Block Browser Coin Miners

Status
Not open for further replies.

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
TEST miner page of mineblock.org: MINEBLOCK - Block web miners & crypto scripts

Normally we have this inscription on the page:

"Can't start miner. Your browser is safe!"

___________________________________________

Evjl's Rain wrote:
"I have more links with more mining hosts that many well-known extensions fail to block. I collected them for testing purpose"
- so could you pass these links here, please?

- then BitBlock is useful to look on CPU Percentage:)

_____________________________________________

In Post #59 I've added about minerBlock add-on/extension, which inject too blocking script on all open tabs.
 
Last edited:

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
- so could you pass these links here, please?
the right ones are the mining hosts these websites use

The Luxury Spot - Style | Travel | Fashion - minescripts.info
Consertos de Malas - nablabee.com
Asian Drama, Movies and Shows English Sub Full HD | Dramacool - losital.ru

- then BitBlock is useful to look on CPU Percentage:)
not necessary. It will increase CPU usage while browsing regular websites

simply just use ublock, it has a very updated list with >3000 mining hosts

all the extensions only have a list of <190 hosts. some have <50

this is quite paranoid. Usually, 99% of mining websites use coinhive or jsecoin. if both are blocked, users are likely to be protected
 
Last edited:

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
Thank you Evjl's Rain for links and explanations!
- but on your links I don't see the increase in CPU load (CPU load of 1.56 to6% it's nothing), and none of my anti-miners wake up... no sign of life, no digit...on CENT.

----------------------------------

On this Home page of MinerBlock: Porter.io
- you have the miners (Forks, Stars - what this is?) growth between October 2017 and February 2018...
 
Last edited:

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Thank you Evjl's Rain for links and explanations!

On this Home page of MinerBlock: Porter.io
- you have the miners (Forks, Stars - what this is?) growth between October 2017 and February 2018...
forks and stars are the numbers of users who star (keep track) and fork (save and experiment) minerblock's github source with their own github account
forks and stars are not miners
 

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
Thank you Evjl's Rain for links and explanations!
- but on your links I don't see the increase in CPU load (CPU load of 1.56 to6% it's nothing), and none of my anti-miners wake up... no sign of life, no digit...on CENT.

BUT on Nightly (= Firefox 55):
First link: nothing,
Second link: 95% CPU.
3rd link: 85% CPU load...
 
Last edited:

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Thank you Evjl's Rain for links and explanations!
- but on your links I don't see the increase in CPU load (CPU load of 1.56 to6% it's nothing), and none of my anti-miners wake up... no sign of life, no digit...on CENT.
so something already blocked it. check your adblocker
all these are blocked by NoCoin Filter List and coinblockerlist

EDIT: I found that all of them are blocked by EasyPrivacy

easyprivacy can also protect you from coinming better than those extensions
try to temporarily disable your adblocker and test it against your extensions. You will drop all your extensions

so far, nothing can pass through my adblocker
 
Last edited:

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
so something already blocked it. check your adblocker
all these are blocked by NoCoin Filter List and coinblockerlist

EDIT: I found that all of them are blocked by EasyPrivacy

easyprivacy can also protect you from coinming better than those extensions
try to temporarily disable your adblocker and test it against your extensions. You will drop all your extensions

- On CENT I don't use EasyPrivacy...but Privacy Defense, that blocked nothing, not my extensions that blocked these links ... but other good spirit...all my extensions are calm, no sign of life

Repeat my precedent Edit:
BUT on Nightly (= Firefox 55):
First link: nothing,
Second link: 95% CPU.
3rd link: 85% CPU load...
 
Last edited:
  • Like
Reactions: AtlBo

frantz

New Member
Feb 25, 2018
2
MINEBLOCK extension is very good!
It's on Chrome Web Store: MINEBLOCK - Block web miners & crypto scripts

I see, that it inject the blocking script on all open tabs in the browser (my CENT), this script (I see if click on Inspect button to go on DevTools/Elements, then click "copy element"):
<script type="text/javascript" src="chrome-extension://d................../js/minerkill.js"></script>

So I'm feel safe with MINEBLOCK...and you:geek:have you MINEBLOCK already?
... and BitBlock too

----------------------------------------------------------

This same work of minerkill.js make on Firefox (my Nightly) the minerBlock add-on (that we have too on Chrome extension) of xd4rker developer...
Home page of MinerBlock: Porter.io
... and link on Firefox add-ons: minerBlock – Add-ons for Firefox

...

MinerBlock Author here. Please be careful when using the MINEBLOCK extension, it's just a copy of the official MinerBlock with some UI changes.
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
I found 1 website that mineblock fails to protect. Even NoCoin, BitBlock, norton can't protect. Virtually all extensions fail to block
only the 2 lists I shared from a previous post can block it

basically all the extensions you share have similar blocklist, just some extra features and craps, sorry. They copy and paste each others. I entered their github and viewed their source code. They have quite a short blocklist

everyone should stick to ublock origin + the 2 lists I posted. They are better than all these extensions combined

I have more links with more mining hosts that many well-known extensions fail to block. I collected them for testing purpose
Are you saying the miner from the website was not blocked or the website itself was not blocked?

I kept the page opened but I'm not seeing any CPU spike increase.

You like to share some more links where I can test my miner blockers?

Thanks
 
Last edited:

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
Good working TEST page with coinhive miner: MINEBLOCK - Block web miners & crypto scripts - I've edited the link, this one is good, it's mineblock.org - sorry for typo that I did before...

In Nightly/Basilisk (= Firefox) DevTools (after click on "Inspect Element") on DOM and Style Inspector (first window exposed) we read:

<script type="text/javascript" src="https://coinhive.com/lib/miner.min.js" async=""></script>

- so on this test page we have the miner, of coinhive.com - if you don't have (on another website you test) the miner script in DevTools here, so you don't have the miner on your website.

