Tag Archive for: Hosted

Website for storing digital currencies hosted code with a sneaky backdoor

Website for storing digital currencies hosted code with a sneaky backdoor

(credit: NoHoDamon / Flickr)

A website that bills itself as providing a safer way to store Bitcoin and other digital currencies has been using a coding sleight of hand to generate private keys that are suspiciously trivial for the operators to guess, leaving all funds stored in the wallets open to theft, researchers with a different service said on Friday.

WalletGenerator.net provides code for creating what are known as paper wallets for 197 different cryptocurrencies. Paper wallets were once billed as a secure way to store digital coins because—in theory, at least—the private keys that unlock the wallets are stored on paper, rather than on an Internet-connected device that can be hacked. (In reality, paper wallets are open to hack for a variety of reasons.) While the site advises people to download the code from this Github page and run it while the computer is unplugged from the Internet, it also hosted a simpler, stand-alone service above all the instructions for generating the same wallets.

Researchers from MyCrypto, which provides an open-source tool for cryptocurrency and blockchain users, compared the code hosted on Github and WalletGenerator.net and found some striking differences. Sometime between August 17 and August 25 of last year, the WalletGenerator.net code was changed to alter the way it produced the random numbers that are crucial for private keys to be secure.

Read 13 remaining paragraphs | Comments

Biz & IT – Ars Technica

Remotely hosted objects used to spread Formbook malware

  1. Remotely hosted objects used to spread Formbook malware  SC Magazine
  2. New Distribution Method Makes FormBook Malware More Insidious  http://totalsecuritydailyadvisor.blr.com/ (press release) (blog)
  3. Full coverage

malware news – read more

Cryptocurrency Mining Malware Hosted in Amazon S3 Bucket – Threatpost


Threatpost

Cryptocurrency Mining Malware Hosted in Amazon S3 Bucket
Threatpost
The Zminer executable is being dropped from an exploit kit, which in turn connects with an Amazon S3 storage bucket to grab two payloads called Claymore CryptoNote CPU Miner and Manager.exe. Claymore is the mining utility used to produce Monero, an …

exploit kit – read more

Phishing Sites Hosted on Google’s Servers – F-Secure

Google Docs allows users to create documents, spreadsheets, et cetera at google.com (hosted in Google’s cloud): Spreadsheets can even contain functionality, such as forms, and these can be published to the whole world. Unfortunately, that means we …
Read more