Bitcoin Forum
April 25, 2024, 07:09:25 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 [330] 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 ... 1154 »
  Print  
Author Topic: [4+ EH] Slush Pool (slushpool.com); Overt AsicBoost; World First Mining Pool  (Read 4381856 times)
crunchyferrett
Newbie
*
Offline Offline

Activity: 26
Merit: 0



View Profile
April 23, 2013, 09:52:32 PM
 #6581

FAQBot seems to have died in IRC, as well.

Small potatoes when the pool is down, I admit, but still needs to be brought to someone's attention.
1714028965
Hero Member
*
Offline Offline

Posts: 1714028965

View Profile Personal Message (Offline)

Ignore
1714028965
Reply with quote  #2

1714028965
Report to moderator
"Governments are good at cutting off the heads of a centrally controlled networks like Napster, but pure P2P networks like Gnutella and Tor seem to be holding their own." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714028965
Hero Member
*
Offline Offline

Posts: 1714028965

View Profile Personal Message (Offline)

Ignore
1714028965
Reply with quote  #2

1714028965
Report to moderator
1714028965
Hero Member
*
Offline Offline

Posts: 1714028965

View Profile Personal Message (Offline)

Ignore
1714028965
Reply with quote  #2

1714028965
Report to moderator
1714028965
Hero Member
*
Offline Offline

Posts: 1714028965

View Profile Personal Message (Offline)

Ignore
1714028965
Reply with quote  #2

1714028965
Report to moderator
camaro69327
Newbie
*
Offline Offline

Activity: 59
Merit: 0



View Profile
April 23, 2013, 09:54:25 PM
Last edit: April 23, 2013, 10:06:02 PM by camaro69327
 #6582

I'm investigating it.
...well ya did something....miners just started back up...good Job


Edit to Say:....is it Cgminer that is giving really weird #'s or is something amis on your end ...I like the #'s but know they are not Right...hahha

My 300 Mhash is getting 500 Mhash
660 Mhash is saying 1.2 Ghash..I wish its only a 7970...hahha
phazedoubt
Newbie
*
Offline Offline

Activity: 18
Merit: 0



View Profile
April 23, 2013, 09:56:35 PM
 #6583

Does it seem to be a secondary problem caused by Ddos?  Have you tried moving behind Cloudflare?  May be way off base, just shooting in the dark.
dmphotog
Newbie
*
Offline Offline

Activity: 17
Merit: 0



View Profile
April 23, 2013, 10:02:07 PM
 #6584

Mine are not connecting at all. I know you're working on it though. Just thought you should know.

I will wait patiently.
 Undecided
VacantPaper
Newbie
*
Offline Offline

Activity: 28
Merit: 0



View Profile
April 23, 2013, 10:02:33 PM
 #6585

Website isn't working for me, or stratum.

Care to explain?
dellnull
Newbie
*
Offline Offline

Activity: 30
Merit: 0


View Profile
April 23, 2013, 10:04:31 PM
 #6586

Those f**king DDoS:ers.. What's the point? Is it really that profitable to DDoS out sluch pool?
nybbler905
Full Member
***
Offline Offline

Activity: 213
Merit: 100



View Profile
April 23, 2013, 10:12:06 PM
 #6587

funny that.... swapped to getwork from Stratum since it's been 4 days and no shares ( usually 3 per day even if i am CPU mining) and ... insta share ( for a whole 0E-8 but it IS a share! ).  Also, have had no stale shares on Stratum ( or any shares ) since the DDos.

[EDIT]
Great, now insta 2 stale shares on get work....

Always looking for donations even as low as 1uBTC
14XfpYPdtYiGoEiDcKrSzuvBM3ukhwANUh - BTC
LS7FEfu9ajp3NQcDjui9TSKscwQesj9i8k - LTC
LHe9g5ixMyfdtqAEHU5vErG1eQrDshBFRW -Luckycoin
solitude
Hero Member
*****
Offline Offline

Activity: 674
Merit: 500


View Profile
April 23, 2013, 10:25:22 PM
 #6588

During the last ddos I mined for about ten hours on HHTT's pool, but never got a payout.  Anyone know how long you have to mine with them before you are eligible for a payout?

Hardly anyone speaks English on this forum.
z1ppy
Newbie
*
Offline Offline

Activity: 12
Merit: 0



View Profile
April 23, 2013, 10:33:59 PM
 #6589

funny that.... swapped to getwork from Stratum since it's been 4 days and no shares ( usually 3 per day even if i am CPU mining) and ... insta share ( for a whole 0E-8 but it IS a share! ).  Also, have had no stale shares on Stratum ( or any shares ) since the DDos.

[EDIT]
Great, now insta 2 stale shares on get work....

is this a typical problem for you/others? i just started GPU mining a couple of weeks ago and don't know if i'm getting stale shares or not...but i'm getting paid every other day so how bad can it be? not mining at any sort of impressive rate, but it's working as proof of concept for future build plans  Cool

btw, thx to slush for operating the pool. i see a lot of whining and complaining in this thread, but not too many thank yous. so thanks.
nottm28
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
April 23, 2013, 10:48:49 PM
 #6590

Those f**king DDoS:ers.. What's the point? Is it really that profitable to DDoS out sluch pool?

