Re: hacked for the second time

2019-04-08 Thread bofh
On Thu, Apr 4, 2019 at 8:16 PM Cord wrote: > > "Second time" of my title means: > Install first time openbsd desktop --> ssh key stealing --> hacked --> > wipe and reinstall > Install second time openbsd desktop --> not my webmail session opened --> > maybe hacked --> wipe and reinstall I don't

Re: hacked for the second time

2019-04-04 Thread Luca Cappelletti
try to restart over and then security/aide take the db offline and check again that db every time and then use another OS to check that db (i.e. FreeBSD on an RaspberryPi, if you have, ask a friend to download for you the img off your daily "garden") LC

Re: hacked for the second time

2019-04-04 Thread Cord
Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Thursday, April 4, 2019 2:23 PM, Solene Rapenne wrote: > On Thu, Apr 04, 2019 at 11:42:15AM +, Cord wrote: > > > Sent with ProtonMail Secure Email. > > ‐‐‐ Original Message ‐‐‐ > > On Thursday, April 4, 2019 1

Re: hacked for the second time

2019-04-04 Thread Cord
On Thursday, April 4, 2019 1:58 PM, Kevin Chadwick wrote: > On 4/4/19 10:57 AM, Cord wrote: > > > Hi, my english seems very bad because my problem is not to make secure the > > ssh key. My problem is how do not be hacked. > > I have talked about the ssh key stealing to show signs that my pc was

Re: hacked for the second time

2019-04-04 Thread Solene Rapenne
On Thu, Apr 04, 2019 at 11:42:15AM +, Cord wrote: > > > > Sent with ProtonMail Secure Email. > > ‐‐‐ Original Message ‐‐‐ > On Thursday, April 4, 2019 12:27 PM, Normen Wohner wrote: > > > Seeing that OpenBSD comes secure out of the Box the most likely > > thing is that you yoursel

Re: hacked for the second time

2019-04-04 Thread Cord
‐‐‐ Original Message ‐‐‐ On Thursday, April 4, 2019 1:41 PM, Peter N. M. Hansteen wrote: > On Wed, Apr 03, 2019 at 06:56:39PM +, Cord wrote: > Please read my last email to misc, I tried to explain again. > If you see ssh sessions that shouldn't be there, kill those sessions.

Re: hacked for the second time

2019-04-04 Thread Peter J. Philipp
On Thu, Apr 04, 2019 at 11:42:15AM +, Cord wrote: >=20 >=20 >=20 > Sent with ProtonMail Secure Email. >=20 > ? Original Message ? > On Thursday, April 4, 2019 12:27 PM, Normen Wohner wro= te: >=20 > > Seeing that OpenBSD comes secure out of the Box the m

Re: hacked for the second time

2019-04-04 Thread Kevin Chadwick
On 4/4/19 10:57 AM, Cord wrote: > Hi, my english seems very bad because my problem is not to make secure the > ssh key. My problem is how do not be hacked. > I have talked about the ssh key stealing to show signs that my pc was been > compromised. > I can for sure make secure my ssh key but how t

Re: hacked for the second time

2019-04-04 Thread Cord
Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Thursday, April 4, 2019 12:27 PM, Normen Wohner wrote: > Seeing that OpenBSD comes secure out of the Box the most likely > thing is that you yourself compromised your System through 3rd > party software. If it even is the

Re: hacked for the second time

2019-04-04 Thread Peter N. M. Hansteen
On Wed, Apr 03, 2019 at 06:56:39PM +, Cord wrote: > I have some heavy suspect that my openbsd box was been hacked for the second > time in few weeks. The first time was been some weeks ago, I have got some > suspects and after few checks I have found that someone was been connected

Re: hacked for the second time

2019-04-04 Thread Normen Wohner
your >> mobile phone (e.g. Kryptonite -- https://krypt.co; do read caveat regarding >> Android crypto). >> >> Good luck. >> >> On Wed, Apr 03, 2019 at 06:56:39PM +, Cord wrote: >> >>> Hi, >>> I have some heavy suspect that my openbsd box

Re: hacked for the second time

2019-04-04 Thread Flipchan
Setup snort or verbose logging to find out whats wrong On April 3, 2019 8:56:39 PM GMT+02:00, Cord wrote: >Hi, >I have some heavy suspect that my openbsd box was been hacked for the >second time in few weeks. The first time was been some weeks ago, I >have got some suspects and afte

Re: hacked for the second time

2019-04-04 Thread Cord
ey's keyphrase, store it off-client -- for example using your > mobile phone (e.g. Kryptonite -- https://krypt.co; do read caveat regarding > Android crypto). > > Good luck. > > On Wed, Apr 03, 2019 at 06:56:39PM +, Cord wrote: > > > Hi, > > I have some heav

Re: hacked for the second time

2019-04-04 Thread Tor Houghton
ivate key's keyphrase, store it off-client -- for example using your mobile phone (e.g. Kryptonite -- https://krypt.co; do read caveat regarding Android crypto). Good luck. On Wed, Apr 03, 2019 at 06:56:39PM +, Cord wrote: > Hi, > I have some heavy suspect that my openbsd box was bee

Re: hacked for the second time

2019-04-03 Thread Mark Leonard
don't go on this list. You've posted no > > evidence - a big no no. You need a high level of forensic verification > > before you bring this problem to the list. > > > > Good luck, > > > > Zeb > > > > On Wed, Apr 3, 2019 at 11:59 AM Cord wr

Re: hacked for the second time

2019-04-03 Thread R0me0 ***
; Zeb > > On Wed, Apr 3, 2019 at 11:59 AM Cord wrote: > > > Hi, > > I have some heavy suspect that my openbsd box was been hacked for the > > second time in few weeks. The first time was been some weeks ago, I have > > got some suspects and after few checks I have found tha

Re: hacked for the second time

2019-04-03 Thread Zeb Packard
efore you bring this problem to the list. Good luck, Zeb On Wed, Apr 3, 2019 at 11:59 AM Cord wrote: > Hi, > I have some heavy suspect that my openbsd box was been hacked for the > second time in few weeks. The first time was been some weeks ago, I have > got some suspects and af

Re: hacked for the second time

2019-04-03 Thread Anders Andersson
On Wed, Apr 3, 2019 at 8:58 PM Cord wrote: > > Hi, > I have some heavy suspect that my openbsd box was been hacked for the second > time in few weeks. The first time was been some weeks ago, I have got some > suspects and after few checks I have found that someone was been con

Re: hacked for the second time

2019-04-03 Thread Raul Miller
If someone is using your ssh key and you do not want that to happen, please replace your keys. Thanks, -- Raul On Wed, Apr 3, 2019 at 2:58 PM Cord wrote: > > Hi, > I have some heavy suspect that my openbsd box was been hacked for the second > time in few weeks. The first time w

hacked for the second time

2019-04-03 Thread Cord
Hi, I have some heavy suspect that my openbsd box was been hacked for the second time in few weeks. The first time was been some weeks ago, I have got some suspects and after few checks I have found that someone was been connected to my vps via ssh on a non-standard port using my ssh key. The