Break your neighborhood's free Wi-Fi for Monero mining

Monero mining or Bitcoin mining: Due to the value of Bitcoin and other cryptocurrencies, mining has become a common target of hackers trying to turn any stolen computer resource into cash.

Antivirus and adware makers have responded immediately by trying to stop any code that enables CPU mining, particularly through programs .

For those interested in breaking the law, sorry to do a little research on computer security, a Spanish programmer nicknamed Arnau, published a PoC which describes how to use public Wi-Fi networks for mining.

mining

His project is called CoffeeMiner, and allows a kind of man-in-the-middle that is used by hackers usually in cafes that have free Wi-Fi.

The CoffeeMiner is designed to scramble Address Resolution Protocol (ARP) messages on a local network in order to intercept encrypted traffic from other devices on the network.

Η is conducted by man-in-the-middle using a software called mitmproxy to inject the following line of HTML code into non-HTTPS, or otherwise unencrypted, web pages browsed by network visitors:

When loaded, these web pages run JavaScript and with the computer's CPU generate Monero, using it CoinHive encryption.

As Arnau explained, the attack can be automated. The published one it doesn't work with requests for HTTPS websites, although the prop of sslstrip could solve the problem.

The code is mostly Python, and it is available at GitHub.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.100 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).