Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
We sadly need to announce that our wallet has been compromised thus DO NOT send any further funds to any of the coin wallets, BTC, DVC, LTC, etc. We will setup a new wallet and reset all the addresses. This will most likely take the whole weekend.
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Ouch, good luck with it. Bitcoin central's down too, looks like someone's being a pain in the ass.
Image may be NSFW. Clik here to view.
Logged
julz: "Susanne Posel's unwitting work in shepherding the dumbest of the dumb away from Bitcoin is a great benefit to the community, for which we should all be grateful."
Posted an announcement regarding this at Important Announcements subforum.
Image may be NSFW. Clik here to view.
Logged
My BTC Tip Jar: 1NB1KFnFqnP3WSDZQrWV3pfmph5fWRyadz My GPG key ID: B3AAEEB0 My OTC ID: johnthedong Free escrow service available - tips appreciated! (PM Me)
Full Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
Further update: The system was not breached, no passwords were compromised (they are salted and multiple times hashed anyways). The attacker used a RubyOnRails vulnerability that was released yesterday (http://www.exploit-db.com/exploits/24019/) to withdraw the funds therefore.
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Further update: The system was not breached, no passwords were compromised (they are salted and multiple times hashed anyways). The attacker used a RubyOnRails vulnerability that was released yesterday (http://www.exploit-db.com/exploits/24019/) to withdraw the funds therefore.
Sorry for your lose.
Amm ... the RoR volnurability was posted to multiple large forums, including Slashdot.
Did the attacker see the announcement before you were able to realize it affects you and shut off your systems? How come you missed it for so long that you didn't shut your stuff off / upgrade in time?
Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
Staff
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Ouch, good luck with it. Bitcoin central's down too, looks like someone's being a pain in the ass.
That's just scheduled maintenanceImage may be NSFW. Clik here to view. We deployed the fixes within five minutes after receiving the notification from the Rails security mailing list.
Image may be NSFW. Clik here to view.
Logged
Buy and sell EUR at Bitcoin-Central.net. Also check-out Instawallet and Instawire, don't need to sign-up to anything! -- The problem with the French, is that they don't even have a word for entrepreneur
Staff
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Buy and sell EUR at Bitcoin-Central.net. Also check-out Instawallet and Instawire, don't need to sign-up to anything! -- The problem with the French, is that they don't even have a word for entrepreneur
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
Staff
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Service restored: deposits, trading and withdrawals are working again
Did you switch servers ?
Image may be NSFW. Clik here to view.
Logged
Buy and sell EUR at Bitcoin-Central.net. Also check-out Instawallet and Instawire, don't need to sign-up to anything! -- The problem with the French, is that they don't even have a word for entrepreneur
Sr. Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
No we did not switch servers, we: - applied the Ruby Rails patch - backed up all log files for further analysis - log files show the XML code injection, we validated all triggered commands to ensure nothing other than withdrawing funds (e.g. backdoor) was done.
2AM here, will need to catch some sleep, mistakes are easily made when being too tired.
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Online
Hero Member Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view.Image may be NSFW. Clik here to view. Image may be NSFW. Clik here to view. Offline
I'm not sure if I feel worse for bitcoin, vicurex, the people with funds there, or ruby on rails.
Image may be NSFW. Clik here to view.
Logged
TorGuard VPN: Don't get caught using Bittorrent! Spend your bitcoins on a topnotch VPN/Proxy service! I'm renewing my subscription again later this year.