Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #257307
| From | Jesper Dybdal <jd-debian-user@dybdal.dk> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Am I infected with a rootkit? |
| Date | 2023-04-16 18:50 +0200 |
| Message-ID | <GldJD-2sal-1@gated-at.bofh.it> (permalink) |
| References | <Gl9G1-2pKU-1@gated-at.bofh.it> <GlaiJ-2qdS-1@gated-at.bofh.it> <GlbHP-2qZ1-13@gated-at.bofh.it> <GlcXf-2rFp-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 2023-04-16 17:57, Greg Wooledge wrote: > On Sun, Apr 16, 2023 at 04:30:51PM +0200, Jesper Dybdal wrote: >> My .bashrc has: >>> export HISTCONTROL=ignoreboth >> and that's all. And your description of the default behaviour matches what >> I experience with bash. > There is simply no scenario where all of these things can be simultaneously > true. > > Bash doesn't read the contents of the history file into the in-memory > history unless you run "history -r". If you had some kind of ksh-like > setup where you combined "history -w" and "history -r" commands in your > PROMPT_COMMAND or other variables, then we might be able to reconcile > the statements we've been given. > > In the absence of that, there's just no way you could have commands in > your shell history that were not typed in that same shell session. Or somehow inserted into the PuTTY ssh client on the Windows machine to become part of the ssh session. You've just about convinced me that that must be the situation. I've just checked once more: the Windows machine does not have any remote control server (VNC or Remote Desktop) enabled. If it had, it could have been an intrusion into the WiFi LAN. So it's not that simple - unless there is some hidden remote control server functionality. > The most stupidly paranoid, off-the-wall, tin-foil-hat scenario that I > can come up with, which holds all these statements true, is that someone > hacked into the Debian system as root, attached gdb (or some similar > program) to a running bash, and used this opportunity to modify your > shell's history. Not to do anything. Just to fuck with you. To make > it LOOK like someone hacked you... and that the hacker was a halfwit. *Too* paranoid. And it would make sense only if I discovered it - if I hadn't happened to use the history, I would never have seen anything strange. > The other scenario that comes to mind is that you actually typed the > commands yourself, and forgot doing it. Yes. I certainly do not claim to always remember which commands I typed an hour earlier, so if those lines had been something that could remotely make sense to me, then I might well think I had done it myself. But those 4 lines? If I had somehow typed such a mess, I would remember it. > Maybe you have dissociative > identity disorder or something, who knows. Who knows? But if so, this is the first time it has shown symptoms. > The last scenario... is that one or more of the statements you've given > us are false. Well - I happen to know that they're not. Sometimes I almost think I must have dreamt it, but then I look at the 4 lines that I cut from the history file and saved. Thanks for your help - you've made it clear that the problem originated from the Windows machine. Though that doesn't quite rule out that damage could have been done to the Debian system at the same time, I think that in combination with the apparent clumsiness of those commands, I can almost trust that the Debian system is ok. The question then remains: what to do with the Windows system before I dare run a root ssh session from that machine again? Perhaps restore a backup, but from when? Thanks, Jesper -- Jesper Dybdal https://www.dybdal.dk
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 14:30 +0200
Re: Am I infected with a rootkit? Eduardo M KALINOWSKI <eduardo@kalinowski.com.br> - 2023-04-16 14:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:20 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 16:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-18 15:50 +0200
Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-18 21:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-19 16:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 15:00 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:10 +0200
Re: Am I infected with a rootkit? Jeffrey Walton <noloader@gmail.com> - 2023-04-16 16:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 15:10 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? Greg Wooledge <greg@wooledge.org> - 2023-04-16 18:00 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 18:50 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-16 19:30 +0200
Re: Am I infected with a rootkit? "Thomas Schmitt" <scdbackup@gmx.net> - 2023-04-16 19:40 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 20:50 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 22:20 +0200
Re: Am I infected with a rootkit? Curt <curty@free.fr> - 2023-04-17 18:50 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jd-debian-user@dybdal.dk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-16 17:20 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-18 06:50 +0200
Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 07:40 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 10:00 +0200
Re: Am I infected with a rootkit? debian-user@howorth.org.uk - 2023-04-18 13:00 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 13:10 +0200
Re: Am I infected with a rootkit? David <bouncingcats@gmail.com> - 2023-04-18 14:10 +0200
Re: Am I infected with a rootkit? <tomas@tuxteam.de> - 2023-04-18 14:30 +0200
Re: Am I infected with a rootkit? songbird <songbird@anthive.com> - 2023-04-18 18:00 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-18 18:30 +0200
Re: Am I infected with a rootkit? Andy Smith <andy@strugglers.net> - 2023-04-18 20:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
Re: Am I infected with a rootkit? David Wright <deblis@lionunicorn.co.uk> - 2023-04-16 16:40 +0200
Re: Am I infected with a rootkit? David Christensen <dpchrist@holgerdanske.com> - 2023-04-17 03:20 +0200
Re: Am I infected with a rootkit? Michel Verdier <mv524@free.fr> - 2023-04-17 17:40 +0200
Re: Am I infected with a rootkit? Stefan Monnier <monnier@iro.umontreal.ca> - 2023-04-17 19:00 +0200
Re: Am I infected with a rootkit? Tim Woodall <debianuser@woodall.me.uk> - 2023-04-17 20:30 +0200
Re: Am I infected with a rootkit? Richmond <dnomhcir@gmx.com> - 2023-04-18 10:40 +0200
Re: Am I infected with a rootkit? Jesper Dybdal <jesper@dybdal.dk> - 2023-04-18 16:00 +0200
Re: Am I infected with a rootkit? Jeremy Ardley <jeremy@ardley.org> - 2023-04-18 16:10 +0200
Re: Am I infected with a rootkit? Charles Curley <charlescurley@charlescurley.com> - 2023-04-18 17:00 +0200
csiph-web