create account

WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution by positive

View this thread on: hive.blogpeakd.comecency.com
· @positive · (edited)
$15.49
WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution
<html>
<p>As far as I can see this hack (rather exploit) has not been prevented, but <strong>if I'm wrong</strong> <strong>please let me know in the comments.</strong></p>
<p><br></p>
<p>I'm mentioning this hack because it was <strong>extremely effective on /r/giftcardexchange</strong></p>
<p><br></p>
<p>And <strong>people have already made this mistake.</strong></p>
<p><br></p>
<h3>The Hack</h3>
<p>1. Buy a reddit account on http://www.redditsecrets.com/buy-reddit-accounts or elsewhere</p>
<p>2. Open an account with a modification of the username bittrex, e.g. bittrrex, bitrrex which haven't yet been taken etc.</p>
<p>3. Wait for people to make mistakes, withdraw when they do, with a large enough sample size you can bet someone will.</p>
<p><br></p>
<p><em>This can be applied </em><em><strong>even more successfully</strong></em><em> with permutations of </em><em><strong>@openledger's name</strong></em></p>
<p><br></p>
<h3>How likely is this to happen?</h3>
<p><br></p>
<p>There is a user @bitrex with whom <strong>people have already apparently made the mistake</strong> and with whom <strong>they apparently continue to make this mistake:</strong></p>
<p>https://s32.postimg.org/7ov5beszp/exploit.png</p>
<p><br></p>
<p>Thanks @venuspcs for bringing it to my attention that it is probably already happening with @poloniex fake accounts.</p>
<p>@polonix @ploniex</p>
<h3>As more people use Steemit the probability of such a mistake occurring will tend to 1.</h3>
<p><br></p>
<h3>How to avoid this</h3>
<p><br></p>
<p>- <strong>Auto fill forms, or perhaps a two layered input prompting users to select whether to send to "user" or "exchange", then drop down menu for exchanges. Many possible similar approaches.</strong></p>
<p><strong>- Users can systematically copy and paste bittrex (and other exchange's names) instead of typing them from memory.</strong></p>
<p><br></p>
<p><strong>#steemit #hack #money #security</strong></p>
<p><br></p>
</html>
👍  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,
properties (23)
authorpositive
permlinkwarning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution
categorysteemit
json_metadata{"tags":["steemit","steem","hack","money","security"],"users":["openledger","bitrex","venuspcs","poloniex","polonix","ploniex"],"image":["https://s32.postimg.org/7ov5beszp/exploit.png"],"links":["http://www.redditsecrets.com/buy-reddit-accounts"]}
created2016-07-20 01:08:48
last_update2016-07-20 07:19:24
depth0
children21
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value13.766 HBD
curator_payout_value1.726 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,965
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,150
net_rshares4,321,304,835,369
author_curate_reward""
vote details (53)
@alexgr ·
$0.04
In a decentralized protocol, how can the creator take control of an account? It's, in a way, the right of the guy to create a bitrex account to steal money - even if it's unethical. What could be done, perhaps, is to mitigate this strategy by tampering the user interface in the online web wallet. Say one tries to enter "bitrex" in the field. Then a message comes out and says "bitrex is a known scam account. Perhaps you meant bittrex - the online currency exchange?" - or something to that effect....
👍  , , ,
properties (23)
authoralexgr
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t013234986z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:32:36
last_update2016-07-20 01:32:36
depth1
children1
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.038 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length503
author_reputation45,645,291,230,585
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,628
net_rshares23,835,816,224
author_curate_reward""
vote details (4)
@positive ·
Yes, a better approach, I agree. By take control I meant create it.
👍  
properties (23)
authorpositive
permlinkre-alexgr-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t013537072z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:35:39
last_update2016-07-20 01:35:39
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length67
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,703
net_rshares3,661,680,528
author_curate_reward""
vote details (1)
@arcaneinfo ·
http://wipeoutmarketing.com/wp-content/uploads/2010/08/WipeOut-Marketing-To-Be-The-Man-SEO.jpg
👍  ,
properties (23)
authorarcaneinfo
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t012519705z
categorysteemit
json_metadata{"tags":["steemit"],"image":["http://wipeoutmarketing.com/wp-content/uploads/2010/08/WipeOut-Marketing-To-Be-The-Man-SEO.jpg"]}
created2016-07-20 01:25:18
last_update2016-07-20 01:25:18
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length94
author_reputation14,902,978,467,172
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,503
net_rshares2,825,572,593
author_curate_reward""
vote details (2)
@bola ·
Good to know ◕ ‿ ◕, good job.
👍  
properties (23)
authorbola
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t011224488z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:12:12
last_update2016-07-20 01:12:12
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length29
author_reputation51,245,914,991,562
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,225
net_rshares8,519,960
author_curate_reward""
vote details (1)
@calamus056 ·
It's not an exploit, it's just disgusting human behavior if they keep the money.
properties (22)
authorcalamus056
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t025642618z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 02:57:33
last_update2016-07-20 02:57:33
depth1
children1
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length80
author_reputation5,645,464,390,253
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id207,457
net_rshares0
@positive ·
Well it is, in the strict sense, security measures haven't been implemented to prevent this from being a problem. Perhaps vulnerability is more accurate. Pretty easy to prevent.
properties (22)
authorpositive
permlinkre-calamus056-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t054042453z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 05:40:45
last_update2016-07-20 05:40:45
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length177
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id210,528
net_rshares0
@cryptorune ·
You can tell from the image he sent it back
properties (22)
authorcryptorune
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t013622684z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:36:24
last_update2016-07-20 01:36:24
depth1
children1
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length43
author_reputation1,658,558,670,598
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,719
net_rshares0
@positive ·
I'm John I like to scam, so I'm keeping it.

