• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Misfortunate Misconfiguration = Fortune!

FrgMstr

Just Plain Mean
Staff member
2FA
Joined
May 18, 1997
Messages
58,067
Researchers from Chinese Cyber Security Firm 360 Netlab have discovered that over $20 million dollars worth of Ethereum has been stolen from users with misconfigured Ethereum applications since March of this year. Just to add a little flavor to the conversation, there were only 3.96 Etherium on the attackers wallet back then, worth around $2K to $3K (USD).

The misconfiguration in question regards leaving the Remote Procedure Call (RPC) interface open on port 8545. If you mine Ethereum and are thinking "Hey! Ethereum Project warned against leaving that port exposed a long time ago!" then CONGRATULATIONS! You win a cookie! If not, you should probably drop what you are doing and go ahead and un-misconfigure your misconfigured configuration.


You can behold the glory of misconfigured misfortune here. Thanks to SCHTASK for the writeup!
 
Really confused. Who is just wandering around with ports open by default on their router intentionally port forwarded to the machine?
 
Really confused. Who is just wandering around with ports open by default on their router intentionally port forwarded to the machine?
Well, you don't need to have ports forwarded at the router to access internal ports. Just need windows (mis)configured to direct traffic pointed to/from [unprotectedport] from/to 8545. ;)
 
Back
Top