TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

UK government sites infected with a cryptominer

23 pointsby flotherover 7 years ago

3 comments

raesene9over 7 years ago
The use of 3rd Party JavaScript is endemic in websites these days, so not a big surprise that attackers are targeting them, given they&#x27;ve got an application (cryptomining) that can generate a revenue stream.<p>Unfortunately a lot of companies don&#x27;t really seem to realise that when they include 3rd party JS they&#x27;re implicitly trusting the security of that third party. I&#x27;d imagine many don&#x27;t do much in the way of due diligence before including the scripts.<p>As mentioned in Scott&#x27;s related blog post (<a href="https:&#x2F;&#x2F;scotthelme.co.uk&#x2F;protect-site-from-cyrptojacking-csp-sri&#x2F;" rel="nofollow">https:&#x2F;&#x2F;scotthelme.co.uk&#x2F;protect-site-from-cyrptojacking-csp...</a>) SRI is a decent at least partial defence against this kind of thing, but unfortunately it hasn&#x27;t (in my experience) seem much in the way of takeup as yet.
notspanishfluover 7 years ago
Related tweet <a href="https:&#x2F;&#x2F;twitter.com&#x2F;fransrosen&#x2F;status&#x2F;962709013329670145" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;fransrosen&#x2F;status&#x2F;962709013329670145</a><p>&quot;Same attack as described here: <a href="https:&#x2F;&#x2F;labs.detectify.com&#x2F;2017&#x2F;07&#x2F;13&#x2F;a-deep-dive-into-aws-s3-access-controls-taking-full-control-over-your-assets&#x2F;" rel="nofollow">https:&#x2F;&#x2F;labs.detectify.com&#x2F;2017&#x2F;07&#x2F;13&#x2F;a-deep-dive-into-aws-s...</a> … it&#x27;s scripts hosted in a S3-bucket without proper access controls&quot;<p>Edit. Also see <a href="https:&#x2F;&#x2F;scotthelme.co.uk&#x2F;protect-site-from-cyrptojacking-csp-sri&#x2F;" rel="nofollow">https:&#x2F;&#x2F;scotthelme.co.uk&#x2F;protect-site-from-cyrptojacking-csp...</a>
pellover 7 years ago
Are these miners effective enough? I guess, at scale they should have some value but my initial gut feeling would lead me to believe that even a huge botnet can hardly compete with dedicated hardware.
评论 #16354144 未加载
评论 #16353700 未加载
评论 #16353424 未加载