Password Scraper Hackers

in password •  7 years ago  (edited)


Source

These types of hackers are referred to as "scrapers" or "trawlers" as what they do is search the blockchain for users who accidentally pasted their passwords somewhere. They look for wallet transfer memos, plain text, or even accidental pastes in chat. This is all they do because it's easy and profitable.

Known Accounts

These are the accounts belonging to (either through registration or permanent transfer) to the hackers:

@chumah

@myperspectives

@sami100

These hackers have other accounts. The actual account does not matter. They don't post on the accounts or use them to spam, they just transfer money around through them.

If you see a transfer of your SBD/STEEM to those accounts, it means you've revealed your password (master key) and they have taken possession of your account as a result.

Information Posts (in this series)

Read these posts to understand how to recover your account.

https://steemit.com/phishing/@guiltyparties/phishing-warning-2-0
https://steemit.com/phishing/@guiltyparties/phishing-messages-faq
https://steemit.com/security/@steemcleaners/phishing-attacks-and-recovery

Additional Post-Recovery Steps

Make sure you revoke all posting roles. Third party applications retain your posting authority even after the password is changed. Hackers, who still have your original password and keys, may continue to use them to spam the blockchain from your account.

Check

To check if you have any apps that have been granted authority, take a look at your steemd page. On the left side you'll see something that looks like this:

Revoke

Log into steemconnect here: https://v2.steemconnect.com/login

Put in your username and the posting key:

You will get something that looks like this:

Click "Revoke" and refresh your steemd page to make sure the transaction went through. You can re-add the third party apps later as you need to.


Like what we're doing? Support us as a Witness.
Go to https://steemit.com/~witnesses
At the bottom, type in guiltyparties
Click VOTE


Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Wawwww great....

I have my account back and am certainly thankful for all you have done @guilyparties and for all this info. I'll be busy today making everything more secure!

💕 ​Welcome back melinda010100❣ We all missed you ❤
Thank you @guiltyparties for helping her back!! 👍👍👍

I can't tell you how good it is to be here! Thanks, @shasta!

  ·  7 years ago (edited)

Thanks, yeah like that. We nuke them pretty fast until the accounts are recovered.

sorry iam see so late now i want recovered my id u help me

Thanks for the information friend, can I translate this post into Spanish?

Yeah man go ahead.

Do you think it would help to generate a bunch of fake keys in some posts in order to waste the resources of these scrapers by flooding them with bad information? I'm assuming it's an algorithm based on formatting so it would probably not analyze non-key parts of a message to determine it's authenticity. I would also imagine eventually they would get smart and notice and have to build in extra logic to look for this but at least make them work for it right?

You can try but its a waste of time for you too. It'll create a lot of reports by people who see the keys unfortunately.

Thank you for your continued support of SteemSilverGold

Passed this on a couple different places my man.

I hope Melinda and others get their account back since they used account recovery - sure @andrarchy is working on this

It is such a relief to have this behind me! What a stressful 4 days it has been. Turning off that powerdown felt marvelous! Thanks so much for you help!

Glad it worked in the end. Steem On

Resteemed, keep it up man.

Gracias por esta excelente información. Es por esto que mereces ser apoyado como testigo, por tu duro trabajo a favor de otros aquí en Steemit.

Thanks for posting as many arent aware of this