedin) Experience

CEO
Ecrypto
October 2013 – Present (3 months)Vancouver, Canada Area
Ecrypto is developing the worlds most advanced cryptocurrency trading platform. Ecrypto is currently in Alpha development with an expected Beta release date of December 1, 2013.
http://www.Ecrypto.net

Projects

Understanding Bitcoin
March 2013
I suspect Bitcoin is a game changer much like windows was. It is hard not to love it once you understand it. The growth of Bitcoin is unprecedented and surprisingly the percentage growth of the alternate digital currency called Litecoin has been even higher. Many millionaires have been created by this and for the rest of us, well we missed the boat - this time.

I see understanding Bitcoin as...more
HeartofGoldProject.ca(Link)



Simon Fraser University
Urban Planning Certificate, Urban Planning
2013 – 2014 (expected)
RFABC
Masters certificate, facility management
2012 – 2013
I have been doing the courses for the past year and a half. I currently need 1 course to complete my certificate, however the course has not been offered - ever. Will complete it ASAP

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
December 31, 2013, 12:24:13 PM
 #22

i wish i lived in canada...

no way to set up a legal action? I didn't lost so much money, but i would be glad to applicate to a collective action...

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
paradiselife
Newbie
*
Offline Offline

Activity: 28
Merit: 0


View Profile
December 31, 2013, 12:26:16 PM
 #23

I am in Canada I have no problem taking actions for people outside of Canada, PM me if you have any ideas
KingGoon
Member
**
Offline Offline

Activity: 112
Merit: 10



View Profile
December 31, 2013, 12:29:31 PM
 #24

  Huh ahahahahah

So Icy E-Money - Frozentalk.org FD1GwdBjTeMPFdZD5v3cVRG7ZoPJBAuLrf
All these girls excited ,Oooo ya know they like it ,Frozen so icy, so icy ,Haters don't try to fight it ,All yo friends invited ,Frozen so icy, so icy!!
mr_random
Legendary
*
Offline Offline

Activity: 1274
Merit: 1001


View Profile
December 31, 2013, 06:27:16 PM
 #25

If he had good intentions and was hacked he should release a statement.
HyAfo
Member
**
Offline Offline

Activity: 101
Merit: 10


View Profile
December 31, 2013, 06:41:17 PM
 #26

I am in Canada I have no problem taking actions for people outside of Canada, PM me if you have any ideas

We need to hire some killer and let him pay by his blood ,silkroad2 coming service .
mr_random
Legendary
*
Offline Offline

Activity: 1274
Merit: 1001


View Profile
December 31, 2013, 07:30:56 PM
 #27

This is his plenty of fish dating profile: http://www.pof.com/viewprofile.aspx?profile_id=25769873

I learned about Bruce that he is "a walking miracle - I am a 1 in 25 million survivor." Also, "there was a time in my life when I was a star athlete and an artist"



This appears to be his localbitcoins profile: https://localbitcoins.com/accounts/profile/smagik/ Last active 1 day ago. Verified phone number.


BrewCrewFan
Hero Member
*****
Offline Offline

Activity: 672
Merit: 501



View Profile
December 31, 2013, 07:42:30 PM
 #28

Amazing he can get one localbitcoin just very recently yet can not update us here?

Ah well, lesson learned. I normally give people the benefit of the doubt, because most people are good people, but guys like this ruin it for the rest. Of course I used caution due to the site being new so I only lost around 1 mil lotto coins....days worth of mining then and was worth a lot more then than now but stilll...  Kinda wished once I saw the site having issues I would have pulled them if I could have.

Now every legit startup exchange is going to have a problem doing just that, starting up, due to assholes like this that burned many people and lost tons of money.

