LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-28-2015, 01:05 PM   #1
Lola Kews
Member
 
Registered: May 2004
Posts: 549

Rep: Reputation: 38
Someone uploading information without permission!


I have instances of someone uploading information from my computer, this happens somewhat often.
Today I was searching for a recipe when all of a sudden my screen dimmed, the search ended and my DSL modem was working like crazy.
No way to tell (as far as I know) if it was uploading or downloading but sense I was doing nothing I'm damn sure someone is uploading information! This went on for 5 minutes give or take!

I have the selections set to "NO" for any of this type of activity in Firefox/Edit/preferences including updating of anything.

Can anyone tell me what is going on?

Running Ubuntu 12.04. Install all updates as soon as they come in on a daily basis. This week alone the system has downloaded and installed over 170 MB of updates.

If you guys have the time I would really appreciate some help.
 
Old 03-28-2015, 08:53 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,326
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
You might find some useful information in this thread about detecting and identifying intruders: http://askubuntu.com/questions/15121...n-ubuntu-12-04

Do you have a wireless router? If so, the first thing to do is change your wireless password, as well as your computer user password(s); you should also change your router password (see the manufacturer's website or the docs for your router for instructions). Your router may also maintain connection logs; it would be worth looking at them.

Since you are using Linux, it is unlikely that you have a virus in the classic sense, but it is possible that you might have been victimized by some "social engineering" or browser exploit.
 
2 members found this post helpful.
Old 03-30-2015, 01:49 PM   #3
Lola Kews
Member
 
Registered: May 2004
Posts: 549

Original Poster
Rep: Reputation: 38
Quote:
Originally Posted by frankbell View Post
You might find some useful information in this thread about detecting and identifying intruders: http://askubuntu.com/questions/15121...n-ubuntu-12-04

Do you have a wireless router? If so, the first thing to do is change your wireless password, as well as your computer user password(s); you should also change your router password (see the manufacturer's website or the docs for your router for instructions). Your router may also maintain connection logs; it would be worth looking at them.

Since you are using Linux, it is unlikely that you have a virus in the classic sense, but it is possible that you might have been victimized by some "social engineering" or browser exploit.
Hi Frank. No router connected. Just a DSL modem connected to the wall jack with my telephone to the second wall jack
 
Old 03-30-2015, 02:11 PM   #4
veerain
Senior Member
 
Registered: Mar 2005
Location: Earth bound to Helios
Distribution: Custom
Posts: 2,524

Rep: Reputation: 319Reputation: 319Reputation: 319Reputation: 319
Okay Frankbell was talking about this dsl modem only.
 
Old 03-30-2015, 02:22 PM   #5
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
Quote:
when all of a sudden my screen dimmed
that would never happen if a program WAS uploading files FROM your machine to a different one
nor if the web browser was garbing files from someplace

Quote:
I'm damn sure someone is uploading information!
HOW ??????

a dim screen says NOTHING about " someone " uploading YOUR files to someplace




seeing as we can only make wild guesses and the only information given was a dim screen and " odd" DSL modem behavior


a temporary under-voltage in the power line

a 1 to 2 second "brown out"
a very VERY VERY common occurrence


Quote:
have the selections set to "NO" for any of this type of activity in Firefox/Edit/preferences including updating of anything.
that is not a good idea
and is in fact a VERY BAD IDEA
-- do not do that --

firefox 36 released a SECURITY!!! update a bit back 36.01
and on Mar 21 they released a out of cycle EMERGENCY security update to
36.04

so have firefox UPDATE!!!!!

Last edited by John VV; 03-30-2015 at 02:27 PM.
 
Old 03-30-2015, 02:26 PM   #6
neilgunton
Member
 
Registered: Jan 2008
Posts: 35

Rep: Reputation: 2
Quote:
Originally Posted by Lola Kews View Post
Hi Frank. No router connected. Just a DSL modem connected to the wall jack with my telephone to the second wall jack
It's always better to put a router between your computer and the modem. Then nobody can connect directly to your computer from the internet. Your computer is given a local, non-routable ip address by the router, and it acts as a shield. This is assuming, of course that your DSL modem is not actually a router as well - sometimes they are all-in-one boxes. You should be able to tell by checking your computer's ip address - if it starts with something like 192.168.x.x or 10.x.x.x then your modem is probably also a router, because those address ranges are non-routable. You can get your ip address by typing ifconfig at the console, usually. This presents a lot of info, but look for the bit that says something like "inet addr".

There are tools to check for rootkits, but I don't know offhand how up-to-date or effective they are (especially if you already have an infection). But it's worth a try: Look for chkrootkit and/or rkhunter. Both should be available for free via apt-get or whatever you use.

I always install tripwire on my machines, and configure it so that it can pick up when important files have been changed without my knowledge. It's too late for your current situation, though, tripwire is something you set up very soon after you have set up the computer (and preferably before exposing it bare to the internet).

Honestly, 99.9% of malware issues can be avoided by following these rules:

1. Never click on links in emails, unless you know for a fact where it came from. Hover your mouse over the link to make sure it's going where it says it's going.
2. Install AdBlock Plus (for Mozilla-based browsers)
3. Always try to have your computer behind a router, this is your first line of defense
4. Learn about making firewall rules for your computer, e.g. iptables
5. Turn off or disable all services that you don't use

If you're already infected then the best course is probably to get a router, then backup all the personal files on your computer (i.e. the ones that you generated or saved, that wouldn't be replaced by a re-install), then do a complete system wipe and re-install from scratch. Re-partition and format the hard drive too, just in case there's some nasty in the boot sector. Then you reinstall from behind your router, with confidence that nobody can connect to your computer from the outside during the install and post-install period. Then lock things down, install tripwire so you have a good snapshot of how things should be, and you should be good to go.

Hope that helps,

Neil
 
1 members found this post helpful.
Old 03-31-2015, 12:28 AM   #7
trevoratxtal
Member
 
Registered: Dec 2012
Location: South Devon, UK
Distribution: PCLinuxOS, Suse, Mint, Puppy.
Posts: 79

Rep: Reputation: 20
If it happens again
Ctrl Esc should tell you what process is active.
 
1 members found this post helpful.
Old 03-31-2015, 01:39 AM   #8
ardvark71
LQ Veteran
 
Registered: Feb 2015
Location: USA
Distribution: Lubuntu 14.04, 22.04, Windows 8.1 and 10
Posts: 6,282
Blog Entries: 4

Rep: Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842Reputation: 842
+1 Neil's advice.

Regards...
 
Old 03-31-2015, 12:42 PM   #9
orasis
Member
 
Registered: Mar 2008
Distribution: Slackware, Free-BSD
Posts: 53

Rep: Reputation: 34
Be safe, but personally I think you're just being paranoid. I also have no idea why you think Firefox options secure your network connection... they don't. Screen dimming in Ubuntu just means the system is too busy to do anything else and is usually swapping like hell, or your machine is too weak to run it full speed.
 
Old 03-31-2015, 02:14 PM   #10
albinard
Member
 
Registered: Jan 2011
Location: New Mexico
Distribution: Xubuntu Core
Posts: 185

Rep: Reputation: 59
Since you're running Ubuntu 12.04, you might check the firewall, which is usually installed as a default:
Code:
sudo ufw status
If the reply is "disabled", run
Code:
sudo ufw enable
That won't let anything in you didn't ask for.
But for what it's worth, a 32-bit installation of 12.04 has been giving me some grief lately by graying out when I try to update stuff. My solution has been to go to Synaptic, hit Reload, then click Mark all updates, then hit Apply: it does the update job through a different path.
 
Old 04-01-2015, 11:05 AM   #11
Lola Kews
Member
 
Registered: May 2004
Posts: 549

Original Poster
Rep: Reputation: 38
My thanks to Neil. What I thought was just a modem must be a combination Router/modem. IP address starts with 192.168........

It happened again, this time I caught this, waxcdn.com and code.jquery.com. I went to the web sites they are some sort of new technlogy that downloads information (Not upload) faster that companies are evidently starting to use in delivering information to the computer. So, evidently I don't have a problem.

albinard, I made a mistake when I said I was running Ubuntu 12.04, it's 14.04, sorry.

Why it dimmed my screen I do not know! My system has more than enough power/ram/disk space.

Maybe I was parinoid, but I would rather be that than sorry!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Permission denied while uploading files in htdocs because owner and group is apache unclesamcrazy Linux - Newbie 7 09-17-2014 08:42 AM
[SOLVED] permission denied when uploading a local file johnifanx98 Linux - Newbie 7 02-29-2012 04:13 PM
permission denied, uploading to folder /etc/php.ini notiq Linux - Newbie 3 09-13-2007 05:34 AM
File permission information gardenair Linux - Newbie 1 03-08-2005 05:11 AM
Uploading files using PHP giving Permission Denied error MatthewG Programming 4 05-27-2004 03:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration