Bitcoin Forum
April 26, 2024, 06:30:18 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 [5]  All
  Print  
Author Topic: ALERT! sgminerwindows.com Stealing Bitcoins!  (Read 13568 times)
flound1129
Hero Member
*****
Offline Offline

Activity: 938
Merit: 1000


www.multipool.us


View Profile
August 09, 2014, 06:07:41 PM
 #81

So is it confirmed that the tainted code was only in recent builds?  If so, how long ago did it happen?

According to LiteSaber, the tainted code was in the most recent binaries which were linked from another site (minersforwindows.com)

Multipool - Always mine the most profitable coin - Scrypt, X11 or SHA-256!
1714113018
Hero Member
*
Offline Offline

Posts: 1714113018

View Profile Personal Message (Offline)

Ignore
1714113018
Reply with quote  #2

1714113018
Report to moderator
1714113018
Hero Member
*
Offline Offline

Posts: 1714113018

View Profile Personal Message (Offline)

Ignore
1714113018
Reply with quote  #2

1714113018
Report to moderator
1714113018
Hero Member
*
Offline Offline

Posts: 1714113018

View Profile Personal Message (Offline)

Ignore
1714113018
Reply with quote  #2

1714113018
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714113018
Hero Member
*
Offline Offline

Posts: 1714113018

View Profile Personal Message (Offline)

Ignore
1714113018
Reply with quote  #2

1714113018
Report to moderator
Piotrsama
Sr. Member
****
Offline Offline

Activity: 407
Merit: 250



View Profile
August 09, 2014, 09:08:03 PM
 #82

He is also the creator of Shire Coin, which is a scam because it uses the same code to steal coins if you download the wallet.
How can I check that?
I downloaded that qt some time ago, so it probably stole my encrypted wallet.dat (haven't lost coins, but still want to know if I should consider the wallet compromised)
I tried decompiling it, but it says it isn't a .net program.
What did you use to view the code? Thanks.
chnchapters
Member
**
Offline Offline

Activity: 106
Merit: 10


View Profile
August 09, 2014, 09:39:06 PM
 #83

I used HexRays/IDA
I can show you exactly how I did when I get off work,
the tainted SGminer programs, and Shire coin both use the same ftp server where the stolen wallets were being up loaded.
Piotrsama
Sr. Member
****
Offline Offline

Activity: 407
Merit: 250



View Profile
August 09, 2014, 11:59:59 PM
 #84

I used HexRays/IDA
I can show you exactly how I did when I get off work,
the tainted SGminer programs, and Shire coin both use the same ftp server where the stolen wallets were being up loaded.
Sure, when you can.

I'm using idaq.exe (i guess that's the program you mention).
I selected the shirecoin-qt.exe and let it analyze it (with default options), but when I tried to go to pseudo code, it told me "decompilation failure"

If I choose binary --> processor type Microsoft - net.
Then it says it can't identify the entry point.
And I get to see hex crap. Can't view pseudo code mode.

Well, first time using this program, so maybe there's some trick.
Thanks.
omgbossis21
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250


View Profile
August 10, 2014, 12:43:47 AM
 #85

What type of file are you decompiling, IDA wont identify the entry point of several different files and only break them down to hex.
Piotrsama
Sr. Member
****
Offline Offline

Activity: 407
Merit: 250



View Profile
August 10, 2014, 01:09:18 AM
 #86

What type of file are you decompiling, IDA wont identify the entry point of several different files and only break them down to hex.
I'm trying to decompile the shirecoin-qt.exe (not sure if possible).
chnchapters said he saw the code, and that it steals the wallets like the miner.
Piotrsama
Sr. Member
****
Offline Offline

Activity: 407
Merit: 250



View Profile
August 14, 2014, 01:03:30 AM
 #87

I used HexRays/IDA
I can show you exactly how I did when I get off work,
the tainted SGminer programs, and Shire coin both use the same ftp server where the stolen wallets were being up loaded.
Sure, when you can.

I'm using idaq.exe (i guess that's the program you mention).
I selected the shirecoin-qt.exe and let it analyze it (with default options), but when I tried to go to pseudo code, it told me "decompilation failure"

If I choose binary --> processor type Microsoft - net.
Then it says it can't identify the entry point.
And I get to see hex crap. Can't view pseudo code mode.

Well, first time using this program, so maybe there's some trick.
Thanks.
@chnchapters: Don't forget, thanks.
Xelpherpolis
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
August 17, 2014, 02:36:12 AM
 #88

What type of file are you decompiling, IDA wont identify the entry point of several different files and only break them down to hex.
I'm trying to decompile the shirecoin-qt.exe (not sure if possible).
chnchapters said he saw the code, and that it steals the wallets like the miner.

Never ever use precompiled binaries of altcoins, always check the code on github first. Any closed source altcoins can not be trusted either.
BrianM
Hero Member
*****
Offline Offline

Activity: 546
Merit: 510



View Profile
August 18, 2014, 09:10:04 AM
 #89

What type of file are you decompiling, IDA wont identify the entry point of several different files and only break them down to hex.
I'm trying to decompile the shirecoin-qt.exe (not sure if possible).
chnchapters said he saw the code, and that it steals the wallets like the miner.

Never ever use precompiled binaries of altcoins, always check the code on github first. Any closed source altcoins can not be trusted either.

To difficult for average user. I have no idea how to do that kinda shit, just instal and launch, that is the only way to go!  Cool
nicehash
Legendary
*
Offline Offline

Activity: 885
Merit: 1006


NiceHash.com


View Profile WWW
August 23, 2014, 01:50:21 PM
 #90

Here you can download trustworthy windows/linux sgminer and cgminer binaries: https://www.nicehash.com/software/

jmintuck
Full Member
***
Offline Offline

Activity: 142
Merit: 100


View Profile
September 12, 2014, 06:10:55 PM
 #91

That's it. I am NOT gonna trust this shit until I hear differently about CLEAN and dependable files with FULL and EXPLICIT clearance. This is so bad.
Blisk
Sr. Member
****
Offline Offline

Activity: 412
Merit: 250


View Profile
November 20, 2014, 07:59:47 AM
 #92

where I can download clean of viruses miner which is compilled for x11 and x13?

nicehash
Legendary
*
Offline Offline

Activity: 885
Merit: 1006


NiceHash.com


View Profile WWW
November 20, 2014, 08:27:24 AM
 #93

where I can download clean of viruses miner which is compilled for x11 and x13?

Here you can download trustworthy windows/linux sgminer and cgminer binaries: https://www.nicehash.com/software/#sgminer

Blisk
Sr. Member
****
Offline Offline

Activity: 412
Merit: 250


View Profile
November 20, 2014, 08:45:41 AM
 #94

ok thanks I see that above. How to setup X11 I didn't see kernel for that?

Pages: « 1 2 3 4 [5]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!