Pages:
Author

Topic: Bitcoinica MtGox account compromised - page 22. (Read 156012 times)

legendary
Activity: 1288
Merit: 1227
Away on an extended break
July 13, 2012, 09:25:24 PM
you're assuming we know what ZT's bad news was. It is possible he contacted them about the source code leak. Or god only knows what.

No. I received this email. I was still in the [email protected] mailing list.

I believe that the theft happened much earlier and no one discovered. No one cared about this spammy-look email either (or they don't check their mailbox).


Quote
From: Bitcoinica Sucks <[email protected]>
To: [email protected]
Date: Friday, 13 July 2012 3:39:55 AM
Subject: Bitcoinica is done

THANK YOU FOR YOU SOURCE CODE.

BITCONICA IS NOW OFFICALY DONE!

LASTPAS PASWORD: c02e1a27-5524-449f-ba65-aff9581ddedc
You posted on the 12th you had bad news about an email you received on the 13th? I'm not following something right here, sorry.



Someone needs to explain this...
Time zones.
rjk
sr. member
Activity: 448
Merit: 250
1ngldh
July 13, 2012, 09:20:54 PM
Lrn 2 timezone
hero member
Activity: 686
Merit: 500
Wat
July 13, 2012, 09:20:19 PM
you're assuming we know what ZT's bad news was. It is possible he contacted them about the source code leak. Or god only knows what.

No. I received this email. I was still in the [email protected] mailing list.

I believe that the theft happened much earlier and no one discovered. No one cared about this spammy-look email either (or they don't check their mailbox).


Quote
From: Bitcoinica Sucks <[email protected]>
To: [email protected]
Date: Friday, 13 July 2012 3:39:55 AM
Subject: Bitcoinica is done

THANK YOU FOR YOU SOURCE CODE.

BITCONICA IS NOW OFFICALY DONE!

LASTPAS PASWORD: c02e1a27-5524-449f-ba65-aff9581ddedc
You posted on the 12th you had bad news about an email you received on the 13th? I'm not following something right here, sorry.



Someone needs to explain this...
hero member
Activity: 504
Merit: 500
July 13, 2012, 09:17:32 PM
you're assuming we know what ZT's bad news was. It is possible he contacted them about the source code leak. Or god only knows what.

No. I received this email. I was still in the [email protected] mailing list.

I believe that the theft happened much earlier and no one discovered. No one cared about this spammy-look email either (or they don't check their mailbox).


Quote
From: Bitcoinica Sucks <[email protected]>
To: [email protected]
Date: Friday, 13 July 2012 3:39:55 AM
Subject: Bitcoinica is done

THANK YOU FOR YOU SOURCE CODE.

BITCONICA IS NOW OFFICALY DONE!

LASTPAS PASWORD: c02e1a27-5524-449f-ba65-aff9581ddedc
You posted on the 12th you had bad news about an email you received on the 13th? I'm not following something right here, sorry.

vip
Activity: 490
Merit: 502
July 13, 2012, 09:14:32 PM
Adding to my previous post agreeing with bitcoinBull. If it was an inside job it wasn't Patrick or Amir.

First we had this.
https://bitcointalksearch.org/topic/m.894435
Posting an update soon.

good news?

If it's related to my previous email to the Bitcoinica team, no, it's a bad news.

This was a pointless and malicious comment.

Are you trying to further harm their reputation or your own? Because they're not entirely separate.

No, I was merely stating a fact. I discovered something unusual and I emailed them. They promised an update. And that's it.

I don't have the right to update you publicly because I have some advantage in obtaining insider information.

I'm not part of the "bad news" and I'm not involved in Bitcoinica. If I didn't tell them they will discover the problem anyway.

Someone care to explain to a dumb guy(me) how is it that a guy who isn't "involved in Bitcoinica" discovers a theft of almost $400k before the ones who are involved in Bitcoinica?

you're assuming we know what ZT's bad news was. It is possible he contacted them about the source code leak. Or god only knows what.

No. I received this email. I was still in the [email protected] mailing list.

I believe that the theft happened much earlier and no one discovered. No one cared about this spammy-look email either (or they don't check their mailbox).


Quote
From: Bitcoinica Sucks <[email protected]>
To: [email protected]
Date: Friday, 13 July 2012 3:39:55 AM
Subject: Bitcoinica is done

THANK YOU FOR YOU SOURCE CODE.

BITCONICA IS NOW OFFICALY DONE!

LASTPAS PASWORD: c02e1a27-5524-449f-ba65-aff9581ddedc
hero member
Activity: 504
Merit: 500
July 13, 2012, 09:12:20 PM
Adding to my previous post agreeing with bitcoinBull. If it was an inside job it wasn't Patrick or Amir.

First we had this.
https://bitcointalksearch.org/topic/m.894435
Posting an update soon.

good news?

If it's related to my previous email to the Bitcoinica team, no, it's a bad news.

This was a pointless and malicious comment.

Are you trying to further harm their reputation or your own? Because they're not entirely separate.

No, I was merely stating a fact. I discovered something unusual and I emailed them. They promised an update. And that's it.

I don't have the right to update you publicly because I have some advantage in obtaining insider information.

I'm not part of the "bad news" and I'm not involved in Bitcoinica. If I didn't tell them they will discover the problem anyway.

Someone care to explain to a dumb guy(me) how is it that a guy who isn't "involved in Bitcoinica" discovers a theft of almost $400k before the ones who are involved in Bitcoinica?

you're assuming we know what ZT's bad news was. It is possible he contacted them about the source code leak. Or god only knows what.
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 09:08:19 PM
Adding to my previous post agreeing with bitcoinBull. If it was an inside job it wasn't Patrick or Amir.

First we had this.
https://bitcointalksearch.org/topic/m.894435
Posting an update soon.

good news?

If it's related to my previous email to the Bitcoinica team, no, it's a bad news.

This was a pointless and malicious comment.

Are you trying to further harm their reputation or your own? Because they're not entirely separate.

No, I was merely stating a fact. I discovered something unusual and I emailed them. They promised an update. And that's it.

I don't have the right to update you publicly because I have some advantage in obtaining insider information.

I'm not part of the "bad news" and I'm not involved in Bitcoinica. If I didn't tell them they will discover the problem anyway.

Someone care to explain to a dumb guy(me) how is it that a guy who isn't "involved in Bitcoinica" discovers a theft of almost $400k before the ones who are involved in Bitcoinica?
hero member
Activity: 686
Merit: 500
Wat
July 13, 2012, 08:56:00 PM
This whole mess should have been in the hands of a third party administrator long ago and at the very least a police report filed.

Setting up a company is the essence of government interference and to turn around and to claim you dont believe in government interference after you do that doesnt make sense, which is the reason they claim they never filed a police report.
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:54:43 PM
genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes

Given his history, I think incompetence is more likely than malice, definitely in genjix's case.

That patrick would walk away right now looks suspicious, if he were a smart thief he would come back and finish the claims so everyone gets their 66% (like myBitcoin). So in a counter-intuitive way, I think that he "walked away" in anger/frustration is actually a sign that it wasn't an inside job. Its very plausible and at least equally likely that there was another thief IMO (see below)...


I agree with you on this one. If it was an inside job, and I'm not saying it is(I mean the thefts, not the source code leak), it was from someone else and not Patrick or Amir. They would have to be completely nuts to screw up on something that would tarnish their reputation in this manner.
legendary
Activity: 826
Merit: 1001
rippleFanatic
July 13, 2012, 08:48:53 PM
@BitcoinBull  I assume by 'box' you mean his personal computer?

More likely his VPS (virtual private server), which he explained was the cause of the last breach. He said he gives many "noobs" from #C++, etc access to that VPS.


genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes

Given his history, I think incompetence is more likely than malice, definitely in genjix's case.

That patrick would walk away right now looks suspicious, if he were a smart thief he would come back and finish the claims so everyone gets their 66% (like myBitcoin). So in a counter-intuitive way, I think that he "walked away" in anger/frustration is actually a sign that it wasn't an inside job. Its very plausible and at least equally likely that there was another thief IMO (see below)...



I think the probability is about the same as finding a sha-256 collision in bitcoin   Smiley

So its probably silly to imagine it happened. Compare the chance of an inside job (someone told the thief where to look or told them the actual password) or a keylogger (etc) type attack was used to discover it, in such cases the fact one can find it in the source code is merely a red herring, whether deliberately dyed red or merely accidentally happening to be red.

-MarkM-


I didnt see a "lastpass master pasword " label on that string.

This.

Was ANYONE here even aware that the bitcoinica source code had been leaked, prior to genjix's OP on this thread?

Plugging the file URL into Google gives only a handful of results, with this thread being the earliest incidence of it, as far as I can tell.

That, plus the fact that the tar file appears to have been packed by username genjix.

Additionally, there's the fact that the lastpass password was supposedly the MtGOX KEY (username) and not the SECRET. A bizarre thing to do, which smells more like it's a fuck-up in an attempt to make up a plausible hack story.

The whole story is just too cute for me.


The source code was leaked on reddit almost a week ago (0 points from 9 downvotes, that's why I personally missed it).

It is plausible that someone would try the mtgox api key as the LastPass password. A very lucky someone could've confirmed months ago that [email protected] was a LastPass account, because LastPass tells you if you try log-in with an invalid username/e-mail ("Unknown e-mail address") or if its a valid LastPass account ("Invalid password").

So when the source code was leaked, they saw the API key and decided to try it.

legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:43:42 PM

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.

genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes
no one is giving an 'explanation'. We are jsut trying to trace this stuff back as close to 'source' as possible..


@BitcoinBull  I assume by 'box' you mean his personal computer?

I will not give much importance to bitcoinBull's assumptions as 20 minutes ago he was assuming I was looking at the file on the OP and not at the file I had downloaded from the link at the pastebin and decoded with the instructions posted at reddit...

well, in your opinion, did it come from his gihub or his computer? And would it not be easy enough to edit that stuff to make it look like it came from a particular source?

Anything is possible. I could create a VM and have a user with the name genjix and achieve the same result.
That still doesn't give me a solution to be able to clone a private github repo, much less edit the HEAD file to include genjix name on it, for I would need to clone the repo first Grin
hero member
Activity: 504
Merit: 500
July 13, 2012, 08:41:01 PM

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.

genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes
no one is giving an 'explanation'. We are jsut trying to trace this stuff back as close to 'source' as possible..


@BitcoinBull  I assume by 'box' you mean his personal computer?

I will not give much importance to bitcoinBull's assumptions as 20 minutes ago he was assuming I was looking at the file on the OP and not at the file I had downloaded from the link at the pastebin and decoded with the instructions posted at reddit...

well, in your opinion, did it come from his gihub or his computer? And would it not be easy enough to edit that stuff to make it look like it came from a particular source?
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:37:07 PM

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.

genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes
no one is giving an 'explanation'. We are jsut trying to trace this stuff back as close to 'source' as possible..


@BitcoinBull  I assume by 'box' you mean his personal computer?

I will not give much importance to bitcoinBull's assumptions as 20 minutes ago he was assuming I was looking at the file on the OP and not at the file I had downloaded from the link at the pastebin and decoded with the instructions posted at reddit...
legendary
Activity: 2198
Merit: 1311
July 13, 2012, 08:36:02 PM
Which is BS since you can be a level 47 verified and you all will sit on a wire transfer for weeks. Especially a larger transfer.

No BS here. As I said before and as Mark explained, we cannot discuss these details here, however I strongly advise you to read the 20 (pages) of this thread.

PS. We are on your side not against you.

Just want to pop in and say thanks to MtGox for pursuing this.
legendary
Activity: 826
Merit: 1001
rippleFanatic
July 13, 2012, 08:34:34 PM
Therefore, I would like to know WHOSE LastPass got compromised.

Tihan created the LastPass account (I believe from reading his post). My guess, Tihan set the password by copy-pasting the mtgox api key, which was in a text file given to him by zhoutong.

Tihan shared the LastPass account and password with Bitcoin Consultancy, who "assumed" it was "secure", so he's blaming them because they didn't tell Tihan to change it. I agree with Tihan, they should have recognized it as the API key and changed it, both because they hyphens are suggestive of an API key and because they should have already seen the same string in the bitcoinica source code (failed to put 1 + 1 together). In any case, they should have changed it.
hero member
Activity: 504
Merit: 500
July 13, 2012, 08:32:38 PM

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.

genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes
no one is giving an 'explanation'. We are jsut trying to trace this stuff back as close to 'source' as possible..


@BitcoinBull  I assume by 'box' you mean his personal computer?
legendary
Activity: 1358
Merit: 1002
July 13, 2012, 08:28:10 PM
How did the hacker also get access to genjix account on github ?

that is what I am wondering, with following that part of the thread..

It wasn't from genjix's github account. Genjix cloned the github repo to his own box . It was accessed from there.



But how did you get this to claim that he packed it:
Code:
drwxr-xr-x genjix/genjix     0 2012-07-07 20:18 bitcoinica_legacy/

You are implying that genjix intentionally leaked the code. I can't confirm that.

This
Code:
$ tar -jtvf bit.tar.bz2 | head -n1
gives this
Code:
drwxr-xr-x genjix/genjix     0 2012-07-07 20:18 bitcoinica_legacy/
which means that the bitcoinica_legacy folder that was packed to the encrypted file had the owner genjix from group genjix and was last modified at 2012-07-07 20:18

I posted all you needed to do to. Not sure why you're asking lol

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.

genjix's box was hacked? Who told you that? Shocked

So, the simplest explanation is the one you gave and not that genjix himself leaked the source code? Roll Eyes
legendary
Activity: 826
Merit: 1001
rippleFanatic
July 13, 2012, 08:21:41 PM
How did the hacker also get access to genjix account on github ?

that is what I am wondering, with following that part of the thread..

It wasn't from genjix's github account. Genjix cloned the github repo to his own box . It was accessed from there.



But how did you get this to claim that he packed it:
Code:
drwxr-xr-x genjix/genjix     0 2012-07-07 20:18 bitcoinica_legacy/

You are implying that genjix intentionally leaked the code. I can't confirm that.

This
Code:
$ tar -jtvf bit.tar.bz2 | head -n1
gives this
Code:
drwxr-xr-x genjix/genjix     0 2012-07-07 20:18 bitcoinica_legacy/
which means that the bitcoinica_legacy folder that was packed to the encrypted file had the owner genjix from group genjix and was last modified at 2012-07-07 20:18

I posted all you needed to do to. Not sure why you're asking lol

Thanks. So the leaker who accessed genjix's box packed it on his box as him. That's why it says genjix/genjix, genjix's box was hacked.
rjk
sr. member
Activity: 448
Merit: 250
1ngldh
July 13, 2012, 08:14:22 PM
LastPass offers this following cool feature: The ability to share a saved password with a third party, while both keeping said password secret and not sharing the rest of your passwords. You can see a screenshot of how it works below.
IF we assume that passwords were being shared using this facility, then we can also reasonably assume that each LastPass user has his own password that is different. Therefore, I would like to know WHOSE LastPass got compromised.

hero member
Activity: 686
Merit: 500
Wat
July 13, 2012, 08:13:53 PM
How did the hacker also get access to genjix account on github ?

I did git pull, looks like genjix's account required public key.


The authenticity of host 'github.com (207.97.227.239)' can't be established.
RSA key fingerprint is 16:27:ac:a5:76:28:2d:36:63:1b:56:4d:eb:df:a6:48.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'github.com,207.97.227.239' (RSA) to the list of known hosts.
Permission denied (publickey).
fatal: The remote end hung up unexpectedly



If only you needed a public key to withdraw from Gox Smiley
Pages:
Jump to: