LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-11-2018, 07:45 PM   #1
Danwilliams1989
LQ Newbie
 
Registered: Feb 2018
Location: Swansea
Distribution: Ubuntu
Posts: 27

Rep: Reputation: 0
Novice needing help


Hi.

Not greatly familiar with linux.
My home network has been breached.
Have tried all the basics changing my password etc.
Have a router supplied by isp called bt smart hub 6.
Attackers used to be my neighbours and think they cracked in and used a man in the middle attack and now everything is screwed.

Port scanning over my router shows net bios port 137 open constantly as well as port 445 showing up as microsoft-ds.

Seems there has been a samba set up on it.

They've recently moved but these people have got something the matter with them because I'm still having random mac addresses crop up on logs. Also they have seemed to have configured every device I've connected to some how tunnel my ip back to them. Even if I'm on mobile data on my phone or at someone else house with Wi-Fi.

Have had open ports related to pptp tmux telnet ssh. Open on my external ip. Also they are using cloud based services such as aws google cloud.

I'm fine apache everywhere on my devices would like some advice if someone knows what that is exactly.

I think they've done a mitm attack once doing this they have then configured each device to strip down ssl and then somehow get my session cookies and be able to snoop on what I'm doing.

My Windows laptop has just been toasted. I'm just wondering whether anyone has any good ideas for a honey trap I can get or a way to catch them. They are constantly using uninstalling apps on my phone adding lib files and reverse engineering and reinstalling.

Just wonder if I can catch them in the act.

Or if someone can suggest a way I can prove this is happening without a doubt. As police and isp are waiting for the indisputable proof would also like to know how I'm supposed to stop them remotely getting into my router. And remotely getting into my phone when I'm using mobile data
 
Old 04-11-2018, 08:21 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,351
Blog Entries: 28

Rep: Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147Reputation: 6147
A few thoughts:

Do you have your firewall configured and running? If not, configure it. (Linux firewall capability is built-in; it's called iptables. Linux "firewall applications" are generally utilities to make configuring iptables easier.)

Install fail2ban; it's in the repos.

If you have not done so, change your router password from the default, then close any public-facing ports in the router that you do not actively need; consult your router manufacturer's documentation for how to do this. (You should do this in any case, regardless of the OS you are running on your computer.)

A web search for hardening linux will turn up a number of useful articles.
 
Old 04-13-2018, 09:12 AM   #3
snowman81
Member
 
Registered: Aug 2006
Location: Michigan
Distribution: Ubuntu
Posts: 282

Rep: Reputation: 30
You've used a lot of terms but I'm curious what evidence you have that any of them are true? Not to doubt you but your post doesn't make a whole lot of sense.
 
  


Reply

Tags
hack



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Stop! Are you a novice? political-paul LinuxQuestions.org Member Intro 3 06-11-2015 05:07 PM
Novice 2Linux LinuxQuestions.org Member Intro 1 08-16-2013 07:02 AM
Novice needs Bash help. manwithaplan Programming 12 02-25-2009 08:29 PM
I am a novice mohand71 LinuxQuestions.org Member Intro 1 11-16-2008 12:43 PM
I'm a Novice danbinful Mandriva 4 04-14-2005 07:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration