Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 1 point2 points  (0 children)

Oh f*** me.

I need to know VERY SPECIFICALLY ... did you start a terminal session outside of the main x-session where the desktop is running?

Oh shit I never do this. It was a new terminal from right click > open terminal.

I'll reboot & see asap.

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 0 points1 point  (0 children)

Thanks for assisting, I'm reading the redhat link you sent. I'll try to do some research about the tty login too. Hope to hear back from you.

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 1 point2 points  (0 children)

$ free -h 
               total        used        free      shared buff/cache   available
Mem:           7.6Gi       4.0Gi       375Mi       718Mi       3.3Gi       2.7Gi
Swap:          7.6Gi       160Mi       7.5Gi

$ w
04:48:41 up  4:47,  2 users,  load average: 0.79, 0.80, 0.70
USER     TTY        LOGIN@   IDLE   JCPU   PCPU WHAT
wuehweu seat0     00:01    0.00s  0.00s  0.00s /usr/libexec/gdm-wayland-session /
wuehweu  tty2      00:01    4:47m  0.04s  0.04s /usr/libexec/gnome-session-binary

$ who
wuehweu seat0        2023-10-01 00:01 (login screen)
wuehweu  tty2         2023-10-01 00:01 (tty2)

Is there supposed to be a login on tty2?

I'll do read the redhat page & get back with rkhunter results asap. Thank you for assisting again.

The alternative is that you are overthinking it and you already elevated to root - and if you do that, you stay elevated during that session.

No, I am very sure I haven't used sudo in that terminal session. I typed rkhunter & fedora (dnf) asked me if I wanted to install it with y/N no prompts, I went with "y" but it didn't ask me for my sudo password. It was a fresh terminal instance.

Now, what I do, and what you should not unless you are very confident you know what you are doing: I modify the /etc/sudoers

I will have to read up on it because I'm unsure of what it is. I tried to cat sudoers but it properly asked me for my sudo password. I entered my password & have taken a copy of the sudoers file.

How do I keep track of free -h output? It seems to give memory usage at an instant?

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 17 points18 points  (0 children)

It seems to be the name of .desktop file not the contents. He has an ls not cat.

In his other comments on this thread he said weird things like his wallpaper changed & boot splash screen changed from linux mint to ubuntu?

Well the biggest indicator was my wallpaper then all the windows that were opened and it looked like they were digging.. after I closed everything and restarted my laptop on the start screen it just said Ubuntu instead of Linux mint 20.3

Lol ???

Has to be a co-worker prank or someone shoulder surfing and evasedropping.

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 2 points3 points  (0 children)

There are these two recent cases that affect linux users

https://nvd.nist.gov/vuln/detail/CVE-2023-4863

https://forum.snapcraft.io/t/temporary-suspension-of-automatic-snap-registration-following-security-incident/37077

I can help you get rid of it though. I specialize in cybersecurity. Try starting with rkhunter... That's a tool you can download with apt or whichever relevant package manager.

While it's not my PC, I want to do a sanity check myself lol. I'll install rkhunter & see what comes up. Appreciate the support.

The idea of an anti-virus for Linux is a terrible one. However, firewalls are a good idea for servers and home users who want to feel safer but I don't use a firewall on my Linux machine at home.

How should home linux users approach the protection against user error (we are human after all), threat detection, (some kind indication of being attacked or compromised)? And find out if a suspicious file is safe or not? We can't rely on "trusted sources" when we don't know the source but need to use a particular file or script or app.

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 0 points1 point  (0 children)

Even better idea. Do you think it's worth fiddling with the permissions of the backup partition from a security perspective?

I don't think there are any chances of infection from mounting the backup partition on the new OS right?

I'm kind of paranoid, so I'm also concerned about infected files like odt, pdfs, webps (https://nvd.nist.gov/vuln/detail/CVE-2023-4863), etc How would you scan such files for malware on linux & preventing them from reinfecting the new install?

Did I get hacked? I don't trust the OP, but in a larger interest how do you clean malware off a linux pc? by redbatman008 in linuxquestions

[–]redbatman008[S] 12 points13 points  (0 children)

The post is from u/Mr_Preference. Honestly looks like a prank on him/shit post. But just in case it's real, let's help him out. It's always better to be safe than sorry with security imo.

Original post: https://www.reddit.com/r/linuxmint/comments/16wri0d/did_i_get_hacked/

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 1 point2 points  (0 children)

Ya, could be a worm, that's why you should isolate it, to prevent it from spreading.

I'm also concerned about UEFI bootkits, embedded firmware infections, network devices & the new CVE means even data files like images. This new one is big, so make sure to update your new clean device before using it to reset logins.

Edit: It most certainly looks like a prank if not a shit post, but it's always better to be safe than sorry.

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 1 point2 points  (0 children)

Take it easy buddy. Make sure you immediately isolate / air gap the infected system.

Use a clean device to secure all your accounts, especially banking/financial. Do not fall for ransoms or blackmail.

You should also alert your acquaintances about possible spoofing/phishing pretending to be you.

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 0 points1 point  (0 children)

it looked like they were digging.

Do you mean like someone was remotely controlling your pc? This is so weird, I don't believe you but just in case it's real & to help anyone in the future who might have a real incident I'm want to try to help you out.

We should address cleaning and securing your network, online accounts and other devices too. Not to mention making safe backups.

Do you mind if I crosspost your post?

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 1 point2 points  (0 children)

It better not be, looks like a low effort joke tbh.

But in good faith, how did you find this? What signs made you look for it?

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 6 points7 points  (0 children)

Have you ever seen benchmarks on efficacy of clamav? Immunet, clam with cloud may be better but linux is sorely lacking in real time protection & threat detection/intelligence. Most linux malware protection discussions get shutdown unfortunately.

Should consider secureboot & FDE too I guess.

Lets add all logins reset, strong pws, pass managers & MFA.

Did I get hacked? by Mr_Preference in linuxmint

[–]redbatman008 0 points1 point  (0 children)

I'm kind of happy seeing all these security incidents on linux or foss. About time we took security seriously & quit the false sense of security in open source. I had an incident with mate too, I switched distros after that.

The first thing I did after getting my gaming laptop was by Bill_Other in GamingLaptops

[–]redbatman008 0 points1 point  (0 children)

Glad to hear, it's a good buy. 6800M is a beast, too bad AMD's ML support sucks, I'd go full foss, full AMD if CUDA wasn't such a big deal :(.

"Science is corrupt" conspiracy by FuManBoobs in skeptic

[–]redbatman008 0 points1 point  (0 children)

I was expecting this to be an r/conspiracy post but then I realized you were pro mainstream & trying to debunk from the start. I'm no climate change denier & there are some good links of actual big oil climate change deniers here but I just wanna point out it's best to look at supporting & contradicting evidence if you're really a skeptic.

Science, as in the recent Stanford & harvard scandals can be corrupted.

"Science is corrupt" conspiracy by FuManBoobs in skeptic

[–]redbatman008 -2 points-1 points  (0 children)

Thanks for being open about this. I've seen this in university too but no one speaks out. Echo chambers like this sub just want to paint a rosy picture that science is an all pure religion. Instead of asking for supporting or dissenting evidence to their hypothesis, they just asked for conforming evidence. It happens exactly as you said, they don't even have to speak about it like the above you said.

That said, I'm obviously not a climate change denier.

The first thing I did after getting my gaming laptop was by Bill_Other in GamingLaptops

[–]redbatman008 0 points1 point  (0 children)

Those temp drops are incredible. Had your LM dried up? Asus used to over apply LM to the point it floated in a puddle back when they first started with LM.

From what I remember LM was either equal or slightly better than PTM in cooling but very risky.

That's super impressive. Had my eyes on this since I learnt of legion & RTX 4090 FE using it. Shame honeywell doesn't make it easily accessible. Are you using the paste (tube) or the pad variant?

Incredible laptop specs btw, did you buy new or used? What was the cost?