[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 69 KB, 899x720, FC5BCD05-0BBA-411B-91CC-200F5929CD23.jpg [View same] [iqdb] [saucenao] [google]
22637526 No.22637526 [Reply] [Original]

I just sold a malware (for xmr) that is stealing eth from metamask
imagine being so retard to store your wealth in a fucking browser extension

>> No.22637568

OK big guy, steal my ETH Im waiting MR hacker ? Come on bro do it DO IT PUSSY

>> No.22637719
File: 59 KB, 1000x1000, 2C12B106-A924-4AF8-911F-18D9FFD1AD84.jpg [View same] [iqdb] [saucenao] [google]
22637719

>>22637568
I’m not stealing anything, other people will, I already had my stash of xmr converted into btc

>> No.22637787
File: 269 KB, 646x595, 1600520312087.png [View same] [iqdb] [saucenao] [google]
22637787

>using metamask without a hardware wallet
nobody does this, right?

>> No.22637927

>>22637787
>nobody
80%+ of bizlets according to data mining threads

>> No.22637952

>>22637787
Does a hardware wallet make things safer for people?

>> No.22637971

>>22637526
describe principles of exploit....(requires clicking a link, etc)

>> No.22638018

>>22637952
yes, private keys never touch the computer, this is effectively an air

>> No.22638040

>>22638018
gapped system that prevents niggers like OP from stealing yo coinz ayoo finnna nibba

>> No.22638083

>>22637971
henlo broker
nope that’s not my part
just the shellcode to inject the browser and fuck it up (steal pass / export private key), ready to be chained

>> No.22638109

>>22637787
I use a paper wallet, is that ok?

>> No.22638126

>>22638109
smartest choice, don’t lose it in a boating accident

>> No.22638161

>>22637719
Jokes on you I don't download anything

>> No.22638213

>>22638083
ok suppose you have an RCE in unpatched browsers. how do you even retrieve the private key considering metamask use a password to encrypt it and I would imagine the password itself if saved is also in an encrypted keychain

>> No.22638226

>>22638109
don't listen to him, it's a terrible choice. a paper wallet won't stop anyone who infects your computer from getting your private key the moment you enter it. it's good for coldstorage, but the second you decide to input it on a computer it's as good as garbage. you should use a ledger.

>> No.22638231

>>22638213
you wait for the user to enter it aaaaand goodbye funds

>> No.22638259

i keep my net worth in a trezor and i sleep with it tucked in between my buttcheeks nice try tho

>> No.22638279

>>22637526
Imagine being so retarded you cant prevent yourself from fallinh for malware

>> No.22638289

>>22638213
two most probable ways:

1. he is spoofing the password page and captures password
2. he as some out-of-process program that watches browser state somehow and notices when extension has been opened / unlocked and then executes.

my bet is on #1

>> No.22638401

>>22638279
if someone chain it with a 0day and a sandbox escape good look, you can be the smartest folk in the planet and still lose your funds
use an hardware wallet

>> No.22638468

All these advices to use a hardware wallet are fine, but how am I going to do constant trading like that?

I'm currently planning to have small amounts for trading in my Metamask, and long-term hodl in a hardware wallet, is that a smart thing to do?

>> No.22638483

>>22638289
no, everything runs as a separate process
inject good candidates and wait for the jackpot

>> No.22638513

>>22638226
Obviously use an airgapped pc and generate tx offline before uploading to net attached pc to broadcast. No one should even own crypto who doesn't know this shit.

>> No.22638521

>>22638401
Dont download from sketchy sites or watch porn on the same pc. It's that easy folks

>> No.22638544

>>22638226
or you can just use a clean live linux distro when accessing it (from a burned dvd so shit don’t get saved)

>> No.22638572

>>22638521
lol, you will get pwned at the first http page you visit regardless of porn

>> No.22638632

>>22638572
If it's not https I don't bother

>> No.22638669

>>22637526
and this is new, how? shits been around for years

>> No.22638705

>>22638669
just a warning to bizbros to not fuck it up, using a 1M+ metamask wallets and not signing tx somewhere else

>> No.22638771
File: 6 KB, 224x225, Nerves.jpg [View same] [iqdb] [saucenao] [google]
22638771

>>22637787
Wait I'm a newfag. So you should never keep funds in metamask right? It's effectively just a wallet for temp use to transfer funds to uniswap and back using ETH?

>> No.22638831

>>22638771
if you are playing with pocket money who cares, you have several k please use an hardware wallet or you will lose it sooner or later

>> No.22638958

>>22638705
yeah it should be common sense to not leave a chunk of your portfolio in metamask. It's probably fine if you have small amounts of uniswap shitcoins but if you're dealing with money that you CAN'T afford to lose always, always use a cold wallet or even storing it on exchanges is a better bet. Another common sense tip which might not be common for some people, make it a habit to double confirm which address you're inputting when sending/receiving crypto. There are clipboard hijacking malwares that can replace your address with the hacker's so if you're not careful that's another way you get pwned.

>> No.22639017

>>22638231
Enter what? Password or private key?

>> No.22639051

noob here, if I have more than 2 metamask wallets, can I used one trezor for both?

>> No.22639125

>>22639051
also what happens if the battery dies?

>> No.22639210

bump
real messed up

>> No.22639538

Can someone unironically tell me if Stakenet Dex is more secure than Metamask. Need to find the best alternative to an exchange.

>> No.22639618

>>22639051
yes

>>22639125
imagine thinking there's a battery in the trezor. it's fucking usb powered

>> No.22640019

Bamp

>> No.22640343

>>22637719
>xmr converted into btc
What a strange choice

>> No.22640384
File: 11 KB, 296x292, 1581288134068.gif [View same] [iqdb] [saucenao] [google]
22640384

>>22637526
What OS does it work on OP? Windows I assume right?

>> No.22640407

What do you guys think about mobile phone non-custodial wallets? I found some with pretty good autentification (can't be used if someone steals the phone or something like that), would that be ok?

>> No.22640416

>>22637952
yes because you need physical access to the wallet to send the coins

>> No.22640431

>>22638083
hahaha

nice larp OP

there is 1MM bounty on any critical vulnerability for FF and Chrome.

anybody responding to this thread is an actual retards, anyone who can ship actual browser malware these days works for the government or makes millions per year selling exploits to the government

>> No.22640473

>>22637971
This. Op is a complete faggot.

>> No.22640920

>>22640431
and we got the buyer in the thread!

>> No.22640990

>>22640343
well, what do you do with xmr anyway?
it’s a useful coin but definitely not a coin you want to hold, look at the chart
>>22640431
most of the people don’t even update the browser, why do you need a 0day?

>> No.22641680

Bamp

>> No.22641747

>>22637526
maybe larp but I did always think it was retarded as fuck that the standard choice for an eth wallet is a fucking browser extension

>> No.22641784
File: 21 KB, 382x382, 6F140247-7CE9-4EEF-9522-50E50F605F63.jpg [View same] [iqdb] [saucenao] [google]
22641784

>>22641747

>> No.22642170

>>22638468
Yes. Cold wallet vs. Hot wallet

>> No.22642243

Is Metamask with Mycrypto safe?

>> No.22642310

Jokes on you RETARD, I use Mac OS

>> No.22642354

>>22638468
You can use uniswap on expert mode to purchase from hot wallet and send to cold wallet

>> No.22642364

>>22638831
Im thinking of buying one, trezor or ledger? I will pay for it with UNI gains.

>> No.22642409

>>22642364
nice, I literally saved 100 lives today

>> No.22642445
File: 100 KB, 820x559, 1563104040096.jpg [View same] [iqdb] [saucenao] [google]
22642445

>>22637526
sure you did anon..

>> No.22642511

>>22637526
You what?? I'm an NSA agent and you've just hacked my browser?!?! This is literally terrorism, I hope you're ready for what's coming, buddy.

>> No.22642609

>>22638572
How tf does visiting a http site pose a threat at all? That just means the communication between you and the site isn't encrypted.

>> No.22642666

>>22642609
He hacked your ISP obviously.

>> No.22642687

>>22642511
Wait, Richard? You're the one everyone at the office was talking about? Thank god we're running an actual investigation this time.

>> No.22642693

>>22638831
why

>> No.22643028

>>22642687
No no I'm Steven, Richard's replacement. The poor bastard. Some kid in India hacked his fitbit and had his wife call while crossing the road. You updated on the Superpower by 2020 report yet?

>> No.22643043

>>22642666
Govs do this all the time but there is no need at all
Play the big number game:
-shitty old router full of rce out there, just do a shodan query
-inject js
-get a shitty 1 day public chain
-throw a shitty malware at it
Done, if you get lucky you win a few millions, it’s not rocket science...

>> No.22643405

Anyone remember that post was floating around, about one of the hardware wallets gets forced firmware updates? Was that the Trezor?

>> No.22643558
File: 247 KB, 705x527, 55667.jpg [View same] [iqdb] [saucenao] [google]
22643558

Do you see how impossible all the crypto thing is? How can it ever become mainstream, one day?

>> No.22643969

>>22643558
It won’t. Crypto will always be exclusive to nerds on image boards who have nothing better to do with their lives than obsess over digital tokens.

>> No.22644452
File: 2 KB, 108x125, 1569514909209s.jpg [View same] [iqdb] [saucenao] [google]
22644452

>>22643405
AHHHH I asked in the earlier thread now SOMEONE ANSWER ME OR I AM KILLING A THREAD to ask separately
and I'll make sure its a shill thread for something one of you has

>> No.22645390

>>22644452
Happened to someone's ledger I think, but they were a retard by all accounts. If you update the software it is easy to do a quick google and see if it's legit from official channels.

>> No.22645508

I lost 1 fucking eth after uni.
FFFFFFUUUUUUUU
I really hope every scammers wakes up with fucking linfoma and pancreatic cancer