Hacked by hydra. At wits end.

Help for Current Versions of MX
When asking for help, use Quick System Info from MX Tools. It will be properly formatted using the following steps.
1. Click on Quick System Info in MX Tools
2. Right click in your post and paste.
Message
Author
scatman98
Posts: 31
Joined: Fri Mar 30, 2018 12:56 am

Re: Hacked by hydra. At wits end.

#21 Post by scatman98 »

siamhie wrote: Mon Jan 13, 2025 9:26 am What are you searching for?
The distro is locking me out of internet access, login access to desktop, folder/file access , and sometimes fixing itself randomly so i'm looking to fix this behaviour.

User avatar
Eadwine Rose
Administrator
Posts: 15025
Joined: Wed Jul 12, 2006 2:10 am

Re: Hacked by hydra. At wits end.

#22 Post by Eadwine Rose »

Does this similar behavior also happen on the LiveUSB?


How have you installed things on your system?
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

scatman98
Posts: 31
Joined: Fri Mar 30, 2018 12:56 am

Re: Hacked by hydra. At wits end.

#23 Post by scatman98 »

Eadwine Rose wrote: Mon Jan 13, 2025 10:06 am Does this similar behavior also happen on the LiveUSB?


How have you installed things on your system?
edit: I had this happen especially with the writable usb option i think the usb drive was corrupted while running live? only tried with non writable option after that and yes same behavior.
clean install.
Last edited by scatman98 on Mon Jan 13, 2025 10:27 am, edited 2 times in total.

User avatar
Eadwine Rose
Administrator
Posts: 15025
Joined: Wed Jul 12, 2006 2:10 am

Re: Hacked by hydra. At wits end.

#24 Post by Eadwine Rose »

I was thinking more of the software ON the system.

Did you use the recommended method MXPI, or did you use deb downloads, stuff like that?
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

scatman98
Posts: 31
Joined: Fri Mar 30, 2018 12:56 am

Re: Hacked by hydra. At wits end.

#25 Post by scatman98 »

Eadwine Rose wrote: Mon Jan 13, 2025 10:12 am I was thinking more of the software ON the system.

Did you use the recommended method MXPI, or did you use deb downloads, stuff like that?
i downloaded using mxpi

when i run sudo for one program only in terminal, say, nordvpn client, it auto updates all repos and i get the same behaviour.

User avatar
Eadwine Rose
Administrator
Posts: 15025
Joined: Wed Jul 12, 2006 2:10 am

Re: Hacked by hydra. At wits end.

#26 Post by Eadwine Rose »

Nokkaelaein wrote: Mon Jan 13, 2025 7:26 am What you are listing is not malware; they are just "regular" software packages, tools for different purposes. Why they get installed seemingly automatically on your system is something that will hopefully be cleared below, but a hacker next door causing this seems to be on the unlikely side of the possible causes here :wink:
Likely indeed just dependencies of things that were intended to install.
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

User avatar
siamhie
Global Moderator
Posts: 3588
Joined: Fri Aug 20, 2021 5:45 pm

Re: Hacked by hydra. At wits end.

#27 Post by siamhie »

scatman98 wrote: Mon Jan 13, 2025 10:25 am
Eadwine Rose wrote: Mon Jan 13, 2025 10:12 am I was thinking more of the software ON the system.

Did you use the recommended method MXPI, or did you use deb downloads, stuff like that?
i downloaded using mxpi

when i run sudo for one program only in terminal, say, nordvpn client, it auto updates all repos and i get the same behaviour.

Why are you running the nord client as sudo? Run it as a user. These are the commands I use.
The first one is to just connect quickly. The second is when I'm torrenting.
The third is when I want to use a double vpn connection. The last is to disconnect.

Code: Select all

nordvpn connect
nordvpn connect P2P
nordvpn connect double_vpn
nordvpn disconnect
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

Nokkaelaein
Posts: 351
Joined: Fri Jul 17, 2020 10:32 am

Re: Hacked by hydra. At wits end.

#28 Post by Nokkaelaein »

Eadwine Rose wrote: Mon Jan 13, 2025 10:43 am Likely indeed just dependencies of things that were intended to install.
Ah no, that was about the results of "apt search", and a misunderstanding of what the command is used for (i.e. listing all available packages fitting the search, instead of showing packages somehow related to the software on the local system).

User avatar
Eadwine Rose
Administrator
Posts: 15025
Joined: Wed Jul 12, 2006 2:10 am

Re: Hacked by hydra. At wits end.

#29 Post by Eadwine Rose »

I'd say: if you are scared of having been hacked, or basically, if you did something which you have no idea of what you did, and your system is not behaving, start over, and install from MXPI only.

In the time it takes to go on a chase, because I still really don't understand what you want or what is going on, you could be up and running properly again.
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

User avatar
Stevo
Developer
Posts: 14755
Joined: Fri Dec 15, 2006 7:07 pm

Re: Hacked by hydra. At wits end.

#30 Post by Stevo »

Captain America was pretty good at fighting Hydra...
MXPI = MX Package Installer
QSI = Quick System Info from menu
The MX Test repository is mostly backports; not the same as Debian testing

Locked

Return to “MX Help”