Bitcoin Forum
May 14, 2024, 04:59:27 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Warning: One or more bitcointalk.org users have reported that they strongly believe that the creator of this topic is a scammer. (Login to see the detailed trust ratings.) While the bitcointalk.org administration does not verify such claims, you should proceed with extreme caution.
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34] 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 ... 280 »
  Print  
Author Topic: Eligius: 0% Fee BTC, 105% PPS NMC, No registration, CPPSRB  (Read 1061088 times)
This is a self-moderated topic. If you do not want to be moderated by the person who started this topic, create a new topic.
Tursk
Member
**
Offline Offline

Activity: 92
Merit: 10


View Profile
March 13, 2014, 07:49:55 PM
 #661



So it looks like today's manual NMC payout went to a thief.

My NMC address was changed too.

1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
"In a nutshell, the network works like a distributed timestamp server, stamping the first transaction to spend a coin. It takes advantage of the nature of information being easy to spread but hard to stifle." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
1715662767
Hero Member
*
Offline Offline

Posts: 1715662767

View Profile Personal Message (Offline)

Ignore
1715662767
Reply with quote  #2

1715662767
Report to moderator
gallery2000
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


Live Stars - Adult Streaming Platform


View Profile
March 13, 2014, 08:13:08 PM
 #662

How long does it take to get pay?  I got 0.9 BTC but have not been paid for two days.

MrTeal
Legendary
*
Offline Offline

Activity: 1274
Merit: 1004


View Profile
March 13, 2014, 08:18:17 PM
 #663

How long does it take to get pay?  I got 0.9 BTC but have not been paid for two days.
After an orphan WK has to do a manual payout, which he usually does once per day. There's some traveling going on right now though, so expect a delay. I also wouldn't be surprised if there was a delay related to the NMC kerfuffle.
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 08:34:49 PM
 #664

Investigating issue with stats/My Eligius exploit.

Taking stats offline temporarily to investigate and compare database with the most recent backups and to parse through some logs.

I will put them back online as soon as I have pulled the majority of the data to a secondary server for verification.  Shouldn't take more than an hour.

There has been no compromise of the pool or its servers.  

Yes, most of the NMC payouts went to some rogue address today. Sad  This, honestly, is my fault, because I generally at the very least do a cursory parse through the NMC payout list before submitting it to the network.  In my haste I did not today and seems that was a mistake on my part which will not happen again.  There is enough NMC buffer to cover the loss and I will make sure everyone gets paid properly once I correct the issues.

I will post more details as soon as I finish my audits of the stats code.

-wk

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 08:41:36 PM
 #665

Are we ok to continue mining?

Yes, there has been no compromise of any server.  This just affects stats and NMC.

The security model of how the pool servers are partitioned from the web server prevents any issue like this from affecting the pool itself.

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
praeluceo
Full Member
***
Offline Offline

Activity: 123
Merit: 100


View Profile
March 13, 2014, 08:50:54 PM
 #666

Investigating issue with stats/My Eligius exploit.

Taking stats offline temporarily to investigate and compare database with the most recent backups and to parse through some logs.

I will put them back online as soon as I have pulled the majority of the data to a secondary server for verification.  Shouldn't take more than an hour.

There has been no compromise of the pool or its servers.  

Yes, most of the NMC payouts went to some rogue address today. Sad  This, honestly, is my fault, because I generally at the very least do a cursory parse through the NMC payout list before submitting it to the network.  In my haste I did not today and seems that was a mistake on my part which will not happen again.  There is enough NMC buffer to cover the loss and I will make sure everyone gets paid properly once I correct the issues.

I will post more details as soon as I finish my audits of the stats code.

