Bitcoin Forum
May 12, 2024, 05:11:17 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 3 4 5 6 7 8 »  All
  Print  
Author Topic: Hackers steal data from MtGox server and release it with Mark's reddit account.  (Read 15312 times)
DeathAndTaxes (OP)
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
March 09, 2014, 04:52:47 PM
Last edit: March 10, 2014, 04:04:23 AM by DeathAndTaxes
 #1

http://www.reddit.com/r/Bitcoin/comments/1zz21j/mtgox_2014_hack_database_revealed_live_from_mark/

(oh and the dump is hosted on Mark's blog).

WARNING:  I haven't verified or scanned the files.  It is at least possible they contain malware including the bitcoin stealing kind.   BE SMART and take precautions when downloading unknown files from self described hackers.

On edit: the exe in the zip file a wallet stealer.  Don't run unless you have too many bitcoins and then it will solve that problem for you.
1715490677
Hero Member
*
Offline Offline

Posts: 1715490677

View Profile Personal Message (Offline)

Ignore
1715490677
Reply with quote  #2

1715490677
Report to moderator
Once a transaction has 6 confirmations, it is extremely unlikely that an attacker without at least 50% of the network's computation power would be able to reverse it.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715490677
Hero Member
*
Offline Offline

Posts: 1715490677

View Profile Personal Message (Offline)

Ignore
1715490677
Reply with quote  #2

1715490677
Report to moderator
1715490677
Hero Member
*
Offline Offline

Posts: 1715490677

View Profile Personal Message (Offline)

Ignore
1715490677
Reply with quote  #2

1715490677
Report to moderator
Definit
Sr. Member
****
Offline Offline

Activity: 357
Merit: 250



View Profile
March 09, 2014, 05:16:41 PM
 #2

they just removed his post.
Beliathon
Hero Member
*****
Offline Offline

Activity: 784
Merit: 1000


https://youtu.be/PZm8TTLR2NU


View Profile WWW
March 09, 2014, 05:24:01 PM
 #3

they just removed his post.
Well that was fast.

Remember Aaron Swartz, a 26 year old computer scientist who died defending the free flow of information.
Moebius327
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500



View Profile
March 09, 2014, 05:25:39 PM
Last edit: March 10, 2014, 10:53:36 AM by malevolent
 #4

Mod note: be careful with the executable, run it only on an isolated virtual machine

Files are legit. I verified them myself with my account balance. Be careful with .exe and .pdf (didn't take a look at that)

Edit: Here is the leak http://pastebin.com/f7DPskc7

the hackers removed december, january and february, but the user endbalances are right.
dserrano5
Legendary
*
Offline Offline

Activity: 1974
Merit: 1029



View Profile
March 09, 2014, 05:27:43 PM
Last edit: March 10, 2014, 10:52:13 AM by malevolent
 #5

they just removed his post.
Well that was fast.

Mod note: be careful with the executable, run it only on an isolated virtual machine

Copy: http://pastebin.com/f7DPskc7
bitjoint
Sr. Member
****
Offline Offline

Activity: 333
Merit: 250


Commander of the Hodl Legions


View Profile
March 09, 2014, 05:28:08 PM
 #6

It's back...

http://www.reddit.com/r/Bitcoin/comments/1zz21j/mtgox_2014_hack_database_revealed_live_from_mark/cfya4jg
Moebius327
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500



View Profile
March 09, 2014, 05:30:33 PM
 #7

It seems gox were 450 000 btc short, but still had around 501 000 btc in storage. So this is getting interesting.
Kenshin
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
March 09, 2014, 05:32:05 PM
Last edit: March 10, 2014, 10:51:45 AM by malevolent
 #8

Mod note: be careful with the executable, run it only on an isolated virtual machine

You can still get them from here:

http://blog.magicaltux.net/wp-content/uploads/2014/03/MtGox2014Leak.zip [1] (716MB)

http://89.248.171.30/MtGox2014Leak.zip [2]

http://pastebin.com/f7DPskc7 [3]

http://burnbit.com/download/280433/MtGox2014Leak_zip

https://mega.co.nz/#!0VliDQBA!4Ontdi2MsLD4J5dV1-sr7pAgEYTSMi8rNeEMBikEhAs

The magnetlink is:

magnet:?xt=urn:btih:b6545ecc7db8d44c8cbc4e93989edf8221af75f5&dn=MtGox2014Leak.zip&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F%2Ftracker.ccc.de%3A80&tr=udp%3A%2F%2Ftracker.istole.it%3A80&tr=udp%3A%2F%2Ftracker.publicbt.com%3A80&ws=http%3A%2F%2Fblog.magicaltux.net%2Fwp-content%2Fuploads%2F2014%2F03%2FMtGox2014Leak.zip

encrypto
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
March 09, 2014, 05:36:42 PM
 #9

UPDATE: Guys on irc confirmed that the dump is legit!!!

