ajareselde
Legendary
Offline
Activity: 1722
Merit: 1000
Satoshi is rolling in his grave. #bitcoin
|
|
August 17, 2014, 11:33:51 AM |
|
It's one of the basic rule for all the newcomers out there, "CHANGE THE PASSWORD REGULARLY"
& never use the same password on different sites! It doesnt get more simpler than that, but still some people keep on making the same mistake. Keeping the passwords for a long time is also a bad choice. Hope we dont get more bad press from things like this again
|
|
|
|
Hfleer
Sr. Member
Offline
Activity: 448
Merit: 250
Changing avatars is currently not possible.
|
|
August 17, 2014, 11:48:33 AM |
|
Just use a password manager like Keepass ...
|
██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
|
|
|
MakeBelieve
|
|
August 17, 2014, 12:17:30 PM |
|
Just use a password manager like Keepass ...
That doesn't prevent people from leaking websites with your password...it only helps remembering all the passwords.
|
On a mission to make Bitcointalk.org Marketplace a safer place to Buy/Sell/Trade
|
|
|
Hfleer
Sr. Member
Offline
Activity: 448
Merit: 250
Changing avatars is currently not possible.
|
|
August 17, 2014, 12:24:19 PM |
|
Just use a password manager like Keepass ...
That doesn't prevent people from leaking websites with your password...it only helps remembering all the passwords. No, that makes you use the password that the password manager creates for you. This way you never use the same password for all the sites.
|
██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
|
|
|
Aurum (OP)
|
|
August 17, 2014, 07:14:45 PM |
|
more bad news, him databases is true i contact him by email and brought the 3 database by 10btc, in one btc wallet private to no one know. the admin of bitcoin.de talk there no possible hahahaha, bitcoin.de site is very secure, really i dont cant open any account since de 2fa is active on them site, but one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now . i spent 10 btc in them all database, so i am in a good profit now yes i am crazy, but i need to test it, now i am enjoying my weekend. Now i buy him exploit for all faucet sites, i am testing with, if tomorrow i get fell good, i will share with yours the code PS: the freebitco.in dont have 450k users, have 672157 users emails is too much text to read . Lets work.
|
ghghghfgh
|
|
|
Aurum (OP)
|
|
August 17, 2014, 07:18:05 PM |
|
Sure i dont know because him is selling the db by 10 btc if him can get more than 500 btc hacking the users, These hackers are insane. him talk me him apollogy dont are hack users. Him dont want innocent members money, and him orgasm is hack sites. For me is the best hacker until now.
|
ghghghfgh
|
|
|
Cortex7
|
|
August 17, 2014, 07:27:41 PM |
|
...in most cases today passwords are not hashed in the database...
Unbelievable and lame. No excuse for a crypto currency site! It's so easy to add this to the PHP: $sPassHash = hash( "sha1", $sPassword );
|
|
|
|
Aurum (OP)
|
|
August 17, 2014, 07:57:28 PM |
|
...in most cases today passwords are not hashed in the database...
Unbelievable and lame. No excuse for a crypto currency site! It's so easy to add this to the PHP: $sPassHash = hash( "sha1", $sPassword ); yeah its add more hard, but dont impossible.One tip, in one database the password is clean pure text
|
ghghghfgh
|
|
|
Kieran Bass
Newbie
Offline
Activity: 17
Merit: 0
|
|
August 17, 2014, 08:07:07 PM |
|
So bad for a crypto site(s) to have their site hacked like this.
|
|
|
|
jbreher
Legendary
Offline
Activity: 3038
Merit: 1660
lose: unfind ... loose: untight
|
|
August 17, 2014, 09:24:32 PM |
|
i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now . It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief.
|
Anyone with a campaign ad in their signature -- for an organization with which they are not otherwise affiliated -- is automatically deducted credibility points.
I've been convicted of heresy. Convicted by a mere known extortionist. Read my Trust for details.
|
|
|
Aurum (OP)
|
|
August 17, 2014, 09:32:58 PM |
|
i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now . It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief. sure i dont american, sure i dont forced know english, but iam profit. looooooool. with your skillls in english, you have money? good to you! bulshit people have to fucked, my teory.
|
ghghghfgh
|
|
|
Aurum (OP)
|
|
August 17, 2014, 09:42:39 PM |
|
If you are hacked for your fall, use paypal them can return your money, i use bitcoin and have more than 100k on them, hack it, i doubt!
|
ghghghfgh
|
|
|
wzb422
Newbie
Offline
Activity: 57
Merit: 0
|
|
August 17, 2014, 11:03:32 PM |
|
They might have got their hands on the 3 crap sites
|
|
|
|
Razick
Legendary
Offline
Activity: 1330
Merit: 1003
|
|
August 17, 2014, 11:05:56 PM |
|
...in most cases today passwords are not hashed in the database...
Unbelievable and lame. No excuse for a crypto currency site! It's so easy to add this to the PHP: $sPassHash = hash( "sha1", $sPassword ); It's not that easy if you want to do it right. Straight sha is too fast so you should use many iterations or sha2 or whirlpool.
|
ACCOUNT RECOVERED 4/27/2020. Account was previously hacked sometime in 2017. Posts between 12/31/2016 and 4/27/2020 are NOT LEGITIMATE.
|
|
|
Cortex7
|
|
August 18, 2014, 12:04:12 AM |
|
...in most cases today passwords are not hashed in the database...
Unbelievable and lame. No excuse for a crypto currency site! It's so easy to add this to the PHP: $sPassHash = hash( "sha1", $sPassword ); It's not that easy if you want to do it right. Straight sha is too fast so you should use many iterations or sha2 or whirlpool. Thanks for the heads up! This stack exchange comment seems pretty thourough: http://security.stackexchange.com/questions/211/how-to-securely-hash-passwords/31846#31846
|
|
|
|
jbreher
Legendary
Offline
Activity: 3038
Merit: 1660
lose: unfind ... loose: untight
|
|
August 18, 2014, 02:26:44 AM |
|
i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now . It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief. sure i dont american, sure i dont forced know english, but iam profit. looooooool. with your skillls in english, you have money? good to you! bulshit people have to fucked, my teory. Karma has a way of catching up...
|
Anyone with a campaign ad in their signature -- for an organization with which they are not otherwise affiliated -- is automatically deducted credibility points.
I've been convicted of heresy. Convicted by a mere known extortionist. Read my Trust for details.
|
|
|
dadaas
Sr. Member
Offline
Activity: 490
Merit: 250
Super Smash Bros. Ultimate Available Now!
|
|
August 18, 2014, 03:52:20 AM |
|
Yes, them use md5, the auroracoin forum use the traditional forum salt that is more hard to decrypt.
but with a good pay decoder with trillion hashes decode it no can be hard.
examples (hashes get from freecoinworld): 30fca77cebf16fe3c5b5b4db4371dee4 - cinta3segi 842df9fecdc99ad5aea6deb7ab117ae0 - me4ta12345
One question, how does anybody crack those codes? Isn't it right that it takes long time to bruteforce those codes? Isn't that the whole point of hashing passwords, to make them practically uncrackable?
|
|
|
|
annoyingorange
Member
Offline
Activity: 72
Merit: 10
|
|
August 18, 2014, 07:35:35 AM |
|
Fake pastebin posts like this are common, but you really should use a password manager like keepass or 1password and generate unique random passwords for every website login. You can make them easy to read/type such as "phi8lugh7ku9re" or near impossible to brute force like "uBw=wr,9i[RrdX" Always have 2fa enabled for your email / dropbox / etc and if in doubt change your password.
|
|
|
|
TheTruth4
Member
Offline
Activity: 108
Merit: 10
|
|
August 18, 2014, 08:04:52 AM |
|
What do you mean? This looks like a legit pastebin. What is going on with this post?
|
|
|
|
|
|