Pages:
Author

Topic: Openex hacked but coins recovered - page 8. (Read 14287 times)

legendary
Activity: 2321
Merit: 1292
Encrypted Money, Baby!
January 14, 2014, 09:22:43 AM
I don't see how these people even get servers running. On tutorial sites I've seen comments such as "do I also type in the eg."

It also bothers me the elite developers keep inventing new crap like nodejs when we haven't learned the simplest of things.
Sorry, but that's nonsense. There's enough people understanding node.js and i can assure you that.
Also, i would consider someone who needs to visit tutorial sites being not in a good position to actually run a server.

Don't get me wrong, but it's not just about stolen Bitcoin, it's also about all those hundreds of thousands of spam machines who are all run by some kids who "can i haz server, pls?", which require me (and others) to constantly setup and finetune spam filters, watch spam folders and crap because they're just not able to secure a machine.
If people want to play, no problem. There's plenty of server software you can run on your local machine to try and test and become a pro one day. But please, keep the internet clean from those sloppily setup machines who bring a hell of an effort if they're being compromised again.

By the way, this is one of the points which literally cry for a regulation!
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 09:22:13 AM
Sorry to hear this happened r3wt Sad

Yeah me too. back to the drawing board once more.
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 09:20:43 AM
I was hoping things would go well for this exchange since it was open source. but having it open source before security auditing may have given some clue about its insecurity unfortunately. hope you will have better luck next time or at least hire someone reputable to help with security.

also, I was wondering if username/passwords where stolen, or any other coins? was the hack only affecting btc wallet?

0.14203175btc @ 1PFo41TnkogkD1DJWxFwMWc5ShMn1tJxhN

whoever it was only in the server for 6 minutes before i found out.

we do not know, but as a precaution we are having everyone withdraw all coins. database will be completely wiped, along with wallet.dats and conf files. have to start over from scratch. who knows what they took while they were in there.

Sorry to insist, but as I can see you will delete the entire database and wallet, what about pending DEPOSITS ? I'd be happy to withdraw my money but I can't.
0.02569114 BTC - Deposit address at the time : 1A4LKQVr4r7WgG3rTYMBfDrM4qhpRU6ufR. But you changed that address since then so don't know it this will be of any help...


I will be happy to help you phil. let me know the details via pm.
legendary
Activity: 1344
Merit: 1000
January 14, 2014, 09:18:41 AM
It's better to have bad things at start, rather than when you are operating 500 btc-s.
And yeah, shit happens.
newbie
Activity: 47
Merit: 0
January 14, 2014, 09:17:55 AM
I was hoping things would go well for this exchange since it was open source. but having it open source before security auditing may have given some clue about its insecurity unfortunately. hope you will have better luck next time or at least hire someone reputable to help with security.

also, I was wondering if username/passwords where stolen, or any other coins? was the hack only affecting btc wallet?

0.14203175btc @ 1PFo41TnkogkD1DJWxFwMWc5ShMn1tJxhN

whoever it was only in the server for 6 minutes before i found out.

we do not know, but as a precaution we are having everyone withdraw all coins. database will be completely wiped, along with wallet.dats and conf files. have to start over from scratch. who knows what they took while they were in there.

Sorry to insist, but as I can see you will delete the entire database and wallet, what about pending DEPOSITS ? I'd be happy to withdraw my money but I can't.
0.02569114 BTC - Deposit address at the time : 1A4LKQVr4r7WgG3rTYMBfDrM4qhpRU6ufR. But you changed that address since then so don't know it this will be of any help...
full member
Activity: 168
Merit: 100
legendary
Activity: 1596
Merit: 1010
January 14, 2014, 09:11:11 AM
Sorry to hear this happened r3wt Sad
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 09:10:42 AM
I was hoping things would go well for this exchange since it was open source. but having it open source before security auditing may have given some clue about its insecurity unfortunately. hope you will have better luck next time or at least hire someone reputable to help with security.

also, I was wondering if username/passwords where stolen, or any other coins? was the hack only affecting btc wallet?

0.14203175btc @ 1PFo41TnkogkD1DJWxFwMWc5ShMn1tJxhN

whoever it was only in the server for 6 minutes before i found out.

we do not know, but as a precaution we are having everyone withdraw all coins. database will be completely wiped, along with wallet.dats and conf files. have to start over from scratch. who knows what they took while they were in there.
newbie
Activity: 9
Merit: 0
January 14, 2014, 09:08:25 AM
I pay a bounty of 1'000 BinaryCoin (BIC) to someone where find this very poor burglar and take him to justice.

