Bitcoin Forum
May 09, 2024, 10:46:55 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Doubt about BitcoinTalk  (Read 540 times)
Security Engineer (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
August 29, 2019, 06:13:02 PM
 #21

Is this the human rights dude?

Do I look like a "human right dude"? Huh, Mr.  Lebowski? I would be proud if someone calls me that way but unfortunately I'm just a pure engineer looking for answers around BitcoinTalk and theymos.
The trust scores you see are subjective; they will change depending on who you have in your trust list.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715294815
Hero Member
*
Offline Offline

Posts: 1715294815

View Profile Personal Message (Offline)

Ignore
1715294815
Reply with quote  #2

1715294815
Report to moderator
1715294815
Hero Member
*
Offline Offline

Posts: 1715294815

View Profile Personal Message (Offline)

Ignore
1715294815
Reply with quote  #2

1715294815
Report to moderator
1715294815
Hero Member
*
Offline Offline

Posts: 1715294815

View Profile Personal Message (Offline)

Ignore
1715294815
Reply with quote  #2

1715294815
Report to moderator
suchmoon
Legendary
*
Offline Offline

Activity: 3654
Merit: 8922


https://bpip.org


View Profile WWW
August 29, 2019, 06:14:04 PM
 #22

Is this the human rights dude?

Yes.
dkbit98
Legendary
*
Offline Offline

Activity: 2226
Merit: 7147



View Profile WWW
August 29, 2019, 06:17:33 PM
 #23

Funny that a Hungarian also was in the project called Laszlo Hanyecz. Hungarians are invented a ton of things including the Hydrogen bomb, holography, self-replicating computer programs...  Roll Eyes  Grin

Funny that you know a lot about Hungarians... but cant read or speak hungarian....

ELFOGATÓPARANCS ALAPJÁN KÖRÖZÖTT SZEMÉLY

Should we call Interpol?

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
Security Engineer (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
August 29, 2019, 06:23:57 PM
Last edit: August 29, 2019, 07:32:27 PM by mprep
 #24

Funny that a Hungarian also was in the project called Laszlo Hanyecz. Hungarians are invented a ton of things including the Hydrogen bomb, holography, self-replicating computer programs...  Roll Eyes  Grin

Funny that you know a lot about Hungarians... but cant read or speak hungarian....

ELFOGATÓPARANCS ALAPJÁN KÖRÖZÖTT SZEMÉLY

Should we call Interpol?

You talk about a Hungarian human rights dude and it is totally off-topic. Again, you have serious problems, hallucinations, paranoia and we will see what else. I going to leave a feedback on your profile about that you only disrupting conversation. Interpol?  Grin Call them and tell them an engineer looks suspicious on BitcoinTalk.  Roll Eyes You can also contact the U.S. Cyber Command and tell them I'm using Bitcoin to buy zerodays for attacking, manipulating the votes in the U.S. election of 2020. Cheesy

Tell them I'm a Russian spy with a Huawei phone Shocked!




Before to move to the bitcointalk domain, the forum with the same SMF was on bitcoin.org/forum (or something like that, if I remember correctly) . That was the first transition from sourceforge to SMF. Seems that the database was moved to the new domain so that's why you can find the posts prior to the domain registration date.

I do not have a PC around me but if you check the wayback machine you'll find all you need to know.
If you want I can  check it out tomorrow Smiley


That would be great! Thanks!

Who is responsible for the security of this forum? Anyone noticed that there is an exploit for SMF 1.1.19?
Remote Memory Exfiltration Exploit

I do recommend to upgrade SMF to version 2.0.15!

Code:
SMF 2.0.15                                                    November 19, 2017
===============================================================================

September 2017
 ! Fixed a minor $smcFunc bug in Search-Fulltext.php
 ! Fixed a saving Settings.php bools being reset bug
 ! Fixed a security issue (Reported by Daniel Le Gall from SCRT SA)

June 2017
-------------------------------------------------------------------------------
 ! Cache the admin search results in the session and avoid IE's 2083 character limit
 ! Fixed a Mark Board Read bug

May 2017
-------------------------------------------------------------------------------
 ! Fixed Proxy URLs not handling redirects properly due to case sensitivity
 ! Fixed SendTopic using incorrect Post data
 ! Fixed SSI.php having a bad login panel
 ! Fixed Maintenance Page having a double login button
 ! Fixed a minor unsigned int typo in MySQL DB
 ! Fixed Deprecated installer message for ftp_connection.
 ! Fixed a loop bug in custom search
 ! Fixed SM Stat collection
 ! Added SM Stat collection registration to the Admin Control Panel