Free SIGNs giving everyday. Be part, do not miss!.
SqMe5ceYfdcGsRyVpgvpYb6bRLS9j8omvB

XChat : Addy : XYuZESQpeMtZ2wit8nVVnXKGytfiaTBCo6 PubKey : eteshLzeq8Bh54BRjGSunMTc6Ytxtk7HYaSmDYMQn61z
HyAfo
Member
**
Offline Offline

Activity: 101
Merit: 10


View Profile
December 31, 2013, 09:04:26 PM
 #29

Updated
He removed his facebook face  , sure scam .
https://www.facebook.com/smagik

I will start a bounty to make him pay with his bl^^d    Wink
 
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
December 31, 2013, 09:09:22 PM
 #30

This guy wasn't too smart, was he? There's going to be a lot of angry people who want answers.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
bluemyst
Full Member
***
Offline Offline

Activity: 126
Merit: 100


View Profile
December 31, 2013, 11:11:48 PM
 #31

UPDATE!!

Explanation for loss of service and plans for recovery and repayment.

From the day Ecrypto started operating it was under attack. Many attempts to penetrate the servers occured and attempts to hack my personal accounts were constant. Unfortunatly on the morning of December 28 the attacker was successful in gaining entry to the wallet servers. Things were operating normally when I noticed the wallet balance had gone to -11 BTC. A few minutes later the wallet servers stopped responding completly, and access to them through the command line became impossible. Digital Ocean began to investigate the problem and after some time sent this response.

Greetings,

I appreciate your patience. After loading your droplet's into a recovery environment, it appears that someone has compromised both of your droplet's, and stolen your bitcoin from the `W2` droplet. This is confirmed from the `.bash_history` file, which the attack did not effectively remove. In an attempt to cover their tracks, they attempted to wipe out your droplets filesystem with `rm -rf /`, but mistakenly left the `/root` folder, which left some of the data for the blocks you had found.

On the `W1` droplet, it is not apparent if there were any *coin's transferred, as the .bash_history folder over there was effectively wiped out prior to the `rm -rf /` on that droplet.

For your reference, both droplets remain in the recovery environment right now, and have the drives mounted. I've taken a few screenshots of the console and pulled of the transfer of your 11 bitcoin on blockchain.info to confirm the theft:
http://screencast.com/t/Ba7Mvgh6md0
http://screencast.com/t/1eKtogngnw
https://blockchain.info/address/19Xn6GPjMoj8FMLMWg77Wq7PNiFSUsZxSV

Given the nature of bitcoin, this theft is effectively irreversible. Unfortunately, even if the data of your droplet's did remain intact, the theft would remain irreversible.

I would certainly be quite suspicious of this compromise, as if these bitcoin were just transferred last night, it would seem someone associated with you, or the other party, is well aware of your two mining droplets, or may have had access to the droplet's prior.

Unfortunately, there is truly nothing more that we are able to do for you at this point.

Regards,
Russell Mitchell | Support Team

There is noone with access to the account information hare so clearly this was a pure hack. I made great efforts to make the servers impossible to hack, however the hacker simply walked right in and stole everything. The coins they did not steal, they deleted. Since the attack I have just been sick to my stomach. Ecrypto has taken 6 months of 16 hour days to build, and anyone suggesting this was a theft by me is a complete fool. The total stolen was only 11 BTC which is not a huge amount. If the hacker had waited, they would have been able to steal a significant amount more, but it is obviously just an impatient child. I am currently reworking the entire setup, making significant changes that will make it impossible to penetrate. The wallet servers will have NO communications with the website server at all, and gaining access to them should be impossible. The weak point will be the weak passwords that Digital Ocean automatically generates for servers, but since the wallet server will have no connection with the website, even finding the server will be nearly impossible. I will also change the location of the wallet server at least once a week, and transfer the majority of BTC and LTC in the wallets into cold storage for additional security.

So the next question is, when will you get the coins you lost back? We have backup images of the wallet balances at the time of the attack. When the site comes back up, 100% of fees collected by the site will go to pay back lost coins. Not only will you receive the coins you lost, you will receive a 50% bonus. So for every 2 coins you had at the time of the attack - you will receive 3 coins as repayment.