*To check your balance, you need your Mtgox USER ID, from your first email of registration at MtGox.

broolstoryco
Member
**
Offline Offline

Activity: 76
Merit: 10


Enemy of the State


View Profile
March 09, 2014, 05:59:49 PM
 #10

The posts keep disappearing off /r/bitcoin. this is some serious bullshit
BitCoinDream
Legendary
*
Offline Offline

Activity: 2324
Merit: 1204

The revolution will be digital


View Profile
March 09, 2014, 06:00:14 PM
 #11

Insane !!! How they got access to even Mark's personal blog ?

leopard2
Legendary
*
Offline Offline

Activity: 1372
Merit: 1014



View Profile
March 09, 2014, 06:05:12 PM
 #12

It seems gox were 450 000 btc short, but still had around 501 000 btc in storage. So this is getting interesting.

so hackers manage to do this piece of bookkeeping in their free time

the guys who own Gox had 365 days a year to do it, and never noticed that coins were missing?

absolutely fucking ridiculous and it stinks to the moon.

Truth is the new hatespeech.
stsbrad
Full Member
***
Offline Offline

Activity: 168
Merit: 100

Brad Willman, SSCP, LTCP, MCTS,SCE,BCE


View Profile
March 09, 2014, 06:08:47 PM
 #13

So user data is in the zip? Ugh
Taras
Legendary
*
Offline Offline

Activity: 1386
Merit: 1053


Please do not PM me loan requests!


View Profile WWW
March 09, 2014, 06:12:32 PM
 #14

 I'll proceed to make cool visualizations with this zip.
Remember remember the 5th of November
Legendary
*
Offline Offline

Activity: 1862
Merit: 1011

Reverse engineer from time to time


View Profile
March 09, 2014, 06:13:34 PM
 #15

So user data is in the zip? Ugh
No sensitive user data, I believe.

BTC:1AiCRMxgf1ptVQwx6hDuKMu4f7F27QmJC2
WindMaster
Sr. Member
****
Offline Offline

Activity: 347
Merit: 250


View Profile
March 09, 2014, 06:14:24 PM
Last edit: March 09, 2014, 06:41:14 PM by WindMaster
 #16

*To check your balance, you need your Mtgox USER ID, from your first email of registration at MtGox.

For anyone curious, here's how to find your balance.  For example, my original account creation Email from Gox looks about like this (with some numbers redacted):


Quote
Welcome to Mt.Gox!

Thank you for creating your account with us.

Your login: ZZZZZZZ

In order to enable your account, you need to enter your validation code on the Mt.Gox website.

Your confirmation code: ZZZZZZZZZZZZZZZZ

Alternatively you can click on or copy it into your browser via this url:
https://mtgox.com/signup/validate?ID=00000000-0000-0000-0000-000000000000&Code=ZZZZZZZZZZZZZZZZ


Best regards,
The Mt.Gox Team
info@mtgox.com
https://mtgox.com/

Note the bolded portion above.  I've replaced mine with 0's in the above, but yours will have a UUID-looking string of hexadecimal groups of numbers separated by hyphens.  Cross-reference this with the "mtgox_balances" file from the leak.  Your user ID will match the "User__" column.

I can confirm my BTC balance shown there matches what it was when Gox shut down, so this is recent data and appears to be a legit database dump.
WindMaster
Sr. Member
****
Offline Offline

Activity: 347
Merit: 250


View Profile
March 09, 2014, 06:17:58 PM
 #17

No sensitive user data, I believe.

While true, I'm sufficiently convinced (by checking my own account and BTC balance) that it's a legit database dump, so I'm also convinced Gox was pretty thoroughly owned and it is likely that all data Gox had was compromised.  That means everyone's sensitive user data is probably out there *somewhere*, just not necessarily included in this particular set of leaked files.
crazynoggin
Full Member
***
Offline Offline

Activity: 176
Merit: 100



View Profile
March 09, 2014, 06:25:29 PM
 #18

While these guys who released the files likely are doing it for the good of the community, there is that possibility that sensitive files are out there and you might want to assume that is the case and do all you can to protect yourself.

Use my referral link if you want: https://primedice.com/?ref=Crazynoggin
leopard2
Legendary
*
Offline Offline

Activity: 1372
Merit: 1014



View Profile
March 09, 2014, 06:26:54 PM
 #19

Yikes. Sure I would not want to be in M.K.'s shoes these days.  Tongue

Truth is the new hatespeech.
DeathAndTaxes (OP)
Donator
Legendary
*
Offline Offline

Activity: 1218
Merit: 1079


Gerald Davis


View Profile
March 09, 2014, 06:27:19 PM
 #20

Since the data seems to have been stolen around the time MtGox shutdown or later the question would be ... why would you keep this information on a webserver if you aren't actively using it anymore?  
Pages: [1] 2 3 4 5 6 7 8 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!