10 ms·
Detecting Monero Miners with Bpftrace
- _8j50 5y agoI just use a list of mining pool domains. Works well.
- m00dy 5y agoHow can we detect it inside the browser ?
- blacksmith_tb 5y agoDetect, or block? There are a few options for blocking, if you run uBlock Origin[1] the Resource Abuse list covers many. 1: https://github.com/gorhill/uBlock https://github.com/gorhill/uBlock
- m00dy 5y agoDetect. How can we detect js-implemented monero miner inside a browser ? E.g. Is chrome dev tools exposing vm internals like in the blog post ?
- crecker 5y agoI do not think it's possible to mine using RandomX and a browser. From docs: > Web mining is infeasible due to the large memory requirement and the lack of directed rounding support for floating point operations in both Javascript and WebAssembly. So you can do whatever you want, but you will end with nothing.
- dmitrygr 5y agoSo? implement soft float and round any way you please. Slow? Sure. But don’t say “infeasible”.
- xiphias2 5y agoinfeasible - not possible to do easily or conveniently; impracticable.
- dmitrygr 5y agoFor many us embedded folk, implementing soft float is a fact of life and isn’t impractical or uncommon. Not everyone lives in nodeJS land.
- retrac 5y agoOne can mine Bitcoin on an IBM 1401 [1] from 63 years ago. Runs at 50 kHz and there are no binary operations so you have to simulate XOR using a subroutine operating on strings to represent bitstrings. Slow. As in seconds per hash not hashes per second. But it works! Still. I am inclined to call that "impractical". In the same way softfloat-in-JS miners are impractical. A vast botnet of such might buy a coffee after a year or two. At a certain point, slow enough turns into impractical, and then practically impossible. [1] http://www.righto.com/2015/05/bitcoin-mining-on-55-year-old-ibm-1401.html?m=1 http://www.righto.com/2015/05/bitcoin-mining-on-55-year-old-...
- selestify 5y ago> At a certain point, slow enough turns into impractical, and then practically impossible. That is, after all, the whole idea behind asymmetric cryptography. You could perhaps crack some things by brute forcing until the heat death of the universe, but that's so slow as to be impossible for all practical purposes.
- Scoundreller 5y agoMy employer does a pretty good job of giving us terrible hardware so the thought of mining on it is self-discouraging. They have no problems giving us space heaters though. As largely a joke, I sometimes fire up monero mining on my laptop at home because the average proceeds exceed electricity cost, even though it’ll take me about a decade to ever get a block. The heat is just cake icing.
- selestify 5y ago> even though it’ll take me about a decade to ever get a block Why don't you join a pool to get some of that average payout?
- Scoundreller 5y agoWhy pay a percentage?
- garaetjjte 5y ago>If these cryptojackers were to mine Bitcoin or Ethereum, their transaction details would be open to the public, making it possible for law enforcement to track them down That doesn't actually matter at all. Monero is used for these purposes probably just because it's mineable only on CPU, thus viable to mine on ordinary hardware. (Bitcoin requires ASIC and Ethereum high-end GPU)
- anonporridge 5y agoYep. Monero is explicitly designed to remain CPU mineable, so that theoretically it remains more decentralized and mined by individuals rather than an industrial complex like bitcoin and ethereum have become. Counterintuitively, I think this also makes it more susceptible to nation state attacks, since you can easily deputize fleets of existing CPUs to 51% attack the network, whereas no nation state on the planet can easily get enough sha256 ASIC miners to attack bitcoin, not even accounting for the enormous electricity requirements to sustain a destructive attack. Then again, the consolidation of bitcoin mining as an industry is also a systemic risk compared to millions of individuals in the network mining. Tradeoffs.
- rspeele 5y ago> no nation state on the planet can easily get enough sha256 ASIC miners to attack bitcoin What if you set up several sock puppet mining pools, all supposedly independent and in competition with each other, and beat the existing pools on fees by enough that miners join you en masse? That would take some investment on your end as you would have to run pool infrastructure at a loss. But if you are a nation state, it's not a huge investment. You don't need to have any mining hardware of your own if you offer miners better returns for the use of their hardware than the other pools do. Once your pools, taken together, have a dominant share of miners, I would think you could run a 51% attack without ever acquiring a single ASIC. The reputation of your pools will not survive but I think you could complete a 1 hour attack (reversing 6-conf transactions) before you lose the miners. Would this work?
- anonporridge 5y ago
- devops000 5y agoMonero is not anonymous anymore as soon as you want to convert to fiat.
- rosndo 5y agoSo? Monero also makes it trivial to create a fake paper trail for the origins of your money.
- devops000 5y agoWhen you will receive the bank wire from the exchange you need to provide to IRS the source of income. What will you say to them?
- dpacmittal 5y agoJust sell an NFT to yourself.
- wnevets 5y agorelevant https://fortune.com/2022/02/16/melania-trump-nft-auction/ https://fortune.com/2022/02/16/melania-trump-nft-auction/
- rosndo 5y agoYou provide them accounting from your fake business which accepts only monero payments for digital goods and doesn’t keep access logs? This is really basic stuff. You will never be caught unless other evidence leads them from the original crime to you. Unless you fuck up it’s not possible to link incoming Moneroj to any specific source, this means that you can fairly easily hide your money laundering activities even from somebody with full visibility into your business.
- 323 5y agoYou live in some fantasy land if you think you can just say "oh, I just received 100 dollars worth of Monero from 1 million unknown entities, my $100 million is totally legit, fuck off". Unlike criminal law where you are "innocent until proven guilty", in most AML/KYC situations you are "guilty until proven innocent".
- unnouinceput 5y agoTitle is somehow misleading. This is not about uncovering Monero users in the wild and exposing them which are criminals, as I first believed when reading the title. This is about detecting unwanted Monero miner on your system. But if you're already pwned that an unwanted process is already running on your system, a Monero miner is the least of your worries.
- jakelazaroff 5y agoThat's not necessarily true. You could be a cloud provider offering compute resources within a container, for example.
- bigiain 5y agoIt's a bit buried, but the article says: "We want to detect traces of RandomX (the CPU-intensive mining function for Monero) running on a cluster. " This isn't for "Has someone rooted my laptop and started mining Monero on it", this is for "Have any of the nodes in my cluster (of potentially thousands of machines) been rooted and had Monero miners dropped on them." Your comment about being pwned totally applies to your container orchestration or hypervisor though...
- asfdgadrhadfh 5y ago
- wanderer_ 5y agoNow they just need to do it with the chip's EM signature like in that PoC a few weeks ago... https://hackaday.com/2022/01/19/identifying-malware-by-sniffing-its-em-signature/ https://hackaday.com/2022/01/19/identifying-malware-by-sniff...
- alfonmga 5y agoI feel bad about this because I wrote an article[0] about how to hide Monero miners on Linux systems. Sometimes I ask myself if I should unpublish it as probably some of the criminals doing this type of attacks found it helpful. [0] https://alfon.xyz/posts/hiding-cryptominers-linux https://alfon.xyz/posts/hiding-cryptominers-linux
- nigma1337 5y agoGreat article, i'd keep it up, as another commenter says, this is mostly rootkits 101 stuff. I'm wondering, how would one go about finding one of these rootkits? Looking through loaded kernel modules for anything "weird"? EDIT: I should really start reading the articles before going to comments, how to find these is litterally what the article is about..
- teruakohatu 5y agoHow much search engine traffic does that article get?
- alfonmga 5y agoI don't know exactly how much traffic it gets because I don't do any type of tracking. I frequently receive emails from anonymous persons asking for help and even some of them are willing to pay me to set up it for them… so you can imagine what these last ones are using it for.
- philkuz 5y agoThat article is very interesting! Looks like a similar approach to: https://sysdig.com/blog/hiding-linux-processes-for-fun-and-profit/ https://sysdig.com/blog/hiding-linux-processes-for-fun-and-p... I wouldn't feel bad about it. The article provides info for security experts about a potential attack vector that exists. That doesn't change if you unpublish the post. Keep it up!
- striking 5y agoYou could remove references to crypto without changing the rest of the article. That way the cool educational bits remain, and helping bad people do bad things with very very little effort is gone.
- a_bonobo 5y agoOverheard this from HPC people: 'it's easy to detect cryptominers on the system, it's the only software that uses the nodes efficiently'