Author

Topic: Wall Observer BTC/USD - Bitcoin price movement tracking & discussion - page 23650. (Read 26711650 times)

donator
Activity: 1736
Merit: 1014
Let's talk governance, lipstick, and pigs.
My ignore list is growing fast. Over 200 so far.
legendary
Activity: 2380
Merit: 1823
1CBuddyxy4FerT3hzMmi1Jz48ESzRw1ZzZ
legendary
Activity: 1554
Merit: 1014
Make Bitcoin glow with ENIAC
The future of Crypto is Bitcoin and Digibyte

What about ethereum?
full member
Activity: 224
Merit: 100
The future of Crypto is Bitcoin and Digibyte
hero member
Activity: 910
Merit: 1003
The forum got hacked by exploiting improper sanitisation of images. If I understand it right, somebody managed to upload a .php file.

Like that old piece of Unix wisdom:

  Q: How many system administrators does it take to change a light bulb?
  A: Just one, to lock the room and declare it off-limits to everybody.

legendary
Activity: 2772
Merit: 1127
Litecoin been taking a whoopin today... I think others have finally caught on, but litecoin and the alt market in general is a harbinger to the direction of bitcoin itself, because they're smaller and we see the effects quicker. This bear market is far from over, folks. We're going nowhere but down. Cut your loose.


Litcoin already in the pre october, 2013 levels.

I wonder where it will stop and if BTC will follow the same pattern
full member
Activity: 364
Merit: 102
Litecoin been taking a whoopin today... I think others have finally caught on, but litecoin and the alt market in general is a harbinger to the direction of bitcoin itself, because they're smaller and we see the effects quicker. This bear market is far from over, folks. We're going nowhere but down. Cut your loose.
legendary
Activity: 2842
Merit: 1511
Also if credit card and banks were so paranoid about security it would avoid many headaches for most of his customers and for themselves too

Seriously, someone explained why @theymos disabled avatars: because of a post out there showing that one can hide javascript in headers of image files. 

However, he must have misread that post.  It said that the hacker can post an HTML page containing a tag and put malicious javascript inside the gif file.  When victims download that page,the javascript obviously gets executed.

But the only bad thing about that is:  if an admin is trying to analyze a malicious webpage and is looking at the javascript files it downloads, he may miss that one, because its name ends in ".gif" instead of ".js", and it can even be displayed as an image (for instance, in a previous tag). 

However, that risk does not exist for this forum.  The forum's HTML pages are not served by the hacker, only by the bitcointalk server; and they will not have and put malicious javascript inside the gif file.  When victims download that page,the javascript obviously gets executed.

But the only bad thing about that is:  if an admin is trying to analyze a malicious webpage and is looking at the javascript files it downloads, he may miss that one, because its name ends in ".gif" instead of ".js", and it can even be displayed as an image (for instance, in a previous tag). 

However, that risk does not exist for this forum.  The forum's HTML pages are not served by the hacker, only by the bitcointalk server; and they will not have