TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

My brother got hacked, what's the most plausible attack vector?

2 pointsby orange_teeover 4 years ago
My brother got a desktop from Ebay. It arrived yesterday and had Windows preinstalled. He installed Manjaro, found out the wifi driver required fiddling and removed it again and installed Deepin Linux instead. And he kept Windows installed also.<p>A day later I discover that he has an ssh server running on his desktop and connected to Russian, Chinese and Thailandese IPs.<p>Other things he had running were Chromium and Zoom as he was attending a lecture.<p>The way I found out is because I tried SSHing into a media server that I have at his home, and I mistakenly ended up sshing into his desktop. The media server and his desktop shared the same not very secure password since he had set it up for me and he is careless like that. Because I didn&#x27;t care enough about the media server I was using password login (not public key auth). Once I logged into my media server it was untouched. BTW we aren&#x27;t VIP or anything. It was probably some kind of botnet.<p>What is puzzling me is how his desktop got infiltrated. Because how could he have an openssh server running on an almost new installation with practically no use? He is certain he didn&#x27;t do it himself. The other question is, how did they get the password?<p>Edit: Through http:&#x2F;&#x2F;www.blocklist.de, I found out that the botnet once connected was doing bruteforcelogin on other targets. So that is likely how they got in. Still not sure how the openssh server was running.

2 comments

netizen-9748over 4 years ago
I thought most distros come with SSH standard? When I spin up Debian and centOS VMs I don&#x27;t have to do anything special before I can SSH into them.
评论 #25782406 未加载
GrumpyNlover 4 years ago
Sounds to me the distro is already infected. Can you delete it all and repeat the steps and notice when it happens?