Bitcoin Forum
May 11, 2024, 03:14:15 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: The attack on Electrum servers seems to be over  (Read 230 times)
djhomeschool (OP)
Full Member
***
Offline Offline

Activity: 340
Merit: 164


View Profile
April 15, 2019, 06:47:10 AM
 #1

I have no problems anymore, everything running smooth again and synchronizing fast and without problems.

Is the attack over?
1715440455
Hero Member
*
Offline Offline

Posts: 1715440455

View Profile Personal Message (Offline)

Ignore
1715440455
Reply with quote  #2

1715440455
Report to moderator
1715440455
Hero Member
*
Offline Offline

Posts: 1715440455

View Profile Personal Message (Offline)

Ignore
1715440455
Reply with quote  #2

1715440455
Report to moderator
"There should not be any signed int. If you've found a signed int somewhere, please tell me (within the next 25 years please) and I'll change it to unsigned int." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715440455
Hero Member
*
Offline Offline

Posts: 1715440455

View Profile Personal Message (Offline)

Ignore
1715440455
Reply with quote  #2

1715440455
Report to moderator
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7137



View Profile
April 15, 2019, 08:38:05 AM
 #2

At the moment there is no official announcement from Electrum on their Twitter or Reddit pages. The official site offers no information that the attack is over either.
https://twitter.com/ElectrumWallet
https://www.reddit.com/r/Electrum/

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
HCP
Legendary
*
Offline Offline

Activity: 2086
Merit: 4316

<insert witty quote here>


View Profile
April 15, 2019, 09:13:01 AM
 #3

I wouldn't be confident enough to say it is "over"... I suspect that IP list of the DDoS botnet that got released (and was constantly being updated) might have mitigated the attack to the point that the network is more or less running "OK".

No doubt it is quite expensive trying to spool up more and more devices as they are constantly being rendered useless. Tongue

I'd be more prone to say that this "round" is over...




█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
anu1908
Sr. Member
****
Offline Offline

Activity: 770
Merit: 268


View Profile
April 15, 2019, 10:16:37 AM
 #4

my electrum is running smoothly since yesterday even though i've used automatic selection. but that's not a guarantee that the same attack or problems happen in the future unless there's an official fix to prevent such thing from happening. so far, afaik electrum node runner has mitigated this problem with blocking the ip addresses that were used to attack their server as hcp mentioned so that's probably the reason why it seems the attack was stopped.
moha sasa
Jr. Member
*
Offline Offline

Activity: 35
Merit: 2


View Profile
April 15, 2019, 07:29:39 PM
 #5


- I have a question, what is to be gained from such an attack!!??

+ Thanks in advance.
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6984



View Profile WWW
April 15, 2019, 07:35:14 PM
 #6


- I have a question, what is to be gained from such an attack!!??

+ Thanks in advance.
Quoting my post in another thread:

I assume they are attacking the Electrum's servers so their malicious ones can be the only ones working. The user will try servers/close and reopen Electrum until one synchronizes (the bad one), which will give him the “please update” fake message. Obviously this only works in old versions, but the servers are the same, so we all can feel the attack.

This just increases the chances of a uninformed user getting phished.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Abdussamad
Legendary
*
Offline Offline

Activity: 3612
Merit: 1564



View Profile
April 16, 2019, 11:28:00 AM
 #7

They probably moved on to targeting altcoin clients.
hugeblack
Legendary
*
Offline Offline

Activity: 2506
Merit: 3650


Buy/Sell crypto at BestChange


View Profile WWW
April 17, 2019, 01:15:43 PM
 #8

I assume they are attacking the Electrum's servers so their malicious ones can be the only ones working. The user will try servers/close and reopen Electrum until one synchronizes (the bad one), which will give him the “please update” fake message.
[/quote]
Many people are still on older versions.
If this is true and there is a profit from these attacks do not expect to disappear soon.
There will be tours that will continue from time to time until profits reach zero.

Also, do not rule out attacks because of trying to distorting electurm wallet reputation for another new rising wallets. <I do not expect that is the reason this time.>

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
NeuroticFish
Legendary
*
Offline Offline

Activity: 3668
Merit: 6383


Looking for campaign manager? Contact icopress!


View Profile
April 17, 2019, 06:17:15 PM
 #9

what is to be gained from such an attack!!??

Many people are still on older versions.

And this is a big problem, because versions older than 3.3 would only connect to the bad servers and will also show the scammy update message.
This is what they gain from the attack: still real chances to catch uninformed users update to their clone of Electrum.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Artemis3
Legendary
*
Offline Offline

Activity: 2030
Merit: 1563


CLEAN non GPL infringing code made in Rust lang


View Profile WWW
April 17, 2019, 07:45:38 PM
 #10

With Electrum server nature which allow anyone to connect (exception for blacklist known IP used for DDoS/malicious acitivty), it's over for now.

Attacker will find another way as long they have money and will to do it.

Out of fun these days i decided to run my own Electrum server, since i have a full bitcoin node synced and all... And i got one called "Electrum Personal Server", Lo and behold, it made the Electrum wallet work like Bitcoin Core or better. So if the public servers go down i could always use mine now. Next i could try running Electrumx or the other one, not sure which is better, but if i do, i would run it only over tor as a hidden service...

██████
███████
███████
████████
BRAIINS OS+|AUTOTUNING
MINING FIRMWARE
|
Increase hashrate on your Bitcoin ASICs,
improve efficiency as much as 25%, and
get 0% pool fees on Braiins Pool
pooya87
Legendary
*
Offline Offline

Activity: 3444
Merit: 10558



View Profile
April 18, 2019, 02:43:19 AM
 #11

With Electrum server nature which allow anyone to connect (exception for blacklist known IP used for DDoS/malicious acitivty), it's over for now.

Attacker will find another way as long they have money and will to do it.

Out of fun these days i decided to run my own Electrum server, since i have a full bitcoin node synced and all... And i got one called "Electrum Personal Server", Lo and behold, it made the Electrum wallet work like Bitcoin Core or better. So if the public servers go down i could always use mine now. Next i could try running Electrumx or the other one, not sure which is better, but if i do, i would run it only over tor as a hidden service...

it probably is better if you run ElectrumX since it is the most used and because of that it has least amount of bugs. but you shouldn't ignore the alternatives either. the only thing to consider when running an alternative is to check if it is actually an "alternative implementation" or is it the same thing translated into another programming language or if it is a simple wrapper around the main one with additional features.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!