Pages:
Author

Topic: MtGox attack from Poland: accounts compromised - page 2. (Read 8368 times)

hero member
Activity: 896
Merit: 500
Dolphins Finance TRUSTED FINANCE
Hello,

It seems that there is an attack going on right now on MtGox from attackers in Poland. The timing of the attack is well chosen: MtGox support service is off in the week-end, the account holders cannot contact MtGox, thus leaving the attackers free to withdraw any money they want.


THE SITUATION:

We are an MtGox customer. We use it to transfer relatively large amounts of money.
In the last few weeks, MtGox has surprisingly stopped processing withdrawals, some of our withdrawals have been pending for 3 weeks now. These are international wire transfers. For Euro SEPA transfer, MtGox warns that it could take months to have it processed.  MtGox is blaming a "large backlog". It might or might not be true, this is MtGox after all.

Today, we received an email about a password reset.
Of course, we never initiated this password reset. MtGox mentions the IP address of the attacker in the password reset email: 178.42.125.117 . This IP address comes from Poland. It seems that the attackers don't even bother using proxies. This request from a IP in Poland didn't worry MtGox, although we consistently access our MtGox account from the UK, and only the UK.

Now, this wouldn't be that worrying, but the thing is we never gave the user ID of our account to anyone or publicly. The only way for an attacker to initiate this password reset would be to have access to the MtGox database.
Furthermore, MtGox sends the password reset email in CLEAR over the internet.

TO SUM UP:

So we have this situation where:
- MtGox doesn't process withdrawals anymore, so all our money sits on the MtGox account.
- MtGox database has been compromised by attackers, presumably in Poland.
- MtGox sends password reset emails in clear.
- MtGox customer service is off in the weekend.


THE RESULT:

Now, if an attacker got access to the MtGox database (at the very least they've got the list of user IDs, since they've got ours), he can also put a server in the same colocation areas as MtGox servers, sniffing their traffic, thus the password reset emails and validation code.

This is presumably what the attacker did.

At the moment, we have no access to our account (but surely the attacker has), and we have no way to contact MtGox, even sending them an email to urgently freeze our account is impossible, as they don't work in the weekend. Meanwhile, the attacker is surely enjoying his new bitcoins, since the bitcoin withdrawal system works very well, even in the weekend.

If anyone has any idea how to handle this type of issue, I would be very thankful.

But you have 2-Factor Authentication enabled right???

Then they couldnt get into your account with just your email and password/

Right  Cool
newbie
Activity: 33
Merit: 0
How do you know mtgox database was compromised?

What do you think is more probable: mtgox db compromised or a trojan in your machine?

If you move such quantities of money through mtgox why do you not use 2 factor auth?

If it was a trojan on a machine, the attacker wouldn't even bother requesting for an email reset.
Please read the full message and know what you're talking about before posting stupidities.

Maybe it was your email account that was compromised then.
newbie
Activity: 56
Merit: 0
How do you know mtgox database was compromised?

What do you think is more probable: mtgox db compromised or a trojan in your machine?

If you move such quantities of money through mtgox why do you not use 2 factor auth?

If it was a trojan on a machine, the attacker wouldn't even bother requesting for an email reset.
Please read the full message and know what you're talking about before posting stupidities.


You have ZERO room to call out posting stupidities. I certainly wouldn't announce that I was making $10K EYR transfers on this forum.

How is this related to the topic? How would you use such information? The forum doesn't even have a usable IP address.
Please respond with facts.
hero member
Activity: 770
Merit: 500
This guy 
From here: https://bitcointalksearch.org/topic/m.2308485

OP:
Quote
Hi,
hxxp://mtgox.de and hxxp://mtgox.org are SCAM websites.
Do not download any EXE, they are virus.
OP:
Quote
Did Mtgox confirm it was a scam?
I don't think they did.

newbie
Activity: 56
Merit: 0
Can you please define who the "we" is that you keep referring to please?

It's a company account, hence "we". How does this help?
Trolling?
Totally unrelated to the topic, again.
newbie
Activity: 56
Merit: 0
How do you know mtgox database was compromised?

What do you think is more probable: mtgox db compromised or a trojan in your machine?

If you move such quantities of money through mtgox why do you not use 2 factor auth?

If it was a trojan on a machine, the attacker wouldn't even bother requesting for an email reset.
Please read the full message and know what you're talking about before posting stupidities.
hero member
Activity: 546
Merit: 500
Can you please define who the "we" is that you keep referring to please?
newbie
Activity: 56
Merit: 0
Quote
Website: https://mtgox.com/
Facebook: https://www.facebook.com/MtGox
Twitter: https://twitter.com/MtGox
Phone: +81345501529
E-mail: [email protected]
Country: Japan
City: Tokyo
Street: Round Cross Shibuya 5F

Why not call them if this was true? FUD FUD FUD FUD FUD FUD FUD FUD FUD

Because they are sleeping, and don't work weekend.
TROLL TROLL TROLL
People like you should be banned from trolling once and for all.

Why are you calling all the people in this thread trolls? Just wanted to help. It seems you are the troll after all.

You want to help by writing this one line:

"Why not call them if this was true? FUD FUD FUD FUD FUD FUD FUD FUD FUD"

That's a line of a troll, not someone here to help.
A moderator can confirm that.
newbie
Activity: 33
Merit: 0
How do you know mtgox database was compromised?

What do you think is more probable: mtgox db compromised or a trojan in your machine?

If you move such quantities of money through mtgox why do you not use 2 factor auth?
newbie
Activity: 56
Merit: 0
Anyway, you don't have a lot of options, right now.
You can throw the IP out for investigation in the deep net, if you have any contact there.
Or you can wait for monday, regain access to your account, and depending on the damage, decide wether it's worth trying to file a complaint or not.
Oh, and before you receive your yubikey, at least go for google auth, as it will stop most script kiddies brutally.

Thanks for the advice, really appreciate it since it's the first post of this kind.
hero member
Activity: 770
Merit: 500
Quote
Website: https://mtgox.com/
Facebook: https://www.facebook.com/MtGox
Twitter: https://twitter.com/MtGox
Phone: +81345501529
E-mail: [email protected]
Country: Japan
City: Tokyo
Street: Round Cross Shibuya 5F

Why not call them if this was true? FUD FUD FUD FUD FUD FUD FUD FUD FUD

Because they are sleeping, and don't work weekend.
TROLL TROLL TROLL
People like you should be banned from trolling once and for all.

Why are you calling all the people in this thread trolls? Just wanted to help. It seems you are the troll after all.
newbie
Activity: 56
Merit: 0
Hey Ivan,

Been waiting for 10 days now for a SEPA withdrawal, the withdrawal status is "confirmed".
Amount is 10,000 EUR.

Posting things like this paint a hug red flag on you.

~BCX~

Doesn't reveal anything about the account, how would you use such information?
Please provide facts this time, not just trolls.
newbie
Activity: 56
Merit: 0
Quote
Website: https://mtgox.com/
Facebook: https://www.facebook.com/MtGox
Twitter: https://twitter.com/MtGox
Phone: +81345501529
E-mail: [email protected]
Country: Japan
City: Tokyo
Street: Round Cross Shibuya 5F

Why not call them if this was true? FUD FUD FUD FUD FUD FUD FUD FUD FUD

Because they are sleeping, and don't work weekend.
TROLL TROLL TROLL
People like you should be banned from trolling once and for all.
legendary
Activity: 1792
Merit: 1111
You use mtgox "to transfer relatively large amounts of money" without using google authentication (you don't need to order a yubikey)? Your loss is deserved
newbie
Activity: 56
Merit: 0
Has MtGox made any announcement yet?
So far it's just your word.

That's true, i might be overly dramatic and it might be a false alert.
We are trying to get advice from here, since MtGox support is off for the weekend.
hero member
Activity: 770
Merit: 500
Quote
Website: https://mtgox.com/
Facebook: https://www.facebook.com/MtGox
Twitter: https://twitter.com/MtGox
Phone: +81345501529
E-mail: [email protected]
Country: Japan
City: Tokyo
Street: Round Cross Shibuya 5F

Why not call them if this was true? FUD FUD FUD FUD FUD FUD FUD FUD FUD
newbie
Activity: 56
Merit: 0
Look at your post title, overly dramatic.

How do you know that MTGOX was compromised?

How do you know it was more than one account?

More than likely you or your company's carelessness combined with the fact you blatantly talk about $10,000 EUR MTGOX transfers in several previous post which is STUPID.

~BCX~

No one knows which account is concerned by this. You won't be able to link it to the forum identity.
So how is this "STUPID"?
Please explain, otherwise you're just trolling, like your other posts.
sr. member
Activity: 336
Merit: 250
Cuddling, censored, unicorn-shaped troll.
Anyway, you don't have a lot of options, right now.
You can throw the IP out for investigation in the deep net, if you have any contact there.
Or you can wait for monday, regain access to your account, and depending on the damage, decide wether it's worth trying to file a complaint or not.
Oh, and before you receive your yubikey, at least go for google auth, as it will stop most script kiddies brutally.
member
Activity: 87
Merit: 10
Has MtGox made any announcement yet?
So far it's just your word.
newbie
Activity: 56
Merit: 0
Spreading FUD you are.

Please provide factual information about what is FUD in my message. Trolling is frowned upon on this forum.

Just because you're supposedly detailed doesn't make it factual.

Why are you the only person so far supposedly attacked?

Look at your post headline, overly dramatic with zero proof that "accounts" were compromised.

Maybe yours because you're careless or make yourself a target, that doesn't make it GOX fault now does it?

~BCX~

Since you edit your posts after they have been replied to (a common trollish behavior), I reply to your edited post:

What make you say we're careless and make ourself a target?
Complete troll.
How come you don't discuss the arguments, but relying on insulting the messenger?
Pages:
Jump to: