How to crack into Bitcoin miners
by ToxicAvenger4 - Thursday October 17, 2024 at 09:15 AM
#1
As my first post lets start off with a bit of a bang.


All Bitcoin miners no matter the manufacturer all have the same flaw. They all run a lightweight open source web server Lighttpd 1.4.32 for remote configuration of the machine which is redundant if you understand how to mine cryptocurrencies cause there should be no situation where you cannot physically access your machine and need to remotely access it.


Whats this mean? Well that means many MANY Bitcoin, Ethereum and Litecoin miners have open HTTP login pages pointed to the internet. Login pages that are highly vulnerable to bruteforcing, directory traversal and XSS and SQL injection. Theoretically an attacker could gain access to an entire Bitcoin mining farm in a matter of seconds more realistically a couple of hours and change their output to a private pool the attacker owns. Even without gaining access one could in theory compile a list of miners IP's and DDoS them offline taking down a few thousand miners would have a direct impact on the market prices allowing for someone to short and distort the markets at will. No miners ='s no transactions.


How to find them?  Shodan, Censys whatever service floats your boat use queries such as "Antminer", "Jasminer", "Avalon" and watch all the IP's with open HTTP ports pop up. Most of which have Lighttpd 1.4.32 running if you were to click on one it will bring up a very basic login page. If one were able to cause the miner to reset with say a DoS attack( CVE-2013-4560) most miners revert to the default login "root/root" or "(at sign)root/root".


Enjoy!
Reply
#2
Could you maybe elaborate on this? It seems very interesting, I am still learning most of this stuff so I would really appreciate it, from what Ive read you need to locate the monitored directories to attack them (cve-2013-4560)?
Reply
#3
This is a great thread, I never thought about this. With all the crypto mining, I imagine there are many people trying to make cheaper, faster miners. Like software web developers, many of them probably don't know how to implement security leading to serious vulnerabilities.
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Self-Ban | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you wish to be unbanned in the future.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Help crack ntlm Mas_PangaREP 3 1,248 01-23-2025, 10:26 AM
Last Post: soros1
  Any guides how to crack into miner rigs? auxius 0 829 12-25-2024, 01:32 PM
Last Post: auxius
  How To Crack Zynga Leaked Passwords? breachxyz 6 1,085 11-05-2024, 02:23 PM
Last Post: laksor
  Pay to buy tutorials or methods that can perfectly crack facial biometrics life19911 0 625 08-18-2024, 01:22 AM
Last Post: life19911
  how to crack cpanel? xql27k 5 1,302 05-06-2024, 08:47 AM
Last Post: salv

Forum Jump:


 Users browsing this thread: 1 Guest(s)