SMF 2.0.14                                                         May 14, 2017
===============================================================================
 ! Updating session handlers
 ! Adding HTTPS
 ! fetch_web_data now uses cURL, falling back to sockets
 ! Ported image proxy support from SMF 2.1
 ! Also added HTTPS for avatars
 ! Added a simple exception handler
 ! Check session while logging in
 ! Sanitize some fields to help guard against XSS
 ! Validate email addresses with PHP’s filter method
 ! Fix search highlighting to not mangle/expose some HTML
 ! Fix password acceptance when special characters were used in UTF-8;
 ! Correct some random logic errors in the profile area
 ! Use ampersands instead of semi-colons for PayPal’s return link
 ! Fix sending multiple MIME-Version headers in notification mail
 ! Fix sending multipel Content-Type headers in all requests

SMF 2.0.13                                                      January 4, 2017
===============================================================================
 ! Some file versions didn't get modified in the 2.0.12 patch
 ! Added check and sanitization for $_REQUEST['u'] in LogInOut.php and Reminder.php
 ! Added check and sanitization for $_REQUEST['uid'] in Reminder.php
 ! Properly sanitize author's website for packages
 ! Added session check when uploading packages
 ! Added session check when copying template files from one theme to another
 ! The code to remove empty BBCode was sometimes breaking things (reported by @rjen; fix provided by Sesquipedalian)
 ! Remove hardcoded limits for safe_unserialize as it was causing cache problems
 ! Update the cal_max_year setting to 2030

SMF 2.0.12                                                         July 7, 2016
===============================================================================
 ! Fixed word censor injection by disallowing an empty 'proper word'
 ! Fixed vulnerable unserialize() code by converting all instances to safe_unserialize()
 ! Added a more thorough safe_unserialize() function to prevent object injection
 ! Fixed a bug where leaving a custom profile field blank on registration that has an email mask would throw an error
 ! Fixed PayPal integration to comply with the new forced SSL
 ! Fixed a bug where notifications were sent for messages in inaccessible boards
 ! Fixed editor to make the editor work with Microsoft Edge
 ! Fixed issue where smiley popup is blank on iOS 9 devices
 ! Fixed WYSIWYG editor in mobile devices
 ! Fixed an undefined $_POST['icon'] in Sources/Post.php
 ! Fixed a minor bug in Login2()
 ! Fixed an issue where SMF doesn't recognize new domain names and considers these as invalid
 ! Fixed an issue where SMF would allow empty BBC
 ! Fixed an issue where theme variants could not be selected
 ! Fixed an issue where the file version of Subs-Post.php could have been 2.0.8 or 2.0.11. It will be updated to 2.0.12 in either case.
 ! Updated copyright year to 2016

SMF 2.0.11                                                    September 18 2015
===============================================================================

September 2015
-------------------------------------------------------------------------------
 ! Security vulnerability patched (Reported by Andrea Palazzo - Truel IT)
 ! safe_unserialize() function added to Subs.php
 ! Instances of unserialize() with user-supplied data changed to safe_unserialize()

Security vulnerability patched (Reported by Andrea Palazzo - Truel IT) Author of the exploit mentioned above!
AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
August 29, 2019, 07:29:56 PM
 #25

<>

You do understand the version of SMF the forum is running on is heavily modified right?

Also, if there's an actual exploit you can make use of; why not exploit it? - If it's actually useable, you can make a lot of money.

See https://bitcointalk.org/index.php?topic=309785.0

Otherwise it might be best to just shut up.

Security Engineer (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
August 29, 2019, 07:36:55 PM
 #26

<>

You do understand the version of SMF the forum is running on is heavily modified right?

Also, if there's an actual exploit you can make use of; why not exploit it? - If it's actually useable, you can make a lot of money.

See https://bitcointalk.org/index.php?topic=309785.0

Otherwise it might be best to just shut up.

I do believe some of the responsible person know how to patch or diff.

Try to write a security.txt and publish it to https://bitcointalk.org/.well-known/security.txt similar to this: https://securitytxt.org/.well-known/security.txt
TheBeardedBaby
Legendary
*
Offline Offline

Activity: 2184
Merit: 3134


₿uy / $ell


View Profile
August 29, 2019, 07:51:22 PM
 #27

~
I was wrong about the real forum link, it's not bitcoin.org/forum but bitcoin.org/smf
Here is the link to Satoshis profile: http://web.archive.org/web/20100716225740/http://bitcointalk.org/index.php?action=profile;u=3

TIDOVEE
Sr. Member
****
Offline Offline

Activity: 1246
Merit: 255



View Profile
August 29, 2019, 08:20:29 PM
 #28

BitcoinTalk was created around 2011 by Satoshi Nikamoto,A Japanese, he also created the first block chain database and he's the author of Bitcoin and  white paper.  A computer expert and cryptographer. What's you doubt or fears about.nothing to worry about, Bitcoin is real, many may think it is a Ponzi scheme and create fear in people investing into it. 
Security Engineer (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
August 29, 2019, 09:32:36 PM
Last edit: August 29, 2019, 09:59:50 PM by Security Engineer
 #29

