• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Bios rootkit infection detected with dd wrt and open wrt?

Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
R-T-B saw this 1 time in 2019 i think, you'd have to be Jerry Epstein, John McAfee to be attacked.
Not sure about that level, but if you have a multimillion net worth, start thinking about this more.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Not sure about that level, but if you have a multimillion net worth, start thinking about this more.
Examples of "targets" that had tons of cash and certain dirty info on certain people.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
Oh and i forgot to address the question in the title about a router OS being able to detect these attacks

1. The router has to be programmed to recognise the traffic, meaning it's gotta be a previously known and identified attack
2. the router needs enough CPU power and RAM (and advanced programming) to sniff out the ports used by the known attack, and verify it's an attack and not legitimate traffic
3. The only way a lightweight device can do this is by taking samples of the data and submitting it to someone else (like antivirus do) to be manually checked, and that wont be cheap OR secure for important people and businesses
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Oh and i forgot to address the question in the title about a router OS being able to detect these attacks

1. The router has to be programmed to recognise the traffic, meaning it's gotta be a previously known and identified attack
2. the router needs enough CPU power and RAM (and advanced programming) to sniff out the ports used by the known attack, and verify it's an attack and not legitimate traffic
3. The only way a lightweight device can do this is by taking samples of the data and submitting it to someone else (like antivirus do) to be manually checked, and that wont be cheap OR secure for important people and businesses
Herustics i guess is only way...
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Examples of "targets" that had tons of cash and certain dirty info on certain people.
Not saying they didn't qualify, just saying just having tons of money will also get you there. You don't have to be famous necessarily. Just someone needs to want something you have, bad.
 

antirootkitbios

New Member
Joined
Jul 10, 2021
Messages
7 (0.01/day)
Oh and i forgot to address the question in the title about a router OS being able to detect these attacks

1. The router has to be programmed to recognise the traffic, meaning it's gotta be a previously known and identified attack
2. the router needs enough CPU power and RAM (and advanced programming) to sniff out the ports used by the known attack, and verify it's an attack and not legitimate traffic
3. The only way a lightweight device can do this is by taking samples of the data and submitting it to someone else (like antivirus do) to be manually checked, and that wont be cheap OR secure for important people and businesses
can i transform an intel i7 computer into a dedicated router with dd wrt>? it will have enough cpu and ram to act as a super firewall, could be that possible?
make a full dd wrt computer sounds like a challenge >o

my computer has 3 ethernet cards
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
can i transform an intel i7 computer into a dedicated router with dd wrt>? it will have enough cpu and ram to act as a super firewall, could be that possible?
make a full dd wrt computer sounds like a challenge >o

my computer has 3 ethernet cards
you can definitely turn PC's into high end firewalls/routers

13 Best Open Source Router OS for Small to Large Networks (2021) (networkstraining.com)

i think i recall using PFsense years ago, but routers got better and i havent bothered since
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
you can definitely turn PC's into high end firewalls/routers

13 Best Open Source Router OS for Small to Large Networks (2021) (networkstraining.com)

i think i recall using PFsense years ago, but routers got better and i havent bothered since
I actually run a windows firewall/router on my network using RRAS.

But I do it mostly to stay sharp on Windows Server, because honestly, it's a major PITA. PFSense is what I'd advise.

And you'll need to know malware specifics, such as what IP's it calls home to, etc. Without that it'll be useless.

PS: To give you an idea of how high level these types of attacks are, my last client with this got it from... his cable node, which had been compromised and specifically in such a way as to redirect common urls to specific malware packages made for him. Police were involved, as mentioned. I know nothing beyond that it was some real shit, as once the police entered the picture they wanted the frog gone. I still have a big box of my stuff they sent back, I had tried (like you) to help him with a DD-WRT router and new hardware, only to learn that the new hardware would quickly get reinfected as did the router itself. That's when I started looking at logs and discoverd the origin was false routing tables , sites, certificates etc at his node.

My client specifically authorized sharing nonspecific technical details by the way in exchange for services (in the name of "research" at the time because I was curious) so this isn't any big secret.
 
Last edited:
Joined
Jan 31, 2010
Messages
5,379 (1.03/day)
Location
Gougeland (NZ)
System Name Cumquat 2021
Processor AMD RyZen R7 7800X3D
Motherboard Asus Strix X670E - E Gaming WIFI
Cooling Deep Cool LT720 + CM MasterGel Pro TP + Lian Li Uni Fan V2
Memory 32GB GSkill Trident Z5 Neo 6000
Video Card(s) Sapphire Nitro+ OC RX6800 16GB DDR6 2270Cclk / 2010Mclk
Storage 1x Adata SX8200PRO NVMe 1TB gen3 x4 1X Samsung 980 Pro NVMe Gen 4 x4 1TB, 12TB of HDD Storage
Display(s) AOC 24G2 IPS 144Hz FreeSync Premium 1920x1080p
Case Lian Li O11D XL ROG edition
Audio Device(s) RX6800 via HDMI + Pioneer VSX-531 amp Technics 100W 5.1 Speaker set
Power Supply EVGA 1000W G5 Gold
Mouse Logitech G502 Proteus Core Wired
Keyboard Logitech G915 Wireless
Software Windows 11 X64 PRO (build 23H2)
Benchmark Scores it sucks even more less now ;)
can i transform an intel i7 computer into a dedicated router with dd wrt>? it will have enough cpu and ram to act as a super firewall, could be that possible?
make a full dd wrt computer sounds like a challenge >o

my computer has 3 ethernet cards

Why would you need to do that what are you really afraid of are you a nuclear reactor designer a rocket scientist or a terrorist trying to hide from the govt's of the world or some such I mean what is it that's on your PC that makes you think some malicious person or govt entity is going to go through all that hard effort to try and flog a few cat videos or step mom porn pics from your PC's hard drive
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Why would you need to do that what are you really afraid of are you a nuclear reactor designer a rocket scientist or a terrorist trying to hide from the govt's of the world or some such I mean what is it that's on your PC that makes you think some malicious person or govt entity is going to go through all that hard effort to try and flog a few cat videos or step mom porn pics from your PC's hard drive
If he really is high profile, he'd be an idiot to tell you.

But on the other hand, I haven't seen any evidence to suggest infection, so... I really do feel this is a case of paranoia without further evidence. Sorry.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
I agree, he could be high profile or high risk (secret bitcoin millionaire or whatever) and sharing that increases the risk.

That's fine, it's plausible.

But... this is just not something a single person or home user can do. For that level of security, keep a device offline. no wireless connections at all. Including the power cord when you aint on it.
 

Frick

Fishfaced Nincompoop
Joined
Feb 27, 2006
Messages
18,933 (2.85/day)
Location
Piteå
System Name Black MC in Tokyo
Processor Ryzen 5 5600
Motherboard Asrock B450M-HDV
Cooling Be Quiet! Pure Rock 2
Memory 2 x 16GB Kingston Fury 3400mhz
Video Card(s) XFX 6950XT Speedster MERC 319
Storage Kingston A400 240GB | WD Black SN750 2TB |WD Blue 1TB x 2 | Toshiba P300 2TB | Seagate Expansion 8TB
Display(s) Samsung U32J590U 4K + BenQ GL2450HT 1080p
Case Fractal Design Define R4
Audio Device(s) Line6 UX1 + some headphones, Nektar SE61 keyboard
Power Supply Corsair RM850x v3
Mouse Logitech G602
Keyboard Cherry MX Board 1.0 TKL Brown
VR HMD Acer Mixed Reality Headset
Software Windows 10 Pro
Benchmark Scores Rimworld 4K ready!
I actually run a windows firewall/router on my network using RRAS.

