Bitcoin Forum
July 02, 2024, 04:16:29 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Dont buy miners from lketc.com Locked out SSH root to user, Stealing your hashes  (Read 10824 times)
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 09, 2014, 06:48:23 AM
Last edit: June 09, 2014, 07:02:16 AM by cryptoceelo
 #21


But I found a link related to the SD card in other forums.

https://dl.dropboxusercontent.com/u/92967009/dragon_image.7z  


Is this one a fresher boot image? Does it have English UI?

Thanks!

I have the same iso at home where i translated the index.html from chinc to english and removed all the branding from the company, but even that iso has a cron script that constantly replaces the webroot with original branded files, even then i couldnt work out where that is being copied from. try it by editing the index and you will see it change back to the original, i had to change the default index file in lightppd lol (try it yourself and see) but that iso is at home and im currently in czech



Here is the English version : https://www.dropbox.com/s/yz02suc4j24ium4/dragonboot-4BLADE-ENG.7z

But it can only be used to Windows, not Mac.

Thanks.

Thanks, but got that one Smiley Have anything fresher?

i will post my english version with updated lighthttpd when i am home for you

Wow, another company on the avoid list.

Defiantly avoid especially since the yellow belled snakes wont even explain why.

Jesus that's terrible I will not be buying any units from them, I wonder if the closed off OS has you balanced mining on one of there pools.
Like i said i left the farm mining on our machines to return in the morning to find them mining on theirs

Aren't you able to reset it to factory defaults somehow? Also this is really negative feedback for them, not allowing someone who bought something access to it? That's insane.

They are the factory so i guess it is their default Cheesy their Default shitnami iso


But I found a link related to the SD card in other forums.

https://dl.dropboxusercontent.com/u/92967009/dragon_image.7z  


Is this one a fresher boot image? Does it have English UI?

Thanks!

Here is the English version : https://www.dropbox.com/s/yz02suc4j24ium4/dragonboot-4BLADE-ENG.7z

But it can only be used to Windows, not Mac.

Thanks.
Think your confused dearest Lisa, the iso is used on the miners and is a linux distro, it doesnt matter if you use mac or windowzzz

To paraphrase jim Layhey

Quote
You know, iketc grew up as a little shit-spark from the old shit-flint. And then he turned into a shit-bonfire and then driven by the winds of their monumental ignorance, he turned into a raging shit-firestorm. If I have my way, then I will unleash a shitnami tidal wave that'll engulf iketc and extinguish their shit-flames forever. And with any luck, they'll drown in the undershit of that wave. Shit-waves.
psahx
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
June 09, 2014, 06:59:05 AM
 #22


i will post my english version with updated lighthttpd when i am home for you

Thanks a lot! Can you tell me, whats the advantage of yours?

P.S. Dekuji za pomoc. Smiley Preji pekny zbytek dne.
Justin00
Legendary
*
Offline Offline

Activity: 910
Merit: 1000


★YoBit.Net★ 350+ Coins Exchange & Dice


View Profile
June 09, 2014, 07:05:05 AM
 #23

i understand what root is for as I am very familiar with *nix
but do you need root to setup/use the system ?
sometimes manufactoruers dont want you messing with the vitals ?

I am not sticking up for them or defending!! I am just asking a question.

sounds like you have been fucked around and I would not of been happy either if I was you!

cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 09, 2014, 07:09:05 AM
 #24


i will post my english version with updated lighthttpd when i am home for you

Thanks a lot! Can you tell me, whats the advantage of yours?

P.S. Dekuji za pomoc. Smiley Preji pekny zbytek dne.

HAHA velmi dobrý, ale moje čeština je špatná, im z Anglie


It's exactly the same as the version i posted in the mega link, but the interface translated to UK, and the default index file in lightppd config changed from index.html to default.html so that the cron script doesnt constatly write over your changes. I guess the cron script copies original files from somewhere to web folder, but like i said i couldn't find out where from.

i understand what root is for as I am very familiar with *nix
but do you need root to setup/use the system ?
sometimes manufactoruers dont want you messing with the vitals ?

I am not sticking up for them or defending!! I am just asking a question.

sounds like you have been fucked around and I would not of been happy either if I was you!
You dont need root to setup the system it can be done from the interface, which is fine managing a few machines, we are running a 100 for a test with the plan of running hell alot more, to make this easier, i developed a web program called 'smart Farm' that automated deployment and setup of the miners, as well as allowing you to remotely manage them and access all cgminer statistics, which required SSH and access to CGminer API to open listen. The iso shipped did not have cgminer API open so could not be turned on unless you had root. It also made it impossible to debug any issues. i understand they might not want you to mess around with settings but at the end of the day the chinese really dont care if you bork your system because then you just have to buy a new one from them or pay them to fix it Cheesy all they care about is da moonies
psahx
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
June 09, 2014, 07:18:18 AM
 #25

i understand what root is for as I am very familiar with *nix
but do you need root to setup/use the system ?
sometimes manufactoruers dont want you messing with the vitals ?

I am not sticking up for them or defending!! I am just asking a question.

sounds like you have been fucked around and I would not of been happy either if I was you!

My situation was, that miners will not connect to the pools I input. Wanted to SSH, to ping the server from the PI. Default password was not working, so I have contacted my reseller, which has denied me with the access. I was in an impression, that the reseller is the one, who does not want me to have the SSH access, so I quited talking to him, and found the original English dragon 4 blade boot image here https://bitcointalk.org/index.php?topic=485497.msg6378219#msg6378219 and flashed the SD cards with it. And it worked straight away.

After that I have noticed, that cryptoceelo has the same problem with his 100 dragons, and that he can not get the access directly form the LKETC. That said, I am pretty much confident, that my reseller did not have the access either, so he just refused me, without going into the details and explaining, why he does not have the credentials.

Regarding messing with vitals, I think Raspberry PI boot is an open source project, isn't it? Or even if not, when you buy a Linux or Windows distributive, it comes with root level access right Smiley Same when you buy a hardware, with preinstalled firmware. Normal companies will give you the access, if you know where to ask:) If not, there is always a way to gain it.

Cheers
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 09, 2014, 07:22:04 AM
 #26

i understand what root is for as I am very familiar with *nix
but do you need root to setup/use the system ?
sometimes manufactoruers dont want you messing with the vitals ?

I am not sticking up for them or defending!! I am just asking a question.

sounds like you have been fucked around and I would not of been happy either if I was you!

My situation was, that miners will not connect to the pools I input. Wanted to SSH, to ping the server from the PI. Default password was not working, so I have contacted my reseller, which has denied me with the access. I was in an impression, that the reseller is the one, who does not want me to have the SSH access, so I quited talking to him, and found the original English dragon 4 blade boot image here https://bitcointalk.org/index.php?topic=485497.msg6378219#msg6378219 and flashed the SD cards with it. And it worked straight away.

After that I have noticed, that cryptoceelo has the same problem with his 100 dragons, and that he can not get the access directly form the LKETC. That said, I am pretty much confident, that my reseller did not have the access either, so he just refused me, without going into the details and explaining, why he does not have the credentials.

Regarding messing with vitals, I think Raspberry PI boot is an open source project, isn't it? Or even if not, when you buy a Linux or Windows distributive, it comes with root level access right Smiley Same when you buy a hardware, with preinstalled firmware. Normal companies will give you the access, if you know where to ask:) If not, there is always a way to gain it.

Cheers

Good point you just made linux is open source by closing it off they are breaking the licensing agreement. then again the chinese dont give a fuck about copyright -> http://en.wikipedia.org/wiki/Wonderland_Amusement_Park_(Beijing) Cheesy
psahx
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
June 09, 2014, 07:25:21 AM
 #27


HAHA velmi dobrý, ale moje čeština je špatná, im z Anglie


It's exactly the same as the version i posted in the mega link, but the interface translated to UK, and the default index file in lightppd config changed from index.html to default.html so that the cron script doesnt constatly write over your changes. I guess the cron script copies original files from somewhere to web folder, but like i said i couldn't find out where from.


Then you do not need to post it, if it is the same, do not want to mess with a working system Smiley

P.S. I live in US, but I have got my BA from VSFS Prague, lived and studied there for 6 years. Miss it so much;)
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 09, 2014, 07:41:48 AM
 #28


HAHA velmi dobrý, ale moje čeština je špatná, im z Anglie


It's exactly the same as the version i posted in the mega link, but the interface translated to UK, and the default index file in lightppd config changed from index.html to default.html so that the cron script doesnt constatly write over your changes. I guess the cron script copies original files from somewhere to web folder, but like i said i couldn't find out where from.


Then you do not need to post it, if it is the same, do not want to mess with a working system Smiley

P.S. I live in US, but I have got my BA from VSFS Prague, lived and studied there for 6 years. Miss it so much;)

changing a html file and the index root wont cause any issue, we run these with the web server off for additional security.

Im only here building the farm, but prague is beautiful
pandacoin
Legendary
*
Offline Offline

Activity: 1554
Merit: 1000


View Profile
June 09, 2014, 07:43:36 AM
 #29

Thanks for letting us know. These days we can't trust any company, sadly.
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 09, 2014, 01:39:09 PM
 #30

Yes unfortunate you have to still be extremely careful with what are perceived to be legit companies

Any way fuck lketc and their clandestine ways, they are not the biggest issue now heat is
Versatile
Newbie
*
Offline Offline

Activity: 14
Merit: 0


View Profile WWW
June 11, 2014, 09:33:01 PM
 #31

well this problem came to me also and with help of cryptoceelo finally i have fixed it. so i just wrote a tutorial to help peoples regarding this with special thanks to cryptoceelo who came up with this issue infront of world and helped me a lot to learn something new.
Code:
https://bitcointalk.org/index.php?topic=648730.0
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 12, 2014, 08:01:28 AM
 #32

Thanks man no worries for the help


UPDATE

We had a few psu burn out, so we took them to a repair shop in the area, when the technician opened up the unit, he found that the power supply is in fact a 650watt power supply in a 1050watt casing, even more we have been checking the power draw on a standard not over clocked system to be 1260 average highest reading 1380watt.

So the chinese strike again with fake power supplies and tech that doesnt perform as advertised.

Stay clear of LKetc
psahx
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
June 12, 2014, 09:20:34 AM
 #33

Thanks man no worries for the help


UPDATE

We had a few psu burn out, so we took them to a repair shop in the area, when the technician opened up the unit, he found that the power supply is in fact a 650watt power supply in a 1050watt casing, even more we have been checking the power draw on a standard not over clocked system to be 1260 average highest reading 1380watt.

So the chinese strike again with fake power supplies and tech that doesnt perform as advertised.

Stay clear of LKetc

Man, it is gonna be some kind of deja-vu thingy Smiley It seems, whatever happens to you, happens to me too:) Just today got failover twice on one of my dragons, the PSU will shut itself down completely. Will not start again, until cooled properly. I think I need to replace the PSU, until it is too late:) Can you tell me how to check, if I got the same 650W inside a 1000 case?

Thanks again!
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 12, 2014, 05:42:24 PM
 #34

I have pictures of the psu compared to the correct ones but cant uplaod atm as im at the airport, the 650w psu say 650watt on the mobo of the psu i can see mine through the fan grill, also check your power consumption all ours are running above 1200watt which isnt as advertised
psahx
Full Member
***
Offline Offline

Activity: 154
Merit: 100


View Profile
June 12, 2014, 05:43:43 PM
 #35

Got it, thanks!
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
June 19, 2014, 11:53:39 AM
 #36

So finally i was right about my paranoia in some way, confirmed Chinese ship hardware pre installed with spyware
jdot007
Member
**
Offline Offline

Activity: 73
Merit: 10


View Profile
June 19, 2014, 09:07:57 PM
 #37

Could you please be a bit more specific? I'll like to make sure my units aren't infected.

paranoia indeed

 
Smallminerpretendingbig
Newbie
*
Offline Offline

Activity: 17
Merit: 0


View Profile
June 20, 2014, 09:53:39 AM
 #38

Never ever buy any products from China, buy US made poducts instead.
It is your own GREED,  that you made the decision to buy from Chinese.
Don't buy Bjorn Borg underwear from China, it will made your Dick grow smaller. Grin
cryptoceelo (OP)
Member
**
Offline Offline

Activity: 68
Merit: 10


View Profile
July 06, 2014, 02:51:40 AM
 #39

Never ever buy any products from China, buy US made poducts instead.
It is your own GREED,  that you made the decision to buy from Chinese.
Don't buy Bjorn Borg underwear from China, it will made your Dick grow smaller. Grin

lol both butterfly labs and hashfast have both been proven to be scam hardware suppliers so get off your high horse please, while the Chinese might be sneaky at least we get our products rather than waiting around for months and months while the owners go out and buy ferrari's with our money


Could you please be a bit more specific? I'll like to make sure my units aren't infected.

paranoia indeed


We found the machines are sending back encrypted packets back to a Chinese IP address, the packets are encrypted so we are not sure weather its sending back hashes or somethig more sinister.

We have re-wrote the lketc dragon miner software our self and found the units to be hashing 10% more, so likely stealing hashes from our power.

i will release more proof and our clean dragon miner software after more tests.
grn
Sr. Member
****
Offline Offline

Activity: 357
Merit: 252


View Profile
July 06, 2014, 05:44:45 AM
 #40


i do not want some slinty eyed chinese person having full ssh control over my farm and £100sK pounds worth of equipment.


You racist piece of shit! lost all my interest right there. I could have helped if you were being scammed but now i hope you are

How is that Lexical analysis working out bickneleski?
Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!