Shop OBEX P1 Docs P2 Docs Learn Events
Recent web security panic! — Parallax Forums

Recent web security panic!

VIRANDVIRAND Posts: 656
edited 2010-01-25 03:36 in General Discussion
Over the past MONTH, I have been experiencing some bizarre malfunctions while on the web
at an increasing pace, having had to change and fix computers while on the web usually immediately
after mentioning large evil companies and how and why they are likely to go out of business just
like Enron and Madoff. I won't name names because I don't want another mess to clean up, but
apparently this is what is happening:

Something is bypassing software and firewalls and attacking hardware.
-Keylogging in BIOS
-Webcam and Microphone turning on and broadcasting WiFi before the OS even booted.
-A router no longer needs a password
-Machines with only LINUX (various distributions) and various browsers installed are affected.
-The browsers run things and get cookies even when told not to get THOSE cookies.
-Things are getting in that are specifically blocked.
-Youtube also turns on the microphone and webcam, which I physically disabled.
-No memory is allocated for storage.
-No downloading or P2P or "vice-ware" involved, these machines don't even have hard drives!
-Remote controlled navigation of web sites, scrolling and cursor and mouse movements.
-Write protection on SD cards is being ignored, and things being deleted.
-BIOS settings are being modified.
-There is not enough code or memory for code for usual malware.
-OS is installed in ROM, and cannot be modified by the PC.
-BIOS writing seems to be a major part of it unless there are a lot of pre-programmed bug chips in new computers.
-Java and Javascript forums like this one seem to aggravate the situation.

Since 2005, I abandoned Windows, and until last month have not had to waste half my time fixing computers.
It is incredible to see all this nonsense with all the effort I put into avoiding it.
I am now looking for a HARD, HOMEBUILT, NON-REMOTE-PROGRAMMABLE firewall or filtering proxy.

The world is strange, everyone is throwing away virus infested Windows machines and telling me how wonderful
they are to buy again, and now I am even thinking of getting rid of all of these PCs of Junk!

Any help blocking the hardware self-destruct codes, or filtering the evil java and scripts, and still having
web functionality would be appreciated. Of course, after all the BSoDs I've seen lately, I'll puke on you if you say
get WINDOWS 7.


Perhaps a DOS based browser or a 1981 Commodore 64 running GEOS or WHEELS will WORK RIGHT FOREVER.

I know how things work right. I made and use a lot of old stuff that has outlived any and all x86 GUI Garbage.
My PALM PILOTS still work. My Atari 800 still works. My TRS-80 still works. My walkman and boomboxes still work.
My Vinyl still plays, even the 100 year old stuff that you wind up the turntable for and sound comes out the horn,
and the one with the crank that plays wax cylinders, and my FIRST CD PLAYER from 1988, and the VCR
that's so old it DOESN'T EVEN HAVE THE BLINKING 12:00 FEATURE, my rotary phone and my tube radio still work too.

I hope that if I upgrade to a nice 486 machine, the hardware won't update itself with such dangerous insecure evil.
I never threw away a computer, and I'm sure one has PROM instead of FLASH on the motherboard, and UNIX is
faster than WINDOWS. I have KNOPPIX 6 (*) running faster and looking better than Windows 8 possibly could!

(*) Now THIS one is acting up. It's the end of the internet as we know it. All I had to do was type WINDOWS and
KNOPPIX on the same line. I'm using neither now, just a browser in a VM! OK, a tab just changed color. No I am
not tripping. Will it let me send before my BIOS goes blank?...NO?...TRYING AGAIN...

Comments

  • VIRANDVIRAND Posts: 656
    edited 2010-01-18 12:36
    I'm just watching this thing go bonkers now. When I typed KNOPPIX 6 above, that is when the cursor jumped up and
    the 6 appeared on the top line after there was some scrolling. Now it looks like a Sci-Fi computer going bonkers.
    And whoever is in this machine knows there is no dirty pictures nor P2P apps to frame me with, nor any place to
    put them in here.

    It calmed down, but somehow some more packets got in...

    I'll look at the ... Looking at the processes now... nothing unusual... HOW THE HECK CAN THIS HAPPEN?
    Something comes to mind about "halloween documents", I'll try to look that up as a kamikaze mission.

    Post Edited By Moderator (Chris Savage (Parallax)) : 1/19/2010 7:16:34 PM GMT
  • IRobot2IRobot2 Posts: 164
    edited 2010-01-18 14:05
    VIRAND, I gotta' say, after I read your two post I moved my head back from the screen and blinked for a few seconds and said "wow"..... Really?.... I mean,... wow.....

    I am not really sure why your techno world is melting down.... it sounds like something out of an 80's scifi tech movie.... gone wrong. Could you give a short overview of what we could do to help you out? As for diagnosing what is going on.... you got me. I know you stated the older generations of stuff you have still works but it might be the EOL for some of those boxes you are using. -Alex

    PS. ... WOW....

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Alex Burke
    "Beware of computer programmers that carry screwdrivers." -Leonard Brandwein
  • W9GFOW9GFO Posts: 4,010
    edited 2010-01-18 17:55
    logo.jpg

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    The Simple Servo Tester, a kit from Gadget Gangster.
  • Mike GreenMike Green Posts: 23,101
    edited 2010-01-18 18:52
    Sounds like a techy poltergeist (en.wikipedia.org/wiki/Poltergeist). It's a bit out of my league.
  • IRobot2IRobot2 Posts: 164
    edited 2010-01-18 18:54
    @W9GFO - That is the funniest thing I have seen all friggin year. I printed that out and have it hanging on my cubicle now. I like tux in a tinfoil hat. I can think of all sorts of funny quotes for that.

    Anyway, have you actually used tinfoil hat linux before?

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Alex Burke
    "It is not how smart you are rather, it is how you are smart." -Jon Campbell

    Post Edited (IRobot2) : 1/18/2010 7:15:02 PM GMT
  • AJMAJM Posts: 171
    edited 2010-01-18 20:42
    Just looking at your post for the firewall suggestion, I would recommend OpenBSD.

    Good Luck
  • Phil Pilgrim (PhiPi)Phil Pilgrim (PhiPi) Posts: 23,514
    edited 2010-01-18 21:28
    VIRAND,

    Are you using a wireless keyboard or wireless mouse? You may be getting interference, or it may just be a case of low batteries. I've seen some of your reported symptoms on my Win XP machine, and changing the batteries in my mouse always fixes things. This also occurred once when I had two wireless mice on at the same time. Finally, if your keyboard and mouse are both hardwired, you may have a bad cable or connector.

    -Phil

    Post Edited (Phil Pilgrim (PhiPi)) : 1/18/2010 9:37:13 PM GMT
  • AJMAJM Posts: 171
    edited 2010-01-18 23:27
    Following up to Phil's post in regards to mouse movements

    Are you using a laptop?

    I have had issues with synaptic touch pads under linux where the mouse cursor liked to scroll around by itself. I can't recall what kernel version this was however; something around 2.6.26-28?
  • VIRANDVIRAND Posts: 656
    edited 2010-01-19 00:17
    W9GFO said...
    logo.jpg
    I expected this and laugh, but only as Noah might have laughed back at the people who laughed about
    there being no such thing as Rain.

    On another forum someone said something like "What can you expect from something as unpredictable as
    a computer system?" I laughed at that too because unpredictable computer systems are useless and
    unfamiliar to me, except between 1995 and 2005 when I was forced to tolerate random BSoDs.

    Looking things over, I find that YTIMG.COM can break and enter at any time after using Youtube.
    It is blackhat spyware as far as I can tell, it can change BIOS settings and it turns on the microphone
    and webcam if it is connected. That is its MAIN PURPOSE. It's secondary purpose is serving thumbnails
    and ads, which for some reason I rarely see. It is BLOCKED but still gets in. It has a MULTITUDE of random
    IP addresses. Believe me, you can still watch videos on Youtube if and when you can block YTIMG.COM,
    and YTIMG.COM can enter even if you don't go to Youtube or a site that has a link to a video.
    It is as dangerous as being fool enough to use FACEBOOK (and its trojan apps), which is voluntary spyware,
    like taking off the beanie and opening your skull for all authority (i.e. your boss) to look for policy-violating
    thoughts, and consequentially getting fired. If you have never heard of this scenario before then you have tinfoil
    earplugs. As for turning on your mics and webcams if you have them, there is or used to be a setting hidden
    on the video player lower edge that has switches for mic and webcam access THAT DON'T DO ANYTHING,
    and YTIMG.COM may also be keylogging (why not or who else) since I've detected keyloggers outgoing
    packets before, most recently while looking at a Wikileaks archive just after Wikileaks recently went down,
    but it is more obvious when words like MIKRO$AFT, MAFIAA, and piRIAAtes are used, since there is an
    immediate beginning of strange activity. THE MECHANISM SEEMS TO BE THE CORRUPTION OF THE STANDARD
    JAVA AND JAVASCRIPT CODE. THIS WILL NEVER HAPPEN ON ANY SITE WITHOUT JAVA OR JAVASCRIPT WHICH
    WORKS WITH THOSE BLOCKED BY THE BROWSER unless, and until, the security settings and trojan plugins
    have been installed by using a script site and enabling scripts. Since these forums sometimes require some
    JAVA and JAVASCRIPT, that is why it happens here. I would like to know if the scripts on this site are from
    SUN JAVA or M$ JAVA. The evidence suggests the latter, since M$ JAVA is intentionally corrupted. Proof
    or Evidence beyond reasonable doubt if needed may be provided in a future post on this thread.

    I am not (never was) a willing win user nor a EULA signer so I wonder if that makes any difference to
    help litigators against M$, but they are already convicted and going unpunished, OR who knows? Maybe
    they paid double their fines to make the EULA the next CONSTITUTION of the willfully AGREEing USA.

    Generally all malware is enabled by failure to write protect. There is no write protect switch on an HD,
    like on floppies and ZIP/JAZ and CDROM (esp. nonburning drives) and there is more than reasonable doubt
    that SD write protect is implemented since it is not a real switch and Propeller FSRW doesn't obey it.

    Since Flash BIOS is software programmable unlike PROM BIOS, it can be bugged. Malware can bug win
    drivers also, but M$ probably uses them as bugs since most M$ drivers are redundant to the ones in
    the BIOS (which obviously has drivers in it, for keyboards, video, disks, USB, network, mouse, PRINTER, etc.).

    This is not a rant but factual technical info to the best of my knowledge, which includes the ability to build
    a PC-like computer from scratch using NAND gates and then program and USE it, although it would NOT be
    as powerful as most Parallax products. I designed and built some very thin client terminals in the mid 1990s, still alive.


    I did have to use tinfoil on my wifi antennas to interrupt an attack in progress, by the way.
    Just for fun and curiosity I will go see if there is a "Tinfoil Hat Linux".

    The last attack was "undone" with a SYSTEM RESET and VM reload, which is not an option with "win" because
    it makes you wait for it to be "safe" to pull the plug, plenty of warning for the malware you get to find somewhere
    to hide from the fading ... unpowered ... unrefreshed DRAM memory.

    Win or no win, Hard Drive failure is "unpredictable", which is why using them should be avoided,
    (BTW, avoid deleting files except by wipe or reformat. Delete doesn't really erase, it just frags and corrupts.)

    Whoa. This time I enabled JAVA+JAVASCRIPT and nothing happened. Even reloading the page,
    The smileys didn't animate and
    SUBMIT didn't do anything. It usually works to do a Quick Reply, now trying that.

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    VIRAND, If you spent as much time SPINNING as you do Trolling the Forums,
    you'd have tons of awesome code to post!
    (Note to self)
  • VIRANDVIRAND Posts: 656
    edited 2010-01-19 00:27
    Weird. I can only Quick Reply, and can't see the TinFoil Penguin anymore. SN(except somehow bizarrely)AFU.
    Enough wasting time on this nonsense. Obviously a distraction from soldering, because I want to hack the doody
    out of the bugger, but I should just toss this box behind the recycle bin.

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    VIRAND, If you spent as much time SPINNING as you do Trolling the Forums,
    you'd have tons of awesome code to post!
    (Note to self)
  • W9GFOW9GFO Posts: 4,010
    edited 2010-01-19 05:50
    IRobot2 said...
    Anyway, have you actually used tinfoil hat linux before?

    No, I haven't. I like the picture though!

    Rich H

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    The Simple Servo Tester, a kit from Gadget Gangster.
  • BradCBradC Posts: 2,601
    edited 2010-01-19 06:36
    AJM said...

    Are you using a laptop?

    I have had issues with synaptic touch pads under linux where the mouse cursor liked to scroll around by itself. I can't recall what kernel version this was however; something around 2.6.26-28?

    I've had this under all operating systems if my mobile phone was near the touchpad when it checked into the tower. Took me _ages_ to figure out what was going on.

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Life may be "too short", but it's the longest thing we ever do.
  • LuckyLucky Posts: 98
    edited 2010-01-19 07:23
    Are you kidding me! Noooooooooo! I was just searching online for magnetic tape a few minutes ago and I clicked on YTIMG.COM. Then my internet browser froze and
    I had to do CTR + ALT + DEL and end internet explorer. Now I am really worried from what Virand said. Now I'm afraid to turn off my computer because of what will happen when I turn it on again! [noparse]:([/noparse]....... Any suggestions of what course of action, if any, I should take.

    EDIT: I did some research and it turns out ytimg stands for youtube image. Google bought youtube so apparently they added this for some copyright protection. Now that I know it is google/youtube related, I'm not as worried, though im still curious as to why ie stopped working.

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    "You do not really understand something unless you can explain it to your grandmother."


    -Lucky[size=-1][/size]

    Post Edited (Lucky) : 1/19/2010 7:34:41 AM GMT
  • Phil Pilgrim (PhiPi)Phil Pilgrim (PhiPi) Posts: 23,514
    edited 2010-01-19 07:42
    ytimg.com is owned by Google via YouTube (hence the "yt"). It's used by YouTube for serving static images. I doubt seriously that it's the source of any malware. (That doesn't rule out DNS poisoning, however.) Anyway, here's the Norton analysis of the site: safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.ytimg.com%2F

    -Phil
  • VIRANDVIRAND Posts: 656
    edited 2010-01-19 09:01
    BradC said...
    I've had this under all operating systems if my mobile phone was near the touchpad when it checked into the tower. Took me _ages_ to figure out what was going on.
    Wow. Now testing. That's a good possibility since I just got a new phone last month and its been in my pocket.
    I'm testing recklessly on the same box to see if it acts up after I just put the phone away.
    I couldn't get online with anything else I tried all day.

    I really hope that that is it. I reaffirm the synchronicity with having typed certain provocative things.
    The first time it happened was just after I got the phone AND wrote about Big Evil INCs on the forum site of
    a well known tabloid that 'prints all the news that fits'.
    It is like how the sodium lights always go out when I walk directly under them at night.

    My brother once told me that his phone really messes up his computer while his 1KW ham radio transmitter
    does NOT. He even described all kinds of weird screen effects, but I guess I imagined it more like what happens
    if you put a strong magnet on a color tube screen (warning, permanent damage, if you still have one), than the
    unlikely seeming convincing illusion of remote access and remote control. PCs always used to freeze and halt
    if they were glitched, until I rebooted.
    About those net terminals I mentioned making, I used to demonstrate that
    they could withstand having the motherboard buried in small screws and nuts, shorting the bus, and having the
    screen glitch up like an Atari if you yank out the game you're playing, and then the terminal would recover while
    still powered up when the board was turned upside down so all the metal hardware fell off of it. It is a surprise
    to me that any PC even in Linux could just misbehave while glitched by microwaves and not crash. BUT this month
    is the first time ever since starting in 2005 that I've ever seen Linux malfunction at all!


    IT LOOKS LIKE IT IS HAPPY AGAIN WITHOUT THE PHONE!

    hop.gifturn.gif Thank you very much. Penguins don't like Microwaves! lol.gif

    jumpin.giflol.gifAnd Microwaves don't like TinFoil Hats ! lol.gif

    NOW, will the SUBMIT button do more than make a clicking noise?
    If this is the last line then I correctly predicted YES!
  • VIRANDVIRAND Posts: 656
    edited 2010-01-19 09:13
    P.S. I didn't exaggerate the symptoms.
    THE BIOS WAS ALTERED. THE BOOT SECTOR AND OTHER CRITICAL THINGS WERE DELETED.
    This microwaving your computer with a phone phenomenon is too dangerous to use as a prank!

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    VIRAND, If you spent as much time SPINNING as you do Trolling the Forums,
    you'd have tons of awesome code to post!
    (Note to self)
  • BradCBradC Posts: 2,601
    edited 2010-01-19 09:49
    In my case the mobile phone was simply causing the electronics in the touchpad to see touches that were not there. I've seen phones do all sorts of strange stuff to electronics that are inadequately protected. GSM uses a fairly potent transmit power, but it's low duty cycle so it averages out. Electronics don't seem to see the whole averaging thing and the induced noise can be hair raising. Especially when you have left your phone on the lighting desk and the mixing console next door is connected to about 20,000 Watts of FOH amplification [noparse];)[/noparse] Way to Smile of the sound engineer!

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Life may be "too short", but it's the longest thing we ever do.
  • skylightskylight Posts: 1,915
    edited 2010-01-19 13:36
    could be the start of Odyssey 5? only 5 years to go jumpin.gif
  • AJMAJM Posts: 171
    edited 2010-01-19 14:03
    BradC said...


    I've had this under all operating systems if my mobile phone was near the touchpad when it checked into the tower. Took me _ages_ to figure out what was going on.

    That is wild. I searched for so long trying to figure out what was happening. I suppose it was coincidence that around the time I recompiled my kernel I stopped placing my phone near my laptop.

    I will check this later when I get home.

    Thanks!
  • Lab RatLab Rat Posts: 289
    edited 2010-01-19 15:35
    yeah my phone does stupid stuff to my laptop like disabling the wireless card. i actually have to manually turn of the wireless card and turn it back on to fix

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Parallax posesses power beyond belief.

    Believe in it.
    Visit me at
    http://jrelectromech.services.officelive.com/default.aspx
    ·
  • Peter KG6LSEPeter KG6LSE Posts: 1,383
    edited 2010-01-19 18:52
    VIRAND said...

    My brother once told me that his phone really messes up his computer while his 1KW ham radio transmitter
    does NOT. He even described all kinds of weird screen effects
    I have a issue with 2M SSB and the Fire Pull boxes in my dorm room ..

    Mind you 100W at 435MHz right next to this pull box does nothing !
    but 5 W of 144.200MHz Sig just in my room and WHAM! there goes the alarm ..

    also the the Cat5 UTP wireing in my home in CA gives off alll kinds of trash .



    GSM is cute as it is its NOT RFI frendly .. My friends GSM ATT Phne is NOT allowed In my room as it does wacky things to my sound system
    but My Verizon based thingy (gets better reception ) and does not put tons of trash on the air ..

    I use RHEL 5.2 and I have never had a issue with it so far ..

    Peter KG6LSE

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    "Carpe Ducktum" "seize the tape!!"
    peterthethinker.com/tesla/Venom/Venom.html
    Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. —Tanenbaum, Andrew S.
    LOL
  • HollyMinkowskiHollyMinkowski Posts: 1,398
    edited 2010-01-22 21:11
    There is a write enable pin on the bios chip that you can disable.
    You could run it to a switch so you can update the bios eeprom later
    if you need to.
  • Alex41Alex41 Posts: 112
    edited 2010-01-24 13:57
    BradC said...


    I've had this under all operating systems if my mobile phone was near the touchpad when it checked into the tower. Took me _ages_ to figure out what was going on.


    Just imagine the effect the phone has on your brain when you hold the phone to your ear while actively talking on it........


    Alex
  • ForrestForrest Posts: 1,341
    edited 2010-01-24 16:07
    Virand,

    Do you have any enemies? Hackers have demonstrated they can read keystrokes over power lines and use lasers to detect keyboard vibration on a laptop! hackaday.com/2009/07/29/black-hat-2009-powerline-and-optical-keysniffing/

    I've read about viruses that can hide inside the unused keyboard processor memory. These viruses are very difficult to kill because every time you turn on your PC your computer will be reinfected from the keyboard.

    Maybe you want to pickup an old PowerPC based Macintosh and run IPNetRouterX on it www.sustworks.com/site/index.html. Add to the fact there are no known viruses for OSX.
  • BradCBradC Posts: 2,601
    edited 2010-01-24 16:19
    Alex41 said...
    BradC said...


    I've had this under all operating systems if my mobile phone was near the touchpad when it checked into the tower. Took me _ages_ to figure out what was going on.


    Just imagine the effect the phone has on your brain when you hold the phone to your ear while actively talking on it........

    Which is why I use a bluetooth handsfree kit that hangs around my neck. It can affect my heart instead while my hand cops the big radiation [noparse]:)[/noparse] But, yes.. I'm pretty horrified by the thought of pumping all that RF into your noggin. Non-ionizing radiation indeed. Where's my Al-foil hat? (We don't do tinfoil in Australia. It's Aluminium)

    ▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔▔
    Life may be "too short", but it's the longest thing we ever do.
  • VIRANDVIRAND Posts: 656
    edited 2010-01-25 03:36
    Somebody said...
    Do you have any enemies? Hackers have demonstrated they can read keystrokes over power lines and use lasers to detect keyboard vibration on a laptop! hackaday.com/2009/07/29/black-hat-2009-powerline-and-optical-keysniffing/

    I've read about viruses that can hide inside the unused keyboard processor memory. These viruses are very difficult to kill because every time you turn on your PC your computer will be reinfected from the keyboard.

    Maybe you want to pickup an old PowerPC based Macintosh and run IPNetRouterX on it www.sustworks.com/site/index.html. Add to the fact there are no known viruses for OSX.
    1 Almost everything imaginable is possible.
    2. My keyboards have i8048 chips. No unused memory. Not rewritable devices. They can't get viruses.
    If your keyboard has a virus, you either agreed with its EULA or your lawyer will return it to the manufacturer
    for a million dollar rebate!
    3. There are no known or possible viruses for ANY honest write-protected software.
    BradC said...

    Where's my Al-foil hat? (We don't do tinfoil in Australia. It's Aluminium)
    Tin foil existed when Edison recorded "Mary Had a Little Lamb" on it, but I think not since Aluminum foil was invented.
Sign In or Register to comment.