[Full-disclosure] Fun with Bitcoin, or how an exploit can hide in plain sight

2012-02-01 Thread Aidan Thornton
So most people on here have probably heard of Bitcoin from somewhere, and most of you have probably got tired of it - but bear with me because this is kind of entertaining. For those of you that have been stuck in a darkened room with a disassembler and no internet access for the past few months, B

Re: [Full-disclosure] Fun with Bitcoin, or how an exploit can hide in plain sight

2012-02-01 Thread Dan Kaminsky
Welcome to why BitCoin is so impressive. You've got this app. It's wide open to the Internet, to the point where it opens up firewall rules if necessary. It's running some home grown network protocol, that ostensibly ships little executable programs around. It's written in C++, the non-memory s

Re: [Full-disclosure] Fun with Bitcoin, or how an exploit can hide in plain sight

2012-02-02 Thread Aidan Thornton
On Wed, Feb 1, 2012 at 10:27 PM, Dan Kaminsky wrote: > > Welcome to why BitCoin is so impressive.  You've got this app.  It's wide > open to the Internet, to the point where it opens up firewall rules if > necessary.  It's running some home grown network protocol, that ostensibly > ships little ex