Bitcoin Forum
May 03, 2024, 06:05:38 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Duplicate Shares Exploit -- Most Pools Affected  (Read 1520 times)
hdmediaservices (OP)
Hero Member
*****
Offline Offline

Activity: 630
Merit: 504


View Profile
May 19, 2015, 05:08:19 PM
Last edit: May 20, 2015, 08:50:13 PM by hdmediaservices
 #1

I have a feeling most Scrypt mining pools are still affected by the duplicate shares exploit.

Perhaps this topic will get the other ones moving to fix the exploit where a miner can submit duplicate shares -- receiving 2x, 3x, 4x or more credit for their mining share on a pool.

The following Scrypt pools have FIXED the issue:

1.  Hash-to-Coins.com
2.  IPOMiner.com
3.  Smarterhash.com
4.  Huh??

1714759538
Hero Member
*
Offline Offline

Posts: 1714759538

View Profile Personal Message (Offline)

Ignore
1714759538
Reply with quote  #2

1714759538
Report to moderator
1714759538
Hero Member
*
Offline Offline

Posts: 1714759538

View Profile Personal Message (Offline)

Ignore
1714759538
Reply with quote  #2

1714759538
Report to moderator
"If you don't want people to know you're a scumbag then don't be a scumbag." -- margaritahuyan
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714759538
Hero Member
*
Offline Offline

Posts: 1714759538

View Profile Personal Message (Offline)

Ignore
1714759538
Reply with quote  #2

1714759538
Report to moderator
mrbodz
Hero Member
*****
Offline Offline

Activity: 800
Merit: 1000


View Profile
May 19, 2015, 11:05:45 PM
 #2

ipominer has definitely fixed theirs. Me and wuher were discussing it a couple of weeks ago.

Ahmed
djm34
Legendary
*
Offline Offline

Activity: 1400
Merit: 1050


View Profile WWW
May 19, 2015, 11:19:50 PM
 #3

I have a feeling most Scrypt mining pools are still affected by the duplicate shares exploit.

Perhaps this topic will get the other ones moving to fix the exploit where a miner can submit duplicate shares -- receiving 2x, 3x, 4x or more credit for their mining share on a pool.

The following Scrypt pools have fixed the issue:

1.  Hash-to-Coins.com
2.  IPOMiner.com
3.  Huh?


thanks for the tip  Grin gpu will rule again scrypt soon Grin

djm34 facebook page
BTC: 1NENYmxwZGHsKFmyjTc5WferTn5VTFb7Ze
Pledge for neoscrypt ccminer to that address: 16UoC4DmTz2pvhFvcfTQrzkPTrXkWijzXw
zccopwrx
Full Member
***
Offline Offline

Activity: 306
Merit: 100



View Profile
May 20, 2015, 12:23:41 PM
 #4

This thread is all and dandy, but how about someone sharing actual details on the issue, and what branch of stratum has it repaired, and the proof of said repair?
hdmediaservices (OP)
Hero Member
*****
Offline Offline

Activity: 630
Merit: 504


View Profile
May 20, 2015, 03:25:27 PM
 #5


Wow - all I can say is choose your pools wisely.  Ask them if they have made the fix otherwise you could be cheated in your payments by someone else submitting duplicate shares.

I'm not sure how this is fixed - as I'm not a coder, but it affects practically every pool out there.

zccopwrx
Full Member
***
Offline Offline

Activity: 306
Merit: 100



View Profile
May 20, 2015, 05:10:57 PM
 #6

Heres is a example of the fix.

To summarize, you need to force lowercase on all submitted shares.  The exploit occurs when someone submits an valid share, then resubmits it and changes capitalization on any part of it (because shares are case insensitive to be valid)

https://github.com/ahmedbodi/powerpool/commit/b82e8b5ec4c79c0bbf820c898fba246ccf273cb5

Now go on, fix all the pools!
Miner-TE
Hero Member
*****
Offline Offline

Activity: 499
Merit: 500



View Profile
May 20, 2015, 06:44:28 PM
 #7

Stratum-mining reportedly fixed 14 days ago.

https://github.com/Crypto-Expert/stratum-mining/commit/d5b4ffddf60117c177945e0ea544288e9a9b2db9

I have not heard reports of NOMP base pools being exploited and have been told NOMP is unaffected by this issue. 

BTC - 1PeMMYGn7xbZjUYeaWe9ct1VV6szLS1vkD - LTC - LbtcJRJJQQBjZuHr6Wm7vtB9RnnWtRNYpq
hdmediaservices (OP)
Hero Member
*****
Offline Offline

Activity: 630
Merit: 504


View Profile
May 20, 2015, 07:34:00 PM
 #8


This is good to know if true.  Who has indicated that NOMP is unaffected?

mrbodz
Hero Member
*****
Offline Offline

Activity: 800
Merit: 1000


View Profile
May 20, 2015, 08:40:08 PM
 #9

NOMP is affected. Ive checked it from what i can tell

Ahmed
hdmediaservices (OP)
Hero Member
*****
Offline Offline

Activity: 630
Merit: 504


View Profile
May 20, 2015, 08:45:04 PM
 #10


Perhaps this is why pool owners are being very very quiet about this exploit.

lifeforcepools
Sr. Member
****
Offline Offline

Activity: 616
Merit: 253


View Profile
May 20, 2015, 08:46:34 PM
 #11

http://pools.smarterhash.com pools have been patched to guard against this exploit.

BUY CRYPTO AT REASONABLE RATES
▄▄███████▄▄
▄█████▀ ▀█████▄
██████ ▄█▄ ██████
██████ █████ ██████
█████ ▄ ███ ▄ █████
████▌▐██ █ ██▌▐████
███▄ ▀▀▌ ▐▀▀ ▄███
▀████▄▄ ▄▄████▀
▀▀███████▀▀
▄▄███████▄▄
▄█████▀█▀█████▄
████        ▀████
███████  ███  █████
███████      ▀█████
███████  ███  █████
████        ▄████
▀█████▄█▄█████▀
▀▀███████▀▀
▄▄███████▄▄
▄█████▀▀▀█████▄
██████   ▐███████
██████▌   ▀▀███████
█████▀    ▄████████
████▄    ▀▀▀▀▀▀████
███▌         ▄███
▀█████████████▀
▀▀███████▀▀
&OTHER
COINS
mrbodz
Hero Member
*****
Offline Offline

Activity: 800
Merit: 1000


View Profile
May 20, 2015, 11:05:46 PM
 #12


Perhaps this is why pool owners are being very very quiet about this exploit.



most just dont know about it. to put it bluntly. 99% of altcoin hash is in 1 place. suprnova. so he's the only one who should care about the patch
hdmediaservices (OP)
Hero Member
*****
Offline Offline

Activity: 630
Merit: 504


View Profile
May 20, 2015, 11:30:29 PM
 #13


LOL - Really?  How much does SuprNova have total for Scrypt mining?  As I'm not seeing much.

Miner-TE
Hero Member
*****
Offline Offline

Activity: 499
Merit: 500



View Profile
May 21, 2015, 01:07:29 AM
 #14

Looks like I may have gotten wrong information on NOMP not being affected.  Anyone have a modified miner to test with?


https://github.com/zone117x/node-open-mining-portal/issues/430

BTC - 1PeMMYGn7xbZjUYeaWe9ct1VV6szLS1vkD - LTC - LbtcJRJJQQBjZuHr6Wm7vtB9RnnWtRNYpq
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!