Kumala



Offline



Activity: 525

Merit: 500









Hero MemberActivity: 525Merit: 500 VIRCUREX January 11, 2013, 12:19:25 PM

Last edit: March 16, 2013, 10:11:48 AM by Kumala #1 We sadly need to announce that our wallet has been compromised thus DO NOT send any further funds to any of the coin wallets, BTC, DVC, LTC, etc. We will setup a new wallet and reset all the addresses. This will most likely take the whole weekend.



Hacked Account! Don't send any money.

Kumala



Offline



Activity: 525

Merit: 500









Hero MemberActivity: 525Merit: 500 Re: VIRCUREX !!! IMPORTANT !!! January 11, 2013, 01:58:50 PM #4





Further update: The system was not breached, no passwords were compromised (they are salted and multiple times hashed anyways). The attacker used a RubyOnRails vulnerability that was released yesterday ( http://www.exploit-db.com/exploits/24019/ ) to withdraw the funds therefore. Hacked Account! Don't send any money.

Kumala



Offline



Activity: 525

Merit: 500









Hero MemberActivity: 525Merit: 500 Re: VIRCUREX !!! IMPORTANT !!! January 11, 2013, 03:14:21 PM #7 Before the wild speculations beginn, the service will be recovered and we pay the losses out of our own pockets. Hacked Account! Don't send any money.

Kumala



Offline



Activity: 525

Merit: 500









Hero MemberActivity: 525Merit: 500 Re: VIRCUREX !!! IMPORTANT !!! January 11, 2013, 05:05:41 PM #11



For the time being, some restrictions apply until we have sorted out the account details and validated data integrity.



Trading Deposits Withdrawals BTC Active Active On hold NMC Active Active On hold LTC Active Active On hold DVC Active Active Active SC Active Active On hold IXC Active Active Active PPC Active Active Active USD Active Active Active EUR Active Active Active Service restored: deposits, trading and withdrawals are working againFor the time being, some restrictions apply until we have sorted out the account details and validated data integrity. Hacked Account! Don't send any money.

Kumala



Offline



Activity: 525

Merit: 500









Hero MemberActivity: 525Merit: 500 Re: VIRCUREX !!! IMPORTANT !!! January 11, 2013, 05:58:42 PM #14 It's been a couple of stressful hours here.



No we did not switch servers, we:

- applied the Ruby Rails patch

- backed up all log files for further analysis

- log files show the XML code injection, we validated all triggered commands to ensure nothing other than withdrawing funds (e.g. backdoor) was done.



2AM here, will need to catch some sleep, mistakes are easily made when being too tired. Hacked Account! Don't send any money.