canonical-web-and-design / tutorials.ubuntu.com

Other
172 stars 146 forks source link

Advanced Persistent and System Undetected Exploit-kit Attack #1106

Closed TheOtakumyst closed 4 years ago

TheOtakumyst commented 4 years ago

I can't get a decent download to clean install from to save my life. The Persistent local storage has been local on the system but it's so fast that the entire apartment building get reconfigured before I can even get the to type in sudo apt-get update.

During the install I being alerted that pid 999 is taking ownership of this that and the third but even though the console is aware in does little other than just telling me that we don't own our own permissions, halfway through the install.

Info on this attack can be read about going back to at least 2009 so I don't want to hear about what's normal and what's not.

There's just way too much much happening during the actual installing process than there needs to be. I don't understand why the actual install can't just be the UEFI migration and then once that it securely in place then the next logical module or rest even?

The problem is that the malware does not have to wait for all the fat to settle, it can just get right to it's undetected infecting.

All of the config file are written in seconds. You cannot fix these by hand it's impossible. Fixing the printer settings would take you a week... And why is the printer so important? Stop including it and it's security flaws like it's 1995 still. Bolt too. Get rid of it. It ain't about to get any safer.

I went for about 4 months not noticing that my environment variables "$LS_COLOR' was a key containing malicious trojan data.. server ip subnet masks are hidden within normal looking preferences keys until you notice there's way too many 255's in that group of numbers.. Too many 192's and 168's too be coincidence. There's too many red flags that are missed and I'm not buying the "hidden processes" deal, the system should know by deducting reasoning that something is off. When the user spends all day and night with utilities for a month, something is wrong.

A major piece is the browser hijacking and javascript content manipulation. ISP's don't even believe client complaints yet .mozilla firefox let's sidechannel attacks right into the same page they're hosting their breach disclosure from... Weekly.

I have 53 active PCI anonymous dbus and ibus or systemd fake users, mice and keyboards plugged in appearently and they all are also their own hotspots with servers... All with higher escalated permissions than God that NOBODY GAVE PERMISSION TOO.

Serously don't act brand new, how do you fix this idiot Tech Industry Stalker BS, I'm over it. Regular users aren't developer test dummies. Eventually you guys are gonna start paying for this shit.

