simplecoin (OP)
|
|
October 18, 2011, 07:56:37 PM Last edit: October 20, 2011, 07:15:00 PM by simplecoin |
|
UPDATE: Site online, BTC/NMC pools are active. GG & TBX pools will return once I can match all the txids from the previous wallets.
While there was no evidence of foul play. I was still uncomfortable flipping the server back online. So, I started from scratch making it more secure along the way. There was no loss of funds and all balances remain.
All accounts were locked just in case there was a data breach, use the password recovery to unlock your account. If you have any troubles doing so, please msg me here or in #simplecoin on freenode.
Thanks, Mike (simplecoin)
(Previous Message) _______________________________________________________________________________ _________________________
I regret to inform everyone there was a likely breach at simplecoin.us.
What is known so far: The main pool server home directory was wiped clean, including wallet backups. The pool username also had the password changed. The live pool wallets were thankfully not in the home directory and were recovered.
What has been done: The balances of the wallets are being transferred. There are no apparent losses so far. The servers have been physically shut down to prevent any other data loss.
What this means to you: It is possible your user data is compromised. While PINs & Passwords were encrypted, please change any passwords that you used here.
I am working hard to minimize the damage from this likely intrusion, I will post updates as more information is known.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
RyNinDaCleM
Legendary
Offline
Activity: 2408
Merit: 1009
Legen -wait for it- dary
|
|
October 18, 2011, 08:04:17 PM |
|
thank you!
hoping for the best!
|
|
|
|
REF
|
|
October 18, 2011, 08:17:33 PM |
|
well that sounds like a definite hack not Probable. Its good to hear that user wallets are safe. I hope the situation doesn't change and everything is recovered without problems.
|
|
|
|
simplecoin (OP)
|
|
October 18, 2011, 08:19:49 PM |
|
well that sounds like a definite hack not Probable. Its good to hear that user wallets are safe. I hope the situation doesn't change and everything is recovered without problems.
Short of someone at the datacenter changing things (they were fixing ipv6 issues), it most likely is an intrusion.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
hmblm1245
|
|
October 18, 2011, 08:46:55 PM Last edit: October 18, 2011, 09:03:06 PM by hmblm1245 |
|
thank you!
hoping for the best!
Agreed, good luck. Let me know if you need any help parsing through logs, checking IPs... of course i know a lot of that is sedative data anyways, but the offer still stands. Edit: sensitive (crazy auto correct)
|
|
|
|
simplecoin (OP)
|
|
October 18, 2011, 08:49:21 PM |
|
thank you!
hoping for the best!
Agreed, good luck. Let me know if you need any help parsing through logs, checking IPs... of course i know a lot of that is sedative data anyways, but the offer still stands. Thanks. Right now I'm focusing on the coins. Maybe I'll get lucky and the IP will be in the user logs. I'm hoping shutting the machine down kept them from covering their tracks.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
Coinbuck @ BTCLot
|
|
October 18, 2011, 09:01:33 PM |
|
Good to know that, a friend of mine was asking me all the afternoon what happened to simplecoin.
Please keep us informed.
Regards,
|
|
|
|
Mobius
|
|
October 18, 2011, 09:15:49 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
|
|
|
|
Eveofwar
|
|
October 18, 2011, 09:16:40 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
I regret to inform everyone there was a likely breach at simplecoin.us.
What is known so far: The main pool server home directory was wiped clean, including wallet backups. The pool username also had the password changed. The live pool wallets were thankfully not in the home directory and were recovered.
What has been done: The balances of the wallets are being transferred. There are no apparent losses so far. The servers have been physically shut down to prevent any other data loss.
What this means to you: It is possible your user data is compromised. While PINs & Passwords were encrypted, please change any passwords that you used here.
I am working hard to minimize the damage from this likely intrusion, I will post updates as more information is known.
|
|
|
|
simplecoin (OP)
|
|
October 18, 2011, 09:20:01 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
I will be paying out balances as soon as I can confirm their validity.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
Mobius
|
|
October 18, 2011, 09:27:16 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
I regret to inform everyone there was a likely breach at simplecoin.us.
What is known so far: The main pool server home directory was wiped clean, including wallet backups. The pool username also had the password changed. The live pool wallets were thankfully not in the home directory and were recovered.
What has been done: The balances of the wallets are being transferred. There are no apparent losses so far. The servers have been physically shut down to prevent any other data loss.
What is your specific time frame for completion of this task, since "There are no apparent losses so far."
|
|
|
|
Eveofwar
|
|
October 18, 2011, 09:30:12 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
I regret to inform everyone there was a likely breach at simplecoin.us.
What is known so far: The main pool server home directory was wiped clean, including wallet backups. The pool username also had the password changed. The live pool wallets were thankfully not in the home directory and were recovered.
What has been done: The balances of the wallets are being transferred. There are no apparent losses so far. The servers have been physically shut down to prevent any other data loss.
What is your specific time frame for completion of this task, since "There are no apparent losses so far." When will you be paying all outstanding balances? or was that compromised also?
I will be paying out balances as soon as I can confirm their validity.
|
|
|
|
simplecoin (OP)
|
|
October 18, 2011, 09:32:21 PM |
|
When will you be paying all outstanding balances? or was that compromised also?
I regret to inform everyone there was a likely breach at simplecoin.us.
What is known so far: The main pool server home directory was wiped clean, including wallet backups. The pool username also had the password changed. The live pool wallets were thankfully not in the home directory and were recovered.
What has been done: The balances of the wallets are being transferred. There are no apparent losses so far. The servers have been physically shut down to prevent any other data loss.
What is your specific time frame for completion of this task, since "There are no apparent losses so far." Right now the priority is to transfer funds as the blocks are confirmed. There is not a specific time frame, as the level of damage has not yet even been fully assessed.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
simplecoin (OP)
|
|
October 18, 2011, 10:47:01 PM |
|
Ok, upon reboot. Everything is still intact. User tables, user data, even the missing files.
I'd like to hope this is a false alarm and just a mounted drive issue. However, I'm still going to thoroughly audit everything before turning the site back on.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
hmblm1245
|
|
October 18, 2011, 11:56:53 PM |
|
Ok, upon reboot. Everything is still intact. User tables, user data, even the missing files.
I'd like to hope this is a false alarm and just a mounted drive issue. However, I'm still going to thoroughly audit everything before turning the site back on.
Sounds like a professional response. Thanks.
|
|
|
|
simplecoin (OP)
|
|
October 19, 2011, 05:18:01 PM |
|
While everything checks out, even the logs (no successful connections to ssh or webmin but my own either)... I'm still not sold that there was no foul play.
So, I'm wiping the servers and restoring everything freshly.
That may add another day of downtime, but I want to be sure this issue is resolved once and for all.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
Iyeman
|
|
October 19, 2011, 05:33:24 PM |
|
While everything checks out, even the logs (no successful connections to ssh or webmin but my own either)... I'm still not sold that there was no foul play.
So, I'm wiping the servers and restoring everything freshly.
That may add another day of downtime, but I want to be sure this issue is resolved once and for all.
Wiping the server and starting over is only going to solve the problem if you fix however someone got access to it...since you can't fiind a way that someone accessed it then the problem can't be fixed (if there is a problem) so wiping and reloading seems like a waste of time lol
|
|
|
|
simplecoin (OP)
|
|
October 19, 2011, 05:44:11 PM |
|
While everything checks out, even the logs (no successful connections to ssh or webmin but my own either)... I'm still not sold that there was no foul play.
So, I'm wiping the servers and restoring everything freshly.
That may add another day of downtime, but I want to be sure this issue is resolved once and for all.
Wiping the server and starting over is only going to solve the problem if you fix however someone got access to it...since you can't fiind a way that someone accessed it then the problem can't be fixed (if there is a problem) so wiping and reloading seems like a waste of time lol Wiping WILL remove any possible threats (I could have just turned the pool back on, but I'd rather be safe). I will be taking additional precautions as well. SSH will be locked to my local certificate and IP. Webmin will be locked to my local IP. The only publicly open ports will be nginx and possibly pushpool (although I've heard of no one who needed to bypass the proxy). All others will be firewalled off entirely.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
martychubbs
|
|
October 19, 2011, 08:58:19 PM |
|
We appreciate the hard work! What your planned time-frame to go live again?
|
|
|
|
simplecoin (OP)
|
|
October 19, 2011, 08:59:47 PM |
|
We appreciate the hard work! What your planned time-frame to go live again?
If all works out, I should be ready tonight (CST), if not hopefully tomorrow. The rebuild has gone very smoothly so far.
|
Donations: 1VjGJHPtLodwCFBDWsHJMdEhqRcRKdBQk
|
|
|
|