Unfortunatly this is the best I can do for now. I personally suffered a large loss as well which makes it impossible to repay the lost coins faster than the plan.

When will the service resume operations? I am thinking a month or so. I need to make the servers bulletproof, and that will take time. If you feel the need to rant or call me names you can email ecryptox@gmail.com. Reasonable emails will be responded to ASAP.
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
December 31, 2013, 11:26:04 PM
Last edit: December 31, 2013, 11:49:59 PM by Oldminer
 #32


There is noone with access to the account information hare so clearly this was a pure hack. I made great efforts to make the servers impossible to hack, however the hacker simply walked right in and stole everything. The coins they did not steal, they deleted. Since the attack I have just been sick to my stomach. Ecrypto has taken 6 months of 16 hour days to build, and anyone suggesting this was a theft by me is a complete fool. The total stolen was only 11 BTC which is not a huge amount. If the hacker had waited, they would have been able to steal a significant amount more, but it is obviously just an impatient child. I am currently reworking the entire setup, making significant changes that will make it impossible to penetrate. The wallet servers will have NO communications with the website server at all, and gaining access to them should be impossible. The weak point will be the weak passwords that Digital Ocean automatically generates for servers, but since the wallet server will have no connection with the website, even finding the server will be nearly impossible. I will also change the location of the wallet server at least once a week, and transfer the majority of BTC and LTC in the wallets into cold storage for additional security.

So the next question is, when will you get the coins you lost back? We have backup images of the wallet balances at the time of the attack. When the site comes back up, 100% of fees collected by the site will go to pay back lost coins. Not only will you receive the coins you lost, you will receive a 50% bonus. So for every 2 coins you had at the time of the attack - you will receive 3 coins as repayment.

Unfortunatly this is the best I can do for now. I personally suffered a large loss as well which makes it impossible to repay the lost coins faster than the plan.

When will the service resume operations? I am thinking a month or so. I need to make the servers bulletproof, and that will take time. If you feel the need to rant or call me names you can email ecryptox@gmail.com. Reasonable emails will be responded to ASAP.

Thanks for the update, but whats with the cow? One would think if you honest you would have put up some sort of message to at least let people know whats going on? And why respond now only after the owners personal details are posted all over the forum? If you are genuine about repaying monies lost with a 50% commission then this is admirable, though I hope for your sake you are not simply trying to placate investors fears & are able to follow it through.

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
mr_random
Legendary
*
Offline Offline

Activity: 1274
Merit: 1001


View Profile
December 31, 2013, 11:30:13 PM
 #33

Thanks for the update. The old posting pof dating profile trick usually works  Cheesy Tbh it looks like you're only updating because you're realised you can't just run away from this without consequences. Why has it taken you so many days to issue *any* kind of statement?

I made great efforts to make the servers impossible to hack, however the hacker simply walked right in and stole everything.

Someone suggested you was not sanitising user input on your GET variables? Is this true? Because it would leave the doors to your database wide open for anyone to walk in via SQL injection.
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
December 31, 2013, 11:31:36 PM
 #34

Well, we've got a response. He's told us what's supposedly happened, so all we can do is wait to see if he keeps his word. As long as this is not somehow some way to placate people, and the site will be coming back, and people will be reimbursed, then that is something. I'm willing to give anyone the benefit of the doubt, but the wall of silence has been worrying a lot of people.

The cynic in me would say that it's strange how we've now heard an update now that all his personal details have been revealed, but hey, I'm just suspicious like that. Benefit of the doubt. Everybody should get it at least once.

Thanks for the update. The old posting pof dating profile trick usually works  Cheesy Tbh it looks like you're only updating because you're realised you can't just run away from this without consequences. Why has it taken you so many days to issue *any* kind of statement?

I made great efforts to make the servers impossible to hack, however the hacker simply walked right in and stole everything.

