Re: is this result of keylogger? am i hacked?

2011-11-26 Thread Sergey Spiridonov
Hi 21.07.2010 14:39, Sergey Spiridonov пишет: > I found yesterday that some files in /etc/ (/etc/shells and > /etc/default/default/schroot) are changed. They contain data which I was > typing on keyboard. Strange enough, this files are not overwritten, but > contain data they should contain + some

Re: is this result of keylogger? am i hacked?

2010-07-27 Thread Alexey Salmin
On Wed, Jul 28, 2010 at 4:44 AM, Sergey Spiridonov < sergey.spirido...@gmail.com> wrote: > However chkrootkit and fsck found no problem. > > What else can I check? > -- > Best regards, Sergey Spiridonov > May be try smartctl test to check for hard drive errors? Alexey

Re: is this result of keylogger? am i hacked?

2010-07-27 Thread Sergey Spiridonov
Hi On 27.07.2010 00:09, Jordon Bedwell wrote: On 7/26/10 5:05 PM, Sergey Spiridonov wrote: # cryptsetup create md1-crypt /dev/md1 # pvdisplay /dev/mapper/crypt-md1 No physical volume label read from /dev/mapper/md1-crypt Failed to read physical volume "/dev/mapper/md1-crypt" I should probably

Re: is this result of keylogger? am i hacked?

2010-07-27 Thread Sergey Spiridonov
Hi On 07/27/2010 02:38 AM, Rob Owens wrote: You can apt-get install things in Knoppix. It'll just install it using available RAM, and won't actually write it to the disk. I did not have internet for some time at that machine. Now I get internet and installed cryptsetup. But now I have anothe

Re: is this result of keylogger? am i hacked?

2010-07-26 Thread Rob Owens
On Sun, Jul 25, 2010 at 05:30:45PM -0500, Jordon Bedwell wrote: > On 7/25/10 12:52 PM, Sergey Spiridonov wrote: >> Hi >> >> I ran memcheck 4.0, it showed no problem. Unfortunately I can not use >> knoppix to mount and check my partitions with fsck and chkrootkit, >> bevause latest knoppix (6.2.1) f

Re: is this result of keylogger? am i hacked?

2010-07-26 Thread Jordon Bedwell
On 7/26/10 5:05 PM, Sergey Spiridonov wrote: Hi On 26.07.2010 00:51, Jordon Bedwell wrote: Also, to add, if you plan on doing a cryptographic integrity check, you need to do this from a liveCD not from a liveUSB. The only reason you would do a liveUSB is for things like fsck and chkrootkit (whe

Re: is this result of keylogger? am i hacked?

2010-07-26 Thread Sergey Spiridonov
Hi On 26.07.2010 00:51, Jordon Bedwell wrote: Also, to add, if you plan on doing a cryptographic integrity check, you need to do this from a liveCD not from a liveUSB. The only reason you would do a liveUSB is for things like fsck and chkrootkit (where you would mount as readonly at first) I

Re: is this result of keylogger? am i hacked?

2010-07-25 Thread Jordon Bedwell
On 7/25/10 5:30 PM, Jordon Bedwell wrote: On 7/25/10 12:52 PM, Sergey Spiridonov wrote: Hi I ran memcheck 4.0, it showed no problem. Unfortunately I can not use knoppix to mount and check my partitions with fsck and chkrootkit, bevause latest knoppix (6.2.1) for whatever reason does not include

Re: is this result of keylogger? am i hacked?

2010-07-25 Thread Jordon Bedwell
On 7/25/10 12:52 PM, Sergey Spiridonov wrote: Hi I ran memcheck 4.0, it showed no problem. Unfortunately I can not use knoppix to mount and check my partitions with fsck and chkrootkit, bevause latest knoppix (6.2.1) for whatever reason does not include cryptsetup. :( You can however use the

Re: is this result of keylogger? am i hacked?

2010-07-25 Thread Sergey Spiridonov
Hi I ran memcheck 4.0, it showed no problem. Unfortunately I can not use knoppix to mount and check my partitions with fsck and chkrootkit, bevause latest knoppix (6.2.1) for whatever reason does not include cryptsetup. :( -- Best regards, Sergey Spiridonov -- To UNSUBSCRIBE, email to debi

Re: is this result of keylogger? am i hacked?

2010-07-23 Thread Sergey Spiridonov
Hi On 07/21/2010 11:51 PM, François TOURDE wrote: I think memory is not the reason, because some time ago I get broken /etc/shells file also on another machine, which is running Lenny. If you are so confident, why asking here? I am not confident and I will do this tests (just need to buy cd

Re: is this result of keylogger? am i hacked?

2010-07-23 Thread Sergey Spiridonov
Hi On 07/21/2010 06:45 PM, Chris Davies wrote: > For breakage of something as significant as /etc/shells, I'd prioritise > investigations in that order. Memtest86+ is a no-brainer, so let it > test your machine. Are you using a kernel that's got known issues with > whatever filesystem you are us

Re: is this result of keylogger? am i hacked?

2010-07-21 Thread François TOURDE
Le 14811ième jour après Epoch, Sergey Spiridonov écrivait: > Hi > > On 07/21/2010 03:40 PM, Jochen Schulz wrote: > >> One possible reason: your memory is corrupt. Run memtest86 to check >> that. > > I think memory is not the reason, because some time ago I get broken > /etc/shells file also on ano

Re: is this result of keylogger? am i hacked?

2010-07-21 Thread Chris Davies
Sergey Spiridonov wrote: > I think memory is not the reason, because some time ago I get broken > /etc/shells file also on another machine, which is running Lenny. Broken memory. Broken kernel (possibly but not necessarily the filesystem driver). Hacked machine. Broken hardware. For breakage of

Re: is this result of keylogger? am i hacked?

2010-07-21 Thread Aaron Toponce
On 07/21/2010 06:39 AM, Sergey Spiridonov wrote: > I found yesterday that some files in /etc/ (/etc/shells and > /etc/default/default/schroot) are changed. They contain data which I was > typing on keyboard. Strange enough, this files are not overwritten, but > contain data they should contain + so

Re: is this result of keylogger? am i hacked?

2010-07-21 Thread Sergey Spiridonov
Hi On 07/21/2010 03:40 PM, Jochen Schulz wrote: One possible reason: your memory is corrupt. Run memtest86 to check that. I think memory is not the reason, because some time ago I get broken /etc/shells file also on another machine, which is running Lenny. -- Best regards, Sergey Spiridono

Re: is this result of keylogger? am i hacked?

2010-07-21 Thread Jochen Schulz
Sergey Spiridonov: > > I found yesterday that some files in /etc/ (/etc/shells and > /etc/default/default/schroot) are changed. They contain data which I > was typing on keyboard. Strange enough, this files are not > overwritten, but contain data they should contain + somewhere in the > middle or

is this result of keylogger? am i hacked?

2010-07-21 Thread Sergey Spiridonov
Hi I found yesterday that some files in /etc/ (/etc/shells and /etc/default/default/schroot) are changed. They contain data which I was typing on keyboard. Strange enough, this files are not overwritten, but contain data they should contain + somewhere in the middle or at the beginning of the