TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)

176 点作者 petteralexander超过 7 年前

14 条评论

moepstar超过 7 年前
I've thought about adding something like this to my guest wifi to mine some cryptocurrency - but quickly dismissed it as most guests would need to use a charger soon(ish) and thus using my electricity :P
评论 #16071084 未加载
评论 #16071356 未加载
评论 #16074338 未加载
mawalu超过 7 年前
I find it funny how, even after publishing this post, the author hasn't configured a http -> https redirect for his own site.
评论 #16073882 未加载
diegorbaquero超过 7 年前
Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.
评论 #16070722 未加载
poxrud超过 7 年前
This is why it's important to always use a VPN when connecting to an untrusted wifi, such as a coffee shop or airport wifi. Either pay $3 /month to a provider or setup your own with something like pivpn.
评论 #16075072 未加载
cesarb超过 7 年前
Given the recently disclosed vulnerabilities, instead of a cryptocurrency miner, it could be a Spectre exploit trying to scan and exfiltrate data from the computer's memory. We might be now at the point where disabling all Javascript for non-HTTPS pages is a good default.
评论 #16073030 未加载
mnx超过 7 年前
This is (one of the reasons) why we need https.
dre85超过 7 年前
I guess all it takes is one request to a non-https site?
评论 #16070939 未加载
beiller超过 7 年前
Interesting method, but yes; wouldn&#x27;t HTTPS mitigate this script from being injected? Trying to get awareness for my own original miner written from scratch <a href="https:&#x2F;&#x2F;www.sparechange.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sparechange.io&#x2F;</a> Interesting learning WASM.
rishabhsagar超过 7 年前
Some buildings (hostels and shared accomodations) have shared internet (secured with WPA2). This type of attack might be particularly profitable in such situations.
评论 #16075009 未加载
评论 #16072465 未加载
spraak超过 7 年前
Does someone need to have control of the router to do this? Or how could it work otherwise?
评论 #16075207 未加载
hellbanner超过 7 年前
(OT: petteralexander&#x27;s name shows a different color than other usernames. Why?)
评论 #16070822 未加载
simooooo超过 7 年前
Won&#x27;t modern browsers block this anyway?
rhlala超过 7 年前
Https everywhere extension fix it right?
rootsudo超过 7 年前
This is great! Wow!