Pages:
Author

Topic: About the recent server compromise - page 10. (Read 15385 times)

sr. member
Activity: 280
Merit: 250
May 25, 2015, 11:18:25 AM
#68
I guess the password changes which were done yesterday (when the forum cane online for a few hours) were reverted back, cause I changed my password yesterday but I had to use my previous password to login today. Idk why was it done.

Also, is it just me or the forum looks plain to everyone? Like I am not able to identify what has changed by the layout looks a bit flat.
staff
Activity: 3304
Merit: 4115
May 25, 2015, 11:14:45 AM
#67
Unfortunatly this seems to be a reoccuring issue. Again, good job in minimising the damage done. Keep us up to date on the situation regarding how they obtained the information needed to gain access.
AGD
legendary
Activity: 2070
Merit: 1164
Keeper of the Private Key
May 25, 2015, 11:13:37 AM
#66
It is possible the attacker is selling the stolen email address database to spammers to make quick bucks.

ahh, I really don't wanna start any drama. maybe it was just spam in "wrong time" and it is not related at all. just reporting..Smiley

This doesn't look like the average email spam hack to me.
legendary
Activity: 2352
Merit: 1268
In Memory of Zepher
May 25, 2015, 11:05:47 AM
#65
Glad that it's back, but as previously said it's fairly unacceptable that a forum with such a security aura can still be compromised by attackers.
When will the new forum be happening? It's been in speculation for at least a year, if not longer now. It cannot take this long to code a forum software.

Yeah, DDOS you out of digital existence.
Do you think that they would bother? Surely to take down as many people as it would be worth here it would take more resources than what the attacker could get back.
full member
Activity: 224
Merit: 100
May 25, 2015, 11:04:04 AM
#64
uhh already received spam also + many unsuccessful attempts to mail login:(

anyway, thanks for bring the forum up.

What spam did you get? Has anyone else had attempts to compromise their email?

something like "buy iphone with btc" or "some viagra with btc" and similar..

I dunno, if it is related, but I had this acc for years and I never received similar mails until yesterday. coming from some non-sense yahoo addresses.

It is possible the attacker is selling the stolen email address database to spammers to make quick bucks.


Not very much worth it if the reason of the attacker is just to get emails list, it must be sonething else and it might be the attacker is looking for private datas
legendary
Activity: 1036
Merit: 1001
/dev/null
May 25, 2015, 11:03:42 AM
#63
It is possible the attacker is selling the stolen email address database to spammers to make quick bucks.

ahh, I really don't wanna start any drama. maybe it was just spam in "wrong time" and it is not related at all. just reporting..Smiley
sr. member
Activity: 266
Merit: 250
May 25, 2015, 11:02:39 AM
#62
Thanks for the info theymos, i'll have a crack at tracking his email and ip although im sure the email is fake and he used a proxy
legendary
Activity: 1666
Merit: 1185
dogiecoin.com
May 25, 2015, 11:01:40 AM
#61
Can they do anything with our IP addresses?

Yeah, DDOS you out of digital existence. Which is why I don't think the forum should have added a "Skype username" box on people's profiles. Its just asking for revenge DDOSing.
sgk
legendary
Activity: 1470
Merit: 1002
!! HODL !!
May 25, 2015, 11:00:53 AM
#60
uhh already received spam also + many unsuccessful attempts to mail login:(

anyway, thanks for bring the forum up.

What spam did you get? Has anyone else had attempts to compromise their email?

something like "buy iphone with btc" or "some viagra with btc" and similar..

I dunno, if it is related, but I had this acc for years and I never received similar mails until yesterday. coming from some non-sense yahoo addresses.

It is possible the attacker is selling the stolen email address database to spammers to make quick bucks.
legendary
Activity: 1036
Merit: 1001
/dev/null
May 25, 2015, 11:00:00 AM
#59
Can they do anything with our IP addresses?

ahh depends if you had public one (unique, reachable from outside) or some NAT IP which is covering subnets of ISP..
legendary
Activity: 1036
Merit: 1001
/dev/null
May 25, 2015, 10:58:41 AM
#58
uhh already received spam also + many unsuccessful attempts to mail login:(

anyway, thanks for bring the forum up.

What spam did you get? Has anyone else had attempts to compromise their email?

something like "buy iphone with btc" or "some viagra with btc" and similar..

I dunno, if it is related, but I had this acc for years and I never received similar mails until yesterday. coming from some non-sense yahoo addresses.
sr. member
Activity: 420
Merit: 250
Mmmh mhmhh mmmm.
May 25, 2015, 10:55:41 AM
#57
Interesting compromise. I am amazed this can still happen. Good luck to anyone looking for the attacker(s).
legendary
Activity: 3556
Merit: 9709
#1 VIP Crypto Casino
May 25, 2015, 10:54:53 AM
#56
Have you not changed the email you linked to this site mate? I have & I've deleted the other account.

wtf you are talking about? mail addresses are already leaked, so even you will change the mail here, you will get spam..
I closed the email account I 'was' using here.
There wasn't much else on there any way but I'd rather be safe than sorry.
Can they do anything with our IP addresses?
legendary
Activity: 896
Merit: 1000
May 25, 2015, 10:54:16 AM
#55
i have changed my password to make sure my account is safe. this shows that you must never use a password in more than 1 place.
sr. member
Activity: 319
Merit: 251
May 25, 2015, 10:54:06 AM
#54
uhh already received spam also + many unsuccessful attempts to mail login:(

anyway, thanks for bring the forum up.

What spam did you get? Has anyone else had attempts to compromise their email?

NO I Have Not received any Spam from this. Fortunately, I signed up with a unique cloaked email address so If I got one it would show (Cloaked in my in-box)
legendary
Activity: 1652
Merit: 1128
May 25, 2015, 10:49:24 AM
#53
Thanks theymos for the hardwork. I changed my password but not my email ID as I'm not sure if I should do it as the pwd used on this forum wasn't used anywhere else fortunately. I've not received any phishing email except this one yesterday:


You are receiving this message because your email address is associated
with an account on bitcointalk.org.

-----BEGIN PGP SIGNATURE-----

iF4EAREIAAYFAlVhiGI..........................

I hope the above message is genuine.

It is.

Signed on 2015-05-24 04:14 by [email protected] (Key ID: 0xDAB591E7).
The signature is valid and the certificate's validity is fully trusted.

What is theymos's GPG key? Is it published somewhere official? I received the signed email but I can't find a verified source with the key.

All PGP keys are hosted on public keyservers. They're also hosted on the forum's servers, though you shouldn't rely on that solely. https://bitcointalk.org/theymos.asc, https://bitcointalk.org/BadBear.asc

https://pgp.mit.edu/pks/lookup?search=theymos&op=index

For the record.

Code:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Confirming Badbear is Badbear, and not Goodbear or other variations of bears.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBAgAGBQJVY0O5AAoJEKAjO3S1eXxPH40H/jvkkJhKUVxKB6a1whLFE08p
jIJi3qw1WkZPFkM9QWwNXNq+8p8bZxiC+0mIskITUiZBwLqgHgyogFf5FjWNnhSy
lhhmLLh6L+LxXtXg+6kITn2nEPiP+wiZRXkRWwzqRd5mh8c3I1hMMfnYa9DarQG3
hC+TjJXwHKvdYXL5FjcGv4HXGX0QMhXUzwodF05SWXJmH6v8uG3vn6QFej4XRVPd
kWWHh61GlzUAZix0EOxd/cvElgJW6Y8sWl/gH5qBnqhnHDTVnS4/cnQVLjgScyGF
QXVoLZG71Mjkgq+PFX8GRqatKIt/vzMvhBYz7DKKDM8NNzbLRRVexlb2MnpeTx8=
=QK2I
-----END PGP SIGNATURE-----


 
global moderator
Activity: 4018
Merit: 2728
Join the world-leading crypto sportsbook NOW!
May 25, 2015, 10:49:02 AM
#52
uhh already received spam also + many unsuccessful attempts to mail login:(

anyway, thanks for bring the forum up.

What spam did you get? Has anyone else had attempts to compromise their email?
legendary
Activity: 1036
Merit: 1001
/dev/null
May 25, 2015, 10:48:45 AM
#51
Have you not changed the email you linked to this site mate? I have & I've deleted the other account.

wtf you are talking about? mail addresses are already leaked, so even you will change the mail here, you will get spam..
legendary
Activity: 3556
Merit: 9709
#1 VIP Crypto Casino
May 25, 2015, 10:46:14 AM
#50
Received my first spam email last night.   Embarrassed
Have you not changed the email you linked to this site mate?
I have & I've deleted the other account.
Never use an email that you have banking details, card details etc in.
legendary
Activity: 3248
Merit: 1070
May 25, 2015, 10:41:36 AM
#49
theymos, thank you for you hard work. Let's hope we will not have to deal this in the future.


until the new forum is set(one can think that the forum will have some instrument against those kind of attack, maybe a better privacy, better ISP, that don't leak your root credentials...), i do think it will happen again, this isn't the first time after all
Pages:
Jump to: