Bitcoin Forum
May 11, 2024, 01:56:57 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 [5]  All
  Print  
Author Topic: Akka - Default trust account no longer hacked!  (Read 6398 times)
Blazr
Hero Member
*****
Offline Offline

Activity: 882
Merit: 1005



View Profile
January 11, 2015, 02:49:33 PM
 #81

(...)
I received the same PM , however welcome back @Spekulatius.  ( I hope you're not coming to use again  GMX or web.de). I simple gmail address with the 2FA it's the better solution and obviously secure .
It is better when you have your own Mailserver Wink For example with autoban (Try it out on my Server if you want, try 2 times to login - then you get banned for 1 Year: Admin@Dice-Win.com)
Best regards

It locks you out for a year after only 2 failed attempts?! How are you able to login when you are drunk?  Grin

1715435817
Hero Member
*
Offline Offline

Posts: 1715435817

View Profile Personal Message (Offline)

Ignore
1715435817
Reply with quote  #2

1715435817
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715435817
Hero Member
*
Offline Offline

Posts: 1715435817

View Profile Personal Message (Offline)

Ignore
1715435817
Reply with quote  #2

1715435817
Report to moderator
1715435817
Hero Member
*
Offline Offline

Posts: 1715435817

View Profile Personal Message (Offline)

Ignore
1715435817
Reply with quote  #2

1715435817
Report to moderator
Christian1998
Sr. Member
****
Offline Offline

Activity: 474
Merit: 500


View Profile
January 11, 2015, 02:55:07 PM
 #82

(...)
I received the same PM , however welcome back @Spekulatius.  ( I hope you're not coming to use again  GMX or web.de). I simple gmail address with the 2FA it's the better solution and obviously secure .
It is better when you have your own Mailserver Wink For example with autoban (Try it out on my Server if you want, try 2 times to login - then you get banned for 1 Year: Admin@Dice-Win.com)
Best regards

It locks you out for a year after only 2 failed attempts?! How are you able to login when you are drunk?  Grin
Yes it does.
I can remove the ban manually Wink
Because i dont need to login with my password Wink
You can test it if you want - its my server, i allow it to test it.
Best regards
Christian
Spekulatius
Legendary
*
Offline Offline

Activity: 1022
Merit: 1000



View Profile
January 12, 2015, 03:12:08 AM
 #83

I figured I should post there here. Per the message I received from Spekulatius the hacker used the below email and IP address

Quote
-snip-
The attacker used the email screams@live.com and the IP 73.166.140.216.
-snip-


I received the same PM , however welcome back @Spekulatius.  ( I hope you're not coming to use again  GMX or web.de). I simple gmail address with the 2FA it's the better solution and obviously secure .

Ok, changed it to a yahoo.de account. Hope thats secure enough Roll Eyes

Feels good to be back
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
January 12, 2015, 03:14:38 AM
 #84

I figured I should post there here. Per the message I received from Spekulatius the hacker used the below email and IP address

Quote
-snip-
The attacker used the email screams@live.com and the IP 73.166.140.216.
-snip-


I received the same PM , however welcome back @Spekulatius.  ( I hope you're not coming to use again  GMX or web.de). I simple gmail address with the 2FA it's the better solution and obviously secure .

Ok, changed it to a yahoo.de account. Hope thats secure enough Roll Eyes

Feels good to be back
That may work, however the most secure email would be one that cannot possibly exist (IDK why the forum does not allow the option of simply not having an email at all). What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3808
Merit: 2617


Join the world-leading crypto sportsbook NOW!


View Profile
January 12, 2015, 06:02:20 AM
 #85

Ok, changed it to a yahoo.de account. Hope thats secure enough Roll Eyes

Depends how secure you made it. Hope you didn't use some of the basic security questions that are easily guessable.

That may work, however the most secure email would be one that cannot possibly exist (IDK why the forum does not allow the option of simply not having an email at all). What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)

Couldn't theymos or possibly BadBear create those emails and steal the accounts? Grin

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
▄▄██████▄▄
▀█▀
█  █▀█▀
  ▄█  ██  █▄  ▄
█ ▄█ █▀█▄▄█▀█ █▄ █
▀▄█ █ ███▄▄▄▄███ █ █▄▀
▀▀ █    ▄▄▄▄    █ ▀▀
   ██████   █
█     ▀▀     █
▀▄▀▄▀▄▀▄▀▄▀▄
▄ ██████▀▀██████ ▄
▄████████ ██ ████████▄
▀▀███████▄▄███████▀▀
▀▀▀████████▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
January 12, 2015, 06:04:31 AM
 #86

That may work, however the most secure email would be one that cannot possibly exist (IDK why the forum does not allow the option of simply not having an email at all). What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)

Couldn't theymos or possibly BadBear create those emails and steal the accounts? Grin
If they wanted to do this they would simply reset the password to an email they control themselves. Or they could just change the password by editing the DB.
MadZ
Hero Member
*****
Offline Offline

Activity: 908
Merit: 657


View Profile
January 14, 2015, 06:32:12 AM
 #87

I banned him and removed him from my trust list.

The real Akka should email me.

Shouldn't Akka be re-added to your trust list now that he has regained access to his account? I would've assumed he has PMed you by now, but perhaps he hasn't noticed he was removed since his trust ratings still look the same on his end.
Akka
Legendary
*
Offline Offline

Activity: 1232
Merit: 1001



View Profile
January 14, 2015, 06:40:19 AM
 #88

I banned him and removed him from my trust list.

The real Akka should email me.

Shouldn't Akka be re-added to your trust list now that he has regained access to his account? I would've assumed he has PMed you by now, but perhaps he hasn't noticed he was removed since his trust ratings still look the same on his end.

It's honestly not so important for me to be readded, beeing a trusted User it's kinda nice, but that's already it for me. But I still appear as Akka in his list. I that means I'm somehow untrusted in his list, Yes it would be nice if that could be fixed.

All previous versions of currency will no longer be supported as of this update
MadZ
Hero Member
*****
Offline Offline

Activity: 908
Merit: 657


View Profile
January 14, 2015, 06:45:14 AM
 #89

I banned him and removed him from my trust list.

The real Akka should email me.

Shouldn't Akka be re-added to your trust list now that he has regained access to his account? I would've assumed he has PMed you by now, but perhaps he hasn't noticed he was removed since his trust ratings still look the same on his end.

It's honestly not so important for me to be readded, beeing a trusted User it's kinda nice, but that's already it for me. But I still appear as Akka in his list. I that means I'm somehow untrusted in his list, Yes it would be nice if that could be fixed.

You should PM him, he only removed you because your account was hacked. Since you have regained access to your account and properly secured it, he should have no problems re-adding you, or at least removing you from his distrust list if that is all you care about.
qwk
Donator
Legendary
*
Offline Offline

Activity: 3542
Merit: 3411


Shitcoin Minimalist


View Profile
January 14, 2015, 09:58:25 AM
 #90

What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)
In the (unlikely) event of successful DNS poisoning, an attacker might be able to forge an MX record for bitcointalk.org and point it at his own mail server.
It's difficult to estimate the likelihood of such an attack, but I personally would consider that more likely than an attack against a professional mail provider.

Yeah, well, I'm gonna go build my own blockchain. With blackjack and hookers! In fact forget the blockchain.
Quickseller (OP)
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2300


View Profile
January 14, 2015, 12:28:23 PM
 #91

What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)
In the (unlikely) event of successful DNS poisoning, an attacker might be able to forge an MX record for bitcointalk.org and point it at his own mail server.
It's difficult to estimate the likelihood of such an attack, but I personally would consider that more likely than an attack against a professional mail provider.
i thought GMX was a professional mail provider.

This would also prevent any kind of social engineering attack, like using your security question to reset your password.
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
January 14, 2015, 12:30:39 PM
 #92

What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)
In the (unlikely) event of successful DNS poisoning, an attacker might be able to forge an MX record for bitcointalk.org and point it at his own mail server.
It's difficult to estimate the likelihood of such an attack, but I personally would consider that more likely than an attack against a professional mail provider.
i thought GMX was a professional mail provider.

This would also prevent any kind of social engineering attack, like using your security question to reset your password.

Epochtalk is coming soon, and there will be two-factor authentication.
It's gonna make us feel super-safe Cheesy
qwk
Donator
Legendary
*
Offline Offline

Activity: 3542
Merit: 3411


Shitcoin Minimalist


View Profile
January 14, 2015, 01:02:46 PM
 #93

What I recommend using is [username]@bitcointalk.org, since the forum does not offer email services it would not be possible to hack/create that email address (although you would be somewhat out of luck if you forgot your password)
In the (unlikely) event of successful DNS poisoning, an attacker might be able to forge an MX record for bitcointalk.org and point it at his own mail server.
It's difficult to estimate the likelihood of such an attack, but I personally would consider that more likely than an attack against a professional mail provider.
i thought GMX was a professional mail provider.

This would also prevent any kind of social engineering attack, like using your security question to reset your password.
Yes, GMX is a professional mail provider. That's why I would consider DNS poisoning against them highly unlikely.
If there's really an issue there, it's almost certainly something else.

I just wanted to point out that using xxx@bitcointalk.org to counter password attacks against the forum is probably not such a good idea after all.

Yeah, well, I'm gonna go build my own blockchain. With blackjack and hookers! In fact forget the blockchain.
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
January 14, 2015, 07:38:52 PM
 #94

my gmx pw got changed again.

I think it's a different person.

he took my twitter (forgot to change email), got it back.

he requested password reset on bitstamp with IP: 198.237.119.18, but didn't log in probably because of lack 2nd factor.

he posted this on twitter:

https://twitter.com/cotta3/status/555443222793572354



I should really close the gmx account, but I'm afraid because maybe I missed to change email on some important account...

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
January 14, 2015, 07:43:06 PM
 #95

molecular: Check them all again, and change when needed. You shouldn't be lazy in a situation like this Wink
molecular
Donator
Legendary
*
Offline Offline

Activity: 2772
Merit: 1019



View Profile
January 14, 2015, 09:17:08 PM
 #96

molecular: Check them all again, and change when needed. You shouldn't be lazy in a situation like this Wink

how to find which sites I used the email-address on, though?

sift through 14270 emails (I copied to local)?

look in my head? (done that)

I hope there is a way to lock/deactivate the gmx account and keep others from registering that particular address for at least some time.

PGP key molecular F9B70769 fingerprint 9CDD C0D3 20F8 279F 6BE0  3F39 FC49 2362 F9B7 0769
Parazyd
Hero Member
*****
Offline Offline

Activity: 812
Merit: 587


Space Lord


View Profile WWW
January 14, 2015, 09:22:57 PM
 #97

molecular: Check them all again, and change when needed. You shouldn't be lazy in a situation like this Wink

how to find which sites I used the email-address on, though?

sift through 14270 emails (I copied to local)?

look in my head? (done that)

I hope there is a way to lock/deactivate the gmx account and keep others from registering that particular address for at least some time.


You could filter the emails, Google your email or your username.
Pages: « 1 2 3 4 [5]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!