Bitcoin Forum
November 15, 2024, 10:31:10 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 [29] 30 31 32 33 34 35 36 37 38 39 40 41 42 43 »
  Print  
Author Topic: [ANN] | freshmarket.co.in - Closed. Refunds till 10/02/14  (Read 41800 times)
filipej
Newbie
*
Offline Offline

Activity: 15
Merit: 0


View Profile
February 05, 2014, 12:53:31 PM
 #561

My coins was refund !!!  Thx you!

Please return from you marketplace quickly !! Eliminate all errors, raise your level of safety and back online!!

All the best for futures!
tsjaar
Full Member
***
Offline Offline

Activity: 135
Merit: 100


View Profile
February 05, 2014, 01:05:23 PM
 #562

My coins was refund !!!  Thx you!

Please return from you marketplace quickly !! Eliminate all errors, raise your level of safety and back online!!

All the best for futures!

+1 concept is good.

WARNING HIGH SPEED - UTC - Ultracoin
coinmarket.io
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
February 05, 2014, 01:08:47 PM
 #563

Running an exchange on PHP is as smart as it gets.
Not salting the passwords before hashing is ... plain stupid.
Allowing an SQL injection to happen is ... amateurish.

People, you cannot run a mission-critical application on a LAMP stack that has tens of 0-day exploits flying around every day.
fud_etra
Sr. Member
****
Offline Offline

Activity: 394
Merit: 250



View Profile
February 05, 2014, 01:12:45 PM
 #564

Still waiting for my coins to be back. Hope you can solve it soon, will update whenever I receive the coins. Thanks for your hard work.

           ▄▄███████▄▄
        ▄███▀▀
▄▄▄▄    ▀▄
     ▄▄█████████████▄▄  ▀▄
  ▄▀▀██▀           ▀▀██▄▄▀▄
▄▀  ██                 ▀██
  ██       ▀▀█▀▀         █
█▀        █ █ █        ▄█▀▄
▀▄         █ █ █       ▄█  █
 ██         █▄▄▄█      ▄█  ▄▀
  ██▄                ▄█▀  ▄▀
  ▀▄▀██▄▄          ▄█▀  ▄▀
   ▀▄ ▀▀███▄▄▄▄▄▄█████▀▀
     ▀▀▄▄▄▄▄▄▀▀▀▀▀▀▀
UTRUST▀████████▄
  ▀███████▄
    ▀██████▄
      ▀██████
       ▀█████
        ▀████▄
         █████
          ▀███
           ███
           ▀██
            ██
             █
●  Download WHITEPAPER  ●
▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ▼ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
facebook      twitter      slack
▀████████▄
  ▀███████▄
    ▀██████▄
      ▀██████
       ▀█████
        ▀████▄
         █████
          ▀███
           ███
           ▀██
            ██
             █
def_ender (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
February 05, 2014, 01:15:22 PM
 #565

Running an exchange on PHP is as smart as it gets.
Not salting the passwords before hashing is ... plain stupid.
Allowing an SQL injection to happen is ... amateurish.
People, you cannot run a mission-critical application on a LAMP stack that has tens of 0-day exploits flying around every day.
>not salting
Individual salt, sha-512
And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
coinmarket.io
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
February 05, 2014, 01:24:24 PM
 #566

And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
What happened? Did the coindaemons balance just drop or did the hacker access the users accounts and emptied some of them?

We know one possible attack scenario that has been used on many of the new exchanges, including ours (we survived the attacks).
Any place where we can inspect the source code of a withdrawal script? It would really be intresting to find out some truth about this "hack".
coinmarket.io
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
February 05, 2014, 01:26:49 PM
 #567

all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money
So you did not have any bruteforce protection on the login side?
def_ender (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
February 05, 2014, 01:31:50 PM
 #568

And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
What happened? Did the coindaemons balance just drop or did the hacker access the users accounts and emptied some of them?
We know one possible attack scenario that has been used on many of the new exchanges, including ours (we survived the attacks).
Any place where we can inspect the source code of a withdrawal script?
Nice idea, but later. Just now devs are too busy making refunds, and i don't have source code.
def_ender (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
February 05, 2014, 01:32:47 PM
 #569

all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money
So you did not have any bruteforce protection on the login side?
As i see - we made it. But you got to speak with devs about it.
ovichef
Newbie
*
Offline Offline

Activity: 18
Merit: 0


View Profile
February 05, 2014, 01:33:45 PM
 #570

account name:ovichef please refund my UTC about 710 to my wallet UmADikawUKmdnGcZq5cwU4AjQqCnWyqNfr and nutcoin i dont remenber how much i hope you can see my balance send to this
NX7VGwEm45FxsvZT7T6MyiEakCJrNQwaTg
DarkHunter04
Member
**
Offline Offline

Activity: 126
Merit: 11


View Profile
February 05, 2014, 01:35:13 PM
 #571

account name:ovichef please refund my UTC about 710 to my wallet UmADikawUKmdnGcZq5cwU4AjQqCnWyqNfr and nutcoin i dont remenber how much i hope you can see my balance send to this
NX7VGwEm45FxsvZT7T6MyiEakCJrNQwaTg

Read this: https://bitcointalk.org/index.php?topic=431365.msg4949863#msg4949863
herbitcoins
Member
**
Offline Offline

Activity: 78
Merit: 10


View Profile
February 05, 2014, 01:41:01 PM
 #572

Confirmation :


LTC refund : ok received
UTC refund : Not yet ok received

updated
sarlangg
Full Member
***
Offline Offline

Activity: 130
Merit: 100


View Profile
February 05, 2014, 01:41:35 PM
 #573

Hello again.
So we have 84% LTC, 64% of all LEAF and 100% of all other currencies.
We have found more than 400 LTC from our own wallets to refund as much as we can.
You have to email to support@freshmarket.co.in with:
your account name
what money and how much you had
adresses for withdrawal for all money.