Someone suggested you was not sanitising user input on your GET variables? Is this true? Because it would leave the doors to your database wide open for anyone to walk in via SQL injection.

I believe I mentioned SQL injection as a possibility in the original thread on ecrypto. It's basic security 101 for SQL and user input though.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
tabnk
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
December 31, 2013, 11:36:57 PM
 #35

I'm still have 243 earth coin at there, how to retrieve back ? Any help ? Sad.
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
December 31, 2013, 11:42:21 PM
 #36

I'm still have 243 earth coin at there, how to retrieve back ? Any help ? Sad.

He says he'll be relaunching the site with better security and paying people anything that was taken with interest. That's what he's stated, anyway.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
mr_random
Legendary
*
Offline Offline

Activity: 1274
Merit: 1001


View Profile
January 01, 2014, 12:31:17 AM
 #37


I believe I mentioned SQL injection as a possibility in the original thread on ecrypto. It's basic security 101 for SQL and user input though.

Someone specifically said the GET variables were not being sanitised. I didn't check myself at the time. If that is the case then it's almost certainly how the hacker gained entrance so easily. A single un-escaped input gives the hacker complete control over the server.
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
January 01, 2014, 12:36:26 AM
 #38


I believe I mentioned SQL injection as a possibility in the original thread on ecrypto. It's basic security 101 for SQL and user input though.

Someone specifically said the GET variables were not being sanitised. I didn't check myself at the time. If that is the case then it's almost certainly how the hacker gained entrance so easily. A single un-escaped input gives the hacker complete control over the server.

There's no way to check for GET sanitation on the front end of the site that I'm aware of, as it happens on the server after it retrieves the input. An SQL query is just a string, like any data. If you're coding a website that processes financial transactions and don't know how to prevent SQL injection, then you shouldn't be coding financial websites period. I cannot express how basic knowledge that is in secure web development.

If this is what caused the hack, then I'm sorry, but I wouldn't put a single Dimecoin on Ecrypto.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
g0re79
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250


I´ve got a picture! Haha!


View Profile WWW
January 01, 2014, 01:58:58 PM
 #39

I'm still have 243 earth coin at there, how to retrieve back ? Any help ? Sad.

LOL

Don´t deal with crappy shitcoins and stop wasting electricity
Support real science instead
[/url]
mr_random
Legendary
*
Offline Offline

Activity: 1274
Merit: 1001


View Profile
January 01, 2014, 02:04:34 PM
 #40


I believe I mentioned SQL injection as a possibility in the original thread on ecrypto. It's basic security 101 for SQL and user input though.

Someone specifically said the GET variables were not being sanitised. I didn't check myself at the time. If that is the case then it's almost certainly how the hacker gained entrance so easily. A single un-escaped input gives the hacker complete control over the server.

There's no way to check for GET sanitation on the front end of the site that I'm aware of, as it happens on the server after it retrieves the input. An SQL query is just a string, like any data. If you're coding a website that processes financial transactions and don't know how to prevent SQL injection, then you shouldn't be coding financial websites period. I cannot express how basic knowledge that is in secure web development.

If this is what caused the hack, then I'm sorry, but I wouldn't put a single Dimecoin on Ecrypto.

Yes I am assuming the person who claimed there is no GET sanitisation injected into the sql to test his hypothesis, otherwise it would make no sense since there's literally a million ways to penetrate a server.

It is v basic php security which you'll learn in any beginner's book on php. This is why I posed OP the question, to ascertain how much of a php noob he is. Unfortunately the fact his site got hacked so damn quickly suggests in itself it was a basic security hole he left uncovered and not some sophisticated hack attempt.
Nullu
Hero Member
*****
Offline Offline

Activity: 532
Merit: 500


View Profile
January 01, 2014, 02:08:43 PM
 #41


I believe I mentioned SQL injection as a possibility in the original thread on ecrypto. It's basic security 101 for SQL and user input though.

Someone specifically said the GET variables were not being sanitised. I didn't check myself at the time. If that is the case then it's almost certainly how the hacker gained entrance so easily. A single un-escaped input gives the hacker complete control over the server.

There's no way to check for GET sanitation on the front end of the site that I'm aware of, as it happens on the server after it retrieves the input. An SQL query is just a string, like any data. If you're coding a website that processes financial transactions and don't know how to prevent SQL injection, then you shouldn't be coding financial websites period. I cannot express how basic knowledge that is in secure web development.

If this is what caused the hack, then I'm sorry, but I wouldn't put a single Dimecoin on Ecrypto.

Yes I am assuming the person who claimed there is no GET sanitisation injected into the sql to test his hypothesis, otherwise it would make no sense since there's literally a million ways to penetrate a server.

It is v basic php security which you'll learn in any beginner's book on php. This is why I posed OP the question, to ascertain how much of a php noob he is. Unfortunately the fact his site got hacked so damn quickly suggests in itself it was a basic security hole he left uncovered and not some sophisticated hack attempt.

Yes, either that, or crying "hacked". Plausible deniability; we have no real way of proving if the site ever got hacked at all. Only his word.

BTC - 14kYyhhWZwSJFHAjNTtyhRVSu157nE92gF
RedHat
Newbie
*
Offline Offline

Activity: 32
Merit: 0



View Profile
January 01, 2014, 02:51:34 PM
 #42

Anyway I've send an email to him for my coins. I have nothing but hope Cheesy
demoniality
Full Member
***
Offline Offline

Activity: 194
Merit: 100



View Profile
January 01, 2014, 05:29:20 PM
 #43

I emailed Bruce some Q's, answers here: https://bitcointalk.org/index.php?topic=387786.msg4256049#msg4256049

ufo: C9icQvu4T4Jo6QpmnP1dgQW5ru1BfPJ4sV
meljohn333
Newbie
*
Offline Offline

Activity: 21
Merit: 0


View Profile
January 11, 2014, 11:17:05 PM
 #44

that was quick, down forever?
tabnk
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
January 16, 2014, 12:12:32 PM
 #45

http://ecrypto.net/

DOWN.

My coin still with them  Sad Sad Sad
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
January 19, 2014, 01:25:42 AM
 #46

Any news?

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
January 31, 2014, 12:18:17 PM
 #47

Bump.


I still didn't forget.

Are there more scammed people?

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
janhajk
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile
February 03, 2014, 09:18:27 AM
 #48

Bump.


I still didn't forget.

Are there more scammed people?

Yep, i lost 0.5 BTC there. I have not forgot!
demoniality
Full Member
***
Offline Offline

Activity: 194
Merit: 100



View Profile
February 03, 2014, 01:10:33 PM
 #49

yep, we are not going to let this go forgotten..

ufo: C9icQvu4T4Jo6QpmnP1dgQW5ru1BfPJ4sV
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
February 03, 2014, 03:52:37 PM
 #50

We do not Forgive.
We do not Forget.

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
February 03, 2014, 04:03:14 PM
 #51

Since many scammed people do know his identity, i'm really scared that someone will threat him in real life if he don't give any feedback soon.
Of course i'll never do that, but i bet that some bad people would be glad to pay a little extra to someone to see him beaten or worst. you'll not see again you money, but it's cheaper than a legal Smiley
In italy you usually get a shoot in your knees for a thing like that.. it's not lethal, but you'll need a baton for the rest of your life.

How do you treat scammers in your countries?


Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
March 26, 2014, 09:36:28 PM
 #52

Anyone here living in BC, Canada able to go pay this guy a visit?

I also just saw the "grinning" cow on the website. He wouldn't have posted it, if he were in over his head. Seems to me, he just ran with all the money he collected.

This is very unfortunate for the people who deposited their coins there.

Which exchange do you trust besides Cryptsy?

I trust cn.bter.com and (maybe) vircurex.

P.S.

