Bitcoin Forum
May 03, 2024, 11:32:46 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bitstamp bruteforce attack on 2FA  (Read 922 times)
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
May 07, 2014, 10:59:19 PM
 #1

Bitstamp doesnt have protection against bruteforce attack on 2FA
1714735966
Hero Member
*
Offline Offline

Posts: 1714735966

View Profile Personal Message (Offline)

Ignore
1714735966
Reply with quote  #2

1714735966
Report to moderator
In order to achieve higher forum ranks, you need both activity points and merit points.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
poordeveloper
Hero Member
*****
Offline Offline

Activity: 896
Merit: 527


₿₿₿₿₿₿₿


View Profile WWW
May 07, 2014, 11:03:23 PM
 #2

Bitstamp doesnt have protection against bruteforce attack on 2FA
Have you contacted them prior to posting this here?

🎰 Bitcoin Casinos ⭐⭐⭐⭐⭐
.
🔵 Buy Bitcoin (Visa / Mastercard / SEPA / Bank Transfer / Western Union / MoneyGram / RIA)
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
May 07, 2014, 11:05:24 PM
 #3

Bitstamp doesnt have protection against bruteforce attack on 2FA
Have you contacted them prior to posting this here?
its not fatal
yes today contacted
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
May 31, 2014, 01:45:57 AM
 #4

i send 100 request per minute
to break bitstamp login 2fa you need only 7 days
Sukrim
Legendary
*
Offline Offline

Activity: 2618
Merit: 1006


View Profile
May 31, 2014, 09:09:48 AM
 #5

The code changes every 30 seconds, so you can try the same 50 codes every 30 seconds and hope to get lucky over time.

https://www.coinlend.org <-- automated lending at various exchanges.
https://www.bitfinex.com <-- Trade BTC for other currencies and vice versa.
arbitrage001
Legendary
*
Offline Offline

Activity: 1067
Merit: 1000


View Profile
June 01, 2014, 03:17:47 AM
 #6

They should freeze account login after 3-5 failed attempts.
Otsu
Full Member
***
Offline Offline

Activity: 546
Merit: 100


View Profile
June 01, 2014, 03:22:17 AM
 #7

That's problematic, they need to set up more parameters to prevent access. Agree, lock out should be implemented.
BigBoy89
Legendary
*
Offline Offline

Activity: 1512
Merit: 1011



View Profile
June 01, 2014, 04:06:30 AM
 #8

this is horrible if there's no limit from bitstamp for failed attemps
someone could get lucky after several tries, and get BTC from user balance
freeze account login after several failed attemps is must implement in bitstamp
i send 100 request per minute
to break bitstamp login 2fa you need only 7 days
what is 7 days? the google code change every 30 seconds
no fixed time to break it, just pure luck

.AMEPAY.
▄▄█████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄█████████▀▀▄▀▀█████████▄

▄██████▄▄█▀ ▀█▄▄██████▄
███████  ▀▀█▄██▀▀▄███████
███████ █ ▄ █ ▄▀▀▄███████
████████ █ █ █ ▄▀▀▄████████
▀█████████▄█ █ ▄██████████▀
▀████████  ▀▀▀  ████████▀
▀█████████████████████▀
▀██
███████████████▀
▀▀█████████▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
│▌
       AMEPAY IEO       
▄██████▄ ▀██████▄
█████████  ▀█████
███████▀     ▀███
██████▀  ▄█▄  ▀██
██████▄  ▀█▀  ▄██
███████▄     ▄███
█████████  ▄█████
▀██████▀ ▄██████▀
   AMEPAY LISTING   
   ▐███▄
   ████▌
▐██████████▄
████████████
 ████▌  █████
▐████  ▄████
██████████▀
 ▀█████▀▀
▐│
▄▄█████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄█████████▀▀▄▀▀█████████▄

▄██████▄▄█▀ ▀█▄▄██████▄
███████  ▀▀█▄██▀▀▄███████
███████ █ ▄ █ ▄▀▀▄███████
████████ █ █ █ ▄▀▀▄████████
▀█████████▄█ █ ▄██████████▀
▀████████  ▀▀▀  ████████▀
▀█████████████████████▀
▀██
███████████████▀
▀▀█████████▀▀
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
June 01, 2014, 07:47:46 AM
 #9

this is horrible if there's no limit from bitstamp for failed attemps
someone could get lucky after several tries, and get BTC from user balance
freeze account login after several failed attemps is must implement in bitstamp
i send 100 request per minute
to break bitstamp login 2fa you need only 7 days
what is 7 days? the google code change every 30 seconds
no fixed time to break it, just pure luck

yes 7 days its mean

100 random codes in minute its 1000000/100 minutes = 7 days
7 days - average value
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
June 01, 2014, 07:49:48 AM
 #10

The code changes every 30 seconds, so you can try the same 50 codes every 30 seconds and hope to get lucky over time.
you just need generate random codes
30 sec has no effect its just probability theory
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
June 01, 2014, 07:50:39 AM
 #11

They should freeze account login after 3-5 failed attempts.


or freeze 2FA on 1 hour after 3 failed attempts
somenick (OP)
Legendary
*
Offline Offline

Activity: 1286
Merit: 1004


View Profile
June 01, 2014, 07:52:12 AM
 #12

They are in no hurry to correct obvious bugs
it is very bad for their reputation
smoothie
Legendary
*
Offline Offline

Activity: 2492
Merit: 1473


LEALANA Bitcoin Grim Reaper


View Profile
June 01, 2014, 07:55:21 AM
 #13

easy fix for users for this problem:

1. Don't keep any funds or BTC on bitstamp

2. Change your password when you plan to send funds to your account. (before you send)

3. When you do send funds to bitstamp either buy or sell and withdrawal immediately.




███████████████████████████████████████

            ,╓p@@███████@╗╖,           
        ,p████████████████████N,       
      d█████████████████████████b     
    d██████████████████████████████æ   
  ,████²█████████████████████████████, 
 ,█████  ╙████████████████████╨  █████y
 ██████    `████████████████`    ██████
║██████       Ñ███████████`      ███████
███████         ╩██████Ñ         ███████
███████    ▐▄     ²██╩     a▌    ███████
╢██████    ▐▓█▄          ▄█▓▌    ███████
 ██████    ▐▓▓▓▓▌,     ▄█▓▓▓▌    ██████─
           ▐▓▓▓▓▓▓█,,▄▓▓▓▓▓▓▌          
           ▐▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▌          
    ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓─  
     ²▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓╩    
        ▀▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀       
           ²▀▀▓▓▓▓▓▓▓▓▓▓▓▓▀▀`          
                   ²²²                 
███████████████████████████████████████

. ★☆ WWW.LEALANA.COM        My PGP fingerprint is A764D833.                  History of Monero development Visualization ★☆ .
LEALANA BITCOIN GRIM REAPER SILVER COINS.
 
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!