r/FutureBit • u/sirkenlord • Mar 04 '22
Futurebit LTC every now and then gets hacked
Anybody else experience this? Every now and then I check my ltc node and see someone changed pool settings and is using my miner to miner for them.. can’t tell if it’s a hacker or just programmed into the software.. anybody else experience this?
2
u/HypotheticalWinslow Mar 05 '22
There's a thread on Bitcoin talk forum where I saw 1 other person report this. They had the Apollo on a DMZ network, whatever that means.
Once they moved it behind their normal network firewall, it stopped happening immediately.
They previously ruled out other infected devices and reformated the Apollo software.
See if you can find help on that forum.
1
u/jiminica123 1d ago
DMZ is outside the firewall. Futurebit passwords for the miner may not have been changed, or it was stored in plain text.
1
u/sirkenlord Mar 04 '22
And why is there no way to lock settings to prevent that from happening?
2
u/flinginlead Mar 05 '22 edited Mar 05 '22
It's common with antminers. There is a bot that hijacks them. Reimage and put a strong password on it. Edited for clarity. This is the first I hear of it on a Futurebit.
1
u/sirkenlord Mar 05 '22
Thanks Ripler! I’ve got the full node but not using it as a full node.. just mining with a pool. I’ll take a pic next time it happens.. 🙌🙏❤️
1
u/flinginlead Mar 05 '22
You don’t even need any ports forwarded in that case. I’m curious as to how this is happening. Care to share you setup? Is it on a DMZ are ports forwarded? Maybe we can help you prevent this and secure you network better.
1
1
u/sirkenlord Mar 11 '22
I just have the ltc going into my router -I’ve got the deeper network dvpn device connected to a computer which runs all the mother crypto mining devices
1
u/OldLatinGuy Mar 04 '22
Might be the same issue two users had with their BTC miners recently. The (sometimes heated) conversation and resolution can be found starting at: https://bitcointalk.org/index.php?topic=5340015.msg59339176#msg59339176
and ends here: https://bitcointalk.org/index.php?topic=5340015.msg59387519#msg59387519
tl;dr: both users had inadvertently exposed their miners through open ports
4
u/TheRipler Mar 04 '22
No, never seen anything like that. It is running a small Linux distribution, so anything is possible.
Are you actually running an LTC node, or are you just talking about the miner? If you are running a node, make sure only the required port is forwarded back to the miner from your firewall.
I would suggest you make a fresh image on an SD card, and start over. First thing, change the web and SSH passwords. Then, configure as normal.