Jump to content
IGNORED

I got hacked


Guest Babar

Recommended Posts

In the past two days, i've been massively trying various jailbreaks in order to get android on my iPhone. I tried many versions of redsn0w, because i wanted to use iphoDroid which was supposed to be as easy as one mouse click (lie), until i figured out the guys from the iDroid project unrecommend this shit because of its source code that is not very clear (i do not think iphodroid is the cause of my problem, it's rather one of these versions of redsnow (or several lol)).

 

So i tried many stuffs, some of them asking me for my root password (I'm on a mac) for some usb-via-ssh reasons until I finally decided to follow the "hardcore way" : typing stuffs in the terminal (tutorial from idroidproject.com). I finally succeeded.

 

For some obscure reason i won't explain here, i launched wireshark (a network sniffer) so as to see what kind of stuffs were going thru my wifi interface, until I figured out there was too many packets transitting even though i had killed all my internet-related programs/widibidigets/whatever. I started whoising the ips these packets were going to/from and i stumbled onto a) a russian ip b) a sicilian ip. Shortly after, i could notice a ssh connection (WTF!) nonchalantly giving orders to my computer.

 

So i went on chatmm, acidphakist confirmed i had it up the ass, I blocked my bank card (my iPhone's ssh was activated with default password because of the fresh install and it had my itunes store informations). SUddenly my wireshark got killed, and i wasn't even able to ping google. I rebooted, set an ipfw(firewall) rule in order to block the asshole as well as set my router to paranoid mode but I still have those strange TCP packets that are listed in grey in wireshark, and maybe a bunch of suspect https packets (tunneling ?). When I add a rule to ipfw in order to block these connections, it's immediately replaced by another ip, from another block. the fuck is this shit ? a botnet ?

 

 

Also i'm planning to reinstall everything but i'm still very very suspicious about any file that is on my computer. i know that I mustn't copy any .app, but should I mistrust .pdfs, .jpgs, etc as well ?

 

And may I upload a pcap file so that someone from this forum can explain me a little further what is happening ?

Link to comment
Share on other sites

root kit i guess. they have my root password. I changed it, but i imagine they have a keylogger. and i m not posting this from my computer

Link to comment
Share on other sites

sup - running suspicious code whilst trying to hack phone hardware and handing your root password over to processes of a spurious nature does not constitute a virus. if you hand your linux root password over to someone, you're equally fuxed.

 

having said that, that really sucks, babar. hope you manage to sort that fucker out.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.