I think you do not understand the purpose of the shadow file - the
password field contains a cryptographic hash of your plaintext password,
so this is entirely normal.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
hi
i am reading this and trying to follow along, but having trouble.
-
is “gshock” a username for cantwin, like the main user profile?
-
is “gshock” a username created by a hacker?
-
usually when people say “apt” they think of an aptitude repository for debian based systems, right? So when you are saying APT, do you mean aptitude (like sudo apt upgrade) or something you called Advanced Persistent Threat, which is either a person or group?
-
can someone explain to me what pam is and if it’s normal for there to be a user and user password in pam? Is that something that could in theory happen or is that something that indicates a hacker just doing something as bragging?
-
would there be a security risk of having a plaintext password in pam? usually passwords are stored as hashes and the typed in password is hashed and compared to the hash. unman said this is normal.
-
what tv show is in the background of that pam picture? is it dawson’s creek? this isn’t important, i just want to know.
-
varlibqubes changes because all sorts of temp files are in there, and are sometimes deleted, right? would a change of 19 gb be abnormal or could that happen if someone did an upgrade to templates?
-
usually hacking takes time and can be difficult, even for good hackers, unless they know of 0 day exploits that are hoarded (which would suggest state-level actors). but most likely someone wouldn’t use a 0 day unless you were a high-level target (which you probably are not, since the tv in the background gives data about where you are and who you are, which someone with a high threat model wouldn’t want to do) or had a lot of money to steal. hackers usually breach things for secrets or money or because they are angry. do you see any indication of data exfiltration?
-
you mention your firewall blocking attacks minutes after being reset. are you referring to a physical firewall or sys-firewall? do you know what was being blocked? for example, if i were using a firewall and suddenly a large number of outgoing connections to russia were being blocked, that would be something i could wonder about (especially because a real russian hacker probaly wouldn’t exfiltrate in such an obvious way, although who knows). were you able to run a whois on the ips if they were outgoing blocks? if they were incoming blocks, same question, do you know what ips were being blocked and from where?
-
you mention a bunch of new random processes being run in the background. can you mention what those are and the cpu percentage they used? that would be very interesting if true, but there are a lack of specifics.
-
when you say this person partitioned your drive, can you actually see multiple partitions? are the partitions protected by luks? what are the labels of the partitions? is there any indication of this by using commands in dom0 instead of just looking at logs?
-
You wrote “Towards the bottom he starts a DVM, Disp5101, and changes the policy over Dom0. There’s another photo where he changes the usb qube to change dom0.” I make lots of disp VMs and close them and never remember the exact numbers. How are you sure this isn’t a VM you created? You said there’s a photo where he changes the usb qube to change dom0. How can you see this in a photo?
sometimes people who are fearful of hacks are just anxious and usually when anxiety is the only cause, there is a lack of specificity when people ask follow-up questions. a real hack is like a fractal, with even more detail when examining things, whereas when it’s just someone being anxious, the details are often vague and confusing. if you provide more specific data, people may be able to help you more. right now, these feels like it could be anxiety more than a real hack, but there are brutal incredible hackers out there, so it’s not impossible? can you post more specific information?
if you could list processes that are new, that you wouldn’t expect in dom0, that would help