Bitcoin Forum
May 30, 2024, 11:00:24 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 [3] 4 5 6 »  All
  Print  
Author Topic: Multiple YiiMP pools hacked, this is what we know so far..  (Read 15652 times)
CapeTownMinter
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
September 10, 2017, 12:29:52 AM
 #41

hi....I was mining on both Zpool and Yiimp...... it appears that Zpool also possibly hacked as they have been offline round about the same time as yiimp.
egyptianbman
Full Member
***
Offline Offline

Activity: 216
Merit: 100


https://equipool.1ds.us


View Profile WWW
September 10, 2017, 12:35:43 AM
 #42

hi....I was mining on both Zpool and Yiimp...... it appears that Zpool also possibly hacked as they have been offline round about the same time as yiimp.
Yes, both zpool and yiimp run on yiimp's mining software. Any pool running on yiimp is at-risk, if not already hacked.

Join our mining pool! https://equipool.1ds.us for equihash and https://cryptopool.1ds.us for other altcoins
Our EquiMiner for Windows makes switching between coins and mining software a breeze! https://equipool.1ds.us/getting_started
Only 0.5% pool fee! (BTCZ & BTCP: +0.5% donation to the community!)
CapeTownMinter
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
September 10, 2017, 01:20:24 AM
Last edit: September 10, 2017, 02:07:09 AM by CapeTownMinter
 #43

looks like i lost  about 26 bitsend and 50 featherCoin from Zpool and about 8 bitsend from yiimp ... about 2 day's and half worth of mining on my small rig  Angry
scryptr
Legendary
*
Offline Offline

Activity: 1796
Merit: 1028



View Profile WWW
September 10, 2017, 04:02:08 AM
 #44

YIIMP HAS TRACED SOME WALLET ADDRESSES--

The YIIMP pool maintained by tpruvot, the author of the YIIMP software, has left a trail to certain withdrawals by theft and subsequent deposits.  If the evidence of withdrawal by theft is provided to exchange management, there is a chance of recovery.

I did not loose any BSD mined on YIIMP.  Tpruvot likely reimbursed miners from his own pocket.       --scryptr

TIPS:  BTC - 1Fs4uZ6a9ABYBTaHGUfqcwCQmeBRxkKRQT    DASH - XrK81tW31SLsVvZ2WX9VhTjpT6GXJPLdbQ
          SCRYPTR'S NOTEBOOK: https://bitcointalk.org/index.php?topic=5035515.msg46035530#msg46035530
          GITHUB: "github.com/scryptr"  MERIT is appreciated, also.  Thanks!
CapeTownMinter
Member
**
Offline Offline

Activity: 87
Merit: 10


View Profile
September 10, 2017, 04:38:24 AM
 #45

yea i think my Yiimp bsd is safe....but i may have lost BSD and FTC on zpool .... i was waiting for currency to be exchanged and paid.
xtraelv
Legendary
*
Offline Offline

Activity: 1274
Merit: 1924


฿ear ride on the rainbow slide


View Profile
September 10, 2017, 05:21:46 AM
 #46

Could it be a repeat modified version of the BGP attacks that took place in 2014 ? http://www.zdnet.com/article/hacker-hijacks-isps-steals-83000-from-bitcoin-mining-pools/

We are surrounded by legends on this forum. Phenomenal successes and catastrophic failures. Then there are the scams. This forum is a digital museum.  
* The most iconic historic bitcointalk threads.* Satoshi * Cypherpunks*MtGox*Bitcointalk hacks*pHiShInG* Silk Road*Pirateat40*Knightmb*Miner shams*Forum scandals*BBCode*
Troll spotting*Thank you to madnessteat for my custom avatar hat.
Bulletdodger
Sr. Member
****
Offline Offline

Activity: 337
Merit: 250



View Profile
September 10, 2017, 08:25:29 AM
 #47

Any news about zpool, I am still mining there, and receiving some payments...

_
crombiecrunch
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
September 10, 2017, 12:42:56 PM
 #48

So I ran wapiti again on my site after loading the last code from the githib. The XSS vulnerability still shows.

But when I run wapiti against some of the other sites, some show the vulnerability and some dont.

There hasn't been any more code updates though. Could we get a solution shared?
Decker
Member
**
Offline Offline

Activity: 119
Merit: 61


View Profile
September 10, 2017, 02:52:41 PM
 #49

Have somebody recovered lds.php or logged the cookies payload used in php object injection by attackers through unserialize() funcs? Interesting to understand this attack vector more completely.

crackfoo
Legendary
*
Offline Offline

Activity: 3486
Merit: 1126



View Profile WWW
September 10, 2017, 02:53:13 PM
 #50

Any news about zpool, I am still mining there, and receiving some payments...

no balances will end up not being paid or cleared. It's the risk of running a pool. This hack caused a major overload of work to do to update wallets and transfer balance from old to new. It doesn't help that two of my servers crashed a burned this week too so trying to rebuilding those as well. One still hasn't identified the cause, the other had the CacheCade SSD replaced yesterday. They'll all get caught up for payments, just patients is needed.

Hang in there,

Cheers

ZPOOL - the miners multipool! Support We pay 10 FLUX Parallel Assets (PA) directly to block rewards! Get paid more and faster. No PA fee's or waiting around for them, paid instantly on every block found!
bney
Full Member
***
Offline Offline

Activity: 333
Merit: 100



View Profile
September 10, 2017, 03:03:40 PM
 #51

Appreciate the work you do. This has got to be costing you sleep and making your hair go grey
crackfoo
Legendary
*
Offline Offline

Activity: 3486
Merit: 1126



View Profile WWW
September 10, 2017, 07:34:31 PM
 #52

We're back online with the frontend and api.


ZPOOL - the miners multipool! Support We pay 10 FLUX Parallel Assets (PA) directly to block rewards! Get paid more and faster. No PA fee's or waiting around for them, paid instantly on every block found!
bney
Full Member
***
Offline Offline

Activity: 333
Merit: 100



View Profile
September 10, 2017, 10:38:39 PM
 #53

Looks like a few minor things missing. icons,  and coins mined on the wallet display screen
crackfoo
Legendary
*
Offline Offline

Activity: 3486
Merit: 1126



View Profile WWW
September 10, 2017, 11:26:08 PM
 #54

Looks like a few minor things missing. icons,  and coins mined on the wallet display screen

Hrmm seem fine on my side... I'll check into it more I'm back on a terminal.

ZPOOL - the miners multipool! Support We pay 10 FLUX Parallel Assets (PA) directly to block rewards! Get paid more and faster. No PA fee's or waiting around for them, paid instantly on every block found!
tazmako
Full Member
***
Offline Offline

Activity: 350
Merit: 100


XDNA - Most innovative cryptocurrency in 2018


View Profile
September 10, 2017, 11:35:06 PM
 #55

How long for all pool got fix?

XDNA ❱❭ Dynamic. New. Adaptable.
Revolution in PoW GPU mining | Innovation in Masternode investing
° BitGun ° T.N.T. ° XDNA Foundation °
Stable block reward even with a 10000% increase of hashrate![/url]
                 |Website| Whitepaper| Discord| Telegram | Github|                
bney
Full Member
***
Offline Offline

Activity: 333
Merit: 100



View Profile
September 11, 2017, 12:08:32 AM
 #56

All looking good on Zpool. Thanks for the hard work.
okane818
Legendary
*
Offline Offline

Activity: 1176
Merit: 1000



View Profile
September 11, 2017, 03:07:34 AM
 #57

I think there is a manipulation inside.
I mean the one making to this is only the insider.

Making reason to cover. That is an old reason to believe. NOT NEW!

That's it.


Thank you.
doktor83
Hero Member
*****
Offline Offline

Activity: 2548
Merit: 626


View Profile WWW
September 11, 2017, 05:29:38 AM
 #58

Looks like a few minor things missing. icons,  and coins mined on the wallet display screen

Hrmm seem fine on my side... I'll check into it more I'm back on a terminal.

only the top menu shows, clicking the menu links does nothing.

SRBMiner-MULTI thread - HERE
http://www.srbminer.com
lyolyalya
Sr. Member
****
Offline Offline

Activity: 455
Merit: 250


View Profile
September 11, 2017, 06:46:00 AM
 #59

Looks like a few minor things missing. icons,  and coins mined on the wallet display screen

Hrmm seem fine on my side... I'll check into it more I'm back on a terminal.

only the top menu shows, clicking the menu links does nothing.
confirmed=)
enkayz
Full Member
***
Offline Offline

Activity: 298
Merit: 100

hashbag.cc


View Profile WWW
September 11, 2017, 07:02:46 AM
 #60

hashbag also back online.

have made all the payments to miners that were stolen/delayed, cost me some of my own funds but at least this time I had spare funds for it. servers locked down much harder, hopefully this doesn't happen again..

i don't really charge much fees but maybe I should begin moving what I -do- get out of the pool Tongue

hashbag.cc - where do you put your hash? region based stratums available now: https://bitcointalk.org/index.php?topic=2044808.new
Pages: « 1 2 [3] 4 5 6 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!