TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

My brother got hacked, what's the most plausible attack vector?

2 点作者 orange_tee超过 4 年前
My brother got a desktop from Ebay. It arrived yesterday and had Windows preinstalled. He installed Manjaro, found out the wifi driver required fiddling and removed it again and installed Deepin Linux instead. And he kept Windows installed also.<p>A day later I discover that he has an ssh server running on his desktop and connected to Russian, Chinese and Thailandese IPs.<p>Other things he had running were Chromium and Zoom as he was attending a lecture.<p>The way I found out is because I tried SSHing into a media server that I have at his home, and I mistakenly ended up sshing into his desktop. The media server and his desktop shared the same not very secure password since he had set it up for me and he is careless like that. Because I didn&#x27;t care enough about the media server I was using password login (not public key auth). Once I logged into my media server it was untouched. BTW we aren&#x27;t VIP or anything. It was probably some kind of botnet.<p>What is puzzling me is how his desktop got infiltrated. Because how could he have an openssh server running on an almost new installation with practically no use? He is certain he didn&#x27;t do it himself. The other question is, how did they get the password?<p>Edit: Through http:&#x2F;&#x2F;www.blocklist.de, I found out that the botnet once connected was doing bruteforcelogin on other targets. So that is likely how they got in. Still not sure how the openssh server was running.

2 条评论

netizen-9748超过 4 年前
I thought most distros come with SSH standard? When I spin up Debian and centOS VMs I don&#x27;t have to do anything special before I can SSH into them.
评论 #25782406 未加载
GrumpyNl超过 4 年前
Sounds to me the distro is already infected. Can you delete it all and repeat the steps and notice when it happens?