LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-08-2014, 06:49 PM   #1
LinuxSparkles
LQ Newbie
 
Registered: Aug 2014
Location: Austraila
Distribution: Ubuntu, Suse, CentOS
Posts: 6

Rep: Reputation: Disabled
Angry I Got A Hacker. Bruteforcing, DDOS attacking, and Backdoorin my computers WHAT TO DO!


I don't know what to do. i've been skyping him to stop. I got his ip from a skype resolver. But how do I Report the ip? And How Do I secure my DD-WRT Router(The Router Has Linux. it runs a third-party firmware) so it will be stronger to these attacks he's throwing out.... He's got my ip. all my computers runs Linux no windows. please help me
 
Old 09-08-2014, 08:06 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,668
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
Program the router to DROP the packets. You should be able to use the router's interface to do it.
 
Old 09-09-2014, 10:06 AM   #3
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: Slackware®
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Member Response

Hi,

If you have the violator's IP then do from 'cli' a 'whois xxx.xxx.xxx.xxx' where xxx is the violator's IP. You should get back something like;
Code:
% Abuse contact for 'xxx.xxx.xxx.xxx - yyy.yyy.yyy.yyy' is 'abuse@someDomainName.type'
'yyy' is the end range. You would then report via email to 'abuse@someDomainName.type' the IP and any actions performed by the violator. If you have any logs then attach to the report. Include any relative information for this violation. ISP providers do take these incidents very seriously.

Hope this helps.
 
Old 09-09-2014, 06:43 PM   #4
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
where about in Australia are you
 
Old 09-10-2014, 12:35 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by floppywhopper View Post
where about in Australia are you
How does asking such a question help the OP?
 
Old 09-10-2014, 12:36 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by LinuxSparkles View Post
I Got A Hacker. Bruteforcing, DDOS attacking, and Backdoorin my computers
How long has this been going on?
What tools did you use to determine backdoors are placed?
Can you show us any relevant log file excerpts?
 
Old 09-10-2014, 10:45 AM   #7
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by LinuxSparkles View Post
I Got A Hacker. Bruteforcing, DDOS attacking, and Backdoorin
If he's got a backdoor, why does he need to bruteforce his way "in"?
 
Old 09-10-2014, 01:31 PM   #8
ReaperX7
LQ Guru
 
Registered: Jul 2011
Location: California
Distribution: Slackware64-15.0 Multilib
Posts: 6,558
Blog Entries: 15

Rep: Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097Reputation: 2097
Australia has laws just like other nations. After you drop him, Contact the ISP, submit a log with the infractions, and let them handle it.

Chances are it's not a hacker himself but a zombie unit being used by a botnet.
 
Old 09-10-2014, 02:44 PM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I would like to remind all jumping in that in the LQ Security forum we favour factual, unambiguous information over "thinking", "worrying" and gut feeling in order to avoid potential false positives and problems cause by Something Else Completely.
 
1 members found this post helpful.
Old 09-11-2014, 01:50 PM   #10
ironwalker
Member
 
Registered: Feb 2003
Location: 1st hop-NYC/NewJersey shore,north....2nd hop-upstate....3rd hop-texas...4th hop-southdakota(sturgis)...5th hop-san diego.....6th hop-atlantic ocean! Final hop-resting in dreamland dreamwalking and meeting new people from past lives...gd' night.
Distribution: Siduction, the only way to do Debian Unstable
Posts: 506

Rep: Reputation: Disabled
stay calm, disconnect from the net.

Quote:
Originally Posted by LinuxSparkles View Post
I don't know what to do. i've been skyping him to stop. I got his ip from a skype resolver. But how do I Report the ip? And How Do I secure my DD-WRT Router(The Router Has Linux. it runs a third-party firmware) so it will be stronger to these attacks he's throwing out.... He's got my ip. all my computers runs Linux no windows. please help me
What to do?

This depends on what you want to do.
Do you want to forensicly get all the proof you need, how what where when who to report him or just save your system?

I would just disconnect, reinstall from backup, if you have one.
Or just backup config files you need.

If you have another router, connect it, reboot modem and this will give you a new ip if you have dynamic ip from a cable provider or similar.
Usually, if a dynamic ip is what you have a simple macchanger -r eth0 will give your linux router eth card a new mac, thus, a new ip, just remember to reboot the modem.

Just reinstall.


If you want to go the forensic route, there are plenty of us here who can guide you camly through the process' and steps to do so.
this will at least let you know what was added and changed hopefully so you can ignore this areas upon saveing for reinstall.is depends on what you want to do.
Do you want to forensicly get all the proof you need, how what where when who to report him or just save your system?

I would just disconnect, reinstall from backup, if you have one.
Or just backup config files you need.

If you have another router, connect it, reboot modem and this will give you a new ip if you have dynamic ip from a cable provider or similar.
Usually, if a dynamic ip is what you have a simple macchanger -r eth0 will give your linux router eth card a new mac, thus, a new ip, just remember to reboot the modem.

Just reinstall.


If you want to go the forensic route, there are plenty of us here who can guide you camly through the process' and steps to do so.
this will at least let you know what was added and changed hopefully so you can ignore this areas upon saveing for reinstall.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: World Live DDoS attack maps – Live DDoS Monitoring LXer Syndicated Linux News 0 08-09-2014 08:30 PM
LXer: Hacker's Tiny Spy Computers Aim To Track Targets Around Entire Neighborhoods And Cities LXer Syndicated Linux News 1 08-03-2013 01:38 PM
Alert from snort - Is hacker attacking me? pching Linux - Security 3 03-17-2008 10:09 AM
More bruteforcing attacks -- need help please! RoaCh Of DisCor Linux - Security 2 10-22-2006 06:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration