The only reason I can think of for a redirect rather than just a hijacking is to allow him to repoint to various compromised servers. Enable a MITM for a few seconds, redirect some traffic to a compromised box, turn off MITM. Very difficult to see/catch the MITM happening if its only there for a few seconds, and the results (the redirected miners) will continue happily along for a while.
Check this out:
https://bitcointalk.org/index.php?topic=434464.msg5848594#msg5848594It seems that Betarigs miners are having similar problem with stratum reconnect/hi-jacking?
This is actually very interesting. One of the users we had seen an issue with originally has a backup pool as betarigs.
Can anyone else who has had the issue post if they have a backup pool set for betarigs?
Had the running stratum server code been updated to the patched version correcting the idling problem before all this client.reconnect stuff started happening? -- as cgminer/kcgminer/sgminer users are much more likely to be leaking work to their backup pools if the older code still remains running on the server. I would not recommend changing up any the variables right now in the middle of troubleshooting, but it would a good thing to know.