Skip to main content

BitCoin forum hacked by donor

posted onSeptember 12, 2011
by l33tdawg

A hacker has used a zero day flaw to steal email addresses, hashed passwords and read personal messages from the bitcointalk.org forum.

Forum administrators said the attacker gained root access and was able to run arbitrary PHP code. The attacker gained access on 3 September and was not detected until the attacker injected "annoying JavaScript" into the forum pages a week later.

The forum was shut down and migrated to a new host. The attacker launched a SQL injection to exploit a vulnerability that existed because the forum software did not handle escape characters in username details correctly. The attacker purchased a donor account to gain the access privileges required to illegitimately change usernames, then hijacked the account of administrator Satoshi.

Source

Tags

BitCoin Hackers

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th