I want you to make it public - obvsly there will be tonn of trolls like "I SENT IT WHERE IS MY MONEY", so i want you to post your taken withdrawals.
If your account was hacked - we cant refund you anything, because if we don't see money on your balance we can't really check if it was hacked or you just say you were hacked. We haven't stored passwords, so (as i see) only chance is brutefoce.

Refunds will start just now.

I already sent an E-mail with my E-mail account that was registered.

Username:  sarlangg

Potcoin address: PLzeDdT4jvZss3nERwpwKVyHdaiSdTtAA9
About 4,380?  I cant remember the exact number.

Litecoin address: LakfxNoutVhTSbiT3rRcKPe9EkeyJ87iWM
About 5.4?  I can't remember exact number either.




Also the above amounts are guestimations based on what I remember.  I do know the exact amounts I had 2 days ago:
Potcoin:  3137.96977479 POT
Litecoin:  6.13163135 LTC

I know I had a ton of POT/LTC buy orders in and I had some successful trades, hence why I can't remember the exact amount.
michielcoin
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
February 05, 2014, 01:41:54 PM
 #574

i have my UTC back!

Thanks for the fast refund!
Real1Guy
Member
**
Offline Offline

Activity: 112
Merit: 10


ooo yeaaa, dont worry


View Profile
February 05, 2014, 01:41:59 PM
 #575

Hello again.
So we have 84% LTC, 64% of all LEAF and 100% of all other currencies.
We have found more than 400 LTC from our own wallets to refund as much as we can.
You have to email to support@freshmarket.co.in with:
your account name
what money and how much you had
adresses for withdrawal for all money.

I want you to make it public - obvsly there will be tonn of trolls like "I SENT IT WHERE IS MY MONEY", so i want you to post your taken withdrawals.
If your account was hacked - we cant refund you anything, because if we don't see money on your balance we can't really check if it was hacked or you just say you were hacked. We haven't stored passwords, so (as i see) only chance is brutefoce.

Refunds will start just now.

sent e-mail
user : konjina

It is all good
DarkHunter04
Member
**
Offline Offline

Activity: 126
Merit: 11


View Profile
February 05, 2014, 01:42:46 PM
 #576

Hello again.
So we have 84% LTC, 64% of all LEAF and 100% of all other currencies.
We have found more than 400 LTC from our own wallets to refund as much as we can.
You have to email to support@freshmarket.co.in with:
your account name
what money and how much you had
adresses for withdrawal for all money.

I want you to make it public - obvsly there will be tonn of trolls like "I SENT IT WHERE IS MY MONEY", so i want you to post your taken withdrawals.
If your account was hacked - we cant refund you anything, because if we don't see money on your balance we can't really check if it was hacked or you just say you were hacked. We haven't stored passwords, so (as i see) only chance is brutefoce.

Refunds will start just now.

Username:  sarlangg

Potcoin address: PLzeDdT4jvZss3nERwpwKVyHdaiSdTtAA9
About 4,380?  I cant remember the exact number.

Litecoin address: LakfxNoutVhTSbiT3rRcKPe9EkeyJ87iWM
About 5.4?  I can't remember exact number either.




Also the above amounts are guestimations based on what I remember.  I do know the exact amounts I had 2 days ago:
Potcoin:  3137.96977479 POT
Litecoin:  6.13163135 LTC

I know I had a ton of POT/LTC buy orders in and I had some successful trades, hence why I can't remember the exact amount.
Send an email - I think they have only time for email refunds Smiley
bcpete
Newbie
*
Offline Offline

Activity: 54
Merit: 0


View Profile
February 05, 2014, 01:43:21 PM
 #577

if I wait.....will my balance be still the same???or is it a must for me to get a refund?
def_ender (OP)
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
February 05, 2014, 01:50:38 PM
 #578

if I wait.....will my balance be still the same???or is it a must for me to get a refund?
Sorry, i don't understand the question.

Just now processed 48/111 more unprocessed.
rze
Full Member
***
Offline Offline

Activity: 194
Merit: 100


View Profile
February 05, 2014, 01:52:30 PM
 #579

All sent, thank you! (3.068814 LTC of 3.647 LTC)
jetlee
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
February 05, 2014, 01:55:28 PM
 #580

if I wait.....will my balance be still the same???or is it a must for me to get a refund?
Sorry, i don't understand the question.

Just now processed 48/111 more unprocessed.
i think he mean if he is willing to wait until the website is fixed and restored, is it gona get full refund into his account?
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 [29] 30 31 32 33 34 35 36 37 38 39 40 41 42 43 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!