Silk Road forums

Discussion => Silk Road discussion => Topic started by: hass on May 01, 2013, 07:49 am

Title: Account compromised
Post by: hass on May 01, 2013, 07:49 am
Haven't been around for a while and logged in to find that I have to unlock my pin. Upon further investigation this has happened because someone has guessed at it 5 times and it's been locked. Does this have any relationship with the current attacks on the site? Because I browsed a couple of pages and seen no threads on it. Additionally, whoever gained access to my account, why didn't they change the log in password? 
Title: Re: Account compromised
Post by: scout on May 01, 2013, 07:51 am
They probably logged in, weren't able to guess your PIN, and decided to logout hoping you wouldn't change your password between now and the time that you reset your PIN (so they can give it more guesses).  Who knows.  But I highly doubt it has anything to do with the site attack.
Title: Re: Account compromised
Post by: hass on May 01, 2013, 07:58 am
Thanks scout, that's bit of a relief. But how did they get it? It's a combination of two words merged into one, if you know what I mean, including numerals. Certain I haven't been phished, always enter the url from my memory.

silkroadvb5piz3r.onion

Anyways, I'll get the password changed and hopefully no one else has the same scare haha
Title: Re: Account compromised
Post by: scout on May 01, 2013, 08:03 am
I don't know how it could happen if you haven't been phished and don't use the same password on multiple sites, but it's good at least that you're back in control of your account!
Title: Re: Account compromised
Post by: hass on May 01, 2013, 08:17 am
I don't know how it could happen if you don't use the same password on multiple sites

Created my tormail with the same password the other day, same username too. Coincidence..?  :-\
Thanks for your help mate.
Title: Re: Account compromised
Post by: Secret_Squirrel on May 01, 2013, 10:53 am
Yeah using the same username and password across even two sites is a security risk.  Using the same user name is telling anyone that was wants to look "Hey, I'm here too"

I don't use this name on any other account anywhere and my passwords are always just a little different, like adding !$%@ or 234 to the end of my normal pass...
Title: Re: Account compromised
Post by: AnonymousAddict on May 01, 2013, 11:44 am
tHATS KINDA CRAZY the short time it was up somene tried getting into yur account instead of handling their own business, i always switch my passwords up a little as well//

I did just make it back to the Login page..
Title: Re: Account compromised
Post by: avast on May 01, 2013, 12:51 pm
I don't know how it could happen if you haven't been phished and don't use the same password on multiple sites, but it's good at least that you're back in control of your account!

Doesn't the site have unlimited login attempts? If so a brute force or dictionary attack would be a good means of compromising an account.
Title: Re: Account compromised
Post by: MeatMittens on May 01, 2013, 01:52 pm
Haven't been around for a while and logged in to find that I have to unlock my pin. Upon further investigation this has happened because someone has guessed at it 5 times and it's been locked. Does this have any relationship with the current attacks on the site? Because I browsed a couple of pages and seen no threads on it. Additionally, whoever gained access to my account, why didn't they change the log in password?

You got phished. You didn't go to silkroadvb5piz3r.onion, you went to another site that was (and may still be) up that LOOKED like SR. Your account didn't get "locked" you simply got fooled by a fake login screen on a completely different URL.
Title: Re: Account compromised
Post by: Secret_Squirrel on May 01, 2013, 05:01 pm
Ouch so there was a site that looked like SR and after 1 failed login attempt says something like, account locked enter pin to unlock...?

Anytime you see enter pin on the login screen...HUGE red flag...when I first started purchasing a few months ago I got to page from one of the hidden wiki's asking for a pin. I remembered reading something somewhere that I would never have to enter my pin outside of sending btc and making purchases on SR. 

So I came to the forums and after a few searches I realized it was a phishing attempt, honestly I didn't realize that's what phishing was, I mean it just didn't click for me until it almost happened to me...ya know?

so live and learn and we've all been there don't let it put you off
Title: Re: Account compromised
Post by: itsthecops on May 01, 2013, 07:27 pm
Dont know if this is related, but when O logged in to a vendor account, my PIN didn't work the first four times. 

I'm absolutely certain it was the right PIN.  I just kept typing the same PIN and on try #5, it took it.   
This was for transferring coins to a wallet.  I was one of the first to get into the site last night when it came back.. .  Its since been fantastic.

Anyway.  Just passing a related observation.

BTW   I'm transferring a few dollars to Scout tonight for his awesome patience and professionalism with everyone here.   :-)
Title: Re: Account compromised
Post by: hass on May 02, 2013, 01:28 pm
Haven't been around for a while and logged in to find that I have to unlock my pin. Upon further investigation this has happened because someone has guessed at it 5 times and it's been locked. Does this have any relationship with the current attacks on the site? Because I browsed a couple of pages and seen no threads on it. Additionally, whoever gained access to my account, why didn't they change the log in password?

You got phished. You didn't go to silkroadvb5piz3r.onion, you went to another site that was (and may still be) up that LOOKED like SR. Your account didn't get "locked" you simply got fooled by a fake login screen on a completely different URL.

Did you just not read what else I said mate? I enter it manually each and every time. And i'll never had a failed log in, which is what would happen on a phishing site.