BitCoin forum hacked by donor

Powered by SC Magazine
 

Spruiks CosbyCoins?

Update: A hacker has used a zero day flaw to steal email addresses, hashed passwords and read personal messages from the bitcointalk.org forum.

Forum administrators said the attacker gained root access and was able to run arbitrary PHP code.

The attacker gained access on 3 September and was not detected until the attacker injected "annoying JavaScript" into the forum pages a week later.

According to website buttcoin.org, the Javascript splashed actor Bill Cosby across the forums and replaced all references to BitCoin with CosbyCoin.

It has posted screenshots of the hack.

The forum was shut down and migrated to a new host.

The attacker launched a SQL injection to exploit a vulnerability that existed because the forum software did not handle escape characters in username details correctly.

The attacker purchased a donor account to gain the access privileges required to illegitimately change usernames, then hijacked the account of administrator Satoshi.

From there, the attacker injected arbitrary PHP code into the site by modifying a style template.

Bitcointalk identified a series of compromised accounts and IP addresses that appeared to be used in  the attacks.

Passwords were hashed with the popular SHA-1 function and salted by combining them with usernames -- an ineffective method used by the Simple Machines Forum software.

"It is not known for sure that the attacker copied any password hashes, but it should be assumed that he did," administrators said.

Administrators urged users to change passwords and be alert to BitCoin-related phishing scams.

"Change your password. If you used the same password on any other sites, you should change the password on those sites as well," they advised.

BitCoin is a digital, peer-to-peer currency that can be traded for national currencies – including those of the US, Poland, Britain and the European Union – via various online exchanges.

Earlier this year, more than 61,000 usernames, email addresses and hashed passwords were stolen from the popular BitCoin exchange Mt.Gox.

Copyright © SC Magazine, Australia


BitCoin forum hacked by donor
 
 
 
Top Stories
Meet FABACUS, Westpac's first computer
GE225 operators celebrate gold anniversary.
 
NSW Govt gets ready to throw out the floppy disks
[Opinion] Dominic Perrottet says its time for government to catch up.
 
iiNet facing new copyright battle with Hollywood
Fighting to protect customer details.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  26%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  15%
 
Software development
  26%
TOTAL VOTES: 335

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  57%
 
No
  43%
TOTAL VOTES: 139

Vote