Post
Topic
Board Service Discussion
Re: My CEX.IO account has been hacked and has been drained dry.
by
empoweoqwj
on 06/01/2014, 02:54:48 UTC
I have lost a bit more than 0.5 BTC in total.
I had 11 GH/s and had enough to buy another 1.5.
I have sent the files dumped in my TEMP folder to another CEX user, he will pull it apart and help to discover what and how he managed to get it done.
The webpage listed above ran a JAVA plugin, which I stupidly agreed to run.
What got my attention at first was btc-e loaded in another web browser that was closed.
It also ran an app called mtgox_bot.exe.
The Scumbag has managed to get into my account and change my password, I am locked out.
I was able to see my worker on ghash.io with 0 GH/s just before I was locked out of there.
I'm SAD.

Lesson for everyone. Never run a Java plugin. Sorry for your loss

Java is ok from trusted places or sandboxed. The best one is http://www.sandboxie.com/

I did download whole site as mirror and  applet.jar on the website. Anyone who knows java could look in that what's acctually this script doing.

Zip file is here: http://www38.zippyshare.com/v/80049771/file.html

I suggest any one to run it sundboxed.

You've lost me ..... what Java are you encouraging people to download and run given that the thread was about someone who ran some Java and got hacked because of it ?

My intention was to provide applet which trying to load by visiting site given by OP, to someone who can check what's that plugin doing. I done it sundboxed and plugin done nothing to my laptop.
Someone who knows Java can check it and can provide info how cex account was emptied.
By downloading zip and unpack it nothing will happen. U have to applet.jar to have effect.
I did check this file by opening in editor but cannot find anything-i dont know what im looking for anyway.

You don't know what you are looking for? So why look?

Leave security analysis to people that know what they are doing. They don't need advise about sandboxes either Wink