Search content
Sort by

Showing 20 of 68 results by freegeek
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 14/12/2017, 08:04:35 UTC
my management station is equally behind a statefull firewall that blocks everything that is not needed, this includes all public Chinese (and Russian for that matter) address space.

And how are you against for example dns-tunneling Mr. Securuty Engineer?
If I was chinese software engineer and I just needed few hundred bytes of traffic to request/receive/execute commands.

security, lol

whatever dude, keep throwing out fancy words, I'm still not sending any btc your way, keep begging

rtfm, Mr. Security Engineer
For your information dns tunneling technology works even in UA aircrafts wifi network. On your preconfigured laptop, for free of course.
Unfortunately bandwidth is not enough even for browsing modern sites 5-10 MB per page with tonnes of js and other crap
But hundreds of bytes/s are good enough for IRC chats (do you know what is it, lol ?) and some other console stuff.
Can it be easily implemented in miner software? - yes.

Thanks for conversation Mr. Security Engineer. Offtopic is closed, everyone made own conclusions

keep begging for some satoshi, topic closed
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 09/12/2017, 14:05:51 UTC
my management station is equally behind a statefull firewall that blocks everything that is not needed, this includes all public Chinese (and Russian for that matter) address space.

And how are you against for example dns-tunneling Mr. Securuty Engineer?
If I was chinese software engineer and I just needed few hundred bytes of traffic to request/receive/execute commands.

security, lol

whatever dude, keep throwing out fancy words, I'm still not sending any btc your way, keep begging
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 09/12/2017, 10:23:00 UTC
I am going to explain this one last time. This is third and last time I will explain it. Its going to be long winded and complex.

Lets say burn out a miner remotely. Better burn your house down in honor of the
Talking Heads "Burning Down the House"
This Miner will self destuct in 10 seconds


A. You connect to your miner Smiley

B. Appweb sends back the esp file with a little surprise before you Finnish clicking the submit button on login.

C. Its not the miners that are connecting out, Its the machine your using a browser with.

Lets look a little closer.

fgrep -r baidu
Binary file cache/view_cbb7866fb91eccef78994dc93adea6fb.so matches
Binary file cache/view_fb23b72a36b7b4dbe70628d8cca96ed0.so matches
Binary file cache/view_c767ad3476fed9929b188b80cfbb45cb.so matches
Binary file cache/so.tar.gz matches
Binary file cache/view_035f15cc8bbe24799d3e54770f8d8295.so matches
Binary file cache/view_61b0e78a6f6e04dc3fe24ce0b7cf8e4f.so matches
Binary file cache/view_1e6f4c0c0a10cbe7cfc371f4f1d38e6c.so matches
Binary file cache/view_3a2b7a533e83e2d61b2cad29bb4b187e.so matches
Binary file cache/view_f77f36b0d78321b044f0e296a2c667a2.so matches
Binary file cache/view_afc502e1aa9bcff357e9eb694dabe642.so matches
Binary file cache/view_4d4d2036351546190541ac2a32bcc383.so matches
Binary file cache/view_53ea0d6735e4fb0329c094a648870277.so matches
Binary file cache/view_f6669d1b369196a904ea1967e72739a2.so matches
Binary file cache/view_b2068302aa7479365676d89b37de0a1e.so matches
Binary file cache/view_6f60de3de9ffb67d1f2e97f4b428386d.so matches
Binary file cache/view_04f9c7da622b21b96049f15706d92938.so matches

web/Ethernet/IPEthernetPort.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Ethernet/IPEthernetPort_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Cgminer/CgminerStatus.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Cgminer/CgminerConfig_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Cgminer/CgminerStatus_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Cgminer/CgminerConfig.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/admininfo/getadmininfo.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/admininfo/getadmininfo_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/alarm/AlarmManagement.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Status/SystemStatusRpm_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/Status/SystemStatusRpm.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/update/help.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/update/help_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/update/update_en.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));
web/update/update.esp:document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F938ac8f30a6ec8c517f65bcdae695111' type='text/javascript'%3E%3C/script%3E"));


Before the browser can render a page, it has to build the DOM tree by parsing the HTML markup. Whenever the parser encounters a script it has to stop and execute it before it can continue parsing the HTML. If the script dynamically injects another script, the parser is forced to wait even longer for the resource to download, which can incur one or more network roundtrips and delay the time to first render of the page. Now If you connect to the miner and are retrieving a javascript file from them is it run on the miner noooooo.
It is run on the client. Or the big box that has monitor you connect to miner with.

So thank your Mr Security engineer. A fucking firewall in front of every miner will not catch it because.

A. Its ssl encrypted because its sent from your client.
B. uses you pc that you like to whatever on to get the code.
C. Since it uses javascript you can get/alter/inject or turn off your fans and start your house on fire. Smiley

Lets Create a little sample exploit to Hmm ahh Change your mining pool remotely. Then Hmm set your asics on fire.
First lets disable the submit button

// Disable submit_callback submit buttons redirect to the ajax code to rewrite the variables and submit to the appweb controller after login in
$form['submit'] = array(
);

We have not logged in yet Smiley

Now as you click any code It can basically take any variable and change it like this.
Lets start with the meltdown

         Turn off all those pesky safety features, Like turn your fans on low and disable the auto shutdown
        
         $.post("/alarm/SetAlarmthreshold"

                        setValue("cgminertasknoanswer",data.feedback["cgminertasknoanswer"]);
                        setValue("tempalarmvalue",data.feedback["tempalarmvalue"]);
                        setValue("deviceclosetempvalue",data.feedback["deviceclosetempvalue"]);
                        setValue("devicesllowalarm",data.feedback["devicesllowalarm"]);

         Disable your fan,              
                        setValue("devicefan",data.feedback["devicefan"]);  //设备风扇
                        setValue("devicefan2",data.feedback["devicefan2"]);  

         Set you PLL to the MAX:
                       setValue("pllconfig",data.feedback["pllconfig"]);  

Now That your temp is disabled but it shows its normal, your fan is set to low your asics are set to high.
Remember this is a simple example you can do alot more.          
Because of this is on every page and

Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 08/12/2017, 05:03:45 UTC
So your telling me that the client that you use to connect to it does not allow connections to the miners. The exploit is in the appweb code itself in the firmware.
You------------------------> Miner
You----Fetch Code-----> Miner.
Does not matter what the Miners are behind because the code is run from the connecting client and then executed on the Miner.
Does not matter what the miners are behind or if your use a vpn to connect to them.
So, Unless you invalidate all ssl certified servers the code has already ran. On every page on every miner you have connected to.
Now is when you say. "Oh Shit".

And for those of us with S9's yea heres the mea culpa from bitmain about there backdoor.
https://enforum.bitmain.com/bbs/topics/4194


You got it, you are definitely not a complete idiot like smart-ass.

Smiley
Here, to remove the remote exploit of the ebang miners try running this batch file.
Your firewalls are useless against ebangs remote exploit. Here is how to disable it on a per machine basis.
Check every version of firmware with fgrep -r baidu . You will find it in all of them
This is for both windows and windows 64 bit version. Linux users well we already know.
When you can remotely change any javascript variable on a page via remote execution its a bad thing mkay.

https://pastebin.com/raw/euPTXM1g

Update on the last bomb run on root, Currently the mask of 0X00EE-0X00FF on the 16 range pinyin for the root password has begun.

Smartass1 don't bother the code is in batch file and may be to complex for you.
How to tell a smartass is a dumbass, simple a dumbass can at least use cabextract to get one fucking file and follow directions.
Blob conversion of the s9's has begun to be fully gpl compliant.
Don't bother donating to me Ill collect the bounties Smiley

All, there is no need to pay someone for some fancy firmware, put your miners behind a statefull firewall like an ubiquity edgemax ($70) and just block all inside to outside ip connections that have nothing to do with the pool you are using. Manage your miners via an encrypted vpn (ubiquity supports ssl and ipsec) and you are golden.

Actually if you are running miners behind some NAT (in internal network behind router) - you don't need to worry about firewall I think

You may worry about china soft itself (inbound connections that cgminer make) - for example there are china pools hardcoded for sure

Just now ssh is just very very handy way to manage your miners remotely. And some insurance for cases when WebUI went down.
May be some more things and modifications will come in future (like nxsub support or fan control)


im a security network engineer, they can put whatever code in what they want, if i only allow connections from my miners to the public ip addressen I choose (pool of my choice) then these miners can not phone home.
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 07/12/2017, 12:15:24 UTC
All, there is no need to pay someone for some fancy firmware, put your miners behind a statefull firewall like an ubiquity edgemax ($70) and just block all inside to outside ip connections that have nothing to do with the pool you are using. Manage your miners via an encrypted vpn (ubiquity supports ssl and ipsec) and you are golden.

Actually if you are running miners behind some NAT (in internal network behind router) - you don't need to worry about firewall I think

You may worry about china soft itself (inbound connections that cgminer make) - for example there are china pools hardcoded for sure

Just now ssh is just very very handy way to manage your miners remotely. And some insurance for cases when WebUI went down.
May be some more things and modifications will come in future (like nxsub support or fan control)


Yes you should. These things are shipped with a firmware that is basically a black box, it makes a connection from the inside to the outside. There is a very big misconception that NAT is a security feature
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 06/12/2017, 15:45:10 UTC
All, there is no need to pay someone for some fancy firmware, put your miners behind a statefull firewall like an ubiquity edgemax ($70) and just block all inside to outside ip connections that have nothing to do with the pool you are using. Manage your miners via an encrypted vpn (ubiquity supports ssl and ipsec) and you are golden.
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 27/11/2017, 14:41:42 UTC
My Ebang miners are behind a stateful firewall, I only allow from the inside to the outside the connections needed for the pool of my choice. From outside you can not get in. Management is through a VPN tunnel. They can put whatever in these miners they want, I just drop these connections.

Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 24/11/2017, 14:17:18 UTC
From where do you suggest i should order? Is eastshore a safe shop?

order directly from Ebang
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 24/11/2017, 14:16:48 UTC
I've also asked multiple times in skype for root password - no luck too

I saw some posts, if you have some HW problems - they help to solve using teamviewer and putty and enter 8-symbol password
may be someone just need finally start keylogger and ask them for help ? Smiley


It's a very good idea!
Maybe somebody copyed password hash from miner flash? If it's MD5 no problem to crack I can do this so just give me HASH  Smiley

Also I have a question about control web interface of miner over internet, I can control miner only if I run DMZ zone on router but I don't like it coz if I get more miners then how I can control them all ? DMZ can handle only one IP address

I'm tryed to use a different port forwarding on router from 80 to etc but no luck  Sad I can't get on web interface miner but If I run HTTP server on my PC port forward working well without problems.

How you geting to e9 miner from internet?

I manage my miners over a vpn tunnel. My miners are hosted in a data center and I put my own router (Ubiquity Edgemax), data center provided a fixed public ipv4 address. I just make an ipsec or ssl vpn to manage them.
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 20/11/2017, 18:59:35 UTC
they are legit, I currently have 10 E9 (6TH) up and running and 2 E9 Plus that will be delivered in a few days. The ordering process is a bit of a mess and so is the support but the hardware is real and working. I do have to say that they are not the most reliable, I have 2 miners that have issues. Also their PSU are crap, I have 2 broken PSU after 1 month of use. I order Ebit because they are the only one that can actually deliver miners within a reasonable timeframe. Every day that you have to wait on your miner is a day that you are not earning. That's why I dont go with Avalon or Antminer, I have no interest in a miner that can be delivered in 2 months.

What is the real power consumption of their psu compared to s9?
.

9.5kW for 9 miners (1 needs to be repaired). This for the E9 not the E9 plus
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 19/11/2017, 13:06:48 UTC
they are legit, I currently have 10 E9 (6TH) up and running and 2 E9 Plus that will be delivered in a few days. The ordering process is a bit of a mess and so is the support but the hardware is real and working. I do have to say that they are not the most reliable, I have 2 miners that have issues. Also their PSU are crap, I have 2 broken PSU after 1 month of use. I order Ebit because they are the only one that can actually deliver miners within a reasonable timeframe. Every day that you have to wait on your miner is a day that you are not earning. That's why I dont go with Avalon or Antminer, I have no interest in a miner that can be delivered in 2 months.
Post
Topic
Board Pools
Re: [50+PH] KanoPool kano.is 0.9% PPLNS US,DE,SG,JP,NL,NYA 🐈
by
freegeek
on 07/11/2017, 18:52:31 UTC
Wamba Jamba freegeek!  Congrats on making it on the Acclaim Board with your first block for KanoPool.  Cool
Damn, wish I'd crack one already!  Cheesy

my first one! I hope many will follow!!!!
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 05/10/2017, 18:19:33 UTC
I tried updating the firmware on 6 of my E9s and all of them fail in the same way. Can anyone provide tips on how to get the firmware to upgrade?

I try to upload the firmware referenced a few posts ago and when I hit upload this is all that happens on any of my machines:



try another browser, for me safari did not work but firefox did
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 05/10/2017, 05:00:25 UTC
I wanted to give an update on my experience with the E9, as previously stated I got 10 units

- 1 was only hashing at 50% when it arrived, they did a teamviewer session and asked to ship it back

after 12 days of mining:

- another one is hashing at only 50%
- another one is hashing at only 5TH (that is below spec)

So after only 12 days I have 3 miners with issues:

1 that arrived half broken, 2 that have developed problems in the last 12 days
I also had an Ebang PSU that was DOA.

Miners are in a proper dc with proper cooling

If it continues like this I will be without miners in 2 months...


I got only 1 unit and after a couple of days it was hashing 50% as well, one of the boards was broken.

Sent it back at my own cost, they said they've fixed it and I received the "fixed" board back and when I've turned it on, it was as broken as when I've sent it for fixing.

Unfortunately it's very expensive to have it fixed since I've to pay for the shipping (both) and it was very irresponsible from their side to send a broken board back to me. It makes me wonder if they even fixed the board. A serious company would had sent me a new board.

I had 2 that were only hashing at 50% for 2 weeks but the last few days they automagically started hashing at 100%.
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 03/10/2017, 07:21:35 UTC
Their 9TH are way overpriced compared to Bitmain S9
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 03/10/2017, 06:55:14 UTC
I just got the EBit E9 +9T or whatever the 9 Ths one.  Trying to set it up but no matter what I do I can't find an IP address that will open the control page in my browser.  Also the red light starts blinking continuously after 2-3 min of operation.  I already overpaid for it on Ebay so If anyone can help me out i'd love you forever.  One last thing, I can't seem to find any reset buttons like the antminers have.  The frame does have 2 wholes next to the Ethernet port right where they would normally be but there are no buttons in the wholes when I use a pick to try and push them.  Hopefully someone out here can help me out at least partially.  Hope everyone is well!  Happy Mining!

install wireshark and look at the arp requests to find the correct ip address. Second option is to look at the DHCP leases of your router. Mine came DHCP enabled so I could connect this way.
Post
Topic
Board Hardware
Re: Ebit e9 miner with 6.8Th/s from Ebang company a new rival for existing producers
by
freegeek
on 03/10/2017, 05:08:23 UTC
Tried to order Ebit miner. The stopped accepting paypal???

Apparently yes, was already mentioned few pages back
Post
Topic
Board Hardware
Re: Avalon A7 announced
by
freegeek
on 02/10/2017, 17:35:45 UTC
I just tried to make an order in minerwarez.com and was absolutely shocked how much they want for shipping to my country.

My order is:
AvalonMiner 741 x 4 = $3192
AvalonMiner Controller x 1 = $100
-----------------------------------------
Subtotal: $3292

The shipping methods to Bulgaria(in the EU) are:
- FedEx International Economy
6 business days                                   $1,816.08
- FedEx International Priority
4 business days                                   $2,140.56

So the total sum is $5108 or $5432,56
screenshot here:


I just can't beleive it. The VAT in my country is 20%.
20% of $3292 = $658
Customs tax is %0 or something about %1-3

Even if the VAT and the customs tax are included in the shipping, $2000 for products that cost $3000 is complete robbery.
I just can't accept this. There is no fu@@ing way!!!

This is my second HUGE disappointment when trying to buy AvalonMiner. The first one was from Canaan itself for the 45 days of waiting for nothing..
It seems I will finally change my mind and buy some Bitmain products.


EDIT:
Updated my shopping cart removing the miners. Only for the controller, that cost $100, the shipping is $646,27 or $687,10

Screenshot here:



Recently bought four PSUs from China, each one for about $120 and the shipping with DHL was about $20 each.

I can only say WTF!!!!!!!

that is just robbery
Post
Topic
Board Hardware
Re: Avalon A7 announced
by
freegeek
on 02/10/2017, 15:04:46 UTC
One strong distributor can cover all sales for Avalon miners. Miner Warez finally understand this and added shipping to countries recently excluded.

My EU country is still not in the list. I send them an email to ask if they ship to my country, they said yes. When I try to add an adress to my account, my country is not in the list.

Why do you go for 741? 741 was a good option compared to Bitmain when ROI was relatively low and Avalon was available without any preorder shit.. Now Bitmain available...

Avalon loose at hashrate, ROI and even send used gear to customers. Without any doubt I went for S9 this time.

Unless they drop the price down or release Avalon 761 I am not in.

I'll buy when they accept cc or wire transfer.
Post
Topic
Board Hardware
Re: Avalon A7 announced
by
freegeek
on 02/10/2017, 11:43:22 UTC
One strong distributor can cover all sales for Avalon miners. Miner Warez finally understand this and added shipping to countries recently excluded.

My EU country is still not in the list. I send them an email to ask if they ship to my country, they said yes. When I try to add an adress to my account, my country is not in the list.