Bitcoin Forum
May 30, 2024, 04:12:51 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: ANTMINER S1  (Read 1324 times)
boggle (OP)
Newbie
*
Offline Offline

Activity: 40
Merit: 0


View Profile
February 26, 2014, 10:11:10 AM
Last edit: February 26, 2014, 11:34:54 AM by boggle
 #1

i looked at the mining pool a few minutes ago and one of my miners was offline... Huh strange i thought, so i checked the miner through the web and someones hacked/changed my worker details are set to btcurl.ch4 they minused off my other workers and this has been added to the ssh-keys


ssh-dss AAAAB3NzaC1kc3MAAACBANPLYv0LbB5IrH4M897uha5h56/XUzkGnY3Rcclw2GO5RaVhaHI43jKBTaAJOVEfO2+9YvemcSXAvFOpvSKjmFSLdKoQMLvZnqQTtsM/Z30/jEDJIXCgJlYKC9yyuWHBk4gar0GOdCvTz6mX6AhnaKy3WG+E9MsIjXMmEmJicK5RAAAAFQCGbWk0HJG2YT/oc5djQxGUu6hNIQAAAIEAznZ2v7fhT4JkxOECq7oe6yKxfUMjVU11YPqIZSQjrT4btN5EVWMGLv1/rQcFIwHQiW1rP+hkS9gDvVlzb3/9tBqJE7tYaAHO8CUhOZiq0GJ/ebMTH7SY6f9DZ+BPjuXwcjPbD16Sp3ri/Bg1rUniPV33HDx+RQtARkNTOudW8UMAAACAFi+1zXYIZ2/I+sL9/nLD1knjRDkVYkZApqp90NF671pt3x0hO+iLfH4hp7eBAX+dG+d52zptdKcTOakK1vwxhjZ1V0j/iqkWIj68urHdzqFnKq4tZEQYr7xsyHAUtafpOWfvjfF9jOHVAmrs1mIOBgh66IaKdXSu8G8ur3jEbDs= btcurl0987@vm-0.btcurl0987.koding.kd.io

only the miner on 192.168.x.99 was compromised, the only computer running on this network is a raspberry pi

where can i get the latest firmware??

 
Biffa
Legendary
*
Offline Offline

Activity: 3220
Merit: 1220



View Profile
February 26, 2014, 10:17:57 AM
 #2

i looked at the mining pool a few minutes ago and one of my miners was offline... Huh strange i thought, so i checked the miner through the web and someones hacked/changed my worker details are set to btcurl.ch4 they - off my other workers and this has been added to the ssh-keys


ssh-dss AAAAB3NzaC1kc3MAAACBANPLYv0LbB5IrH4M897uha5h56/XUzkGnY3Rcclw2GO5RaVhaHI43jKBTaAJOVEfO2+9YvemcSXAvFOpvSKjmFSLdKoQMLvZnqQTtsM/Z30/jEDJIXCgJlYKC9yyuWHBk4gar0GOdCvTz6mX6AhnaKy3WG+E9MsIjXMmEmJicK5RAAAAFQCGbWk0HJG2YT/oc5djQxGUu6hNIQAAAIEAznZ2v7fhT4JkxOECq7oe6yKxfUMjVU11YPqIZSQjrT4btN5EVWMGLv1/rQcFIwHQiW1rP+hkS9gDvVlzb3/9tBqJE7tYaAHO8CUhOZiq0GJ/ebMTH7SY6f9DZ+BPjuXwcjPbD16Sp3ri/Bg1rUniPV33HDx+RQtARkNTOudW8UMAAACAFi+1zXYIZ2/I+sL9/nLD1knjRDkVYkZApqp90NF671pt3x0hO+iLfH4hp7eBAX+dG+d52zptdKcTOakK1vwxhjZ1V0j/iqkWIj68urHdzqFnKq4tZEQYr7xsyHAUtafpOWfvjfF9jOHVAmrs1mIOBgh66IaKdXSu8G8ur3jEbDs= btcurl0987@vm-0.btcurl0987.koding.kd.io

only the miner on 192.168.x.99 was compromised, the only computer running on this network is a raspberry pi

where can i get the latest firmware??

 

So you must have ports open from the outside of your network through your router to the miner.

Mine @ pools that pay Tx fees & don't mine empty blocks :: kanopool :: ckpool ::
Should bitmain create LPM for all models?
:: Dalcore's Crypto Mining H/W Hosting Directory & Reputation ::
boggle (OP)
Newbie
*
Offline Offline

Activity: 40
Merit: 0


View Profile
February 26, 2014, 10:25:15 AM
 #3

just patched the ports issue and changed IP's and passwords.. still want to update the firmware
Biffa
Legendary
*
Offline Offline

Activity: 3220
Merit: 1220



View Profile
February 26, 2014, 10:27:15 AM
 #4

just patched the ports issue and changed IP's and passwords.. still want to update the firmware

I wouldn't bother it just maxes out the CPU and causes problems.

Mine @ pools that pay Tx fees & don't mine empty blocks :: kanopool :: ckpool ::
Should bitmain create LPM for all models?
:: Dalcore's Crypto Mining H/W Hosting Directory & Reputation ::
Biffa
Legendary
*
Offline Offline

Activity: 3220
Merit: 1220



View Profile
February 26, 2014, 10:29:13 AM
 #5

just patched the ports issue and changed IP's and passwords.. still want to update the firmware

I wouldn't bother it just maxes out the CPU and causes problems.

Also don't open ports from the public internet to your miners, setup a VPN to your firewall and network and do it that way. Don't mess about with this stuff half heartedly.

Mine @ pools that pay Tx fees & don't mine empty blocks :: kanopool :: ckpool ::
Should bitmain create LPM for all models?
:: Dalcore's Crypto Mining H/W Hosting Directory & Reputation ::
boggle (OP)
Newbie
*
Offline Offline

Activity: 40
Merit: 0


View Profile
February 26, 2014, 10:47:55 AM
 #6

the miner affected was on the default IP connected with a bunch of others S1's to a hub then to the internet router.
this could happen to someone else?

loshia
Legendary
*
Offline Offline

Activity: 1610
Merit: 1000


View Profile
February 26, 2014, 10:57:44 AM
Last edit: February 26, 2014, 11:10:23 AM by loshia
 #7

just patched the ports issue and changed IP's and passwords.. still want to update the firmware

I wouldn't bother it just maxes out the CPU and causes problems.

Also don't open ports from the public internet to your miners, setup a VPN to your firewall and network and do it that way. Don't mess about with this stuff half heartedly.
+1
Unless if there is not some sort of vpn preinstalled on the unit digging a secure tunnel outside your FW Wink
however simple ssh/netstat/ps check will reveal that easily:)
A lot easy will be just to install precompiled cgminer hacked of course which can silently send 10-20% of your shares somewhere Grin
And again simple ssh/netstat will reveal that Cheesy Or better tcpdump of your router watching closely what the suspect is doing
Conclusion - always compile your images alone or use trustable ones

Please help the Led Boy aka Bicknellski to make us a nice Christmas led tree and pay WASP membership fee here:
https://bitcointalk.org/index.php?topic=643999.msg7191563#msg7191563
And remember Bicknellski is not collecting money from community;D
slastar
Full Member
***
Offline Offline

Activity: 147
Merit: 104


View Profile
February 26, 2014, 11:15:38 AM
 #8

Probably someone connect via SSH to the Ant and edit cgminer config (/etc/config/cgminer). Some routers have this port open by default.
Go to http://www.yougetsignal.com/tools/open-ports/ and check SSH port (22) is open. If open , close it, and most of all change default password  to the Ant.
loshia
Legendary
*
Offline Offline

Activity: 1610
Merit: 1000


View Profile
February 26, 2014, 11:20:19 AM
 #9

Probably someone connect via SSH to the Ant and edit cgminer config (/etc/config/cgminer). Some routers have this port open by default.
Go to http://www.yougetsignal.com/tools/open-ports/ and check SSH port (22) is open. If open , close it, and most of all change default password  to the Ant.

Yeah and they have port forwarding by default pointing to ant ip - nonsense dude Wink

Please help the Led Boy aka Bicknellski to make us a nice Christmas led tree and pay WASP membership fee here:
https://bitcointalk.org/index.php?topic=643999.msg7191563#msg7191563
And remember Bicknellski is not collecting money from community;D
boggle (OP)
Newbie
*
Offline Offline

Activity: 40
Merit: 0


View Profile
February 26, 2014, 11:33:01 AM
 #10

Probably someone connect via SSH to the Ant and edit cgminer config (/etc/config/cgminer). Some routers have this port open by default.
Go to http://www.yougetsignal.com/tools/open-ports/ and check SSH port (22) is open. If open , close it, and most of all change default password  to the Ant.


this is my conclusion as well....

caused by poor security/complacency and leaving passwords on default  Shocked
loshia
Legendary
*
Offline Offline

Activity: 1610
Merit: 1000


View Profile
February 26, 2014, 11:52:43 AM
 #11

Probably someone connect via SSH to the Ant and edit cgminer config (/etc/config/cgminer). Some routers have this port open by default.
Go to http://www.yougetsignal.com/tools/open-ports/ and check SSH port (22) is open. If open , close it, and most of all change default password  to the Ant.


this is my conclusion as well....

caused by poor security/complacency and leaving passwords on default  Shocked
Nonsense dude. Any way just my 2 cents read my post carefully and think.

Please help the Led Boy aka Bicknellski to make us a nice Christmas led tree and pay WASP membership fee here:
https://bitcointalk.org/index.php?topic=643999.msg7191563#msg7191563
And remember Bicknellski is not collecting money from community;D
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!