GUIDE: Vendors has your Payout Wallets been changed? Buyers with a strange refund wallet? Are you missing coins from orders? YOU GOT PHISHED!
Vendors has your Payout Wallets been changed? Buyers with a strange refund wallet? Are you missing coins from finalized orders? Pin not working? VERSUS DID NOT SCAM YOU! YOU GOT PHISHED!
This guide is intended for Versus vendor & logged into Versus and found that they were missing coins from finalized or refunded orders and went to their settings or order notes and found their payout wallets / xpub / refund wallet was not their own and blamed Versus market for scamming them.
Well here is the truth The Versus Project did not SCAM you and no the staff / admins were not behind this.
2FA you say? "But hey it must of been Versus because I had 2FA enabled......" Well yes maybe you did have 2FA enabled on you're account and you thought you were safe but at some point you clicked or followed the wrong link this is guaranteed!
"So how did the hacker get into my account with 2FA enabled surely my PGP keys couldn't of been stolen" Well you are correct your keys were most likely not stolen unless you are really really stupid... but the hacker used a MITM proxy attack and when you went to that link that you cannot remember and completely deny ever following (BUT YOU DID) and logged in signing the message requested on the login page the attacker got a thing called a "Session Cookie" now Versus session cookies are named "thisisanewcookiesmartass" and the value of the cookie is what the attacker is after once he has this the attacker has access to you're account for over 1 month! (Yes this is true they don't expire for over a month)
With this session cookie the 2FA challenge has already been solved by you and what you should of noticed is that in the blue box with the message to sign on the phishing page the link will not match the link in you're address bar this is because the correct market link the MITM proxy is pointing at needs to be in the signed message for the login to work. All the attacker needed to do was get you're session cookie head to Versus open inspector on the login page and change the value of cookie "thisisanewcookiesmartass" to the value of you're session cookie and he is in...
Don't believe me? Well test it out you're self head to Versus market and create a new account once created set a PGP Public key on the account and enable 2FA once this is done follow these steps.
Step 1: Right click on the page anywhere and click inspect (You must still be logged in & make sure 2FA is enabled) (You will see a box appear at the bottom of you're Tor Browser.)
Step 2: Click Storage
Step 3: You will see 2 or 3 cookies & you need the value of the cookie that says "thisisanewcookiesmartass" so where it says value next to "thisisanewcookiesmartass" click the value 3 times fast to make sure it is all selected and copy it to you're clipboard and save it in a document ready for in a moment.
Step 4: Grab a new tor identity and head back to the Versus login page.
Step 5: Once at the login page right click and click inspect again and head back to storage.
Step 6: click the value of "thisisanewcookiesmartass" fast 3 times again and erase it all and then paste the value you saved to you're clipboard in the box and then click the address bar and erase the /login and change it to /dashboard and hit enter.
Vola you just bypassed 2FA and session hijacked yourself logging in without PGP Private keys to an account with 2FA enabled. In fact you logged in without even entering the username and password.
You're biggest mistake: Pin Code + Following random links
So the attacker has bypassed you're 2FA and is now in you're account but if you had set a strong pin code on your Versus account ( Must be done after registering in settings ) the attacker would most likely try to message Wickr or other details to you're customers but they could not change payout wallets & xpub or change refund wallets on buyers because they would need the pin.
Your biggest mistake was not going to you're settings page and setting a strong pin code after you registered... For some strange reason Versus does not ask you to set a pin while registering.
NO PIN SET? So now the attacker just set his own pin code on you're account and then changed your wallets and XPUB in you're settings page and is watching you're account daily for vendors to get new orders which now have the attackers wallet on them & the vendor will most times not notice this and process and ship the orders or buyers may not set a new refund wallet when placing an order and the order will now have the attacks wallet set as refund and they can simply ask the vendor to cancel the order. With vendors its a little different so the attacker set his shit on your settings page and you have processed say 50 orders without noticing.
You now start to get finalized orders but you probably won't notice these at first the attacker will sign them with his bitcoin private key and broadcast them making them move from the finalized folder into the completed folder and now if you are a vendor on multiple markets with the same wallets you will still have a flow of coins in you're wallets and most likely won't notice the missing coins for a while.
When you do notice and open a ticket the attacker will close these tickets and change you're password hoping you didn't save you're mnemonic and wait for you're shipped orders to finalize and sign + broadcast and you lost you're coins and its you're own fault!
So what you should of done was verified you're links with the markets key and followed DNM Bible on how to correctly do this.
You should of set a pin.
You should of kept an eye on payout wallets before shipping / ordering.
You should of ignored PM's with a link claiming to be staff.
Next is the guide for how buyers orders stayed unpaid and they called Versus a scam! BUT No It was you're own fault... (Coming soon)
Guides
GUIDE: Vendors has your Payout Wallets been changed? Buyers with a strange refund wallet? Are you missing coins from orders? YOU GOT PHISHED!
Started by Smoking247 · Apr 19, 2022