Bitcoin Forum
May 13, 2024, 05:00:11 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ip address instead of bitcoin talk address?  (Read 511 times)
techman05 (OP)
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


View Profile WWW
January 31, 2014, 01:30:18 AM
Last edit: January 31, 2014, 01:43:08 AM by techman05
 #1

I'm hoping this is not a sign of bad things to come but instead of bitcointalk.org in an address I got an ip address link to the post of interest.

The ip was/is : https://109.201.133.195  

Just thought I'd post it so someone can make sure something didn't die on the domain or if this is something new to expect from this site. I don't normaly open bitcoin talk post by ip since who knows whats on the other end .

Hope this helps the universe.

edit..
http://ip-lookup.net/index.php seems to show this is bitcoin talks ip address, but still weird.

Like the info address for potential tips Wink
BTC 1CL5BnNhdL2wDVmSDwMbW1cNhZew87CAPV
* http://www.miningrigrentals.com/register?ref=563
1715576411
Hero Member
*
Offline Offline

Posts: 1715576411

View Profile Personal Message (Offline)

Ignore
1715576411
Reply with quote  #2

1715576411
Report to moderator
1715576411
Hero Member
*
Offline Offline

Posts: 1715576411

View Profile Personal Message (Offline)

Ignore
1715576411
Reply with quote  #2

1715576411
Report to moderator
1715576411
Hero Member
*
Offline Offline

Posts: 1715576411

View Profile Personal Message (Offline)

Ignore
1715576411
Reply with quote  #2

1715576411
Report to moderator
The Bitcoin software, network, and concept is called "Bitcoin" with a capitalized "B". Bitcoin currency units are called "bitcoins" with a lowercase "b" -- this is often abbreviated BTC.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715576411
Hero Member
*
Offline Offline

Posts: 1715576411

View Profile Personal Message (Offline)

Ignore
1715576411
Reply with quote  #2

1715576411
Report to moderator
Malexo
Newbie
*
Offline Offline

Activity: 56
Merit: 0


View Profile
January 31, 2014, 01:40:19 AM
 #2

talk dot org and talk dot com are not the same... you know that right?
techman05 (OP)
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


View Profile WWW
January 31, 2014, 01:45:00 AM
 #3

Still the address is to bitcoin talk for whatever popped up as an ip address.

Did you get the point that my oops was not the issue being noted.

Like the info address for potential tips Wink
BTC 1CL5BnNhdL2wDVmSDwMbW1cNhZew87CAPV
* http://www.miningrigrentals.com/register?ref=563
Kouye
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250


Cuddling, censored, unicorn-shaped troll.


View Profile
January 31, 2014, 01:58:31 AM
 #4

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Here's what we think happened:

8-14 hours ago, an attacker used a flaw in the forum's AnonymousSpeech registrar to change the forum's DNS to point to 108.162.197.161 (exact details unknown). Sirius noticed this 8 hours ago and immediately transferred bitcointalk.org to a different registrar. However, such changes take about 24 hours to propagate.

Because the HTTPS protocol is pretty terrible, this alone could have allowed the attacker to intercept and modify encrypted forum transmissions, allowing them to see passwords sent during login, authentication cookies, PMs, etc. Your password only could have been intercepted if you actually entered it while the forum was affected. I invalidated all security codes, so you're not at risk of having your account stolen if you logged in using the "remember me" feature without actually entering your password.

For the next ~20 hours, you should only log into the forum if you're quite sure that you're talking to the correct server. This can be done by adding '109.201.133.195 bitcointalk.org' to your hosts file (remember to remove it later!), or by using some browser plugin to ensure that you're talking to the server with TLS certificate SHA1 fingerprint of:
29:0E:CC:82:2B:3C:CE:0A:73:94:35:A0:26:15:EC:D3:EB:1F:46:6B

Simultaniously, the forum has been the target of a massive DDoS attack. These two events are probably related, though I'm not yet sure why an attacker would do both of these things at once.
-----BEGIN PGP SIGNATURE-----

iF4EAREIAAYFAlKb2nkACgkQxlVWk9q1kefhTwD+Ni5k7CUrHjvzG29wO3Gx4Am+
MV5tdw8zE1AAWvbstt8BAIrndOXCYmawoXN+VeSZkLXHnCyQbR8IOftQnpl2aXYs
=465T
-----END PGP SIGNATURE-----


TL;DR : 109.201.133.195 is probably safe, until theymos states otherwise.

[OVER] RIDDLES 2nd edition --- this was claimed. Look out for 3rd edition!
I won't ever ask for a loan nor offer any escrow service. If I do, please consider my account as hacked.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!