I hope that the developer will continue his work. He made a nice open source exchange!
sr. member
Activity: 274
Merit: 254
January 14, 2014, 09:04:46 AM
I was hoping things would go well for this exchange since it was open source. but having it open source before security auditing may have given some clue about its insecurity unfortunately. hope you will have better luck next time or at least hire someone reputable to help with security.

also, I was wondering if username/passwords where stolen, or any other coins? was the hack only affecting btc wallet?

0.14203175btc @ 1PFo41TnkogkD1DJWxFwMWc5ShMn1tJxhN
full member
Activity: 148
Merit: 100
January 14, 2014, 09:04:00 AM
Smiley
full member
Activity: 153
Merit: 100
January 14, 2014, 08:58:08 AM
Give the guy a break. He messed up. And he confessed it. I know others who would have kept it silent until complete crash or recover. Others might have just disappeared.
He may not be a security guru, but his site is working. Not a noob as I would call it. And whoever is keeping lots of funds on an exchange site is a fool. Not saying he shouldn't do something about it: I guess he had his lesson.
@Coinmaster: at last a constructive message. Smiley
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 08:56:32 AM
1) non-standard port
2) no root login
3) ssh key entry only
4) iptables ip restriction
This was posted earlier in the thread.  If you insist on running an exchange at this point in time, I would suggest setting the 'ip address restriction'.  This means no ssh connections can be made to your server from any ip address that is not permitted.  It is not 100% fool proof as your ISP could launch an attack on your server by spoofing your permitted ip addresses.  This is extremely unlikely, but a possibility.  Doing this one thing would likely prevent any future compromises.

i have read a few tutorials on the subject and after discussing with Justin, we have chosen to do the smart thing and have contacted a professional server administrator. he's not cheap but he's agreed to help us get it secured as much as humanly is possible, with the notion that we would hire him full or part time once we can afford it.
full member
Activity: 148
Merit: 100
January 14, 2014, 08:54:05 AM
1) non-standard port
2) no root login
3) ssh key entry only
4) iptables ip restriction
This was posted earlier in the thread.  If you insist on running an exchange at this point in time, I would suggest setting an 'ip address restriction'.
This means no ssh connections can be made to your server from any ip address that is not permitted.  It is not 100% fool proof as your ISP could launch an attack on your server by spoofing your permitted ip addresses.  This is extremely unlikely, but a possibility.  Doing this one thing would likely prevent any future compromises.
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 08:46:43 AM
last time i checked, experience > exams
Would you try flying a plane without a license, without taking exams to determine you are capable and competent.  I hope not.

the loudest voice in the room is often the weakest


You are a dangerous man r3wt! (probably more like reckless actually)

i got the gist of it without the parenthesis

OMG stop responding to comments here and solve our deposits/withdrawals issues on the website !!!

what, i'm not allowed to multitask?
newbie
Activity: 47
Merit: 0
January 14, 2014, 08:45:14 AM
last time i checked, experience > exams
Would you try flying a plane without a license, without taking exams to determine you are capable and competent.  I hope not.

the loudest voice in the room is often the weakest


You are a dangerous man r3wt! (probably more like reckless actually)

i got the gist of it without the parenthesis

OMG stop responding to comments here and solve our deposits/withdrawals issues on the website !!!
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 08:43:55 AM
last time i checked, experience > exams
Would you try flying a plane without a license, without taking exams to determine you are capable and competent.  I hope not.

the loudest voice in the room is often the weakest


You are a dangerous man r3wt! (probably more like reckless actually)

i got the gist of it without the parenthesis
full member
Activity: 148
Merit: 100
January 14, 2014, 08:38:11 AM
last time i checked, experience > exams
Would you try flying a plane without a license, without taking exams to determine you are capable and competent.  I hope not.

the loudest voice in the room is often the weakest


You are a dangerous man r3wt! (probably more like reckless actually)
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 08:37:45 AM
it's my first server, doesn't mean i'm incapable of learning i just don't know because i'm not experienced. maybe i'll find someone who is and hire them to teach me how to properly secure the server.
That in itself is scary.  Security is ongoing, when you say "properly secure the server" you imply that at some point the job is done.  You should not be running a server that has other peoples money stored on it.  My advice would be to get some qualifications first.

thanks for your advice. everyone can learn. you are wrong.

There are no "properly secure the server". Securing a server is a cyclic task with continuous risk assessment, fine tuning your systems and admin procedures, searching for vulnerabilities and fixing them. Perhaps you should take a look at ISO 27001.

I was gonna be sarcastic here, but what the hell. thank you for your informative post.
hero member
Activity: 686
Merit: 504
always the student, never the master.
January 14, 2014, 08:32:57 AM
last time i checked, experience > exams
Would you try flying a plane without a license, without taking exams to determine you are capable and competent.  I hope not.

the loudest voice in the room is often the weakest

Pages:
Jump to: