camaro69327
Newbie
Offline
Activity: 59
Merit: 0
|
|
April 23, 2013, 09:54:25 PM Last edit: April 23, 2013, 10:06:02 PM by camaro69327 |
|
I'm investigating it.
...well ya did something....miners just started back up...good Job Edit to Say:....is it Cgminer that is giving really weird #'s or is something amis on your end ...I like the #'s but know they are not Right...hahha My 300 Mhash is getting 500 Mhash 660 Mhash is saying 1.2 Ghash..I wish its only a 7970...hahha
|
|
|
|
phazedoubt
Newbie
Offline
Activity: 18
Merit: 0
|
|
April 23, 2013, 09:56:35 PM |
|
Does it seem to be a secondary problem caused by Ddos? Have you tried moving behind Cloudflare? May be way off base, just shooting in the dark.
|
|
|
|
dmphotog
Newbie
Offline
Activity: 17
Merit: 0
|
|
April 23, 2013, 10:02:07 PM |
|
Mine are not connecting at all. I know you're working on it though. Just thought you should know. I will wait patiently.
|
|
|
|
VacantPaper
Newbie
Offline
Activity: 28
Merit: 0
|
|
April 23, 2013, 10:02:33 PM |
|
Website isn't working for me, or stratum.
Care to explain?
|
|
|
|
dellnull
Newbie
Offline
Activity: 30
Merit: 0
|
|
April 23, 2013, 10:04:31 PM |
|
Those f**king DDoS:ers.. What's the point? Is it really that profitable to DDoS out sluch pool?
|
|
|
|
nybbler905
|
|
April 23, 2013, 10:12:06 PM |
|
funny that.... swapped to getwork from Stratum since it's been 4 days and no shares ( usually 3 per day even if i am CPU mining) and ... insta share ( for a whole 0E-8 but it IS a share! ). Also, have had no stale shares on Stratum ( or any shares ) since the DDos.
[EDIT] Great, now insta 2 stale shares on get work....
|
Always looking for donations even as low as 1uBTC 14XfpYPdtYiGoEiDcKrSzuvBM3ukhwANUh - BTC LS7FEfu9ajp3NQcDjui9TSKscwQesj9i8k - LTC LHe9g5ixMyfdtqAEHU5vErG1eQrDshBFRW -Luckycoin
|
|
|
solitude
|
|
April 23, 2013, 10:25:22 PM |
|
During the last ddos I mined for about ten hours on HHTT's pool, but never got a payout. Anyone know how long you have to mine with them before you are eligible for a payout?
|
Hardly anyone speaks English on this forum.
|
|
|
z1ppy
Newbie
Offline
Activity: 12
Merit: 0
|
|
April 23, 2013, 10:33:59 PM |
|
funny that.... swapped to getwork from Stratum since it's been 4 days and no shares ( usually 3 per day even if i am CPU mining) and ... insta share ( for a whole 0E-8 but it IS a share! ). Also, have had no stale shares on Stratum ( or any shares ) since the DDos.
[EDIT] Great, now insta 2 stale shares on get work....
is this a typical problem for you/others? i just started GPU mining a couple of weeks ago and don't know if i'm getting stale shares or not...but i'm getting paid every other day so how bad can it be? not mining at any sort of impressive rate, but it's working as proof of concept for future build plans btw, thx to slush for operating the pool. i see a lot of whining and complaining in this thread, but not too many thank yous. so thanks.
|
|
|
|
nottm28
|
|
April 23, 2013, 10:48:49 PM |
|
Those f**king DDoS:ers.. What's the point? Is it really that profitable to DDoS out sluch pool?
Can't be a coincidence that when BTC rises in value, Slush gets DDOS - interesting
|
donations not accepted
|
|
|
VishwaJay
Newbie
Offline
Activity: 56
Merit: 0
|
|
April 23, 2013, 10:55:43 PM |
|
It's almost as if they think he's somehow got coins stored on his computer or something...?
|
|
|
|
roukkie
Newbie
Offline
Activity: 29
Merit: 0
|
|
April 23, 2013, 10:59:28 PM |
|
also here miners dont work...
|
|
|
|
nottm28
|
|
April 23, 2013, 11:01:39 PM |
|
It's almost as if they think he's somehow got coins stored on his computer or something...?
Could just be a problem with amazon EC2 switch - just checked my ec2 cloud servers - runinng OK - this looks like another (boring achieve nothing) DDoS to me
|
donations not accepted
|
|
|
roukkie
Newbie
Offline
Activity: 29
Merit: 0
|
|
April 23, 2013, 11:09:58 PM |
|
but why the site up???
|
|
|
|
nottm28
|
|
April 23, 2013, 11:14:07 PM |
|
but why the site up???
Is it? Press F5 refresh - site is down I think
|
donations not accepted
|
|
|
roukkie
Newbie
Offline
Activity: 29
Merit: 0
|
|
April 23, 2013, 11:17:29 PM |
|
but why the site up???
Is it? Press F5 refresh - site is down I think its down for maintenance,but if was ddos we wouldnt get an error???
|
|
|
|
slush (OP)
Legendary
Offline
Activity: 1386
Merit: 1097
|
|
April 23, 2013, 11:19:03 PM Last edit: April 26, 2013, 12:02:31 AM by slush |
|
The pool has been hacked. Fortunately I noticed it fast enough, so I made database snapshot seconds before attackers overtake the database machine. I lost some amount of bitcoins, but I'll be able to recover it from my pocket. For now I'm evaluating what's next to do, because all machines in OVH has been compromised and they cannot be trusted anymore.
Full story: Today at 3pm UTC I noticed that somebody succesfully resetted the password to OVH manager, the place where servers can be managed, restarted to rescue mode etc. I promptly resetted the password at OVH to something different and I also changed password on my email account and checked that there're no other active connections to my mailbox. I have to say that my mailbox is secured by OTP passwords and I take physical security very seriously, so nobody other had an access to my mailbox. I known that password-reset feature is quite popular attack vector, so I made everything possible to prevent it to happen.
By changing the password at OVH, all other sessions using the old credentials are automatically kicked from the Manager. I also cross-checked that nothing wrong happen to the servers at this time. Unfortunately I didn't find a way how the attackers got access to Manager, so I asked OVH support to provide some additional information and restrict Manager access to my IP range.
That's no surprise that OVH didn't respond to this ticket for hours, but at 11pm UTC I realized that there's another succesful password reset at OVH. This is complete mystery to me, because I'm aboslutely sure that nobody else had access to my mailbox and the email with reset link has been untouched (unread, not deleted). I'd say that attacker won't bother by changing status of the email to "unread", but he'd delete the email instead.
This time I realized that the attacker resetted the machine with the wallet to rescue mode, which means that I lost the control to this machine. I was still succesful by logging into the database and I took the snapshot of database and transferred it to safe location. Few seconds since the migration finished, attackers restarted all remaining machines to rescue mode.
So far it looks like yet another inside job, like Linode two years ago. Or attackers found some shortcut how to gain access to Manager without confirming the request from the email. I don't know what's worse option. I'll investigate this issue in detail later and I hope OVH won't close eyes to this.
I can recover the pool to the normal operation tomorrow.
Edit 01:38 UTC: Stratum servers are running on safe servers at Amazon. Mining works for now. I'll setup new database and webserver on trusted machines in few hours, so the pool will be back in full operation.
Edit 25.04.2013: Bitcoin-central.net which is also hosted at OVH has been hacked today using the same method as described above. It confirms my theory that it was inside job/security issue at OVH and my email wasn't compromised at all.
|
|
|
|
zif33rs
|
|
April 23, 2013, 11:21:52 PM |
|
OFMG
|
New to bitcoin? Want to mine? Not sure where to start out? Check out www.hostedmining.comDonations and Tips btc - 1MkjKHpZbSaRepeYaAcmRMcqt8o3HKQCF ltc - LNz48TP8MZmke38qbZD5gXi53KrktbJG7V ftc - 6iDt92cyDvxXkrDhCzMh4zEmK1b9PqShs4
|
|
|
nottm28
|
|
April 23, 2013, 11:22:32 PM |
|
but why the site up???
Is it? Press F5 refresh - site is down I think its down for maintenance,but if was ddos we wouldnt get an error??? If it was DDoS - the tw*ts would be attacking the pool not the web site - so you may see the website work but your miners not mining - both are down (for me) so I think it's probably DDoS - but it could just be down to teething problems with amazon EC2 switch...
|
donations not accepted
|
|
|
solitude
|
|
April 23, 2013, 11:24:27 PM |
|
So none of our earned bitcoins will be lost?
|
Hardly anyone speaks English on this forum.
|
|
|
slush (OP)
Legendary
Offline
Activity: 1386
Merit: 1097
|
|
April 23, 2013, 11:25:07 PM |
|
So none of our earned bitcoins will be lost?
Ack.
|
|
|
|
|