Pages:
Author

Topic: [ANN] | freshmarket.co.in - Closed. Refunds till 10/02/14 - page 15. (Read 41800 times)

full member
Activity: 130
Merit: 100
Hello again.
So we have 84% LTC, 64% of all LEAF and 100% of all other currencies.
We have found more than 400 LTC from our own wallets to refund as much as we can.
You have to email to [email protected] with:
your account name
what money and how much you had
adresses for withdrawal for all money.

I want you to make it public - obvsly there will be tonn of trolls like "I SENT IT WHERE IS MY MONEY", so i want you to post your taken withdrawals.
If your account was hacked - we cant refund you anything, because if we don't see money on your balance we can't really check if it was hacked or you just say you were hacked. We haven't stored passwords, so (as i see) only chance is brutefoce.

Refunds will start just now.

I already sent an E-mail with my E-mail account that was registered.

Username:  sarlangg

Potcoin address: PLzeDdT4jvZss3nERwpwKVyHdaiSdTtAA9
About 4,380?  I cant remember the exact number.

Litecoin address: LakfxNoutVhTSbiT3rRcKPe9EkeyJ87iWM
About 5.4?  I can't remember exact number either.




Also the above amounts are guestimations based on what I remember.  I do know the exact amounts I had 2 days ago:
Potcoin:  3137.96977479 POT
Litecoin:  6.13163135 LTC

I know I had a ton of POT/LTC buy orders in and I had some successful trades, hence why I can't remember the exact amount.
member
Activity: 78
Merit: 10
Confirmation :


LTC refund : ok received
UTC refund : Not yet ok received

updated
member
Activity: 126
Merit: 11
account name:ovichef please refund my UTC about 710 to my wallet UmADikawUKmdnGcZq5cwU4AjQqCnWyqNfr and nutcoin i dont remenber how much i hope you can see my balance send to this
NX7VGwEm45FxsvZT7T6MyiEakCJrNQwaTg

Read this: https://bitcointalksearch.org/topic/m.4949863
newbie
Activity: 18
Merit: 0
account name:ovichef please refund my UTC about 710 to my wallet UmADikawUKmdnGcZq5cwU4AjQqCnWyqNfr and nutcoin i dont remenber how much i hope you can see my balance send to this
NX7VGwEm45FxsvZT7T6MyiEakCJrNQwaTg
full member
Activity: 140
Merit: 100
all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money
So you did not have any bruteforce protection on the login side?
As i see - we made it. But you got to speak with devs about it.
full member
Activity: 140
Merit: 100
And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
What happened? Did the coindaemons balance just drop or did the hacker access the users accounts and emptied some of them?
We know one possible attack scenario that has been used on many of the new exchanges, including ours (we survived the attacks).
Any place where we can inspect the source code of a withdrawal script?
Nice idea, but later. Just now devs are too busy making refunds, and i don't have source code.
member
Activity: 98
Merit: 10
all passwords are stored as hashed ones. So he just brute-forced all low-security passwords to steal their money
So you did not have any bruteforce protection on the login side?
member
Activity: 98
Merit: 10
And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
What happened? Did the coindaemons balance just drop or did the hacker access the users accounts and emptied some of them?

We know one possible attack scenario that has been used on many of the new exchanges, including ours (we survived the attacks).
Any place where we can inspect the source code of a withdrawal script? It would really be intresting to find out some truth about this "hack".
full member
Activity: 140
Merit: 100
Running an exchange on PHP is as smart as it gets.
Not salting the passwords before hashing is ... plain stupid.
Allowing an SQL injection to happen is ... amateurish.
People, you cannot run a mission-critical application on a LAMP stack that has tens of 0-day exploits flying around every day.
>not salting
Individual salt, sha-512
And we still haven't found sql-injection in code. I just don't know what exactly happened, and can only guess.
sr. member
Activity: 394
Merit: 250
Still waiting for my coins to be back. Hope you can solve it soon, will update whenever I receive the coins. Thanks for your hard work.
member
Activity: 98
Merit: 10
Running an exchange on PHP is as smart as it gets.
Not salting the passwords before hashing is ... plain stupid.
Allowing an SQL injection to happen is ... amateurish.

People, you cannot run a mission-critical application on a LAMP stack that has tens of 0-day exploits flying around every day.
full member
Activity: 135
Merit: 100
My coins was refund !!!  Thx you!

Please return from you marketplace quickly !! Eliminate all errors, raise your level of safety and back online!!

All the best for futures!

+1 concept is good.
newbie
Activity: 15
Merit: 0
My coins was refund !!!  Thx you!

Please return from you marketplace quickly !! Eliminate all errors, raise your level of safety and back online!!

All the best for futures!
member
Activity: 78
Merit: 10
Confirmation :


LTC refund : ok received
UTC refund : Not yet ok received
full member
Activity: 135
Merit: 100
We are processing 1 account for nearly ~3-5 minutes. Just now we have 84 unread messages in our support mail.
So we need atleast 7 hours to refund you your money.
Stay patient please. We are working.

I got my 1.7 Ltc in refund.
Thanks for that!!
Cannot check Utc refund because its on my home wallet. Will reply later.

Succes with the rest.

UPDATE: UTC refund confirmed. Thanx!!
full member
Activity: 224
Merit: 100
I forgot that had an open trade LTC/NYAN

i got my NYAN's, for this great thanx

about LTC.... my wallet on my home pc, about 2 hours i'll reply.

http://ltc.block-explorer.com/address/LL2QYuGabhnMMPpwrdAAgfeqygWCeQgtJD
everything is ok.... i've lost only 3 LTC.... thats a good result ))) 'cause in other situation .... you understand )

admin, thanx
full member
Activity: 140
Merit: 100
We are processing 1 account for nearly ~3-5 minutes. Just now we have 84 unread messages in our support mail.
So we need atleast 7 hours to refund you your money.
Stay patient please. We are working.
member
Activity: 91
Merit: 10
Hi I emailed a little while ago, i had 92 litecoins originally, traded some for UTC, here is my adress from freshmarket,

LPH98HiNKJUBt71krwjUetsRK2v1gLN3QT

You can see i sent them from my btce account,

I should have had with you guys
2600 UTC
66 LTC
User: jacobshm

please let me know when i can expect a refund.

Thanks
hero member
Activity: 535
Merit: 500
any update on my case? i sent a email i was hoping for one back.
newbie
Activity: 15
Merit: 0
@def_ender

Can you refund my ltc, leaf and rdd, can You check this ? I send email to support and PM over an hour ago. I very needs this coin quickly.

name account: filipej
Pages:
Jump to: