Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Zero Day Exploits - How to Reset Everything

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 7 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      weirdpolice Banned
      last edited by

      Hey, I started using pfSense recently and found a network trojan that went to sleep like 30 minutes after I turned on Suricata. Next day, I found some other regular kernel injection stuff - assumed it to be a cover up for a nastier exploit because I started posting about it everywhere and mentioning topics related to time travel and other paranormal activity (blue pill).

      Yadda yadda yadda. Hear a voice that says, "Follow the white rabbit." There's a screen flashing white whenever I click Network Settings. So I follow the white rabbit and now my 4G connection is going through DC at a ridiculous speed when I try to download Qubes OS from my cell phone (since the network is...). Also, tried to download IDA Pro because I figured that would raise some flags for the hackers and thought they might get paranoid and leave my network alone. When I opened my cell phone to start downloading Qubes OS, it flashed on and off and when it came back on it was ridiculously fast.

      Anyway, now my computer is behaiving oddly. The VPN connection push notification is showing up every 3 mins. Also, I can't use my microphone or camera. Also, after I downloaded cat pictures, my computer made a cat sound later.

      pfSense has stopped generating alerts. All I see is this in Suricata is this coming from the FiOS gateway: SURICATA ICMPv4 unknown type.

      Anyway, what am I supposed to do? I downloaded the 5GIG Qubes OS in about 5 minutes on my 4G cell phone. Is that normal? Should I install that? Is DC hooking me up with a copy of Qubes or are they trying to get my copy of Qubes?

      If you have any advice, please post it before the admins delete this post.

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        WTF did I just read? ๐Ÿ˜ต

        -Rico

        JKnottJ 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @Rico
          last edited by

          @Rico

          WTF did I just read? ๐Ÿ˜ต

          Dunno. Maybe he's been in self isolation too long. ๐Ÿ˜‰

          Anyhow, the easiest way to reset to "factory" is to just reinstall. It's not hard.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            @weirdpolice said in Zero Day Exploits - How to Reset Everything:

            Anyway, what am I supposed to do?

            Stop doing whatever mind altering substances you're on would be my first suggestion..

            I'm with @Rico WTF!! ;)

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • ?
              A Former User
              last edited by

              At this point I think I want some of what they're on. Promise not to post wasted :)

              W 1 Reply Last reply Reply Quote 0
              • W
                weirdpolice Banned @A Former User
                last edited by

                @jwj Just believe it is the white rabbit and it will become the white rabbit.

                ๐Ÿ‡

                ๐Ÿ‡

                ๐Ÿ‡

                https://imgur.com/gallery/u5tix60

                1 Reply Last reply Reply Quote 0
                • W
                  weirdpolice Banned
                  last edited by

                  Please guys, I need help. I'm thinking up CRAZY plans to escape from active attahackers. Should I be setting up Microwave comms from my neighbors houses? Should I be going to random WiFis with a brand new computer and USB keys to make install software. Why has no one recommended I get a Network TAP? Should I get a USB Tap? How do I capture the virus for analysis when it crawls from my computer to USB?

                  For now, my plan is to scratch my balls.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    As with any sort of infection.. That you are not sure you can actually clean.. Nuke it from orbit, is the only way to be sure..

                    https://youtu.be/aCbfMkh940Q

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    W 1 Reply Last reply Reply Quote 0
                    • W
                      weirdpolice Banned @johnpoz
                      last edited by

                      @johnpoz Nuking from orbit not recommended.

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by johnpoz

                        Yeah it is - that is how you clean something that you are on sure of.. This is industry standards.. If you feel device is infected and your not 110% sure you can remove the infection.. Then you need to wipe it and install from known clean source.

                        It quite often is faster to get the device back into production as well..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • H
                          Harvy66
                          last edited by Harvy66

                          When I was in IT, I had someone who opened an excel file or something in an unsolicited email. They told me this when I asked them how they may have gotten infected. So I reimaged their computer, sent network share of a zip of their backed up documents, told them to copy off only the ones they absolutely need. Or something along those lines, this was 15 years ago.

                          Short bit later, I get notified that their computer is infected with the same malware/virus again. I asked them what happened. They said they found the original excel file that caused all of this in the backup and wanted to see what was in it.......

                          This time I had to sit down at the keyboard and ask them which folders/files they wanted restored and why. Then I scanned them all. Of course I could also cross check them in the backup history and see they were all unchanged for well before the infection.

                          1 Reply Last reply Reply Quote 0
                          • GertjanG
                            Gertjan @weirdpolice
                            last edited by

                            @weirdpolice said in Zero Day Exploits - How to Reset Everything:

                            @johnpoz Nuking from orbit not recommended.

                            You saw the film / video @johnpoz mentioned ? There were more episodes after that one, problems became epic. Because they decided not to do what she proposed. The nuke option could have reported the problem to several generations later on.
                            No 'nuke' == more work right now.
                            Which brings another conclusion for free : one can't stop evolution (fate ?).

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            JKnottJ 1 Reply Last reply Reply Quote 0
                            • JKnottJ
                              JKnott @Gertjan
                              last edited by

                              @Gertjan said in Zero Day Exploits - How to Reset Everything:

                              You saw the film / video @johnpoz mentioned ?

                              I watched it many (40?) years ago. My girlfriend (later wife) almost jumped out of her seat, when the alien came out of the body! ๐Ÿ˜„

                              PfSense running on Qotom mini PC
                              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                              UniFi AC-Lite access point

                              I haven't lost my mind. It's around here...somewhere...

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.