Name: bruce degrosbois
Organization: sitemagik
Street: 19613-42 ave
City: langley
State/Province: BC
Postal Code: v3a3a3
Country: CA
Phone: +1.6045399527


Experience
Recreation and Tourism Alumni Event Coordinator at Vancouver Island University
Professional Driver at AC Taxi
Coder at Coastal Webmasters (Self-employed)
Assistant Manager at Agape Ministry
Manager at Edmonton Restaurant Slowpitch League, Edmonton, AB
Coder at Coastal Webmasters (Self-employed)



(From Linkedin) Experience

CEO
Ecrypto
October 2013 – Present (3 months)Vancouver, Canada Area
Ecrypto is developing the worlds most advanced cryptocurrency trading platform. Ecrypto is currently in Alpha development with an expected Beta release date of December 1, 2013.
http://www.Ecrypto.net

Projects

Understanding Bitcoin
March 2013
I suspect Bitcoin is a game changer much like windows was. It is hard not to love it once you understand it. The growth of Bitcoin is unprecedented and surprisingly the percentage growth of the alternate digital currency called Litecoin has been even higher. Many millionaires have been created by this and for the rest of us, well we missed the boat - this time.

I see understanding Bitcoin as...more
HeartofGoldProject.ca(Link)



Simon Fraser University
Urban Planning Certificate, Urban Planning
2013 – 2014 (expected)
RFABC
Masters certificate, facility management
2012 – 2013
I have been doing the courses for the past year and a half. I currently need 1 course to complete my certificate, however the course has not been offered - ever. Will complete it ASAP

How we going with the payback plan Brucey boy?

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
March 27, 2014, 04:58:19 PM
 #53

we're still waiting  Angry

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
July 10, 2014, 06:05:57 AM
 #54

bump

you still around brucey?

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
demoniality
Full Member
***
Offline Offline

Activity: 194
Merit: 100



View Profile
July 13, 2014, 11:36:22 PM
 #55

never forget

ufo: C9icQvu4T4Jo6QpmnP1dgQW5ru1BfPJ4sV
jertsy
Sr. Member
****
Offline Offline

Activity: 341
Merit: 250


View Profile
January 01, 2015, 09:44:04 PM
 #56

Bump

I don't suppose anyone's got their money back yet?
erre
Legendary
*
Offline Offline

Activity: 1666
Merit: 1205



View Profile
January 01, 2015, 11:31:06 PM
 #57

No, but every time a service turned out to be a scam, like hashie or mintpal lately, I remeber of this.

This was the first time i was scammed by someone.
I will Never forgive, never forget.

Roll a dice FOR FREE every hour, and win up to $200 in btc ---> CLICK HERE

Tip me using the LIGHTING NETWORK! -->https://tippin.me/@Erre96344121
Oldminer
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001



View Profile
January 02, 2015, 01:10:06 AM
 #58

Ah old Brucey boy...how could we forget...  Roll Eyes

If you like my post please feel free to give me some positive rep https://bitcointalk.org/index.php?action=trust;u=18639
Tip me BTC: 1FBmoYijXVizfYk25CpiN8Eds9J6YiRDaX
Crypty3
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
January 02, 2015, 01:14:41 AM
 #59

How much did he make off with?
jertsy
Sr. Member
****
Offline Offline

Activity: 341
Merit: 250


View Profile
January 02, 2015, 11:27:45 AM
 #60

How much did he make off with?

He claims it was only was only 11 BTC, but he also promised to pay everyone back 150% of what they lost, which he never did.

We only have his word on how much he made off with, and he lied about paying everyone back.


UPDATE!!

Explanation for loss of service and plans for recovery and repayment.

From the day Ecrypto started operating it was under attack. Many attempts to penetrate the servers occured and attempts to hack my personal accounts were constant. Unfortunatly on the morning of December 28 the attacker was successful in gaining entry to the wallet servers. Things were operating normally when I noticed the wallet balance had gone to -11 BTC. A few minutes later the wallet servers stopped responding completly, and access to them through the command line became impossible. Digital Ocean began to investigate the problem and after some time sent this response.

