Tillbaka till svenska Fidonet
English   Information   Debug  
IC   0/2851
INTERNET   0/424
INTERUSER   0/3
IP_CONNECT   719
JAMNNTPD   0/233
JAMTLAND   0/47
KATTY_KORNER   0/41
LAN   0/16
LINUX-USER   0/19
LINUXHELP   0/1155
LINUX   0/22013
LINUX_BBS   0/957
mail   18.68
mail_fore_ok   249
MENSA   0/341
MODERATOR   0/102
MONTE   0/992
MOSCOW_OKLAHOMA   0/1245
MUFFIN   0/783
MUSIC   0/321
N203_STAT   900
N203_SYSCHAT   313
NET203   321
NET204   69
NET_DEV   0/10
NORD.ADMIN   0/101
NORD.CHAT   0/2572
NORD.FIDONET   189
NORD.HARDWARE   0/28
NORD.KULTUR   0/114
NORD.PROG   0/32
NORD.SOFTWARE   0/88
NORD.TEKNIK   0/58
NORD   0/453
OCCULT_CHAT   0/93
OS2BBS   0/787
OS2DOSBBS   0/580
OS2HW   0/42
OS2INET   0/37
OS2LAN   0/134
OS2PROG   0/36
OS2REXX   0/113
OS2USER-L   207
OS2   0/4785
OSDEBATE   0/18996
PASCAL   0/490
PERL   0/457
PHP   0/45
POINTS   0/405
POLITICS   0/29554
POL_INC   0/14731
PSION   103
R20_ADMIN   1117
R20_AMATORRADIO   0/2
R20_BEST_OF_FIDONET   13
R20_CHAT   0/893
R20_DEPP   0/3
R20_DEV   399
R20_ECHO2   1379
R20_ECHOPRES   0/35
R20_ESTAT   0/719
R20_FIDONETPROG...
...RAM.MYPOINT
  0/2
R20_FIDONETPROGRAM   0/22
R20_FIDONET   0/248
R20_FILEFIND   0/24
R20_FILEFOUND   0/22
R20_HIFI   0/3
R20_INFO2   2814
R20_INTERNET   0/12940
R20_INTRESSE   0/60
R20_INTR_KOM   0/99
R20_KANDIDAT.CHAT   42
R20_KANDIDAT   28
R20_KOM_DEV   112
R20_KONTROLL   0/13069
R20_KORSET   0/18
R20_LOKALTRAFIK   0/24
R20_MODERATOR   0/1852
R20_NC   76
R20_NET200   245
R20_NETWORK.OTH...
...ERNETS
  0/13
R20_OPERATIVSYS...
...TEM.LINUX
  0/44
R20_PROGRAMVAROR   0/1
R20_REC2NEC   534
R20_SFOSM   0/340
R20_SF   0/108
R20_SPRAK.ENGLISH   0/1
R20_SQUISH   107
R20_TEST   2
R20_WORST_OF_FIDONET   12
RAR   0/9
RA_MULTI   106
RA_UTIL   0/162
REGCON.EUR   0/2055
REGCON   0/13
SCIENCE   0/1206
SF   0/239
SHAREWARE_SUPPORT   0/5146
SHAREWRE   0/14
SIMPSONS   0/169
STATS_OLD1   0/2539.065
STATS_OLD2   0/2530
STATS_OLD3   0/2395.095
STATS_OLD4   0/1692.25
SURVIVOR   0/495
SYSOPS_CORNER   0/3
SYSOP   0/84
TAGLINES   0/112
TEAMOS2   0/4530
TECH   0/2617
TEST.444   0/105
TRAPDOOR   0/19
TREK   0/755
TUB   0/290
UFO   0/40
UNIX   0/1316
USA_EURLINK   0/102
USR_MODEMS   0/1
VATICAN   0/2740
VIETNAM_VETS   0/14
VIRUS   0/378
VIRUS_INFO   0/201
VISUAL_BASIC   0/473
WHITEHOUSE   0/5187
WIN2000   0/101
WIN32   0/30
WIN95   0/4277
WIN95_OLD1   0/70272
WINDOWS   0/1517
WWB_SYSOP   0/419
WWB_TECH   0/810
ZCC-PUBLIC   0/1
ZEC   4

 
4DOS   0/134
ABORTION   0/7
ALASKA_CHAT   0/506
ALLFIX_FILE   0/1313
ALLFIX_FILE_OLD1   0/7997
ALT_DOS   0/152
AMATEUR_RADIO   0/1039
AMIGASALE   0/14
AMIGA   0/331
AMIGA_INT   0/1
AMIGA_PROG   0/20
AMIGA_SYSOP   0/26
ANIME   0/15
ARGUS   0/924
ASCII_ART   0/340
ASIAN_LINK   0/651
ASTRONOMY   0/417
AUDIO   0/92
AUTOMOBILE_RACING   0/105
BABYLON5   0/17862
BAG   135
BATPOWER   0/361
BBBS.ENGLISH   0/382
BBSLAW   0/109
BBS_ADS   0/5290
BBS_INTERNET   0/507
BIBLE   0/3563
BINKD   0/1119
BINKLEY   0/215
BLUEWAVE   0/2173
CABLE_MODEMS   0/25
CBM   0/46
CDRECORD   0/66
CDROM   0/20
CLASSIC_COMPUTER   0/378
COMICS   0/15
CONSPRCY   0/899
COOKING   28619
COOKING_OLD1   0/24719
COOKING_OLD2   0/40862
COOKING_OLD3   0/37489
COOKING_OLD4   0/35496
COOKING_OLD5   9370
C_ECHO   0/189
C_PLUSPLUS   0/31
DIRTY_DOZEN   0/201
DOORGAMES   0/2025
DOS_INTERNET   0/196
duplikat   6000
ECHOLIST   0/18295
EC_SUPPORT   0/318
ELECTRONICS   0/359
ELEKTRONIK.GER   1534
ENET.LINGUISTIC   0/13
ENET.POLITICS   0/4
ENET.SOFT   0/11701
ENET.SYSOP   33806
ENET.TALKS   0/32
ENGLISH_TUTOR   0/2000
EVOLUTION   0/1335
FDECHO   0/217
FDN_ANNOUNCE   0/7068
FIDONEWS   23548
FIDONEWS_OLD1   0/49742
FIDONEWS_OLD2   0/35949
FIDONEWS_OLD3   0/30874
FIDONEWS_OLD4   0/37224
FIDO_SYSOP   12847
FIDO_UTIL   0/180
FILEFIND   0/209
FILEGATE   0/212
FILM   0/18
FNEWS_PUBLISH   4200
FN_SYSOP   41525
FN_SYSOP_OLD1   71952
FTP_FIDO   0/2
FTSC_PUBLIC   0/13586
FUNNY   0/4886
GENEALOGY.EUR   0/71
GET_INFO   105
GOLDED   0/408
HAM   0/16053
HOLYSMOKE   0/6791
HOT_SITES   0/1
HTMLEDIT   0/71
HUB203   466
HUB_100   264
HUB_400   39
HUMOR   0/29
Möte LINUX, 22013 texter
 lista första sista föregående nästa
Text 6670, 262 rader
Skriven 2006-08-01 13:07:36 av WAYNE CHIRNSIDE (1:123/140)
     Kommentar till en text av MAURICE KINAL
Ärende: Hijacked
================
-> Aug 01 06:56 06, WAYNE CHIRNSIDE wrote to MAURICE KINAL:

->  WC> Only time I operated as SU is during apt-get or when configuring my 
->  WC> user
->  WC> account. 

-> Sounds to me like that is the culprit then.  I've never allowed myself to
use
-> stuff like that over the internet and anyone claiming that I need to have an
-> application that requires root access, including su, is treated with
extremely
-> high suspicion as to their motives or way of thinking, up to and including
-> Debian 'people'.

I had adhered to a similar cautious ethic... until.
Bedridden, no credit card I'm hesitant to ask for help.
Security issues keep me from using the debit card on the internet.
Upgrading via the internet seemed ideal until this bugger hit.

