Puppy 5.1 hacked into remotely?

For discussions about security.
Message
Author
User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

Puppy 5.1 hacked into remotely?

#1 Post by dru5k1 »

my friend hacked into my computer - he said it was nice and easy

User avatar
Aitch
Posts: 6518
Joined: Wed 04 Apr 2007, 15:57
Location: Chatham, Kent, UK

#2 Post by Aitch »

Care to give more details?

What OS were you running?

Was it a remote hack, or did he have access to your PC/network?

If it was puppy, could you send me a pm from him saying what he did/how he did it, rather than post details on the forum

thanks

Aitch :)

User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

#3 Post by dru5k1 »

yes it was puppy (5.1) and was remote

as for pm'ing you, I suppose I could, might take a minute though

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#4 Post by nooby »

Did your friend ask you first or was it a surprise hack? :)

Did he leave some message on your HDD, Did you have the Firewall set the normal way that the Devs have prepared?
Could he mount HDD and such.

Do you use CD or USB or Frugal install or Full install?

Remote he did not go through your open wifi sitting outside in his car or something :)
I use Google Search on Puppy Forum
not an ideal solution though

User avatar
Lobster
Official Crustacean
Posts: 15522
Joined: Wed 04 May 2005, 06:06
Location: Paradox Realm
Contact:

#5 Post by Lobster »

Love to know how it is done
Send me a PM too of this simple method
or better still post it here so we can all have a go :)
Puppy Raspup 8.2Final 8)
Puppy Links Page http://www.smokey01.com/bruceb/puppy.html :D

User avatar
Aitch
Posts: 6518
Joined: Wed 04 Apr 2007, 15:57
Location: Chatham, Kent, UK

#6 Post by Aitch »

[quote-"Lobster"]....or better still post it here so we can all have a go :) [/quote]

I tried to avoid it going public till we know what was done

thanks

Aitch :)

Trobin
Posts: 968
Joined: Fri 19 Aug 2005, 03:16
Location: BC Canada

#7 Post by Trobin »

I'd like to know how it's done as well. I think it should be posted here so that interested parties can protect themselves.

PM please.
[url]http://speakpup.blogspot.com[/url]

User avatar
Flash
Official Dog Handler
Posts: 13071
Joined: Wed 04 May 2005, 16:04
Location: Arizona USA

#8 Post by Flash »

I think it's best if everyone knows how it's done. If it's a vulnerability in Puppy's default configuration, we can fix it. If it's a vulnerability in Linux, it will be fixed. Keeping it secret turns it into a potential FUD attack against Puppy or against Linux.
[url=http://www.murga-linux.com/puppy/viewtopic.php?t=69321][color=blue]Puppy Help 101 - an interactive tutorial for Lupu 5.25[/color][/url]

User avatar
Lobster
Official Crustacean
Posts: 15522
Joined: Wed 04 May 2005, 06:06
Location: Paradox Realm
Contact:

#9 Post by Lobster »

my friend hacked into my computer - he said it was nice and easy
Until we receive a private or public PM this is nothing more than a statement like:
'The dog ate my homework'
'Resistance is Futile'
and
'The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards.' — Gene Spafford

. . . meanwhile I am off to mix some concrete . . . :)
Puppy Raspup 8.2Final 8)
Puppy Links Page http://www.smokey01.com/bruceb/puppy.html :D

User avatar
rjbrewer
Posts: 4405
Joined: Tue 22 Jan 2008, 21:41
Location: merriam, kansas

#10 Post by rjbrewer »

Lobster wrote:
'The dog ate my homework'
'Resistance is Futile'
)
The dog ate my house;
we ran away quickly. :)
Attachments
enormous-animals25.jpg
(183.2 KiB) Downloaded 1267 times

Inspiron 700m, Pent.M 1.6Ghz, 1Gb ram.
Msi Wind U100, N270 1.6>2.0Ghz, 1.5Gb ram.
Eeepc 8g 701, 900Mhz, 1Gb ram.
Full installs

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#11 Post by nooby »

Flash wrote:I think it's best if everyone knows how it's done. If it's a vulnerability in Puppy's default configuration, we can fix it. If it's a vulnerability in Linux, it will be fixed. Keeping it secret turns it into a potential FUD attack against Puppy or against Linux.

At least the Devs should know the details ASAP
. To reveal how to replicate it can be very dangerous so I would prefer Barry and pemasu ttuuxxx and Micko01 and Playdays and iguleder and every such active devs get to know first so them have time to make a solution if it is a serious thing. Or them can explain how to protect against it.
I use Google Search on Puppy Forum
not an ideal solution though

User avatar
James C
Posts: 6618
Joined: Thu 26 Mar 2009, 05:12
Location: Kentucky

#12 Post by James C »

I'll believe it once someone can verify it.

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#13 Post by nooby »

Does any of you know him personally. I hope he look back and asnwer our questions.
I use Google Search on Puppy Forum
not an ideal solution though

User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

#14 Post by dru5k1 »

Hey I'm here, and I talked to him again -it not 'nevermind' I just don't live with him shouting across the living-room "hey bro.."

He's a bit of a joking snobby guy, only saying that the my browser was too old and I need to update my sh*#. we've chatted and exchanged files, also meeting in irc (the way he zeroed in on my address) - he's a windows user and a paying customer of metasploit so I guess he's got exploits for all but the latest software

(I've since updated my sh*# (firefox+chrome from chromium+flashplayer and haven't had any hassles) - it wasn't a dream I know, because I noticed a complete slowdown and reset everything straight away, he said that he already had access but the slowdown was him trying to use a gui.

User avatar
Lobster
Official Crustacean
Posts: 15522
Joined: Wed 04 May 2005, 06:06
Location: Paradox Realm
Contact:

#15 Post by Lobster »

Thanks dru5k1 for giving us more details 8)
Much appreciated . . .

In the world of tin hats, white, black and grey hats
I am nowhere
but it sounds like two vulnerabilities occurred
First you get someone's IP address when connected on IRC
or if sending them a file (using netstat, whois or however it is done)
Then what do you do?
Dunno but I bet
http://www.metasploit.com/
or our very own attackpup would have the required scripts . . .
http://www.murga-linux.com/puppy/viewto ... 022#421022

Maybe your 'joking snobby guy' could get a job with Rupert Murdoch s personal intrusion services? Just an idea . . . :)
Puppy Raspup 8.2Final 8)
Puppy Links Page http://www.smokey01.com/bruceb/puppy.html :D

User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

#16 Post by dru5k1 »

oh my gosh that attackpup is so beautiful

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#17 Post by nooby »

Much appreciated but now we need the computer savvy people among Puppy users to tell us how to protect ourselves.

1. Did you have a router at that time. Did him go through the router then.
2. Or did he lure you to visit some page him had prepared with a Flash thing or
3. did he send you something that had the downloader of something that allowed him to get in?

Was this a vulnerability in the Firefox Flash or something that that program he had paid for used?

I fail to get it.
I use Google Search on Puppy Forum
not an ideal solution though

User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

#18 Post by dru5k1 »

It could well have been flash, because both the firefox, chromium that I installed via quickpet, and flash were all out of date at the time I installed them

(firefox has an updater built in that I ran twice to get fully up to date. chromium had to become chrome, and flash needed to be replaced via downloading and replacement in the file-manager)

User avatar
dru5k1
Posts: 72
Joined: Mon 12 Apr 2010, 01:15

#19 Post by dru5k1 »

(I actually know now to go into Puppy Package Manager ("install" desktop icon) and via the Configure Package Manager button, tick the ubuntu repositories (I chose main, multiverse, and universe) and then click the Update button before searching for chrome

I think chrome is in ubuntu lucid main, but I can't remember to tell the truth

nooby
Posts: 10369
Joined: Sun 29 Jun 2008, 19:05
Location: SwedenEurope

#20 Post by nooby »

Hope it is okay that I am a bit at it. I wonder about this

2. Or did he lure you to visit some page him had prepared with a Flash thing or

Suppose you are right about having an older version of Flash.

But that would only work for him if him had his own Blog or server or some place him could place a file on that make use of that Flash vulnerability.

But if it was through the Router then he has to have a program that actually penetrated from outside through the router.

Is it possible now to look in the log of the router if he came that way?

I guess this did happen days or weeks ago. Has he promised to never try again?

Anything you remember can help the Devs to make Puppy better or them tell us what we have to do to make us more secure.
I use Google Search on Puppy Forum
not an ideal solution though

Post Reply