How I figured out I was hacked and withdrew 3047 Steem… with minutes to spare

in the-hack •  8 years ago 


From my understanding the hack was initiated through some kind of XSS attack, which is a browser based hidden code that enabled the hacker to swipe the keys being used   

We could go into detail about the technicalities of what that means but in a more general sense it was a basically a hacker STD. Yep a sexually transmitted hacker disease!   

When you interacted with a hacked users post, by up/down voting or commenting you would give away the keys to your account.   

They would then empty your account and post under your name, hiding the secret hacker STD code and infect other users.   

This could have gotten way out of control. But the developers shut it down before some serious damage could be done.     

How did I figure it out before I could be drained?.... I was incredibly lucky.            


Someone mentioned that there was a hack going on in the slack, referencing a @dantheman post. So I was already on guard and looking for things that seemed out of place.    

I viewed this post by @dantheman.   

It's been edited now, but it was very out of character, I downvoted it because it looked like someone else was using his account.    

I then went to look at Bittrex to see what was going on and I realized that the hack could have potentially been site wide.   

I noticed that the memos (the text in red) were the same for several accounts. I also knew from reading @complexring and @samupaha s posts and interacting on Slack that they were not the same person.  

Going back to the @dantheman post I noticed that some of those names had interacted with the post and some of the downvotes had been removed. So I removed mine - I think I was already hacked at this point.            

I then initiated the transfer out with minutes to spare...


   

I was probably one of the last accounts to be hacked before the site shut down to contain it, I was lucky to have access to more information than most of the other accounts.                   

I was just using my master password for everything, it was 30 characters long and completely random. It wasn't enough safety.   

Now, with the help of a few articles….   

Can you remember your Steemit password? If so, you are in danger.

by @arhag

Steemit - Security - Exchanges & Why - By a guy that has been in Crypto since 2009 - [NEW PEOPLE - READ THIS NOW]

by @fyrstikken

…I'm signed into my account with my posting key   

My master password is now 100+ characters long of completely random characters and symbols. I use a password manager.     

When I want to initiate a transfer of Steem or Steem Dollars I'll use my active key to do so and then quickly log in again with my posting key. I will NOT interact with any posts in this time.   

The particular hack that came about, I believe has been patched. 

...Will there be more holes in the future?...    

...most likely, but if I use a posting key for posts and votes and then using my active key solely for transferring I will likely be much better protected from any similar hacks in the future.   

I was lucky. Really lucky.   

If you've been procrastinating setting up your security then get on it now! The posts above will help you figure it out.    

If thats not enough... read this recent post from @cass

Compromised account @katecloud

and this whitehat (friendly hacker) hack from @robinhood - who managed to break the passwords of around 500 accounts

Offline Attack on Steem User Credentials

Wake the fuck up and get it sorted! 

The guides above will help you sort it out. It basically comes down to picking a ridiculously long master password, taking note of your private keys in the permissions section and then just using your private posting key for day to day use.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

I'm probably being dense - but could Steemit prevent future hacks by preventing people putting XSS (whatever that is) on their posts?

Not sure of the technicalities, but it seems like these sort of attacks are always a vulnerability. Especially with such an obvious target on Steemits back. I think the developers will sort something out in the future, over time.

No, it's a trojan script in the HTML web pages you load on Steemit. Dan had a post where he said you cannot stop it, one can only minimize it. The whales are safe because they use the CLI steemd to do money transfers, not the web site. I won't feel safe until I'm using CLI steemd for everything.

An STHD haha. Thanks for the tips! And in the long run hopefully the response to this attack will make future attacks less likely.

Haha, I hope so too.

I joined up right after the hack. Glad I wasn't here for that, but I have to say - good eye. This is the kind of information that's handy for us all in the future should something similar happen again.

Hopefully the steps taken will sort it all out. The recovery option and having another user or third party available to confirm your identity should help. You should however make sure to use your posting key so your account can be recovered before any liquid funds are transferred.

Damn worried about hackers on here lol, good on you for looking out for this stuff. any chance you know how to put separate password for owner, can't seem to change anything in preferences.

Click your photo in the top right, go to permissions. Then click 'change password'.

After that create a huge random password and store it in a password manager.

Take note of your private keys by making them visible.

Login with your name/posting and then the private posting key as your password. Only use your posting key in day to day use then use your owner account when you want to make transfers.

Security must be a key element at steemit if we want it to success, thank you very much for share this really usefull info

  ·  8 years ago (edited)

Excellent info and links and definitely a wake up call. I thought my password was quite good - maybe for everyday usage but certainly not for this site. There is no way I would have spotted everything you did so I'll be following the tips and sorting out my security.

I was just lucky, I had access to more info than the accounts that were hacked before me. I was hoping to get this kind of response, so thanks for commenting!

Thanks for this. All users here must understand that you must be careful about the posts you interact with and you must be smart about passwords. I continue to think privacy on Steemit is a big problem, but its encouraging to know the dev team is working on it https://steemit.com/steemit/@ntomaino/does-the-steem-community-care-about-privacy

But

Yep, good to see @dan responded. I was thinking almost a separate account would have to be made to hide any liquid funds, however his option seems like a good one.

That's some freaky stuff man! Do you have password managers that you'd recommend for new Steemians?

  ·  8 years ago (edited)

strongly recommend 1password

I use SafeinCloud, it's a one time low payment to get full access and it syncs with my phone with a fingerprint password. Some of the other managers ask for like $30 a year. I also use Roboform on my desktop, I'd recommend both.

I buy Ethereum and hackers attack the DAO. I buy steem and hackers attack Steemit. I am a Jinx

Haha, it's always going to happen. Sometimes you have to get slapped down to really take a good look at security. In the case of the DAO and the Steemit hack... security didn't do much they still got hacked. I'll be keeping a much more vigilant eye on how to be secure in the future. You'd think after losing money with MtGox and Cryptsy I'd have sorted it out by now... we always have something to learn.

This is a very good summation. Thank you for this post. It does save a lot of trying to wade through the influx of posts.

Thanks. I think the main point of me posting was to rally up some people to take action. Even though I was quick enough to react, even though I had a secure password... I was still hacked. It doesn't take much time, get your security sorted.

I was lucky enough to have survived. But I didn't have anything to lose as well as I literally joined the day before!! Anyways the Steemit team did a really nice job of containing it.

Yep. Get onto securing your account now. It's a few minutes of your time and you'll feel much better once you've done it.

yeah did that as well! I have GOT to stop procrastinating on things!! LOL

haha! Good stuff!

I finally stumbled on real, complete and interesting article! Good job!That's what I personaly would like to read

Great to warn everyone out there! Thanks a lot for this :)