Bitcoin Forum
June 20, 2024, 11:39:03 AM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 »  All
  Print  
Author Topic: Looks like my BTC wallet was hacked  (Read 7166 times)
suprastan
Newbie
*
Offline Offline

Activity: 27
Merit: 0


View Profile
February 18, 2014, 03:43:17 PM
 #41

Mod_Security would most likely have prevented files from being uploaded and executed, which it sounds like happened here.

Sad
Goldshredder
Full Member
***
Offline Offline

Activity: 249
Merit: 100


View Profile
February 18, 2014, 05:45:36 PM
 #42

Perhaps you could reach an arrangement with somebody like fcmatt, to do some private security consulting for you.  At the very least it would be a second layer, a second set of experienced eyes keeping watch on that side of your site.  I always feared right from the start the possibility of thieves coming against you as you became higher profile.
El_Nickio
Member
**
Offline Offline

Activity: 95
Merit: 10


View Profile
February 18, 2014, 06:05:44 PM
 #43

Sorry for your troubles Tommo - I'd be happy for a zeroed account and a fresh start!
dddbtc
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250



View Profile
February 18, 2014, 06:14:54 PM
 #44

Interesting, I've also found a call to the file tompoolforum/library/lib.php, but I don't see this file in the vanilla forums project git. Viewing the file it looks like this:

<?php
$o="QAEAOzh3b3cKDQAjYnV1aHVYdWIAAHdodXNuaWAvMC48Cg1HdGIAAHNYamZgbmRYdnJoc2J0WHUAgHJ pc25qYi83AfFoZVh0c2Z1JABzLwDRI2oBkSc6J2J/d2toY2IAEy8gJ ... (about 40 thousand characters more) ... RsbGxsbGxsbGwpOw=="));return;?>

If I load the page the source looks like this:

<style type="text/css">
   input {font:11px Verdana;BACKGROUND: #FFFFFF;height: 18px;border: 1px solid #666666;}
</style>
<form method="POST" action="">
   <span style="font:11px Verdana;">Password: </span><input name="password" type="password" size="20">
   <input type="hidden" name="doing" value="login">
   <input type="submit" value="Login">
</form>

It renders as a password input field with a Login button.

I am a user of your pool. This is very unfortunate.  I have also been following the hack of the TomCoin portion for the past few days.  Please copy all of suspicious PHP source and make a pastebin.  I should be able to decrypt it and give you more information regarding the attack on your pool.

Thanks and Best of Luck!
Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
February 18, 2014, 11:08:44 PM
 #45

I am a user of your pool. This is very unfortunate.  I have also been following the hack of the TomCoin portion for the past few days.  Please copy all of suspicious PHP source and make a pastebin.  I should be able to decrypt it and give you more information regarding the attack on your pool.

Thanks and Best of Luck!

What would be a good place to upload it? I could put it in a zip file.

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
Hushpupy
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
February 19, 2014, 05:11:00 AM
 #46

Sorry for your troubles Tommo - I'd be happy for a zeroed account and a fresh start!
I will be happy to donate my miners on your pool for a day to help you build up your pool again. 38gh for a day. Let start a donation to Tom pool! Any else would like to make a miner donation to Tom pool?
Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
February 19, 2014, 05:22:51 AM
 #47

Heh many thanks but no need, I'll just get things back up and more secure then hope some miners return Smiley

I've removed the forum software, changed passwords, reviewed files in the web directories and blocked a heap of ports (about the only ones open now are for the web server, mining (stratum) and SSH access).

TomCoin is now up, should have the other pools and multipools up soon. I'm just taking this as an opportunity to load balance between the servers as running so many wallets on my server with lower disk I/O is hurting its performance.

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
fcmatt
Legendary
*
Offline Offline

Activity: 2072
Merit: 1001


View Profile
February 19, 2014, 05:24:27 AM
 #48

Heh many thanks but no need, I'll just get things back up and more secure then hope some miners return Smiley

I've removed the forum software, changed passwords, reviewed files in the web directories and blocked a heap of ports (about the only ones open now are for the web server, mining (stratum) and SSH access).

TomCoin is now up, should have the other pools and multipools up soon. I'm just taking this as an opportunity to load balance between the servers as running so many wallets on my server with lower disk I/O is hurting its performance.

tommo, i am glad to see you up and running again.

perhaps i can message you in the future if i have any curious questions about your experiences running a multicoin pool?
tertius993
Hero Member
*****
Offline Offline

Activity: 1029
Merit: 712


View Profile
February 19, 2014, 07:14:55 AM
 #49

Good news.  My miner switched back automatically when the pool came back online.
Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
February 19, 2014, 01:13:57 PM
 #50

Thanks guys, I've just brought the individual pools and multipools back online, hopefully some smooth sailing from here!

Don't hesitate to contact me fcmatt, thanks for all your help identifying the point of entry you were spot on, I'd be glad to return the favour Smiley

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
dddbtc
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250



View Profile
February 19, 2014, 02:08:45 PM
 #51

I am a user of your pool. This is very unfortunate.  I have also been following the hack of the TomCoin portion for the past few days.  Please copy all of suspicious PHP source and make a pastebin.  I should be able to decrypt it and give you more information regarding the attack on your pool.

Thanks and Best of Luck!

What would be a good place to upload it? I could put it in a zip file.

http://www.zippyshare.com/ would work nicely. They don't have any ads or compulsory registration.
creepywheepy
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
February 19, 2014, 04:05:13 PM
 #52

Sorry to hear that. I wonder cause hacking is really a big problem - what is the best way to protect from hacks?

Donations - d5737925-d46d-47ec-9941-94a12a68861b
Hushpupy
Newbie
*
Offline Offline

Activity: 8
Merit: 0


View Profile
February 19, 2014, 04:16:54 PM
 #53

Tom Pool is up and running again!!!!!
dddbtc
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250



View Profile
February 19, 2014, 04:19:56 PM
 #54

Tom Pool is up and running again!!!!

Have happily kept 30GH/s on tompool the entire time. Thankfully I am auto-withdrawing altcoins to cryptsy and not utilizing TomCoin.  Really glad to see the project wasn't closed due to the hack.
Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
February 21, 2014, 01:06:56 AM
 #55

I've uploaded the lib.php file to here:

http://www8.zippyshare.com/v/82893458/file.html

I'd greatly appreciate if someone could take a look at it just to make sure there isn't anything else I should worry about.

Checked my BTC wallet today and found another transaction, luckily it wasn't significant as everything else had been emptied out earlier... little shit ('scuse my French) going back for more. I did a file contents search and found another instance of it in my web dir under a different name. I'd moved all of the other wallets to another server earlier on so access was only available to the one wallet. I've since deleted this last instance of the craplication.

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
fcmatt
Legendary
*
Offline Offline

Activity: 2072
Merit: 1001


View Profile
February 21, 2014, 01:15:17 AM
 #56

I've uploaded the lib.php file to here:

http://www8.zippyshare.com/v/82893458/file.html

I'd greatly appreciate if someone could take a look at it just to make sure there isn't anything else I should worry about.

Checked my BTC wallet today and found another transaction, luckily it wasn't significant as everything else had been emptied out earlier... little shit ('scuse my French) going back for more. I did a file contents search and found another instance of it in my web dir under a different name. I'd moved all of the other wallets to another server earlier on so access was only available to the one wallet. I've since deleted this last instance of the craplication.

You really need to remove everything from www dir and put back only what you know. Or list all files looking for newer dates, file creation times, files created by www instead of root or your normal user you edit files with,etc They tend to leave multiples of these backdoors for this exact reason.  i failed to mention this to you but i did say start www from scratch or review every file.
Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
February 21, 2014, 02:19:11 AM
 #57

You really need to remove everything from www dir and put back only what you know. Or list all files looking for newer dates, file creation times, files created by www instead of root or your normal user you edit files with,etc They tend to leave multiples of these backdoors for this exact reason.  i failed to mention this to you but i did say start www from scratch or review every file.

Yeah I checked through the files and creation dates, somehow I missed this one.

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
pengoau
Full Member
***
Offline Offline

Activity: 208
Merit: 100


View Profile
February 21, 2014, 10:45:31 AM
 #58

I am a user of your pool. This is very unfortunate.  I have also been following the hack of the TomCoin portion for the past few days.  Please copy all of suspicious PHP source and make a pastebin.  I should be able to decrypt it and give you more information regarding the attack on your pool.

Thanks and Best of Luck!

What would be a good place to upload it? I could put it in a zip file.

Even tho I'm late...

A good file sharing site is:  mega.co.nz

Security suggestion: Implement 2 Factor Auth (now that the backdoor is known and gone) and mod_security to prevent hackers uploading files if they find a new backdoor.

Just my 2c worth...
Any money the hacker is watching this thread and found out about your pool from this forum.

Paranoid much? Smiley

Sucks to hear you got hacked tommo, good to hear you are persisting and this has been a worthwhile learning experience. At least only 10k or so of coins were stolen so there is no real need for clients to come after you. You don't need legal or financial problems to be added to your grief.

Tommo_Aus (OP)
Sr. Member
****
Offline Offline

Activity: 420
Merit: 250


View Profile
July 14, 2014, 12:36:53 AM
 #59

Been a while since this happened but does this mean the coins are still sitting in the same address?

https://blockchain.info/address/1EEERRbx4v6TNxgHJNthgroKBQLhehgdRt

Really sucks seeing the coins there in limbo in someone else's account.

Tompool - http://tompool.org - a 2% fee SHA256/Scrypt/BURST/Groestl multipool supporting ANC, ASC, DGC, EZC, FLO, GLD, GME, MNC, RYC, TGC, TRC, XNC, ZET & more
AliceWonder
Full Member
***
Offline Offline

Activity: 168
Merit: 100



View Profile
July 14, 2014, 08:54:40 PM
 #60

Looks that way to me.

QuarkCoin - what I believe bitcoin was intended to be. On reddit: http://www.reddit.com/r/QuarkCoin/
Pages: « 1 2 [3] 4 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!