~
I was wrong about the real forum link, it's not bitcoin.org/forum but bitcoin.org/smf
Here is the link to Satoshis profile: https://web.archive.org/web/20100716225740/http://bitcointalk.org/index.php?action=profile;u=3


This is from May 16, 2012, 07:10:52 AM captured just about two year after that satoshi posted the welcome.. and this capture includes PHPSESSID=82f1a05469e9dc5d2c2829e58896cb00 Congratulations! Not dangerous (by now), but hey a robot was able to capture Session IDs back in that time? Undecided
Chikito
Legendary
*
Offline Offline

Activity: 2380
Merit: 2054



View Profile WWW
August 29, 2019, 10:35:59 PM
 #30

administrator of this forum without any knowledge of programming. I have read his post from the very first one and nothing indicates he had any knowledge of programming.
Bitcointalk are Big forum have over 2.6 Million member need knowledge of management. And not necesarry know about programing.
Manager can recruit people who have knowledge about it.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Security Engineer (OP)
Newbie
*
Offline Offline

Activity: 14
Merit: 1


View Profile
August 29, 2019, 10:44:20 PM
Last edit: August 29, 2019, 11:16:36 PM by Security Engineer
 #31

administrator of this forum without any knowledge of programming. I have read his post from the very first one and nothing indicates he had any knowledge of programming.
Bitcointalk are Big forum have over 2.6 Million member need knowledge of management. And not necesarry know about programing.
Manager can recruit people who have knowledge about it.
That is correct DroomieChikito!  Wink

If @theymos do what I recommended to him here: https://bitcointalk.org/index.php?topic=5179950.msg52306296#msg52306296 and in PM than he never again would need to even think about that something bad happens to the server(s) of BitcoinTalk. In the current state BitcoinTalk is vulnerable. If he does what I recommended it will mitigate all types of attacks once and forever.

This topic will loose it relevance immediately: https://bitcointalk.org/index.php?topic=309785.msg3326091#msg3326091 meaning that no more bounty. Some regarding the forum and email can be still ongoing but he would need to rewrite the entire post.
AdolfinWolf
Legendary
*
Offline Offline

Activity: 1946
Merit: 1427


View Profile
August 30, 2019, 01:53:00 PM
Last edit: August 30, 2019, 02:05:08 PM by AdolfinWolf
 #32

administrator of this forum without any knowledge of programming. I have read his post from the very first one and nothing indicates he had any knowledge of programming.
Bitcointalk are Big forum have over 2.6 Million member need knowledge of management. And not necesarry know about programing.
Manager can recruit people who have knowledge about it.
That is correct DroomieChikito!  Wink

If @theymos do what I recommended to him here: https://bitcointalk.org/index.php?topic=5179950.msg52306296#msg52306296 and in PM than he never again would need to even think about that something bad happens to the server(s) of BitcoinTalk. In the current state BitcoinTalk is vulnerable. If he does what I recommended it will mitigate all types of attacks once and forever.
I'm sorry, but what exactly is the issue with the session ID? It proves nothing.

I can add any "session id" i want (you can replace PHPSESSID with anything at all.. it doesn't matter..) .. -> http://archive.is/ljBAZ
Code:
https://bitcointalk.org/index.php?ogfidfsighdsfkjgdsfklhdsfkljhsdfkljghdfkljsg=youraas1&action=profile;u=3
Doesn't prove that that is my actual session ID. It doesn't mean anything

Quote
This topic will loose it relevance immediately: https://bitcointalk.org/index.php?topic=309785.msg3326091#msg3326091 (https://bitcointalk.org/index.php?topic=309785.msg3326091#msg3326091) meaning that no more bounty. Some regarding the forum and email can be still ongoing but he would need to rewrite the entire post.
That would be weird considering the topic has been relevant from the moment it was created.

You have a lot of talk, but no proof of anything thus far. If there really is a vulnerability to be exploited, why would the bounty page lose relevance? If anything it's the opposite; you'll stand to make a nice amount of money.. ?



Quote
If he does what I recommended it will mitigate all types of attacks once and forever.
Sounds like you want him to upgrade to some malicious version. I'm sorry but if you think theymos is going to fall for such an obvious troll, well,  you'll be unpleasantly surprised.
I just realized i'm just feeding the troll. Fuck me.

tranthidung
Legendary
*
Offline Offline

Activity: 2268
Merit: 4012


Farewell o_e_l_e_o


View Profile WWW
August 30, 2019, 02:56:14 PM
 #33

BitcoinTalk was created around 2011 by Satoshi Nikamoto,A Japanese
Totally wrong!
Satoshi Nakamoto is actually a Japanese name, but no one knows that it is real name of the founder of bitcoin. I guess base on what bitcoin founder's core attention to stay anonymous, Satoshi Nakamoto is just a nickname, and we can not base on that and come to conclusion that bitcoin founder is a Japanese.

By now, there is no one knows who is real Satoshi Nakamoto. All people appeared and self-claimed that they are real Satoshi Nakamoto have been verified as fake ones.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!