->  WC> Originally unknown to me the default setting configurations
->  WC> in apt-get were high risk. 

-> Anything that requires root access over a networked connection is
suspicious.

->  WC> I fixed that but it's too late now. 

-> Right.  I read further down.  Other then a secondary boot I don't know what
to
-> suggest.  Maybe mke2fs but if the geometry is screwed then that probably
won't
-> work either.  Another option might be to 'dd' the entire drive with
/dev/zero? 
-> Something like 'dd if=/dev/zero of=/dev/hda' and then see if it can be
fdisked

Quoting wrapped off page, is that /dev/zero?          
wish I'd tried it before I pulled the cables.
It's not especially easy for me to even pull cables nor are they
designed to be repeatedly plugged and unplugged.

-> after that.  If it were a tape then a magnet would fix it but I don't
recommend
-> that with harddrives.

Yeah, drive mapping. You'd need the manufacturers HD utility.
Now that's a thought, if only I had a unaffected hard drive :-( 

Wish I had a FIPS prepared boot diskette, that might just put the drive
right, or not, never seen fdisk fail let alone the fdisk x option.

->  WC> There's a root SU account hiding in a hidden partition  
->  WC> operating outside of my control and nothing stops it.

-> Weird.

->  WC> Norton wipeinfo fails also.

-> Norton is garbage.  They started off on the right foot but somewhere along
the
-> line got crappy.  Overbloated crap methinks.                   

Hey, it was on the old slaved Seage I was just bragging on getting
jumpered and working. Legacy software from when Nrton tools we're so
bad.
I gave it a shot.
Nothing appears to phase this beast.

->  WC> Reminds me nothing so much as a Compaq P.C.'s hidden partition ( 
->  WC> which
->  WC> is why I hate Compaqs.)

-> Another reason for me avoiding Compaqs.  The thing about them is all their
-> hardware is the same as everyone else's hardware but they insisted on
crippling
-> it further then everyone else other then maybe HP.  Given they are the same
-> company now it isn't hard to see why.

I was happy with my Dumpster Gateway untill this weekend,
Now it's RAMdrive only with 384 Meg of RAM.

->  WC> Even Linux fdisk in expert mode  doesn't touch this bugger.

-> Is that from a secondary boot?          

From the live CD boot.
The CD drive is read only.
No joy.
fdisk eXpert mode _appears_ to work.
Rebooting proves otherwise.
that this fiendish thing is clever I'll not deny.
Speaks of an intimate knowledge of the workings of hard drives,
programming  and fdisk.

->  WC> Fdisk the hard drive, check the settings and it looks ok but reboot
->  WC> and the previous partitioning scheme is tossed and the invader 
->  WC> has repartitioned the hard drive.                 

-> You need to try all that from a different boot device.  Sounds to me like
-> leakage.            

Let it try to leak into the read only CD or jump across the air where
power and IDE
cables once lay.
I've booted Win 98 OEM CD and fdisked.
Win 98 S.E. image file recovery disk.
I've booted to the Linux live CD, no joy.

->  WC> It never really got repartitioned as the hard drive geometry has been
->  WC> messed with but you wouldn't know until you rebooted and looked

-> Right.  I've seen that happen with Windows formatted drives.  I've even
showed
-> people that but they insist the *NEED* to do that so they are basically
-> screwed.  Go figure eh?

->  WC> Something written to the superblocks, ( whatever they are) persists
->  WC> and prevails over attempts to restore the hard drive.

-> That shouldn't happen.
                                         
But it does, relentlessly.
Changed my online banking account passwords, after yanking cables
and rebooting CD.
Got an email to the effect my password had changed but their web site
shows no record of having sent this though it provides precisely this
tracking for security purposes.
Of course the email warning had a file attachment.
Also of course I'd just set all the account settings into RAM then
had to cold boot to find the warning was a phishing expedition.

->  WC> It _appears_ this hidden partition retains data for Mozilla and
->  WC> Konqueror as both take me right to a fraudulent web side for 
->  WC> a online P.C. adware and trojan scan.     

-> Neither of those gets airtime on any machine here.  I hate that stuff and
now
-> you just gave me another reason to continue hating that stuff.  Again,
-> overbloated crap methinks.                            

A little late I'm becoming a convert but with little else I can do 
it's diverting at least, or was.
Can't even do flash now without downloading to RAM
and installing to same.

->  WC> On a _clean_ install, which isn't in fact clean Mozilla snags
->  WC> "Netscape preferences" and loads them.

-> Get rid of it.      

Along with the hard drive. 
it came bacK with the CD however it's not a writtable CD drive.
I'd not trust even elinks from the infected machine.
Too much of what this malware is doing appears to be happening very
close to hardware level.   
Any access to either hard drive puts me at risk.

->  WC> My name appears in the email account without my ever having entered 
->  WC> it.

-> Wipe it out.
                          
With what?
I didn't try dd before pulling cables but all else.
fdisk was no joy even in expert mode so I'm skeptical dd
would work either though it's likely I'l try it in a few days
after I cable up a drive.
Too bad I soldered that slave or I could master it and use it, maybe but
I think even that little 340 Meg Seagate is affected.
It thinks it's got two FAT 16 partitions and a network drive letter
assigned.
Untrue, it's split three ways type C, 83, 83


->  WC> Then on the first use of mail it says "I don't know how to handle 
->  WC> this",
->  WC> open it with ? or save to disk?                                

-> Get rid of it.

->  WC> Think it's "Spy Killer" or some such ( web site it takes me to.)

-> Never heard of it.  Sounds to me like corruption to the extreme.

not to be unduly dramatic but it _may_ be the end of computers
and independent living for me.
It just got to be too expensive renting hard drives.
Not a bad block between the two of them they're both worse than useless.

->  WC> I need to get a clean hard drive.

-> Right.                                                               

Somewhat unrealistic.
I can manage it this month _just_.
What of my bookmarks?                                     
what did it ride in on?
Apt-get or the Mozilla browser trojan I was reading about.
I can't trust my address.ldfi files on floppy as _something_
is riding in on something in preferences. 

->  WC> I have a installation CD and I'm working from a _clean_ install now
->  WC> however it's no use.

-> You need to wipe out the original before reinstalling else it'll probably
-> persist.  Also just install basics and ensure that everything absolutely
-> required is working properly before installing further.  Definetly don't
-> install Mozilla until you are sure that isn't where the funky stuff is
coming
-> from.

-> Do you like even Mozilla?             

Actually I rather do, or did, no do.
I don't know if that was the actual entry vector though it's highly
affected but when was the last time a browser trojan partitioned your
hard drive, or anyone's for that matter.
This thing doesn't look like it's limited to Mozilla, it owns my hard
drive through faking the hard drive geometry. 

->  WC> I've never seen anything remotely like it myself.

-> Me neither.  You probably should get a new install CD, one that has a
-> console/commandline option and basic tools.

This one has that as a boot option.
Still need a clean hard drive but I'd just be renting as I've no idea of
the entry vector of this monster.

->  WC> Damn thing almost acts intelligent it's so sneaky and devious.

-> Yeah.  Sure sounds suspicious.

It acts like it's thinking and it IS outwitting me.
Whatever I've tried has been anticipated.
I mean it prevents expert mode fdisk from allowing me to alter hard
drive geometry.

->  WC> Being mobility impaired online banking is a necessity as I can't go
->  WC> to the bank.
->  WC> Now I dare not even use that.
->  WC> I've just been warped into the stone age.

-> Ouch.

->  WC> Someone has gone to a lot of trouble to mess with someone here.

-> Right.  Quite a few jerks around that is for sure.

->  WC> All I've got left is some low risk web surfing and fidonet.
->  WC> Can't even have an address list or mail account as this puts others 
->  WC> at
->  WC> risk.

-> Whatever you are using for email get rid of it.

I got rid of ALL of it but to no avail.
Both drives are physically perfect with no bad blocks and they're both
useless. 
worse than useless, much worse.
--- Platinum Xpress/Win/WINServer v3.0pr5
 * Origin: Try Our Web Based QWK: DOCSPLACE.ORG (1:123/140)