Bitcoin Forum
November 05, 2024, 12:25:10 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4] 5 6 »  All
  Print  
Author Topic: Bitcoin sites leaked :( - Big bitcoin members emails database  (Read 8205 times)
ajareselde
Legendary
*
Offline Offline

Activity: 1722
Merit: 1000

Satoshi is rolling in his grave. #bitcoin


View Profile
August 17, 2014, 11:33:51 AM
 #61

It's one of the basic rule for all the newcomers out there, "CHANGE THE PASSWORD REGULARLY"

& never use the same password on different sites!

It doesnt get more simpler than that, but still some people keep on making the same mistake.
Keeping the passwords for a long time is also a bad choice.
Hope we dont get more bad press from things like this again
Hfleer
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


Changing avatars is currently not possible.


View Profile
August 17, 2014, 11:48:33 AM
 #62

Just use a password manager like Keepass ...

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
▓▓▓▓▓  BIT-X.comvvvvvvvvvvvvvvi
→ CREATE ACCOUNT 
▓▓▓▓▓
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
MakeBelieve
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500


View Profile
August 17, 2014, 12:17:30 PM
 #63

Just use a password manager like Keepass ...

That doesn't prevent people from leaking websites with your password...it only helps remembering all the passwords.

On a mission to make Bitcointalk.org Marketplace a safer place to Buy/Sell/Trade
Hfleer
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


Changing avatars is currently not possible.


View Profile
August 17, 2014, 12:24:19 PM
 #64

Just use a password manager like Keepass ...

That doesn't prevent people from leaking websites with your password...it only helps remembering all the passwords.

No, that makes you use the password that the password manager creates for you. This way you never use the same password for all the sites.

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
▓▓▓▓▓  BIT-X.comvvvvvvvvvvvvvvi
→ CREATE ACCOUNT 
▓▓▓▓▓
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
Aurum (OP)
Sr. Member
****
Offline Offline

Activity: 453
Merit: 250


dfgfdgfdg


View Profile WWW
August 17, 2014, 07:14:45 PM
 #65

more bad news, him databases is true Sad i contact him by email and brought the 3 database by 10btc, in one btc wallet private to no one know.

the admin of bitcoin.de talk there no possible hahahaha, bitcoin.de site is very secure, really i dont cant open any account since de 2fa is active on them site, but one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now Smiley.

i spent 10 btc in them all database, so i am in a good profit now Smiley yes i am crazy, but i need to test it, now i am enjoying my weekend.

Now i buy him exploit for all faucet sites, i am testing with, if tomorrow i get fell good, i will share with yours the code Cheesy

PS: the freebitco.in dont have 450k users, have 672157 users emails Smiley is too much text to read Smiley. Lets work.

ghghghfgh
Aurum (OP)
Sr. Member
****
Offline Offline

Activity: 453
Merit: 250


dfgfdgfdg


View Profile WWW
August 17, 2014, 07:18:05 PM
 #66

Sure i dont know because him is selling the db by 10 btc if him can get more than 500 btc hacking the users, These hackers are insane. him talk me him  apollogy dont are hack users. Him dont want innocent members money, and him orgasm is hack sites. For me is the best hacker until now.

ghghghfgh
Cortex7
Full Member
***
Offline Offline

Activity: 238
Merit: 106


View Profile
August 17, 2014, 07:27:41 PM
 #67

...in most cases today passwords are not hashed in the database...

Unbelievable and lame.

No excuse for a crypto currency site!

It's so easy to add this to the PHP:

Code:
$sPassHash = hash( "sha1", $sPassword );



Aurum (OP)
Sr. Member
****
Offline Offline

Activity: 453
Merit: 250


dfgfdgfdg


View Profile WWW
August 17, 2014, 07:57:28 PM
 #68

...in most cases today passwords are not hashed in the database...

Unbelievable and lame.

No excuse for a crypto currency site!

It's so easy to add this to the PHP:

Code:
$sPassHash = hash( "sha1", $sPassword );


yeah its add more hard, but dont impossible.One tip, in one database the password is clean pure text Cheesy

ghghghfgh
Kieran Bass
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
August 17, 2014, 08:07:07 PM
 #69

So bad for a crypto site(s) to have their site hacked like this.
jbreher
Legendary
*
Offline Offline

Activity: 3038
Merit: 1660


lose: unfind ... loose: untight


View Profile
August 17, 2014, 09:24:32 PM
 #70

i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now Smiley.

It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief.

Anyone with a campaign ad in their signature -- for an organization with which they are not otherwise affiliated -- is automatically deducted credibility points.

I've been convicted of heresy. Convicted by a mere known extortionist. Read my Trust for details.
Aurum (OP)
Sr. Member
****
Offline Offline

Activity: 453
Merit: 250


dfgfdgfdg


View Profile WWW
August 17, 2014, 09:32:58 PM
 #71

i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now Smiley.

