Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
11–20 of 56 posts
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#12I guess all it takes is one request to a non-https site?
I suppose you could configure the rogue AP to have one of those registration pages but the registration page tells them the WiFi will only work so long as they keep that tab open.
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#13Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.
Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#14Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.
Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?
And no, that's not a solution. Well at least not everywhere. If the clients aren't completely isolated I can for example poison your DNS and redirect example.com to my computer's web server.
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#15I've thought about adding something like this to my guest wifi to mine some cryptocurrency - but quickly dismissed it as most guests would need to use a charger soon(ish) and thus using my electricity :P
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#16Earlier quoted context omitted.
Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?
If you control the AP, you should disallow client to client communication. Most AP's and routers allow this and it would mitigate this risk.
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#17Earlier quoted context omitted.
New users are green, iirc 50 or 100 karma points required to get normal grey
Feels like they are more superior than us based on his color.
Really, it's not about them being better or worse than a user with more Karna. It's just a signal to everyone that this person might be advertising or AstroTurfing.
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#18Excellent write up. That’s why we need SSL/TLS with HSTS. Pure HTTP, specially in public WiFi, is dead.
Since we won't get https everywhere soon, is WPA2 on a public Wifi with a publicly known key a workaround? Should prevent plain MITM?
AFAIK that wouldn't help because at the very least you can MITM the handshake.
Re: Hacking WiFi to inject cryptocurrency miner to HTML requests (CoffeeMiner)
#19I've thought about adding something like this to my guest wifi to mine some cryptocurrency - but quickly dismissed it as most guests would need to use a charger soon(ish) and thus using my electricity :P
It's also a scummy thing to do and sets a terrible precedent. Do you want friendly customers on your WiFi or do you want angry customers who feel cheated when they learn the truth?