Bitcoin Forum
April 28, 2024, 08:29:20 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 ... 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 [159] 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 ... 294 »
  Print  
Author Topic: [POOL][Scrypt][Scrypt-N][X11] Profit switching pool - wafflepool.com  (Read 465522 times)
comeonalready
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
March 23, 2014, 12:15:45 PM
Last edit: March 24, 2014, 12:15:32 AM by comeonalready
 #3161

The only reason I can think of for a redirect rather than just a hijacking is to allow him to repoint to various compromised servers.  Enable a MITM for a few seconds, redirect some traffic to a compromised box, turn off MITM.  Very difficult to see/catch the MITM happening if its only there for a few seconds, and the results (the redirected miners) will continue happily along for a while.

If he is only sending outgoing client.reconnect message packets to miners, and not rewriting incoming mining.authorize packets from miners, then the rogue stratum server to which he is redirecting hashpower is receiving the original user/pass, or in the case of wafflepool, the original btc address, and ignoring it -- which would mean it is completely under his control.

[changed my mind about this middle part of the post that I removed, and if you saw it then please note that a true mitm could circumvent all of my suggestions originally contained within]

For now, anyone downloading the miner code directly from github can change the client.reconnect command message text string to something else prior to compilation in order to insulate yourself from this current problem.
1714292961
Hero Member
*
Offline Offline

Posts: 1714292961

View Profile Personal Message (Offline)

Ignore
1714292961
Reply with quote  #2

1714292961
Report to moderator
BitcoinCleanup.com: Learn why Bitcoin isn't bad for the environment
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714292961
Hero Member
*
Offline Offline

Posts: 1714292961

View Profile Personal Message (Offline)

Ignore
1714292961
Reply with quote  #2

1714292961
Report to moderator
1714292961
Hero Member
*
Offline Offline

Posts: 1714292961

View Profile Personal Message (Offline)

Ignore
1714292961
Reply with quote  #2

1714292961
Report to moderator
1714292961
Hero Member
*
Offline Offline

Posts: 1714292961

View Profile Personal Message (Offline)

Ignore
1714292961
Reply with quote  #2

1714292961
Report to moderator
poolwaffle (OP)
Sr. Member
****
Offline Offline

Activity: 322
Merit: 254


View Profile
March 23, 2014, 01:21:05 PM
 #3162

The only reason I can think of for a redirect rather than just a hijacking is to allow him to repoint to various compromised servers.  Enable a MITM for a few seconds, redirect some traffic to a compromised box, turn off MITM.  Very difficult to see/catch the MITM happening if its only there for a few seconds, and the results (the redirected miners) will continue happily along for a while.


Check this out: https://bitcointalk.org/index.php?topic=434464.msg5848594#msg5848594

It seems that Betarigs miners are having similar problem with stratum reconnect/hi-jacking?

This is actually very interesting.  One of the users we had seen an issue with originally has a backup pool as betarigs.

Can anyone else who has had the issue post if they have a backup pool set for betarigs?
Meeho
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
March 23, 2014, 01:25:31 PM
 #3163

No, mine was CleverMining.
poolwaffle (OP)
Sr. Member
****
Offline Offline

Activity: 322
Merit: 254


View Profile
March 23, 2014, 01:26:19 PM
 #3164

No, mine was CleverMining.

And you had the issue happen to you?
comeonalready
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
March 23, 2014, 01:27:00 PM
 #3165

The only reason I can think of for a redirect rather than just a hijacking is to allow him to repoint to various compromised servers.  Enable a MITM for a few seconds, redirect some traffic to a compromised box, turn off MITM.  Very difficult to see/catch the MITM happening if its only there for a few seconds, and the results (the redirected miners) will continue happily along for a while.


Check this out: https://bitcointalk.org/index.php?topic=434464.msg5848594#msg5848594

It seems that Betarigs miners are having similar problem with stratum reconnect/hi-jacking?

This is actually very interesting.  One of the users we had seen an issue with originally has a backup pool as betarigs.

Can anyone else who has had the issue post if they have a backup pool set for betarigs?

Had the running stratum server code been updated to the patched version correcting the idling problem before all this client.reconnect stuff started happening?  -- as cgminer/kcgminer/sgminer users are much more likely to be leaking work to their backup pools if the older code still remains running on the server.  I would not recommend changing up any the variables right now in the middle of troubleshooting, but it would a good thing to know.
ycsi
Member
**
Offline Offline

Activity: 84
Merit: 10


View Profile
March 23, 2014, 01:28:05 PM
 #3166

No, mine was CleverMining.

And you had the issue happen to you?

Is it possible that one of the multipools is using cryptovein for mining?
Meeho
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
March 23, 2014, 01:31:54 PM
 #3167

No, mine was CleverMining.

And you had the issue happen to you?

Yes:
https://bitcointalk.org/index.php?topic=433634.msg5844746#msg5844746
https://bitcointalk.org/index.php?topic=433634.msg5853878#msg5853878


I tried to do a traceroute on the ip and it times out after a couple hops from my isp to max of 30 hops ...

anybody do a whois on it?  I don't know command on winblowz.  Suppose I could fire up LMDE in a Virtualbox and try ...

I got this: http://whois.domaintools.com/206.223.224.225
comeonalready
Full Member
***
Offline Offline

Activity: 168
Merit: 100


View Profile
March 23, 2014, 01:35:43 PM
 #3168

I reviewed all my firewall logs (network edge has stateful packet inspection enabled) and did not find any dropped incoming tcp packets from port 3333 on either the hardware or software firewalls, and as my miners never switched to a different pool, it does not appear as if I ever received a client.reconnect message.  Connecting to the useast server.
jedimstr
Hero Member
*****
Offline Offline

Activity: 798
Merit: 1000



View Profile
March 23, 2014, 01:59:45 PM
 #3169

This could still be a MITM attack via DNS Hijacking at Google's nameservers.

Keep in mind that Google has had very recent issues with DNS hijacking over the last week:
http://arstechnica.com/information-technology/2014/03/google-dns-briefly-hijacked-to-venezuela/

Also note that majority of the people posting here for the last few pages with the issue are using Google's DNS servers: 8.8.8.8 and 8.8.4.4

Is there ANYONE who has encountered this hijacking that aren't using Google's DNS servers either on the client or router level?

For instance, I did NOT encounter this hijack issue and I'm using Verizon's local FiOS dedicated DNS servers.

Meeho
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile
March 23, 2014, 02:04:21 PM
 #3170

I use my ISP's DNS servers and had the problem. I think DNS hijack was ruled out, as there is a port change and miner reports being connected to the new server, not showing wafflepool's name anymore. And my separate pings to eu.wafflepool.com showed correct DNS resolving.
Crunchtac
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
March 23, 2014, 02:24:33 PM
 #3171

Poolwaffle, I've PM'd you another network capture Smiley
bit_coin_genuis
Newbie
*
Offline Offline

Activity: 38
Merit: 0


View Profile
March 23, 2014, 02:25:26 PM
 #3172

Hi,

Was wondering why you don't add REDD COIN.  It is more profitable than most of the coins mined on waffle ...

cheers,

miless2111s
Newbie
*
Offline Offline

Activity: 55
Merit: 0


View Profile
March 23, 2014, 03:01:11 PM
 #3173

Hi,

Was wondering why you don't add REDD COIN.  It is more profitable than most of the coins mined on waffle ...

cheers,



There was a post a few pages (well more like 10 I suspect) where we were asked to provide things like the depth of the market (not less than 3BTC as I remember) for PW to consider adding coins - how does REDD look against these criteria?

Miles
FrankieSaysRelax
Member
**
Offline Offline

Activity: 98
Merit: 10


View Profile
March 23, 2014, 03:06:32 PM
 #3174

I;ve been making twice as much mining GPUCoin than I have on WP 8-(
rebweb
Newbie
*
Offline Offline

Activity: 7
Merit: 0


View Profile
March 23, 2014, 03:52:48 PM
 #3175

I was wondering why am I not getting paid my btc? http://wafflepool.com/miner/16oV1eHgFWN5yGu6hexB4ziUhKRiE8FYYv
It's been over 24 hours that my balance is over 0.01 btc.
Rock6.3
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile
March 23, 2014, 04:23:24 PM
 #3176

I was wondering why am I not getting paid my btc? http://wafflepool.com/miner/16oV1eHgFWN5yGu6hexB4ziUhKRiE8FYYv
It's been over 24 hours that my balance is over 0.01 btc.

Operator has been actively fighting/tracking a malware that was stealing hashrate.

However, payments just processed.
fcmatt
Legendary
*
Offline Offline

Activity: 2072
Merit: 1001


View Profile
March 23, 2014, 06:09:25 PM
 #3177

What is the easiest way to determine if this problem is affecting my miners? What to look for?
Teltor
Newbie
*
Offline Offline

Activity: 10
Merit: 0


View Profile
March 23, 2014, 06:10:00 PM
 #3178

I'm thinking about mining with you guys again. What has the average btc/mh been lately? separate from redirect issue
ingrown
Newbie
*
Offline Offline

Activity: 15
Merit: 0


View Profile
March 23, 2014, 06:14:52 PM
 #3179

I'm thinking about mining with you guys again. What has the average btc/mh been lately? separate from redirect issue

This is pretty accurate: http://wafflepool.com/stats
rallasnackbar
Full Member
***
Offline Offline

Activity: 196
Merit: 100


View Profile
March 23, 2014, 06:16:36 PM
 #3180

I sure dont hope we have funds on vircurex atm... BTC, LTC, TRC and FTC funds are getting frozen, so you cant withdraw or spend them.


https://vircurex.com/welcome/ann_reserved.html
Pages: « 1 ... 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 [159] 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 ... 294 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!