It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief.

sure i dont american, sure i dont forced know english, but iam profit. looooooool.

with your skillls in english, you have money? good to you!

bulshit people have to fucked, my teory.

ghghghfgh
Aurum (OP)
Sr. Member
****
Offline Offline

Activity: 453
Merit: 250


dfgfdgfdg


View Profile WWW
August 17, 2014, 09:42:39 PM
 #72

If you are hacked for your fall, use paypal them can return your money, i use bitcoin and have more than 100k on them, hack it, i doubt!

ghghghfgh
wzb422
Newbie
*
Offline Offline

Activity: 57
Merit: 0


View Profile
August 17, 2014, 11:03:32 PM
 #73

They might have got their hands on the 3 crap sites
Razick
Legendary
*
Offline Offline

Activity: 1330
Merit: 1003


View Profile
August 17, 2014, 11:05:56 PM
 #74

...in most cases today passwords are not hashed in the database...

Unbelievable and lame.

No excuse for a crypto currency site!

It's so easy to add this to the PHP:

Code:
$sPassHash = hash( "sha1", $sPassword );





It's not that easy if you want to do it right. Straight sha is too fast so you should use many iterations or sha2 or whirlpool.

ACCOUNT RECOVERED 4/27/2020. Account was previously hacked sometime in 2017. Posts between 12/31/2016 and 4/27/2020 are NOT LEGITIMATE.
Cortex7
Full Member
***
Offline Offline

Activity: 238
Merit: 106


View Profile
August 18, 2014, 12:04:12 AM
 #75

...in most cases today passwords are not hashed in the database...

Unbelievable and lame.

No excuse for a crypto currency site!

It's so easy to add this to the PHP:

Code:
$sPassHash = hash( "sha1", $sPassword );


It's not that easy if you want to do it right. Straight sha is too fast so you should use many iterations or sha2 or whirlpool.

Thanks for the heads up!

This stack exchange comment seems pretty thourough:
http://security.stackexchange.com/questions/211/how-to-securely-hash-passwords/31846#31846


jbreher
Legendary
*
Offline Offline

Activity: 3038
Merit: 1660


lose: unfind ... loose: untight


View Profile
August 18, 2014, 02:26:44 AM
 #76

i contact him by email and brought the 3 database... one user use the same password in email, i open the email and i see the blockchain wallet the same password, for my surprise booommmmmmm 33.78 btc in him wallet, that the btc is in my wallet now Smiley.

It may be that I misunderstand your poor English, but I doubt it. The way this looks, you're a fucking lowlife thief.

sure i dont american, sure i dont forced know english, but iam profit. looooooool.

with your skillls in english, you have money? good to you!

bulshit people have to fucked, my teory.

Karma has a way of catching up...

Anyone with a campaign ad in their signature -- for an organization with which they are not otherwise affiliated -- is automatically deducted credibility points.

I've been convicted of heresy. Convicted by a mere known extortionist. Read my Trust for details.
dadaas
Sr. Member
****
Offline Offline

Activity: 490
Merit: 250


Super Smash Bros. Ultimate Available Now!


View Profile
August 18, 2014, 03:52:20 AM
 #77

Yes, them use md5, the auroracoin forum use the traditional forum salt that is more hard to decrypt.

but with a good pay decoder with trillion hashes decode it no can be hard.

examples (hashes get from freecoinworld):
30fca77cebf16fe3c5b5b4db4371dee4  -  cinta3segi
842df9fecdc99ad5aea6deb7ab117ae0 - me4ta12345

One question, how does anybody crack those codes? Isn't it right that it takes long time to bruteforce those codes? Isn't that the whole point of hashing passwords, to make them practically uncrackable?
annoyingorange
Member
**
Offline Offline

Activity: 72
Merit: 10


View Profile
August 18, 2014, 07:35:35 AM
 #78

Fake pastebin posts like this are common, but you really should use a password manager like keepass or 1password and generate unique random passwords for every website login.
You can make them easy to read/type such as "phi8lugh7ku9re" or near impossible to brute force like "uBw=wr,9i[RrdX"
Always have 2fa enabled for your email / dropbox / etc and if in doubt change your password.
TheTruth4
Member
**
Offline Offline

Activity: 108
Merit: 10


View Profile
August 18, 2014, 08:04:52 AM
 #79

What do you mean? This looks like a legit pastebin. What is going on with this post?
unexecuted
Member
**
Offline Offline

Activity: 175
Merit: 10


View Profile
August 18, 2014, 08:10:57 AM
 #80

What do you mean? This looks like a legit pastebin. What is going on with this post?

It is impossible to prove whether that post is legitimate, unless the bitcoin.de owners admit to the leak.
http://www.reddit.com/domain/pastebin.com/search?q=email&restrict_sr=on&sort=relevance&t=all
Pages: « 1 2 3 [4] 5 6 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!