If click on the next button (Web Console), we read:
"content script loaded
The resource at "https://coinhive.com/lib/miner.min.js" was blocked because tracking protection is enabled." - click too: "Learn more"...
- so native Nightly (Firefox...) browser tracking protection blocks these two miner scripts (you see "2" red digit here).
[If you have tracking/mining on your webpage, you see the Firefox's shield icon on the left side of URL address bar. - haha, on the New Tab - no icon!]

Too, on "Coin Mining Blocker" add-on icon, you have "2" digit, and if you touch the icon with your mouse, you see two miner scripts names (same) in the little window.
In Nightly Tools/Preferences/Privacy tab, I have ticked: "Use Tracking Protection in Private Windows"...

But before all, look in about:config and set to true: privacy.trackingprotection.enabled (default setting is "false"!)
- after doing this, you've nothing to read in the Web Console (but always: "content script loaded")...
- and services.sync.prefs.sync.privacy.trackingprotection.enabled is true (default).

Firefox tracking protection uses Disconnect's tracking list, it's the Disconnect.me add-on.

There we are: best anti-miner are the native tracking protection - in Firefox and forks...but mining blockers add-ons/extensions could assist, help - so thanks to developers!


Some good links to read:
What is tracking protection? Tracking Protection

Firefox 57: full Tracking Protection functionality included: Firefox 57: full Tracking Protection functionality included - gHacks Tech News - and read comments section too...


EDIT:

Another good safe TEST page: Opera's Cryptojacking Test Check if your browser is affected by cryptojacking! Cryptojacking Test

In DevTools/Web Console we read:
"The resource at “https://coin-hive.com/lib/coinhive.min.js?no_cache=1519577...” was blocked because tracking protection is enabled"
 
Last edited:

DavidLMO

Level 4
Verified
Dec 25, 2017
158
mineblock.com uses an invalid security certificate. The certificate is only valid for www.parkingcrew.com The certificate expired on Saturday, July 01, 2017, 6:59 PM. The current time is Sunday, February 25, 2018, 1:30 PM. Error code: SSL_ERROR_BAD_CERT_DOMAIN

And the site is for sale?
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Are you saying the miner from the website was not blocked or the website itself was not blocked?

I kept the page opened but I'm not seeing any CPU spike increase.

You like to share some more links where I can test my miner blockers?

Thanks
I mean the mining scripts were not blocked. The websites themselves are not malicious. They just include a mining script for extra profit
Block Browser Coin Miners
click the spoiler

in order to confirm the website contains miners or not, you have to disable your adblocker and sometimes, your AV temporarily because they can block mining scripts
these minners are uncommon so not many AVs can block them. So far only fortinet and kaspersky
 
Last edited:

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I really like AdGuard approach against Coin Miners, it is generic and warns about the miner, so you know what the website is trying to do.

Example:

Screenshot
please check adguard against these links

I found the english filter doesn't have rules for these scripts
EasyPrivacy and nocoin filters have the rules for them

everyone can block coin-hive and jsecoin so all the test pages are not good
 

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
mineblock.com uses an invalid security certificate. The certificate is only valid for www.parkingcrew.com The certificate expired on Saturday, July 01, 2017, 6:59 PM. The current time is Sunday, February 25, 2018, 1:30 PM. Error code: SSL_ERROR_BAD_CERT_DOMAIN

And the site is for sale?
Good working TEST page with coinhive miner: MINEBLOCK - Block web miners & crypto scripts - I've edited the link in my precedent post, this one is good, it's mineblock.org - sorry for typo that I did before... ah big sorry
- this same good link you have in the Post #61 above.
 
Last edited:
  • Like
Reactions: AtlBo and DavidLMO

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
please check adguard against these links

I found the english filter doesn't have rules for these scripts
EasyPrivacy and nocoin filters have the rules for them

everyone can block coin-hive and jsecoin so all the test pages are not good

Confirmed, without EasyPrivacy and NoCoin Filters (I had to disable it) AdGuard doesnt block 2 of the 3 links above.

Edit: I reported to AdGuard, they usually "fix" these kind of things very quickly.
 
Last edited:

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
please check adguard against these links

I found the english filter doesn't have rules for these scripts
EasyPrivacy and nocoin filters have the rules for them

everyone can block coin-hive and jsecoin so all the test pages are not good

" Asian Drama, Movies and Shows English Sub Full HD | Dramacool - use losital.ru script" - many errors on this page, but losital.ru script NOT found by me?...No miners here... - Where is it, please?

" Бяки.нет | Познавательные и интересные фотографии прикольные картинки - use mebablo.com script" - many errors, but miner not found by me ... why do you think, that mebablo.com script is miner script, please?
 
  • Like
Reactions: AtlBo

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
" Asian Drama, Movies and Shows English Sub Full HD | Dramacool - use losital.ru script" - many errors on this page, but losital.ru script NOT found by me?...No miners here... - Where is it, please?

" Бяки.нет | Познавательные и интересные фотографии прикольные картинки - use mebablo.com script" - many errors, but miner not found by me ... why do you think, that mebablo.com script is miner script, please?
if you cant find any miner, it doesn't mean they don't have any miner
use your adblocker, block everything except losital.ru and mebablo.com, you will see your CPU screaming. block them, the CPU stops working
I took losital and mebablo from nocoin blocklist and tried to find websites using these scripts. They are definitely coinminers, trust me

even Who is mining? the first link - drama-cool who uses losital script is not mining but in fact, yes
 

Attachments

  • Capture.PNG
    Capture.PNG
    25.8 KB · Views: 397
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top