Archive

Archive for the ‘General’ Category

Mt Gox hacked, or you’re only as secure as the sites you give your information to.

June 19th, 2011

Mt Gox was a place to exchange curency for bitcoin, specifically American dollars. The site recently got hacked and the bitcoin exchange rate has plummeted (and from what I hear, currently frozen). If you’ve ever used the site, and use the same / similar password everywhere consider changing it (and for Pete’s sake not using the same password everywhere).

I’ve downloaded a copy of the Mt Gox DB and I was indeed in the list. The data consists only of: userid, user handle, email address, and password hash.

I’ve done a reverse hash lookup, and confirmed it’s not a basic sha1 or md5. From the official “hacked” email the admins of Mt Gox say it’s using “freeBSD MD5 salted hashing”, though some older accounts may be simple md5.

There are 61,000+ records in the db I’ve downloaded. If anybody wants me to check if they’re on there let me know. My gmail
has already requested that I change my password so I’m guessing brute force attacks are occurring.

Mauvis Ledford General