Battle with the hacker continues.

Status
Not open for further replies.
Gibzilla said:
everyone knows about the vtec satire for a Honda crowd. Anyways.

So anyone wanna guess why my router was going off the wall yesterday?

http://www.youtube.com/watch?v=1zWQZzFNpTE

If I didn't record that you folks prolly thought i was lying about it also.

If the routers only connected to WAN that how is "he/she/it" still causing trouble? Even after you claimed to have reflash the firmware?
 
that shot was taken last evening. Don't ask me how he does it. that kind of hardware meddling is way above my league. I'm a n00blar.

Let me reiterate. I left my router on and connected to WAN/Internet only to see what it catches in the log and went out for some dinner. It was fine when I left it. WHen I came back from dinner a few hours later, it was doing this so I immediately grabbed the camera and recorded it.

Got it?
 
Gibzilla said:
Linux is amazing. Ethereal is amazing. It's like I've been living under a rock for all these years as windows user completely oblivious to the outside world.

I need to order a bigger monitor....

Your joking right? Ethereal exists for Windows platform. Packet sniffing is nothing special or inherent to one OS or another.
 
SJConsultant said:
Your joking right? Ethereal exists for Windows platform. Packet sniffing is nothing special or inherent to one OS or another.


Well it's all new to me and linux seemed to be more functional for doing this sort of err stuff.

Oh btw, i guess I spoke too soon about the h@x0r. All my open apps on the desktop hid and opened twice. and no the mouse pointer wasn't anywhere near the show desktop button.
 
Gibzilla said:
Well it's all new to me and linux seemed to be more functional for doing this sort of err stuff.

Oh btw, i guess I spoke too soon about the h@x0r. All my open apps on the desktop hid and opened twice. and no the mouse pointer wasn't anywhere near the show desktop button.

Why don't you capture that on camera instead of blinking lights?
 
KodiakStar said:
Why don't you capture that on camera instead of blinking lights?

I will. It happend too quick for to even reach the camera that time but if I see my mouse curse dance across the screen some other crazy shit, you can bet your bottom dollars I'll video taping it.

Now. Question.

First time using ethereal I've noticed my dlink was sending packet to ssdp notify to 239.255.255.250:1900. isn't that windows only Upnp port? Why is my router sending it?

In case u dunno what i'm talking about.

http://www.nthelp.com/upnpscrewup.htm
http://www.pwg.org/hypermail/pwg-ipp/0060.html

Anyone? Anyone?



Hey wtf I'm not the only one.

http://www.hardforum.com/showthread.php?t=1092449&highlight=upnp
 
Gibzilla said:
Oh btw, i guess I spoke too soon about the h@x0r. All my open apps on the desktop hid and opened twice. and no the mouse pointer wasn't anywhere near the show desktop button.
Were you by some chance leaning on the Windows Key and D??? :p
 
Gibzilla said:
INow. Question.

First time using ethereal I've noticed my dlink was sending packet to ssdp notify to 239.255.255.250:1900. isn't that windows only Upnp port? Why is my router sending it?

here: "According to the RFCs, valid Internet IPs range up to 223.255.255.255."

"The reason you can't ping or trace route to 239.255.255.250 is that it's not a host, per se. Internet routers will ignore that IP because it is not a valid IP for an Internet host. With several exceptions, the 'legal' Internet address space ranges from 0.0.0.0 to 223.255.255.255."

"However, if a router has UPnP enabled, and received UPnP packet on port 1900, it would respond. The IP address 239.255.255.250 is just a standard place to send UPnP traffic. All UPnP compliant devices are configured to listen on that IP and port and will respond."

I shall take the guess and say:
Your Router is announcing its UPNP presence.
 
lesman said:
NOT new, lol. I've seen it here many, many times! ANYWAYS...back to the thread! :D

Sorry, the sarcasm tags were not working at the time of post.. lol.
 
why hasn't this thread been locked yet? why hasn't this person been banned yet?
I sincerely hope that someone as retarded as this 'gibzilla' cannot really exist. some of the other posts by this person on these forums are so stupid and baseless, that I am baffled.
confused.gif


and in the very off chance this is actually legitimate....
gibzilla, you are behind a router, right? then how is a hacker able to access your computer? you would have had to setup NAT rules for someone to access your computer from the internet.

also, why the hell are you running your ubuntu desktop as root? if you wanted a reason for why your computer *could* get hacked, that would be it. have you read *any* of the ubuntu handbook or FAQ on their site? if not, please do so before you ever post here again.
 
I have another question/advice for Gibzilla. If your machine is compromised by a hacker why in the world would you login into your Bank of America account (picture bottom of post #120)? Especially since this compromised PC is a second or more computer that you are just messing around with? If you are serious then I cannot think of a better way for someone to steal your money and identity other than posting your name, SS#, birthdate, account numbers and passwords on a billboard on the freeway!

Better yet since you have another computer that is safe just STOP using this one.
 
Hey draconius, haven't seen you posting recently. Welcome back.

draconius said:
why hasn't this thread been locked yet? why hasn't this person been banned yet?

Humor value.
 
kydsid said:
I have another question/advice for Gibzilla. If your machine is compromised by a hacker why in the world would you login into your Bank of America account (picture bottom of post #120)? Especially since this compromised PC is a second or more computer that you are just messing around with? If you are serious then I cannot think of a better way for someone to steal your money and identity other than posting your name, SS#, birthdate, account numbers and passwords on a billboard on the freeway!

Better yet since you have another computer that is safe just STOP using this one.

Hahah, i had to go back and look. +1 points for kydsid...

You would think that he wouldn't go check how many peso's he has... oh well
 
kydsid said:
I have another question/advice for Gibzilla. If your machine is compromised by a hacker why in the world would you login into your Bank of America account (picture bottom of post #120)? Especially since this compromised PC is a second or more computer that you are just messing around with? If you are serious then I cannot think of a better way for someone to steal your money and identity other than posting your name, SS#, birthdate, account numbers and passwords on a billboard on the freeway!

Better yet since you have another computer that is safe just STOP using this one.
Yeah I noticed that too...

but maybe it was the "hacker" that brought up the Bank of America web page :p
 
Crosshairs said:
All your peso's are belong to me !!!!!!!@@@@!!!!!!!

LMFAO

he's obviously someone who is very bored at work/home with no life whatsoever, but I admire him for sticking to his story, lol

what would be even funnier is if he had a shitty mouse (that do travel accross the screen sometimes btw, it is not uncommmon especially when combined with bad mousepads) and then it sent him off on this wild goose chase :D
 
kydsid said:
I have another question/advice for Gibzilla. If your machine is compromised by a hacker why in the world would you login into your Bank of America account (picture bottom of post #120)? Especially since this compromised PC is a second or more computer that you are just messing around with? If you are serious then I cannot think of a better way for someone to steal your money and identity other than posting your name, SS#, birthdate, account numbers and passwords on a billboard on the freeway!

Better yet since you have another computer that is safe just STOP using this one.

I never logged onto anything important. I did visit b of a but didn't log on.

I did heroin for awhile until some [H] came around and gave me a chain-to-the-lamppost detox.
Rapid Heroin Detox

Seriously though, That linux dvd hasn't come from the vendor yet. I got my err "stuff" waiting to be thrown into action to test vulnerability once the "software" gets here.
 
zrac said:
LMFAO

he's obviously someone who is very bored at work/home with no life whatsoever, but I admire him for sticking to his story, lol

what would be even funnier is if he had a shitty mouse (that do travel accross the screen sometimes btw, it is not uncommmon especially when combined with bad mousepads) and then it sent him off on this wild goose chase :D


What ever I said was/is a true story nothing exaggerated. I wouldn't have believed it had it not happend to ME.
 
draconius said:
why hasn't this thread been locked yet? why hasn't this person been banned yet?
I sincerely hope that someone as retarded as this 'gibzilla' cannot really exist. some of the other posts by this person on these forums are so stupid and baseless, that I am baffled.
confused.gif


and in the very off chance this is actually legitimate....
gibzilla, you are behind a router, right? then how is a hacker able to access your computer? you would have had to setup NAT rules for someone to access your computer from the internet.

also, why the hell are you running your ubuntu desktop as root? if you wanted a reason for why your computer *could* get hacked, that would be it. have you read *any* of the ubuntu handbook or FAQ on their site? if not, please do so before you ever post here again.

I have 3 routers . How do I set up NAT rules?

I don't think Ubuntu has any root acount. I can do sudo though as I found out. Linux is like learning DOS again cept much more complicated.

If I knew how the h@x0r gets in, would I be asking you all for help? I can only guess at how he is getting in. Obviously he can remotely control my desktop which means some activeX trojan he is embedding. I've noticed that he could make me unable to download antivirus software or he'll repeadly turn off live virus database update. So obviously he doesn't want me to get or update virus definitions which means he's afraid of detection which means there is a physical file on the HD that needs to be located....

But where the F is it? No scanner picks it up to be honest I got a few known trojans I've d/l from "war" sites in 1998 and to this day non of the virus scanners picks it up. So....

There's always someone smarter than you.
 
Log into your router and see if there are any IPs other than the computers in your home. If there are any you don't recognize, j00 is h4x3d!!!11@1

In serioussness, if it was an ActiveX control, a delete of temporary internet files would have fixed it.
 
TheOmniscientCreator said:
Log into your router and see if there are any IPs other than the computers in your home. If there are any you don't recognize, j00 is h4x3d!!!11@1

In serioussness, if it was an ActiveX control, a delete of temporary internet files would have fixed it.

Nope nobody, just me my self and irene whoopse I mean my computer. I've found out my dlink's firmware is actually linux?
 
If this is indeed a serious issue, try an online scan. I highly doubt that he can block such a thing.
 
What is this error I get when I shutdown.

SAS Entry point failed. unable to link CRYPT.dll?

I got this for googling http://www.devenezia.com/downloads/sas/sascbtbl/ I think i'm getting closed to finding out how he was compromising my machine. It still doesn't explained the linux side of the story though how he was able to circumbent ehtereal and firestarter.

And what is this error I get when I log on?
 
Have you tried an SELinux live cd? That might shed some light on the situation. Honestly I've had too hard of a time reading through all the crap in this thread to really get a good understanding of the problems you've had.

Do you have any friends or roommates who are pissed at you? That seems fairly likely, since most real hackers are just going to root your machine just enough to turn it into a zombie to add to their network for spamming/ddos purposes. Everytime I've had something really weird happen with one of my machines, it's either been some weird hardware problem or a friend who wanted to mess with my head.

Could you carefully detail your network, which systems have experienced problems, which havn't, and exactly what problems you've been seeing?
 
Does anyone know why the hell my motherboard phones home without my permission?



Can anyone resolve dns on this IP?
72.143.253.104?
 
You probably installed some software that came with the motherboard. As for, "without your permission", you should probably read the EULA.
 
hokatichenci said:
You probably installed some software that came with the motherboard. As for, "without your permission", you should probably read the EULA.

NEVER!

Next suggestion.
 
Danith said:
I don't think a virus can infect a .iso, at least not very easily,, and even so it would have to be targeted at linux.. a windows virus will not work on a linux-running machine.

There have been viruses written against the ISO 9660 format. As far as your mouse pointer moving, could there perhaps be some dust in front of the laser? My mouse will move usually if there's a hair there or something similar.

Run and configure Snort on your system and post some logs
 
reported....

he's just a kid, playing around and having fun... he's prolly sitting at home now laughing his head off about this.

QJ
 
Yup, after that 'bump' it's time to kill this thread. Lock it and throw away the key.
 
Gibzilla said:
nO Just trying to see if anyone else's asus boards phone home.
at what frequency does it do this (phoning home)? Does it use the windows networking stack to do so, or has Asus implemented a hardware IP stack? If the latter, how come you can see if using windows monitoring tools? If the former, what system calls does the board use? Does it create a process or just use its access to the ram to write directly to it? If the latter, how does it make sure that it's now overwriting a process that you are currently using?
 
Gibzilla said:
I think i'm getting closed to finding out how he was compromising my machine.
Alright Gobzilla, I give up. I know you would have caught me in a couple days. I won't mess around with your computer anymore.

You're right about how I was doing it too. If you don't want anyone else doing this in the future, go to the ActiveX control panel in Ubuntu and turn it off, or at least set up a list of whitelisted websites (like for windows update, etc.).
 
Status
Not open for further replies.
Back
Top