See what I mean?
👍  
properties (23)
authorpositive
permlinkre-cryptorune-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t014222770z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:42:27
last_update2016-07-20 01:42:27
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length61
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,863
net_rshares3,661,680,528
author_curate_reward""
vote details (1)
@getssidetracked ·
Good post! Another way that would help from this happening would be if it has saved the usernames you usually send to, so the correct one appears like the auto-fill on google when you type the first letters.
👍  
properties (23)
authorgetssidetracked
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t024007736z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 02:40:12
last_update2016-07-20 02:40:12
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length207
author_reputation4,066,839,697,461
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id207,143
net_rshares3,838,834,630
author_curate_reward""
vote details (1)
@getssidetracked ·
I suggest you woukd remove the reddit account purchase link as it will only make it easier for the ones trying to abuse the system, I read people asking about how many upvotes you need on a reddit account to create new ones here...
properties (22)
authorgetssidetracked
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t024402502z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 02:44:06
last_update2016-07-20 02:44:06
depth1
children1
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length231
author_reputation4,066,839,697,461
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id207,207
net_rshares0
@positive ·
I know what you mean, I hoped to raise alarms by showing how easy this is, but it appears people are more interested in #introduceyourself
properties (22)
authorpositive
permlinkre-getssidetracked-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t054238612z
categorysteemit
json_metadata{"tags":["introduceyourself","steemit"]}
created2016-07-20 05:42:45
last_update2016-07-20 05:42:45
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length138
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id210,583
net_rshares0
@husamia · (edited)
I don't really understand the hack. What is the point of buying a reddit account? what you you referring to when you say people make mistakes? and what you mean make a withdrawal? you didn't really summarize. What is the the reward of this hack?
properties (22)
authorhusamia
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160731t174218980z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-31 17:42:18
last_update2016-07-31 17:42:42
depth1
children1
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length245
author_reputation195,013,962,086
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id515,415
net_rshares0
@positive ·
To withdraw money to bittrex you need to enter their name into a form. So a spelling mistake 'bitrex' for example, would send money to the wrong account.
I could create several accounts (either using cli_wallet or by buying reddit accounts), with common ways to make spelling mistakes of bittrex and poloniex. Waiting for people to make mistakes (which they have already) and accidentally send money to my account.
👍  
properties (23)
authorpositive
permlinkre-husamia-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160731t180906802z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-31 18:09:03
last_update2016-07-31 18:09:03
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length414
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id515,969
net_rshares0
author_curate_reward""
vote details (1)
@jameswoods ·
Thanks Man!
👍  
properties (23)
authorjameswoods
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t011552516z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:16:00
last_update2016-07-20 01:16:00
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length11
author_reputation-584,810,994,410
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,329
net_rshares67,562,172
author_curate_reward""
vote details (1)
@positive ·
This is extremely easy to execute and potentially incredibly lucrative, so please promote this to devs.
👍  , ,
properties (23)
authorpositive
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t014051146z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:40:54
last_update2016-07-20 01:40:54
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length103
author_reputation10,544,818,469,420
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,827
net_rshares6,719,632,971
author_curate_reward""
vote details (3)
@thedashguy ·
Quick thinkin. I like this guy.
👍  ,
properties (23)
authorthedashguy
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t013248905z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:32:48
last_update2016-07-20 01:32:48
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length31
author_reputation27,279,921,688,159
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,633
net_rshares6,858,630,809
author_curate_reward""
vote details (2)
@timotron ·
Thanks!
properties (22)
authortimotron
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t011154601z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 01:11:54
last_update2016-07-20 01:11:54
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length7
author_reputation29,119,376,074
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,217
net_rshares0
@venuspcs ·
This is already a possibility with the Poloniex exchange as well....in a quick search I found @polonex and @ploniex
👍  , ,
properties (23)
authorvenuspcs
permlinkre-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t014746925z
categorysteemit
json_metadata{"tags":["steemit"],"users":["polonex","ploniex"]}
created2016-07-20 01:47:48
last_update2016-07-20 01:47:48
depth1
children2
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length115
author_reputation30,491,473,006,755
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,976
net_rshares10,441,483,294
author_curate_reward""
vote details (3)
@getssidetracked ·
Ugh, people...
properties (22)
authorgetssidetracked
permlinkre-venuspcs-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t024443257z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 02:44:48
last_update2016-07-20 02:44:48
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length14
author_reputation4,066,839,697,461
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id207,219
net_rshares0
@getssidetracked ·
Its like taking advantage of other peoples dyslexia.
properties (22)
authorgetssidetracked
permlinkre-venuspcs-re-positive-warning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution-20160720t024533475z
categorysteemit
json_metadata{"tags":["steemit"]}
created2016-07-20 02:45:36
last_update2016-07-20 02:45:36
depth2
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length52
author_reputation4,066,839,697,461
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id207,232
net_rshares0
@weenis · (edited)
Upvoted!! 
properties (22)
authorweenis
permlinkwarning-easy-potential-social-engineering-hack-steemit-hack-temporary-solution
categorysteemit
json_metadata""
created2016-07-20 01:09:27
last_update2016-07-20 07:20:06
depth1
children0
last_payout2016-08-20 01:28:42
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length11
author_reputation-4,781,861,673,917
root_title"WARNING: Easy Potential Social Engineering Hack! #steemit -#hack + Temporary Solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id205,166
net_rshares0