But I do it mostly to stay sharp on Windows Server, because honestly, it's a major PITA. PFSense is what I'd advise.

And you'll need to know malware specifics, such as what IP's it calls home to, etc. Without that it'll be useless.

PS: To give you an idea of how high level these types of attacks are, my last client with this got it from... his cable node, which had been compromised and specifically in such a way as to redirect common urls to specific malware packages made for him. Police were involved, as mentioned. I know nothing beyond that it was some real shit, as once the police entered the picture they wanted the frog gone. I still have a big box of my stuff they sent back, I had tried (like you) to help him with a DD-WRT router and new hardware, only to learn that the new hardware would quickly get reinfected as did the router itself. That's when I started looking at logs and discoverd the origin was false routing tables , sites, certificates etc at his node.

My client specifically authorized sharing nonspecific technical details by the way in exchange for services (in the name of "research" at the time because I was curious) so this isn't any big secret.

Yeah I remember that. Excellent work on your end, it was very interesting to follow. "The new hardware is infected too? Uh oh."
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I agree, in a strange way it was an honor to be a part of what I consider to be a historic case.

Not sure the people who are infected feel that way though. And I do feel that unfortunately, it's spawned some unneccesary paranoia.
 

antirootkitbios

New Member
Joined
Jul 10, 2021
Messages
7 (0.01/day)
Why would you need to do that what are you really afraid of are you a nuclear reactor designer a rocket scientist or a terrorist trying to hide from the govt's of the world or some such I mean what is it that's on your PC that makes you think some malicious person or govt entity is going to go through all that hard effort to try and flog a few cat videos or step mom porn pics from your PC's hard drive
nono, i was hacked 5 times, last time, for a be a good player in tera, i beat some records, that made mad some people, anyway, tera na is closed, and that was a some years ago, i was planning to play again and mmorpg, and i want to close all the internet, except the IP and Port related to that mmorpg, and an ip to streamming to youtube and twitch

thanks for this conversation people, i found how to make a firewall with dd wrt and a computer, ill began with that.
 
Joined
Apr 15, 2021
Messages
849 (0.77/day)
nono, i was hacked 5 times, last time, for a be a good player in tera, i beat some records, that made mad some people, anyway, tera na is closed, and that was a some years ago, i was planning to play again and mmorpg, and i want to close all the internet, except the IP and Port related to that mmorpg, and an ip to streamming to youtube and twitch

thanks for this conversation people, i found how to make a firewall with dd wrt and a computer, ill began with that.
Tera? I can't imagine people getting that bent out of shape over records and going after you with rootkits. That game is nearly a decade old and has gone to shit. I played it on the PC off & on for like 2 years and just gave up since most of the players online just stand around in the main city doing nothing, and all of the higher end content requires groups where everyone knows what they're doing.
More than likely you downloaded and installed a mod for the game that had a trojan/virus. In particular, they had nude mods for the female characters iirc, so that probably explains why I saw so many noob female characters in the starter zones just doing nothing...
Overall, its just another Black Desert Online... much eye candy and little in the way of being an MMORPG unless you like repetitive done to death.

You probably need to re-evaluate your online habits. If you're viewing/downloading porn, installing illegal/unsupported game mods, accepting files from others you don't know, visiting questionable links, these things are bound to happen. Deep Freeze by Faronics is good for protecting computer configs & settings and against most malware by simply rebooting. I know of at least one college that uses it to avoid the IT nightmare of stupid people messing around on the campus computers. Nevertheless, it won't protect against rootkits or other malware specifically designed to get past reboot-to-restore software, and its not going to protect you from data theft.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Another common thing to infect these days is outdated modems/routers. I find that more plausible for your scenario frankly, for a real old modem an attacker really only needs your ip. That can do a doozy on your whole network, reinfect hardware, all without doing anything to uefi/firmware.

The answer to fixing that of course is to not use ancient network hardware. DD-WRT is a good option for routers too.
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
Umm, what hack methods did they use? How was your network breached?


If they just guessed passwords or caught you with phishing, nothing you do in your home network will change a thing.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
nono, i was hacked 5 times, last time, for a be a good player in tera, i beat some records, that made mad some people, anyway, tera na is closed, and that was a some years ago, i was planning to play again and mmorpg, and i want to close all the internet, except the IP and Port related to that mmorpg, and an ip to streamming to youtube and twitch

thanks for this conversation people, i found how to make a firewall with dd wrt and a computer, ill began with that.

If you have a static IP, have it changed to dynamic
 

antirootkitbios

New Member
Joined
Jul 10, 2021
Messages
7 (0.01/day)
Tera? I can't imagine people getting that bent out of shape over records and going after you with rootkits. That game is nearly a decade old and has gone to shit. I played it on the PC off & on for like 2 years and just gave up since most of the players online just stand around in the main city doing nothing, and all of the higher end content requires groups where everyone knows what they're doing.
More than likely you downloaded and installed a mod for the game that had a trojan/virus. In particular, they had nude mods for the female characters iirc, so that probably explains why I saw so many noob female characters in the starter zones just doing nothing...
Overall, its just another Black Desert Online... much eye candy and little in the way of being an MMORPG unless you like repetitive done to death.

You probably need to re-evaluate your online habits. If you're viewing/downloading porn, installing illegal/unsupported game mods, accepting files from others you don't know, visiting questionable links, these things are bound to happen. Deep Freeze by Faronics is good for protecting computer configs & settings and against most malware by simply rebooting. I know of at least one college that uses it to avoid the IT nightmare of stupid people messing around on the campus computers. Nevertheless, it won't protect against rootkits or other malware specifically designed to get past reboot-to-restore software, and its not going to protect you from data theft.
i began to play that game due my girlfriend, i didnt want to play it, but when she left, i began to play all day haha, i was terrible, and i was insulted for be so bad in the game, and when i became really good in the game, new haters arrived... haters that doesnt like you to be good in the game, and this is the interesting part, if you are bad playing, you get insults, but if you are good in a game, then you began to be accused first, of cheating, next, a lot of haters, and then, finally, the supreme hater, the one that hacks your account

i miss the old internet, i used to play ultima online official server, and it was a very nice place to meet and talk with a lot of people, diablo 2 in the beggining too, helbreath international also, but was maybe in 2008 when everything began to change

in 2001 i was hacked in battle net due a mistake, i started a game through TCP IP, hosting a server through battle .net tool, i didnt know in that momment that my computer was going to be a server haha

who hacked me in tera told me this

we went into a party to do a boss, guess when we go in that mode we are in a node or something, then they can track better the ips, then when we went in the final boss, he told me that he is hacking me remotly, then he was in my computer, passed my firewall, passed everything, he also, moved my mouse to make me die

that was the last die that i played tera, i loved that game, and i was really good, but this guy, made me think how vulnerable internet its, for kids, young girls, young boys

if someoneday i have a kid and he plays a mmorpg, i will buy to him a computer just for that, and other for personal things, nice to see someone that played tera


update about the post: i already mounted a firewall computer, and im playing with iptables in ssh and others things

thanks for all the help people, have a nice week!

If you have a static IP, have it changed to dynamic
i have 3 ISP here, but the problem is, when you log in in a video game, your log in IP is recorded, example, lineage 2 classic, guess was the same with tera, anyway, tera in that year had many vulnerabilities, after i was hacked, someone did a global hack uploading something in the chat general window, i dont really know how many others vulnerabilities tera had, or maybe i was hacked through my youtube channel and twitch live streamming? i had 3 things opened when that happened

twtich streamming
youtube streamming

and tera
i still have the video of that day due while xplit streams, it also makes a video in my hard drive, i have both, the streaming and the hard drive video
was an interesting experience, and is real, you can have a firewall, but if you have something installed, that can create a backdoor, no firewall or antivirus will protect you

guess they found a vulnerability in twtich, youtube, or that game, probabbly that game, youtube and twtich are giant companies, i really doubt the vulnerability was there, more, with that i said about that vulnerability in tera chat days after i was hacked

if there is a game that i will always want to play again will be tera, i hope it be a tera 2 or something

good luck all! and thanks for the help

Umm, what hack methods did they use? How was your network breached?


If they just guessed passwords or caught you with phishing, nothing you do in your home network will change a thing.
my network was fine, at least is what i believe, i didnt have dd wrt, i had cisco default firewall, problem was they found a vulnerability in tera, or in twtich or in youtube, we are talking about like 5 or 6 years ago, probabbly that is fixed now, a lot of time passed

if it was as i think, the problem was an app, not cisco firewall or windows firewall
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
That person likely hacked your *game* server, not your PC or anything locally. Think someone using an aimhack or wallhack - a temporary thing that altered network data, and nothing more.

It's a lot easier to fuck with netcode of a game and move a player around in the game and get them killed by another player in the session, than it is to hack a PC or do anything actually dangerous to your security.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
i began to play that game due my girlfriend, i didnt want to play it, but when she left, i began to play all day haha, i was terrible, and i was insulted for be so bad in the game, and when i became really good in the game, new haters arrived... haters that doesnt like you to be good in the game, and this is the interesting part, if you are bad playing, you get insults, but if you are good in a game, then you began to be accused first, of cheating, next, a lot of haters, and then, finally, the supreme hater, the one that hacks your account

i miss the old internet, i used to play ultima online official server, and it was a very nice place to meet and talk with a lot of people, diablo 2 in the beggining too, helbreath international also, but was maybe in 2008 when everything began to change

in 2001 i was hacked in battle net due a mistake, i started a game through TCP IP, hosting a server through battle .net tool, i didnt know in that momment that my computer was going to be a server haha

who hacked me in tera told me this

we went into a party to do a boss, guess when we go in that mode we are in a node or something, then they can track better the ips, then when we went in the final boss, he told me that he is hacking me remotly, then he was in my computer, passed my firewall, passed everything, he also, moved my mouse to make me die

that was the last die that i played tera, i loved that game, and i was really good, but this guy, made me think how vulnerable internet its, for kids, young girls, young boys

if someoneday i have a kid and he plays a mmorpg, i will buy to him a computer just for that, and other for personal things, nice to see someone that played tera


update about the post: i already mounted a firewall computer, and im playing with iptables in ssh and others things

thanks for all the help people, have a nice week!


i have 3 ISP here, but the problem is, when you log in in a video game, your log in IP is recorded, example, lineage 2 classic, guess was the same with tera, anyway, tera in that year had many vulnerabilities, after i was hacked, someone did a global hack uploading something in the chat general window, i dont really know how many others vulnerabilities tera had, or maybe i was hacked through my youtube channel and twitch live streamming? i had 3 things opened when that happened

twtich streamming
youtube streamming

and tera
i still have the video of that day due while xplit streams, it also makes a video in my hard drive, i have both, the streaming and the hard drive video
was an interesting experience, and is real, you can have a firewall, but if you have something installed, that can create a backdoor, no firewall or antivirus will protect you

guess they found a vulnerability in twtich, youtube, or that game, probabbly that game, youtube and twtich are giant companies, i really doubt the vulnerability was there, more, with that i said about that vulnerability in tera chat days after i was hacked

if there is a game that i will always want to play again will be tera, i hope it be a tera 2 or something

good luck all! and thanks for the help


my network was fine, at least is what i believe, i didnt have dd wrt, i had cisco default firewall, problem was they found a vulnerability in tera, or in twtich or in youtube, we are talking about like 5 or 6 years ago, probabbly that is fixed now, a lot of time passed

if it was as i think, the problem was an app, not cisco firewall or windows firewall

Dynamic ip changes
 
Top