Can't be a coincidence that when BTC rises in value, Slush gets DDOS - interesting

donations not accepted
VishwaJay
Newbie
*
Offline Offline

Activity: 56
Merit: 0



View Profile
April 23, 2013, 10:55:43 PM
 #6591

It's almost as if they think he's somehow got coins stored on his computer or something...?
roukkie
Newbie
*
Offline Offline

Activity: 29
Merit: 0



View Profile
April 23, 2013, 10:59:28 PM
 #6592

also here miners dont work...
nottm28
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
April 23, 2013, 11:01:39 PM
 #6593

It's almost as if they think he's somehow got coins stored on his computer or something...?

Could just be a problem with amazon EC2 switch - just checked my ec2 cloud servers - runinng OK - this looks like another (boring achieve nothing) DDoS to me

donations not accepted
roukkie
Newbie
*
Offline Offline

Activity: 29
Merit: 0



View Profile
April 23, 2013, 11:09:58 PM
 #6594

but why the site up???
nottm28
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
April 23, 2013, 11:14:07 PM
 #6595

but why the site up???

Is it? Press F5 refresh - site is down I think

donations not accepted
roukkie
Newbie
*
Offline Offline

Activity: 29
Merit: 0



View Profile
April 23, 2013, 11:17:29 PM
 #6596

but why the site up???

Is it? Press F5 refresh - site is down I think


its down for maintenance,but if was ddos we wouldnt get an error???
slush (OP)
Legendary
*
Offline Offline

Activity: 1386
Merit: 1097



View Profile WWW
April 23, 2013, 11:19:03 PM
Last edit: April 26, 2013, 12:02:31 AM by slush
 #6597

The pool has been hacked. Fortunately I noticed it fast enough, so I made database snapshot seconds before attackers overtake the database machine. I lost some amount of bitcoins, but I'll be able to recover it from my pocket. For now I'm evaluating what's next to do, because all machines in OVH has been compromised and they cannot be trusted anymore.

Full story:
Today at 3pm UTC I noticed that somebody succesfully resetted the password to OVH manager, the place where servers can be managed, restarted to rescue mode etc. I promptly resetted the password at OVH to something different and I also changed password on my email account and checked that there're no other active connections to my mailbox. I have to say that my mailbox is secured by OTP passwords and I take physical security very seriously, so nobody other had an access to my mailbox. I known that password-reset feature is quite popular attack vector, so I made everything possible to prevent it to happen.

By changing the password at OVH, all other sessions using the old credentials are automatically kicked from the Manager. I also cross-checked that nothing wrong happen to the servers at this time. Unfortunately I didn't find a way how the attackers got access to Manager, so I asked OVH support to provide some additional information and restrict Manager access to my IP range.

That's no surprise that OVH didn't respond to this ticket for hours, but at 11pm UTC I realized that there's another succesful password reset at OVH. This is complete mystery to me, because I'm aboslutely sure that nobody else had access to my mailbox and the email with reset link has been untouched (unread, not deleted). I'd say that attacker won't bother by changing status of the email to "unread", but he'd delete the email instead.

This time I realized that the attacker resetted the machine with the wallet to rescue mode, which means that I lost the control to this machine. I was still succesful by logging into the database and I took the snapshot of database and transferred it to safe location. Few seconds since the migration finished, attackers restarted all remaining machines to rescue mode.

So far it looks like yet another inside job, like Linode two years ago. Or attackers found some shortcut how to gain access to Manager without confirming the request from the email. I don't know what's worse option. I'll investigate this issue in detail later and I hope OVH won't close eyes to this.

I can recover the pool to the normal operation tomorrow.

Edit 01:38 UTC: Stratum servers are running on safe servers at Amazon. Mining works for now. I'll setup new database and webserver on trusted machines in few hours, so the pool will be back in full operation.

Edit 25.04.2013: Bitcoin-central.net which is also hosted at OVH has been hacked today using the same method as described above. It confirms my theory that it was inside job/security issue at OVH and my email wasn't compromised at all.

zif33rs
Full Member
***
Offline Offline

Activity: 196
Merit: 100



View Profile
April 23, 2013, 11:21:52 PM
 #6598

OFMG  Embarrassed

New to bitcoin? Want to mine? Not sure where to start out?
Check out www.hostedmining.com
Donations and Tips  btc - 1MkjKHpZbSaRepeYaAcmRMcqt8o3HKQCF   ltc  - LNz48TP8MZmke38qbZD5gXi53KrktbJG7V  ftc  - 6iDt92cyDvxXkrDhCzMh4zEmK1b9PqShs4
nottm28
Hero Member
*****
Offline Offline

Activity: 574
Merit: 500



View Profile
April 23, 2013, 11:22:32 PM
 #6599

but why the site up???

Is it? Press F5 refresh - site is down I think


its down for maintenance,but if was ddos we wouldnt get an error???

If it was DDoS - the tw*ts would be attacking the pool not the web site - so you may see the website work but your miners not mining - both are down (for me) so I think it's probably DDoS - but it could just be down to teething problems with amazon EC2 switch...

donations not accepted
solitude
Hero Member
*****
Offline Offline

Activity: 674
Merit: 500


View Profile
April 23, 2013, 11:24:27 PM
 #6600

So none of our earned bitcoins will be lost?

Hardly anyone speaks English on this forum.
Pages: « 1 ... 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 [330] 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 ... 1154 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!