-wk

Could you inform us of the address(es) that the thief inserted for the payouts since it'll probably be fixed by the time you bring MyStats back online? I would be...interested in tracking that wallet's historic and future transactions.

edit: didn't realize I was on the wrong page and had lost a page of comments! My mistake, oops, sorry!
Apparently we're watching for this guy: http://explorer.namecoin.info/a/N4CVwS13ELKimdJNEChgMJnLZiA7L6MU5F
freebit13
Hero Member
*****
Offline Offline

Activity: 616
Merit: 500

I got Satoshi's avatar!


View Profile
March 13, 2014, 08:53:03 PM
 #667

How often are NMC payments made? I'm not sure I've ever gotten one. Smiley

Edit: I passed on the situation via support ticket and IRC. I figure that's more useful than just complaining here. Wink
I suggest checking if the exchange wallet you are using supports mined coins, apparently there are some that don't.

Decentralize EVERYTHING!
roy7
Sr. Member
****
Offline Offline

Activity: 434
Merit: 250


View Profile
March 13, 2014, 09:12:58 PM
 #668

How often are NMC payments made? I'm not sure I've ever gotten one. Smiley

Edit: I passed on the situation via support ticket and IRC. I figure that's more useful than just complaining here. Wink
I suggest checking if the exchange wallet you are using supports mined coins, apparently there are some that don't.

I was referring only to NMC. NMC coins aren't mined directly to the payment addresses I believe. For my BTC I mine to my normal Electrum wallet.
ajw7989
Legendary
*
Offline Offline

Activity: 924
Merit: 1000


View Profile
March 13, 2014, 09:45:27 PM
 #669

good to hear that the mining was not compromised I noticed a 2-3 times today that my miner failed to connected to the pool for a few minutes. Is there something going on with the mining server too?
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 09:47:28 PM
 #670

good to hear that the mining was not compromised I noticed a 2-3 times today that my miner failed to connected to the pool for a few minutes. Is there something going on with the mining server too?

I've gone through all of the servers just as a precaution and everything is fine.  Connectivity has been solid, and all pool servers are functional.

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
not.you
Legendary
*
Offline Offline

Activity: 1726
Merit: 1018


View Profile
March 13, 2014, 09:52:07 PM
 #671

I guess I don't understand how everyone's NMC address was changed to the same thing if there was no hack.  I also haven't seen an NMC payout since the 9th.  Do we need to go back and change our NMC addresses to what they should be or will they be restored from backup?
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 10:10:46 PM
 #672

I guess I don't understand how everyone's NMC address was changed to the same thing if there was no hack.  I also haven't seen an NMC payout since the 9th.  Do we need to go back and change our NMC addresses to what they should be or will they be restored from backup?

It was an exploit of the stats code (open source), not a hack of the actual server(s).

And, no, I will fix everyone's NMC addresses using the verified data on the core server, which is not affected by this (since the new options/signatures didn't pass the re-verification).

I will also get the proper payouts out to everyone.

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
bolverk
Newbie
*
Offline Offline

Activity: 52
Merit: 0


View Profile
March 13, 2014, 10:12:31 PM
 #673

Pay attention to what was said:  the pool servers are fine, they didn't get hacked.  The portal, however, is a different story.  Wiz is on it.

Wiz:  I hope you're logging IP addresses, and have some back logs to troll.  I'd be interested in knowing if the jack wagon changing the NMC address did so from the same IP as one of your registered users.  He'd be a poor hacker if he did, but half these script kiddies don't understand how network services work, anyway.
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 10:14:27 PM
 #674

Pay attention to what was said:  the pool servers are fine, they didn't get hacked.  The portal, however, is a different story.  Wiz is on it.

Wiz:  I hope you're logging IP addresses, and have some back logs to troll.  I'd be interested in knowing if the jack wagon changing the NMC address did so from the same IP as one of your registered users.  He'd be a poor hacker if he did, but half these script kiddies don't understand how network services work, anyway.

The IP of the attacker is 178.252.115.200, but this obviously isn't all that useful.  This IP is actually associated with some attempted low-hashrate mining with the following addresses: 141Ui93eV83HSnpyDcvdtGtR3UqwYss5q7, 17hpCt7vWLCksCpUgQpFURjWHjZDhNDYhz, 1MsMx8hfYW6tS1Y9oGZhAbSqvrD8DDgNzN.  But, no earnings to speak of on these, really.

Note: I have no issues publicly revealing private data like this on attackers.

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
not.you
Legendary
*
Offline Offline

Activity: 1726
Merit: 1018


View Profile
March 13, 2014, 10:18:29 PM
 #675

I guess I don't understand how everyone's NMC address was changed to the same thing if there was no hack.  I also haven't seen an NMC payout since the 9th.  Do we need to go back and change our NMC addresses to what they should be or will they be restored from backup?

It was an exploit of the stats code (open source), not a hack of the actual server(s).


Oh I see.  You were being more precise in your terminology than I was, which is weird because usually I am the most pedantic person in any conversation I have.  Thanks for the clarification.
joolzg
Member
**
Offline Offline

Activity: 76
Merit: 10


View Profile
March 13, 2014, 10:35:00 PM
 #676

YEAH got my 1st BTC from my new T-IV machine, only need another 8.3 to break even :-)

joolz
sikke
Sr. Member
****
Offline Offline

Activity: 504
Merit: 250


View Profile
March 13, 2014, 10:36:52 PM
 #677

Pay attention to what was said:  the pool servers are fine, they didn't get hacked.  The portal, however, is a different story.  Wiz is on it.

Wiz:  I hope you're logging IP addresses, and have some back logs to troll.  I'd be interested in knowing if the jack wagon changing the NMC address did so from the same IP as one of your registered users.  He'd be a poor hacker if he did, but half these script kiddies don't understand how network services work, anyway.

The IP of the attacker is 178.252.115.200, but this obviously isn't all that useful.  This IP is actually associated with some attempted low-hashrate mining with the following addresses: 141Ui93eV83HSnpyDcvdtGtR3UqwYss5q7, 17hpCt7vWLCksCpUgQpFURjWHjZDhNDYhz, 1MsMx8hfYW6tS1Y9oGZhAbSqvrD8DDgNzN.  But, no earnings to speak of on these, really.

Note: I have no issues publicly revealing private data like this on attackers.

Yeh. thx for sharing

Russian IP from Saint Petersburg based home internet. fun to know at least  Grin
Luke-Jr
Legendary
*
Offline Offline

Activity: 2576
Merit: 1186



View Profile
March 13, 2014, 10:48:13 PM
 #678

How often are NMC payments made? I'm not sure I've ever gotten one. Smiley

Edit: I passed on the situation via support ticket and IRC. I figure that's more useful than just complaining here. Wink
I suggest checking if the exchange wallet you are using supports mined coins, apparently there are some that don't.

I was referring only to NMC. NMC coins aren't mined directly to the payment addresses I believe.
I would advise against assuming this, even though it is currently correct...

Kivela
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
March 13, 2014, 10:51:21 PM
 #679

Hi,

Will you restore our NMC addresses to a time before the attack or do we need to track this thread
to receive a go to be able to change it ourselves ?

Cheers and thanks for all your effort !
wizkid057 (OP)
Legendary
*
Offline Offline

Activity: 1223
Merit: 1006


View Profile
March 13, 2014, 10:51:53 PM
 #680

Hi,

Will you restore our NMC addresses to a time before the attack or do we need to track this thread
to receive a go to be able to change it ourselves ?

Cheers and thanks for all your effort !

I will fix them.

Tips: 1LDQrLr6dPVqNJmpZm82eZVKqDFRk7ERW8
Operator of the Eligius Mining Pool - 0% Fee, SAPPLNS, GBT, Stratum, IRC+Phone Support, Share Market (coming soon), Generation payouts, and more.
Don't feed the trolls. Science Confirms: Internet Trolls Really Are Narcissistic, Psychopathic, and Sadistic (1)
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 [34] 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 ... 280 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!