Pages:
Author

Topic: Nuovocard Hacking Contest - Hack Us for $3000 (Bounty) - Phase 2 Started - page 6. (Read 6573 times)

legendary
Activity: 1218
Merit: 1003
We are the champions of the night
Nothing is getting deposited to https://blockchain.info/address/mrm4AN6uAExNgXbRtqVL5tA4RmVxR2QtMa and blockchain.info is showing that the Tx hash u have sent does not exist. Is the App properly configured on your app server ?
They are testnet transactions, so you need to use a testnet block explorer

http://blockexplorer.com/testnet/address/mrm4AN6uAExNgXbRtqVL5tA4RmVxR2QtMa
legendary
Activity: 2394
Merit: 1216
The revolution will be digital
Nothing is getting deposited to https://blockchain.info/address/mrm4AN6uAExNgXbRtqVL5tA4RmVxR2QtMa and blockchain.info is showing that the Tx hash u have sent does not exist. Is the App properly configured on your app server ?
hero member
Activity: 602
Merit: 500
Hi Neha, HappY Independence Day Smiley

You have chosen a great day to kickstart the hackathon. As I understand, u dont want us to find where Nuovocard.com is running, i.e. the web server. U want us to find out the server IP from where the mail is originating. Am I wrong ?

That's what he is asking you to do...I'm going to give this a shot!
legendary
Activity: 2394
Merit: 1216
The revolution will be digital
Hi Neha, HappY Independence Day Smiley

You have chosen a great day to kickstart the hackathon. As I understand, u dont want us to find where Nuovocard.com is running, i.e. the web server. U want us to find out the server IP from where the mail is originating. Am I wrong ?
full member
Activity: 168
Merit: 100
IP is: 64.233.166.121

Location:
City:   Mountain View
Country:   United States
State: California

Am I right?

Nope. Thats Google I think.

Update : Yeah that is google. http://64.233.166.121.ipaddress.com/.

Please check who does the IP belong to before you post. Our server currently is not on Google.
newbie
Activity: 22
Merit: 0
IP is: 64.233.166.121

Location:
City:   Mountain View
Country:   United States
State: California

Am I right?
full member
Activity: 168
Merit: 100
Well, I'll give it a shot. I'm not a hacker, but I have lots of experience with MS paint. If a poorly drawn MS paint picture of goatse shows up on your site you know who did it.

Hey, remember the challenge is not to hack the webserver. If you are able to hack the app server...make sure you leave a text file in the home folder with you email address.
full member
Activity: 168
Merit: 100
Challenge accepted, been looking for a place to hone my skills Cheesy

Awesome, make sure you review the instructions of sending the email and communicating with the server. The only way you can reach the server is to send an email to [email protected] with subject as 'transfer' and you will get a Testnet Transaction ID back.

Also, currently we have the server set to check mail every 30 seconds as we dont expect too much traffic. So please wait for 30 seconds to get a reply.
legendary
Activity: 1218
Merit: 1003
We are the champions of the night
Challenge accepted, been looking for a place to hone my skills Cheesy
full member
Activity: 168
Merit: 100
Nope. You are trying to find the IP of the Webserver where as the contest is about the App Server. They are on completely different networks and they dont communicate with each other.
hero member
Activity: 574
Merit: 500
Is it 104.28.3.120 ??
full member
Activity: 168
Merit: 100
$3000 is a lot of money, no doubt someone here is gonna hack your server to pieces Wink

Only thing I don't understand is why you would do this, unless you're a mult-millionare or 100% confident it won't be hacked. Could hire a security expert for $3000 to make your site rock solid instead.

We hope someone hacks the server and tells us exactly. We have even made it easy for people as if no one is able to find the IP address of the server, we will give it away. Theoretically, if no one finds the IP, they cant hack but in the worst case scenario that someone finds the IP and tries to hack, we are simulating that event by giving away the IP. And ofcourse we are confident and ofcourse we had pen test done and ofcourse to your other comment.

Moreover who says that hackers are not security consultants specially when we can have multiple for only $3000???

Also, shouldn't we do everything possible to ensure that customer funds are always safe with us??? Do you really want another example of a Bitcoin Service getting Hacked?
full member
Activity: 168
Merit: 100
Hello Guys. Just to inform everyone that the contest is now Live. We wish all the testers good luck.
full member
Activity: 168
Merit: 100
Furthermore:
Who knows you maybe just hacked their email and now start such a contest that others hack their server?


The Contest is on our website also. Be rest assured that we are not hacked yet on this forum and also an official press release is going out today.

Are you willing to escrow the prize?

Regarding escrow, Escrow would make sense if we want to hide our identity or if we are an individual. We are a part of a big group. Moreover, the first part of the challenge is $200. Do you want me to put $200 in escrow? Moreover, we will not destroy our reputation for only $3000 when we have alot more invested in this venture.
hero member
Activity: 482
Merit: 500
LAUNDER BITCOIN: https://BitLaunder.com
Are you willing to escrow the prize?

First, this is completely legal and there is no threat to anyone hacking as Amazon will not go after them, its the company who has rented the server goes after people who hack. In this case, we are the company.


Its not that easy in every country.
In the act of hacking you also use other infrastructure than just your server.

Furthermore:
Who knows you maybe just hacked their email and now start such a contest that others hack their server?

I don't say you guys are bad.
Its just not well prepared to rule out all concerns and problems.
1/3 of the bounty for a lawyer starting that contest and 2/3 as a price would also have been a good choice.


He already have control of the website. http://www.nuovocard.com/hacking-challenge/
full member
Activity: 168
Merit: 100
[email protected]

Doesn't reply.  tried on normal email app, and telnet .. nothing

Yeah...will reply on 15th when the contest starts.
member
Activity: 98
Merit: 10
[email protected]

Doesn't reply.  tried on normal email app, and telnet .. nothing
full member
Activity: 168
Merit: 100
The challenge is announced 3 days before just to answer all the queries so that people can get to work on the day it starts.

1. How you describe the task is not in any case clearly and therefore a bit confusing.
The first reactions in form of posts already shows it.

2. I have strong legal concerns about this "promotional campaign" especially regarding my 1. point.
People may try to hack the wrong infrastructure despite the fact if the try itself is legal or not in their country.
In germany for example I doubt that it is possible to take part without breaking the law.
If someone now probably tries to hack Amazon then and gets jailed because of taking part in your contest you are probably also responsible for that.
I guess you don't own an own datacenter. Is the datacenter informed about this?

-> I don't feel this contest is very well prepared at the moment and I would not start it under these circumstances.


First, this is completely legal and there is no threat to anyone hacking as Amazon will not go after them, its the company who has rented the server goes after people who hack. In this case, we are the company.

Secondly, I made it very clear on how to communicate with the server


To communicate with the server and check if its running or not, send an email to [email protected] with Subject 'Transfer'. The server will send you an email back with a transaction hash for an instant transaction in the amount of 0.0001 BTC to mrm4AN6uAExNgXbRtqVL5tA4RmVxR2QtMa.


This is the only way to communicate and try to find the IP which is the first step. After this, its upto you. Doing a DOS attack does not make sense as you need to get into the server and its not like we are trying to prevent you that you need to block our access. Also, all ports are closed other than the ports that the app opens and closes automatically. Just to help everyone out, that port range is 32768-61000.

If you wish to try without using our server, I would advise you to setup your own server and I will provide a simple Jar that can talk to gmail. You can do this in your own house and then send us instructions on how to hack and if it works, you win.

Also, there are a couple of firewalls in place before the server, we will test your method with the firewalls and without your firewalls and award you full amount if you break with the firewalls. If your instruction leads to a hack without the firewalls, we will award you $1000. If you anyone wants to try it this way, let me know and I will reveal the server configuration after the part 1 is over.

Questions?
member
Activity: 98
Merit: 10
full member
Activity: 168
Merit: 100
My IP guess: 199.241.30.125

This is not the IP.


To be absolutely correct, your bitcoind is on application server?



Yes. The Application Server will have:-

1. Bitcoind
2. Armoryd
3. Java App
4. Tor Client

Database Server - Mysql 5.6
Pages:
Jump to: