Quantcast
Channel: iTWire - Entertainment
Viewing all articles
Browse latest Browse all 4710

LA Times serving cryptocurrency mining script

$
0
0
LA Times serving cryptocurrency mining script

The Los Angeles Times website is serving a cryptocurrency mining script which appears to have been placed there by malicious attackers, according to a well-known security expert.

British infosec researcher Kevin Beaumont, who has warned that Amazon AWS servers could be held to ransom due to lax security, tweeted that the newspaper's site was serving a script created by Coinhive.

The Coinhive script mines for the monero cryptocurrency.

The S3 bucket used by the LA Times is apparently world-writable and an ethical hacker appears to have left a warning in the repository, warning of possible misuse and asking the owner to secure the bucket.

{loadposition sam08}In his warning, issued recently, Beaumont had also pointed to a number of S3 buckets where the friendly warnings were present.

AWS S3 buckets have been found to be world-accessible on many occasions, notably by the security firm UpGuard.

coin hive

The script found on the LA Times website.

UpGuard has found misconfigured Amazon Web Services S3 buckets leaking data from Paris-based brand marketing company Octoly, California data analytics firm Alteryx, credit repair service National Credit Federation, the NSA, the Pentagon, global corporate consulting and management firm Accenture, publisher Dow Jones, a Chicago voter database, a North Carolina security firm, and a contractor for the US National Republican Committee.

warning

The warning left on the LA Times S3 bucket.

Screenshots: courtesy Kevin Beaumont


Viewing all articles
Browse latest Browse all 4710

Trending Articles