/bin/systemd-analyze:Unit has no Listen setting (ListenStream=, ListenDatagram=, ListenFIFO=, ...). Refusing.Unit configured for accepting sockets, but sockets are non-accepting. Refusing.MaxConnection= setting too small. Refusing.Explicit service configuration for accepting socket units not supported. Refusing.Unit has PAM enabled. Kill mode must be set to 'control-group'. Refusing.Unit has symlinks set but none or more than one node in the file system. Refusing.Failed to read from user lookup fd: %mReceived too short user lookup message, ignoring.Received too long user lookup message, ignoring.Got user lookup message with invalid UID/GID pair, ignoring.Received lookup message with embedded NUL character, ignoring.Got user lookup message but unit doesn't exist, ignoring.User lookup succeeded: uid=%u gid=%uCouldn't add UID/GID reference to unit, proceeding without: %m%s %u is no longer referenced, cleaning up its IPC.hashmap_update(*uid_refs, UID_TO_PTR(uid), UINT32_TO_PTR(c)) >= 0Failed to run 'stop-pre' task: %mIN_SET(s->state, SOCKET_LISTENING, SOCKET_RUNNING)Socket unit configuration has changed while unit has been running, no open socket file descriptor left. The socket unit is not functional until restarted.Socket unit configuration has changed while unit has been running, and some socket file descriptors have not been opened yet. The socket unit is not fully functional until restarted.Got POLLHUP on a listening socket. The service probably invoked shutdown() on it, and should better not do that.Got unexpected poll event (0x%x) on socket.Failed to create communication channel: %mFailed to fork off accept stub process: %mFailed to accept connection socket: %mFailed to send connection socket to parent: %mFailed to receive connection socket: %mSuppressing connection request since unit stop is scheduled.Trigger limit hit, refusing further activation.Service to activate vanished, refusing activation.Too many incoming connections (%u), dropping connection.Too many incoming connections (%u) from source %s, dropping connection.%u-%u.%u.%u.%u:%u-%u.%u.%u.%u:%uGot ENOTCONN on incoming socket, assuming aborted connection attempt, ignoring.Failed to queue service startup job (Maybe the service file is missing or not a %s unit?): %sFailed to determine SELinux label: %mFailed to create listening socket (%s): %mFailed to fork off listener stub process: %mFailed to join network namespace: %mNetwork namespace path configured but network namespaces not supported.Failed to send listening socket (%s) to parent: %mFailed to receive listening socket (%s): %mFailed to open special file %s: %mSetting pipe size failed, ignoring: %mSMACK relabelling failed, ignoring: %mFailed to open message queue %s: %mFailed to listen on sockets: %mFailed to resolve group %s: %mFailed to fork 'start-chown' task: %mRunning next command for state %sGot final SIGCHLD for state %sSocket service %s not loaded, refusing.Socket service %s already active, refusing.IN_SET(s->state, SOCKET_DEAD, SOCKET_FAILED)hashmap_isempty(m->units_requiring_mounts_for)Restoring log target to original %s.Restoring log level to original (%s).Found unreferenced %s %u after reload/reexec. Cleaning up.hashmap_remove(*uid_refs, k) == pFailed to send manager change signal: %m/sys/subsystem/ncgroups-missing:overflowuid-not-overflowgid-not-../src/analyze/analyze-security.cIN_SET(mode, SHOW_STATUS_AUTO, SHOW_STATUS_NO, SHOW_STATUS_YES, SHOW_STATUS_TEMPORARY)Failed to open generator directory %s: %mFailed to peek for child with waitid(), ignoring: %mChild %i (%s) died (code=%s, status=%i/%s)Failed to dequeue child, ignoring: %mFailed to disable SIGCHLD event source: %m../src/analyze/analyze-verify.cCommand %s is not executable: %mGot notification message "%s", ignoring.Got unexpected poll event for notify fd.Failed to receive notification message: %mReceived notify message without valid credentials. Ignoring.Received notify message exceeded maximum size. Ignoring.Received notify message with embedded NUL bytes. Ignoring.Cannot find unit for notify message of PID %i, ignoring.Got extra auxiliary fds with notification message, closing them.Failed to read cgroups agent message: %mGot zero-length cgroups agent message, ignoring.Got overly long cgroups agent message, ignoring.Got cgroups agent message with embedded NUL byte, ignoring.Failed to propagate agent release message: %mService does not define an IP address whitelistService defines IP address whitelist with non-localhost entriesService defines IP address whitelits with only localhost entriesService blocks all IP address rangesFiles created by service are group-writable by defaultFiles created by service are group-readable by defaultFiles created by service are world-writable by defaultFiles created by service are world-readable by defaultFiles created by service are accessible only by service's own user by defaultsigaction(SIGCHLD, &sa, NULL) == 0sigprocmask(SIG_SETMASK, &mask, NULL) == 0Failed to enable ctrl-alt-del handling: %mFailed to enable kbrequest handling: %m/etc/localtime doesn't exist yet, watching /etc instead.Failed to create timezone change event source: %mFailed to set priority of timezone change event sources: %mFailed to stat /etc/localtime, ignoring: %minotify event for /etc/localtimeTimezone has been changed (now: %s).Failed to create timer change timer fd: %mFailed to create time change event source: %mFailed to set priority of time change event sources: %mSet up TFD_TIMER_CANCEL_ON_SET timerfd.MESSAGE_ID=c7a787079b354eaaa9e77b371893cd27Failed to list /run/systemd/ask-password: %mFailed to get unit properties: %sUnit %s not found, cannot analyze.Unit %s is masked, cannot analyze.Unit %s not loaded properly, cannot analyze.Service runs in special boot phase, option does not applyFailed to add cell to table: %mweight = table_get_at(details_table, row, 3)badness = table_get_at(details_table, row, 4)range = table_get_at(details_table, row, 5)cell = table_get_cell(details_table, row, 6)Failed to update cell in table: %m /bin/transmission-gtk:msgwin.cforestgreenblackforeground%02d:%02d:%02dMessage Logprimary-toolbargtk-save-asLevelDebuggetForegroundColor(as)(^a&s)actions(u*)NotificationClosedActionInvoked(us)(u&s)(u)org.freedesktop.NotificationsFailed to create proxy for %sg-signalGetCapabilitiesG_IS_DBUS_PROXY (proxy)Open FileOpen FolderTorrent Complete(susssasa{sv}i)NotifyTorrent Addedg_variant_is_of_type (params, G_VARIANT_TYPE ("(u*)"))/org/freedesktop/Notificationsgtr_notify_torrent_addedgtr_notify_torrent_completedg_signal_callbackTorrent files*.torrentAll filesrecent-download-dir-%durl-entryTorrent Optionsopen-dialog.c_Start when added_Torrent file:Select Source File_Destination folder:Select Destination Folderstrcouldn't select '%s'Open a TorrentShow _options dialogOpen URLOpen torrent from URL_URLMo_ve .torrent file to the trashgtr_torrent_options_dialog_newCouldn't move torrentMoving "%s"gtr-relocate-datachoosermove_rbThis may take a moment…Set Torrent Locationgtk-applyTorrent _location:_Move from the current folderLocal data is _already thereStarted %'d timesStarted %'d timeReset your statistics?_ResetCurrent SessionDuration:TotalThese statistics are for your information only. Resetting them doesn't affect the statistics logged by your BitTorrent trackers.TorrentCellRenderertr_torrent*tr_stat.pieceUploadSpeed_KBpspiece-upload-speedpiece-download-speedBar Heightbar-heightCompact Modecompact%1$s %2$s %3$s %4$s%1$s %2$s%1$s Ratio: %2$sTracker gave a warning: "%s"Tracker gave an error: "%s"Error: %sweb seedsweb seedDownloading from %1$'d %2$s%1$s of %2$s (%3$s%%) - Remaining time unknown%s remainingpropertytorrent-cell-renderer.cscaleforeground-rgbatr_stat.pieceDownloadSpeed_KBpsVerifying local data (%.1f%% tested)Downloading metadata from %1$'d %2$s (%3$d%% done)Downloading from %1$'d of %2$'d %3$s and %4$'d %5$sDownloading from %1$'d of %2$'d %3$sSeeding to %1$'d of %2$'d connected peersSeeding to %1$'d of %2$'d connected peer%1$s of %2$s (%3$s%%), uploaded %4$s (Ratio: %5$s Goal: %6$s)%1$s of %2$s (%3$s%%), uploaded %4$s (Ratio: %5$s)%1$s, uploaded %2$s (Ratio: %3$s Goal: %4$s)%1$s, uploaded %2$s (Ratio: %3$s)%s:%d: invalid %s id %u for "%s" of type '%s' in '%s'���@���X������������������������������������������D���������������������������������������������������������?TrCoreblocklist-updatedport-testedstandard::edit-name%s.added%s %smagnet:%smagnet:?xt=urn:btih:%shttphttpsSkipping unknown torrent "%s"Couldn't read "%s": %sport-testblocklist-updatecore->privUninhibitorg.gnome.SessionManager/org/gnome/SessionManagerAllowing desktop hibernationtr-core.cBitTorrent Activity(susu)Inhibittime::modifiedUnable to rename "%s" as "%s": %sGTK+ client doesn't support connections to remote servers yet.Couldn't uninhibit desktop hibernation: %s.Transmission BitTorrent ClientInhibiting desktop hibernationCouldn't inhibit desktop hibernation: %sgtr_core_set_hibernation_allowed$@/icon-popuptr_corepref-keyidle-dataUpdate BlocklistGetting new blocklist…Blocklist contains %'d rulesBlocklist contains %'d rule%sBlocklist has %'d rules.Blocklist has %'d rule.Unable to update.Update succeeded!Port is openPort is closedTesting TCP port…0.0.0.0http://localhost:%d//html/preferences.htmlStatus unknown_Upload (%s):_Download (%s):Alternative Speed Limits%sU_pload (%s):Do_wnload (%s):_Scheduled times: _to _On days:SaturdayFridayThursdayWednesdayTuesdayMondaySundayWeekendsWeekdaysEvery DaypageTransmission PreferencesGerundDownloadingGerundAdding_Start added torrentsSave to _Location:Download QueueMa_ximum active downloads:IncompleteKeep _incomplete torrents in:GerundSeedingStop seeding at _ratio:Privacy_Encryption mode:Require encryptionPrefer encryptionAllow encryptionEnable _blocklist:_UpdatesessionEnable _automatic updatesNetworkListening PortTe_st PortPeer LimitsMaximum peers per _torrent:Maximum peers _overall:Use PE_X to find more peersUse _DHT to find more peersDesktopNotificationRemoteRemote ControlAllow _remote access_Open web clientHTTP _port:Use _authentication_Username:Pass_word:Addresses:Override normal speed limits manually or at scheduled timestransmission-preferences-dialogAutomatically add .torrent files _from:Show the Torrent Options _dialogDownloads sharing data in the last _N minutes are active:Append "._part" to incomplete files' namesCall scrip_t when torrent is completed:Stop seeding if idle for _N minutes:_Port used for incoming connections:Pick a _random port every time Transmission is startedUse UPnP or NAT-PMP port _forwarding from my routerEnable _uTP for peer communicationuTP is a tool for reducing network congestion.PEX is a tool for exchanging peer lists with the peers you're connected to.DHT is a tool for finding peers without a tracker.Use _Local Peer Discovery to find more peersLPD is a tool for finding peers on your local network._Inhibit hibernation when torrents are activeShow Transmission icon in the _notification areaShow a notification when torrents are a_ddedShow a notification when torrents _finishPlay a _sound when torrents finishOnly allow these IP a_ddresses:IP addresses may use wildcards, such as 192.168..��?/main-window-popupStop at Ratio (%s)enabled-keydirection-keyprivate_dataUnlimitedspeed-keystock-ratio-index%s %sstats-modesession-ratioRatio: %ssession-transfertotal-transfersize|Down: %1$s, Up: %2$sstyle-updatedvisibleTotal Ratiotr-main/main-window-menu/main-window-toolbarLimit Download SpeedLimit Upload SpeedStop Seeding at RatioSeed Forevermargin-leftsizingresizablepopup-menurow-activatedtr-workarea999.99 kB/sSession RatioTotal TransferSession TransferTracker will allow requests in %sClick to disable Alternative Speed Limits /bin/transmission-gtk:xTX00 T^@.@ffffff�?pC�Cpeer-msgs.c[%s] %s - %s [%s]: (%s:%d)outMessage size is now %zurejecting %u:%u->%u...requesting %u:%u->%u...requesting metadata piece #%dsending block %u:%u->%usending a keepalive messageTransmission 2.94sending an ltep handshakedirection [%d] is_active [%d]got Chokegot Unchokegot Interestedgot Not Interestedgot Have: %ugot a bitfieldgot Request: %u:%u->%urejecting an invalid request.got a Cancel %u:%u->%uGot a BT_PORTGot a BT_FEXT_SUGGESTGot a BT_FEXT_ALLOWED_FASTGot a BT_FEXT_HAVE_ALLGot a BT_FEXT_HAVE_NONEGot a BT_FEXT_REJECTGot a BT_LTEPgot ltep handshakemsgs->ut_pex is %dmsgs->ut_metadata_id is %dpeer's port is now %dgot ut pexgot ut metadatapeer sent us an

steverydz commented 4 years ago

Thanks for submitting an issue for this tutorial. We have moved our tutorials to discourse. To contribute going forwards please go to https://discourse.ubuntu.com/c/tutorials.