Greetings,

I appreciate your patience. After loading your droplet's into a recovery environment, it appears that someone has compromised both of your droplet's, and stolen your bitcoin from the `W2` droplet. This is confirmed from the `.bash_history` file, which the attack did not effectively remove. In an attempt to cover their tracks, they attempted to wipe out your droplets filesystem with `rm -rf /`, but mistakenly left the `/root` folder, which left some of the data for the blocks you had found.

On the `W1` droplet, it is not apparent if there were any *coin's transferred, as the .bash_history folder over there was effectively wiped out prior to the `rm -rf /` on that droplet.

For your reference, both droplets remain in the recovery environment right now, and have the drives mounted. I've taken a few screenshots of the console and pulled of the transfer of your 11 bitcoin on blockchain.info to confirm the theft:
http://screencast.com/t/Ba7Mvgh6md0
http://screencast.com/t/1eKtogngnw
https://blockchain.info/address/19Xn6GPjMoj8FMLMWg77Wq7PNiFSUsZxSV

Given the nature of bitcoin, this theft is effectively irreversible. Unfortunately, even if the data of your droplet's did remain intact, the theft would remain irreversible.

I would certainly be quite suspicious of this compromise, as if these bitcoin were just transferred last night, it would seem someone associated with you, or the other party, is well aware of your two mining droplets, or may have had access to the droplet's prior.

Unfortunately, there is truly nothing more that we are able to do for you at this point.

Regards,
Russell Mitchell | Support Team

There is noone with access to the account information hare so clearly this was a pure hack. I made great efforts to make the servers impossible to hack, however the hacker simply walked right in and stole everything. The coins they did not steal, they deleted. Since the attack I have just been sick to my stomach. Ecrypto has taken 6 months of 16 hour days to build, and anyone suggesting this was a theft by me is a complete fool. The total stolen was only 11 BTC which is not a huge amount. If the hacker had waited, they would have been able to steal a significant amount more, but it is obviously just an impatient child. I am currently reworking the entire setup, making significant changes that will make it impossible to penetrate. The wallet servers will have NO communications with the website server at all, and gaining access to them should be impossible. The weak point will be the weak passwords that Digital Ocean automatically generates for servers, but since the wallet server will have no connection with the website, even finding the server will be nearly impossible. I will also change the location of the wallet server at least once a week, and transfer the majority of BTC and LTC in the wallets into cold storage for additional security.

So the next question is, when will you get the coins you lost back? We have backup images of the wallet balances at the time of the attack. When the site comes back up, 100% of fees collected by the site will go to pay back lost coins. Not only will you receive the coins you lost, you will receive a 50% bonus. So for every 2 coins you had at the time of the attack - you will receive 3 coins as repayment.

Unfortunatly this is the best I can do for now. I personally suffered a large loss as well which makes it impossible to repay the lost coins faster than the plan.

When will the service resume operations? I am thinking a month or so. I need to make the servers bulletproof, and that will take time. If you feel the need to rant or call me names you can email ecryptox@gmail.com. Reasonable emails will be responded to ASAP.
Crypty3
Newbie
*
Offline Offline

Activity: 42
Merit: 0


View Profile
January 02, 2015, 11:39:00 AM
 #61


He claims it was only was only 11 BTC, but he also promised to pay everyone back 150% of what they lost, which he never did.
Classic hallmark of a scammer....
HyAfo
Member
**
Offline Offline

Activity: 101
Merit: 10


View Profile
April 02, 2016, 07:33:39 PM
 #62


_https://www.facebook.com/smagik

Blur scammer back to life .

CURRENT CITY AND HOMETOWN

Victoria, British Columbia
Current city

Halifax, Nova Scotia (former city)
Hometown

We never forget to fuck you  Grin
Pages: 1 2 3 4 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!