Author

Topic: AllCrypt Out? (Read 1534 times)

sr. member
Activity: 430
Merit: 250
AS8UDRR8Dc4wTyZkMT7Z5vaXtiWK9zh5Hb
March 16, 2015, 10:47:26 PM
#2
Wow that sux another BTC hit and run... see if it was a Zero Day iframe exploit. This link has some of the details and code you can look for on the logs

Hope this helps. 

https://www.cryptobells.com/fancybox-for-wordpress-zero-day-and-broken-patch/
legendary
Activity: 1260
Merit: 1115
March 16, 2015, 07:25:54 PM
#1
"AllCrypt.com is down for a bit

"Update:
Spent the last 16 hours scouring logs. I believe I know what happened and how. I'll post full details as soon as I know more. The site is down, for now, completely, until I can assess the damage done. I'm not even sure there is anything to bring back up.

"Older notice:
Well, due to some apparent exploit in wordpress, someone, somehow, got into the server tonight, installed some files, and managed to empty the goddamned BTC wallet. Best I can tell it was something with that worthless pile of shit software wordpress.

"I'm fucking done. I run a site, spend thousands of hours of time, thousands of dollars of my OWN money to run it, decide to shut down, and somehow, through ways I cannot even figure the hell out, someone gets in, uploads files to the server, somehow finds the goddamned BTC wallet on the network, and it appears that they slammed it with withdraw requests. Of course, the wallet is locked - but it unlocks when a withdraw is legitimately made through the site. I THINK they made a real wd on the site, and then slammed the backdoor to get the other funds out.

"We had 42 BTC in the wallet. 12 was the sites. 30 was users BTC. I'm fucking done with crypto. I'll post details when I sort this fucking mess out. Not that it will matter, because no one ever actually gives a shit when something like this happens."



Emphasis and .gif added by OP.




Jump to: