Pages:
Author

Topic: ⚠️ How Scammer tried to Hack my Bitcointalk and how to Protect yourself?⚠️ - page 2. (Read 1507 times)

legendary
Activity: 1624
Merit: 2481
For instance, some versions of wallets like Electrum had vulnerabilities.

Just like any other wallet.

Each wallet had vulnerabilities in the past. There is not a single one which didn't.
And some do even still have vulnerabilities which will never be fixed (e.g. jaxx).



Also, don't click on any links you receive via pm or email unless you really know the sender.

Even if you know the sender you shouldn't click on links without verifying it.
If the original sender is compromised, malware could send emails to all contacts. While you'd believe the sender is a well known friend, in reality it is just some attacker who compromised the system of your friend.

Do not trust, verify.
legendary
Activity: 2212
Merit: 7064
Correct, what I mean is devices should be secured as much as possible, and should be the first priority of anyone who want to enter crypto world. Without devices security, they will lose money sooner or later.

I agree with you.
Scammers are smart and they always invent new ways to scam people,
so we have to update our devices on regular basis, and keep them protected as much as possible.

There is no perfect 100% protection ... sadly  Undecided

Make sure the updates are legit. Many programs gained new vulnerabilities after being updated. For instance, some versions of wallets like Electrum had vulnerabilities.
I always say that the safest way is to keep your money offline on a separate device and have another PC to use for torrents, opening emails, forums and chats, and so on.
Also, don't click on any links you receive via pm or email unless you really know the sender.

All good advises, and we should all know them,
but sadly many newbies don't, so we have to remind them all the time.
And even experts can become victims if they are not super careful
legendary
Activity: 2814
Merit: 1192
Correct, what I mean is devices should be secured as much as possible, and should be the first priority of anyone who want to enter crypto world. Without devices security, they will lose money sooner or later.

I agree with you.
Scammers are smart and they always invent new ways to scam people,
so we have to update our devices on regular basis, and keep them protected as much as possible.

There is no perfect 100% protection ... sadly  Undecided

Make sure the updates are legit. Many programs gained new vulnerabilities after being updated. For instance, some versions of wallets like Electrum had vulnerabilities.
I always say that the safest way is to keep your money offline on a separate device and have another PC to use for torrents, opening emails, forums and chats, and so on.
Also, don't click on any links you receive via pm or email unless you really know the sender.
newbie
Activity: 3
Merit: 0
Thanks for taking your time to do this especially for the newbies like us in the forum, I have just been scrolling and getting used to this forum, infact this is my first post so far. Thanks for the lesson.
legendary
Activity: 2212
Merit: 7064
Correct, what I mean is devices should be secured as much as possible, and should be the first priority of anyone who want to enter crypto world. Without devices security, they will lose money sooner or later.

I agree with you.
Scammers are smart and they always invent new ways to scam people,
so we have to update our devices on regular basis, and keep them protected as much as possible.

There is no perfect 100% protection ... sadly  Undecided
legendary
Activity: 2296
Merit: 1014
Correct, what I mean is devices should be secured as much as possible, and should be the first priority of anyone who want to enter crypto world. Without devices security, they will lose money sooner or later.
Which is very wide knowledge to learn. Its about knowing what you doing in computer world, knowing whats possible for hackers (almost everything) and whats not possible. Where you should focus your efforts to stay secure (crypto world).
This knowledge need often branches of more specialized computer knowledge to understand them.

Example from friend of friend, easiest to learn for him is by practice so he tried to write trojan horse, and he saw what is needed (from common shared knowledge) to avoid detection from Anti Virus software and now he knew that AV software is no good and you cant feel secure with it.
legendary
Activity: 2044
Merit: 1018
Not your keys, not your coins!
Correct, what I mean is devices should be secured as much as possible, and should be the first priority of anyone who want to enter crypto world. Without devices security, they will lose money sooner or later.
legendary
Activity: 2212
Merit: 7064
another way to secure your profile is to Stake your Bitcoin address
This step is only helpful to secure forum accounts, not to secure bitcoin.  Grin
Hackers can hack your computers, steal your account, and steal your money.
You can use signed message to get your account back, while your bitcoin will be stolen forever. There is no backwards trip for your bitcoin from hackers to you.

But you can always use empty BTC address with no Bitcoins to stake your address  Wink
hero member
Activity: 1680
Merit: 583
xUSD - The PRIVATE stable coin - Haven Protocol
another way to secure your profile is to Stake your Bitcoin address
This step is only helpful to secure forum accounts, not to secure bitcoin.  Grin
Hackers can hack your computers, steal your account, and steal your money.
You can use signed message to get your account back, while your bitcoin will be stolen forever. There is no backwards trip for your bitcoin from hackers to you.
it's obvious
legendary
Activity: 2044
Merit: 1018
Not your keys, not your coins!
another way to secure your profile is to Stake your Bitcoin address
This step is only helpful to secure forum accounts, not to secure bitcoin.  Grin
Hackers can hack your computers, steal your account, and steal your money.
You can use signed message to get your account back, while your bitcoin will be stolen forever. There is no backwards trip for your bitcoin from hackers to you.
legendary
Activity: 2212
Merit: 7064
another way to secure your profile is to Stake your Bitcoin address

this is the most efficient way to prove your ownership of your Bitcointalk account -> Stake your Bitcoin address here

all you have to do is to use your BTC wallet and make a message like this ->

Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
This is at bitcointalk.org. The current date is .
-----BEGIN SIGNATURE-----


-----END BITCOIN SIGNED MESSAGE-----

and post it in that thread above, someone will quote you and you are safe
if you get hacked, you will proof your identity with your BTC wallet

the tutorial -> How to sign a message?!



Good point.
I added that on the list on page 1,
and I also staked my Bitcoin address some time ago Wink

One more thing would be good to have installed is
Malwarebytes Browser Extension

for Firefox
https://addons.mozilla.org/en-US/firefox/addon/malwarebytes/?src=search

For Brave and Chrome browsers
https://chrome.google.com/webstore/detail/malwarebytes-browser-exte/ihcjicgdanjaechkgeegckofjjedodee




hero member
Activity: 1680
Merit: 583
xUSD - The PRIVATE stable coin - Haven Protocol
another way to secure your profile is to Stake your Bitcoin address

this is the most efficient way to prove your ownership of your Bitcointalk account -> Stake your Bitcoin address here

all you have to do is to use your BTC wallet and make a message like this ->

Code:
-----BEGIN BITCOIN SIGNED MESSAGE-----
This is at bitcointalk.org. The current date is .
-----BEGIN SIGNATURE-----


-----END BITCOIN SIGNED MESSAGE-----

and post it in that thread above, someone will quote you and you are safe
if you get hacked, you will proof your identity with your BTC wallet

the tutorial -> How to sign a message?!


legendary
Activity: 2212
Merit: 7064
I just opened a pull request for MetaMask: https://github.com/MetaMask/eth-phishing-detect/pull/3221

The site should be blocked through the MetaMask extension if they accept it.

My pull request got accepted, MetaMask now blocks the site:


Great news!
Thank you for your support and fast response.
+merit


they've been doing this phishing since the dawn of time but it still works for some. it should be common sense to see something is wrong if there is the need to login again when you know you are already loggedin. the url of the website is very important to notice here.

It may be obvious for you and me, but average user can get distracted
thinking it is just a browser issue, and enter his details, resulting in his account being hacked.
legendary
Activity: 3234
Merit: 1055
they've been doing this phishing since the dawn of time but it still works for some. it should be common sense to see something is wrong if there is the need to login again when you know you are already loggedin. the url of the website is very important to notice here.

I just opened a pull request for MetaMask: https://github.com/MetaMask/eth-phishing-detect/pull/3221

The site should be blocked through the MetaMask extension if they accept it.

My pull request got accepted, MetaMask now blocks the site:



when you aren't sure which app to use your metamask, don't use it. browser apps aren't something you can controll, you may have the privkeys but pick which app to use your metamask.
sr. member
Activity: 588
Merit: 422
I just opened a pull request for MetaMask: https://github.com/MetaMask/eth-phishing-detect/pull/3221

The site should be blocked through the MetaMask extension if they accept it.

My pull request got accepted, MetaMask now blocks the site:

sr. member
Activity: 1050
Merit: 277
That is pretty clever and quite a nasty way to phish. You see the link and click and without thinking you login again. The thing is I always keep myself logged in so if I do log out it is because I logged out myself.
It is a bit odd to get a link right to the reply saying they have replied to you. Though this is a perfect way to let someone know you have replied. I think at anytime you are ever asked to login for any reason what so ever that you should check the address. Even pages I bookmark I check the address just incase.

Very nasty and very easy to fall for this if you not paying much attention which is easy.
legendary
Activity: 2604
Merit: 2353
OK.. please examine the case and catch the fish.
I reported on time, and as fast as I could.


Now your thread has been moved in the beginners section I think very few members will see it.
So I think you should open a thread in Economy > Trading Discussion > Reputation  section, on Kingpin4321. It's the right place for flags and tags.
https://bitcointalk.org/index.php?board=129.0
Listen...
Someone else proposed that I move it to B&H since it is also a guide for newbies
and I don't have extra time to move topics all day round....
It is where it is now.

Thanks.
Nice catch tho, it can really be pretty obvious attempt  from the hacker. I just wondered why choose your account over a higher account which he can benefit more, hmm sounds fishy.
Well, I've got this assumption that the hacker thinks he can get as this user is just a Member rank and have little to know about phishing. Not knowing what he tried to mess is a techy guy and even surpass him on the knowledge about those kinds of things.

It might be good to move this one on B&H board as it is more appropriate there. Nice catch OP.
You didn't understand me, I wasn't suggesting you to move this thread there but to create another one for flagging and tagging Kingpin4321 since he was still hurting people according to Efialtis testimonial.
Now he seems to have been banned, so the issue about him is closed, normally.  

BTW I don't think it's a topic for beginners since the hacker is not targeting newbie accounts and the case is raising concerns about homographic attacks, so it was a rather weird suggestion from this guy...  Undecided



All this above is for those that don't understand phishing sites and that bitcointak internal sites are marked in green when you hover over it with your mouse.
People are not only using old computers with mouse, we are in 2019 now.  Wink
legendary
Activity: 2212
Merit: 7064
One more thing.
It is better to use Firefox browser as it shows warnings for this unsecure logins

This does just mean that the website does not use https.
This is definitely NOT an indicator for the authenticity of a website.

I'd expect any phishing site not created by completely incapable people to have a TLS certificate. You can get them for free.

I know that  Grin
And I just say it is one more step to protect yourself better...
Firefox is better than Chrome... but you still need to use your brain.

As for better protection my suggestions are on first page
legendary
Activity: 1624
Merit: 2481
One more thing.
It is better to use Firefox browser as it shows warnings for this unsecure logins

This does just mean that the website does not use https.
This is definitely NOT an indicator for the authenticity of a website.

I'd expect any phishing site not created by completely incapable people to have a TLS certificate. You can get them for free.
legendary
Activity: 2212
Merit: 7064
One more thing.
It is better to use Firefox browser as it shows warnings for this unsecure logins



Pages:
Jump to: