Hacker?

  • Guten Abend
    Habe heute bemerkt das der smbd Prozess ca 8% CPU load macht und der Switch blinkt auch also nas und Router nun stellt sich mir die frage was wo hin kopiert wird habe alle PCs gecheckt nichts wird kopiert
    Windowsfreigaben sind Passwort geschürzt..


    Bitte um Hilfe


    MfG




    good Evening
    Today I noticed that the smbd process approximately 8 % CPU load and therefore makes the switch flashes NAS and router now makes me wonder what go where copies have all PCs checked nothing is copied
    Windows releases are pursed password ..


    Please help


    (google translator)

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

    Einmal editiert, zuletzt von MrYoshii ()

  • 58.218.205.69.51249 das sieht verdächtig aus oder?




    58.218.205.69.51249 that looks suspiciously like it?

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • i have no open ports
    and i have no chines gf :D




    what about it?

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • IP HomeServer.local.ssh > 221.229.166.205.32791


    221.229.166.205 is a chinese IP address. Suspect.
    239.255.255.250 is multicast in your LAN. Probably unsuspicious.


    PS:
    You can find out, where a specific IP address is located by just searching the web for it.

  • ok




    have but no open ports How is that possible that the access ?

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • OK,


    if your machine is hacked, then the connection is started from inside your lan (NAS).
    Then your router normally allows the communication.
    I would stop the internet connection of the NAS (firewall policy in the router, or taking away the def. GW), backup all data and examine the NAS.
    I think I would reinstall the machine.
    Give the output of
    ps -A
    Perhaps we will see something there.
    Perhaps someone else has also a good idea ?(

  • NAS has been installed 2 days ago
    have banned the Chinese in router


    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • NAS has been installed 2 days ago


    hmmm, that reduces the possibility to be hacked.
    In ps -A I don't see any suspicious processes


    You can try to disable one service after the other (for example: I don't know how and where CLAMAV loads its virus-database updates) and have a look whether the communication stops.


    Or tcpdump the traffic into a file and have a look on it with wireshark.
    Perhaps you find a hint there.


    But keep in mind that I am not a virus-expert.
    Therfore other opinions are strongly welcome.

  • i have blockt the ip area

    Code
    58.218.205.01 - 58.218.205.255
    221.229.166.01 - 221.229.166.255


    and now i have no trafic



    if anything changes I register resist

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • you're right but i have no idea what i can do

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • You can try to disable one service after the other (for example: I don't know how and where CLAMAV loads its virus-database updates) and have a look whether the communication stops.


    Or tcpdump the traffic into a file and have a look on it with wireshark.
    Perhaps you find a hint there.


    If in doubt, I would reinstall my system.

  • ok my question is why he can access t my files i have set a pw with 18 character
    and the root pw has also 18 character

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • Plex installed?


    Greetings
    David

    "Well... lately this forum has become support for everything except omv" [...] "And is like someone is banning Google from their browsers"


    Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.

    Upload Logfile via WebGUI/CLI
    #openmediavault on freenode IRC | German & English | GMT+1
    Absolutely no Support via PM!

  • Zitat

    The router could be the problem. Take a look at him too.


    how ?


    Zitat

    Plex installed?


    no i have no plex installt i have no open ports and all pw a very difficult

    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

  • Here is the auth.log


    Nas Build:

    CPU: Intel Celeron G1840
    MB: Gigabyte GA-H97N-WIFI
    RAM: Kingston KVR1333D3N9 Arbeitspeicher 8GB
    Power Supply: Be quiet! BN140 System Power 7 300Watt
    HDDs: 2x 2TB Seagate Barracuda ST2000DM001, 60GB Hitachi System Drive, 2x 250GB Seagate Drive
    CASE: Fractal Design Node 804


    Regards

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!