"Another user is trying to view your desktop" - Ubuntu

Sysem

Expert Member
Joined
Mar 26, 2009
Messages
1,891
Reaction score
5
So, got home now and a nice little popup displaying this message greeted me.

Of course I'll deny, but anyway to trace who this is? Got some address in the following format:

xxx-xxx-xxxxxx.ntlworld.ie where x is a number.

Would really love to have some fun with this person too...

Any ideas? Or should I just move on, deny and leave it?
 
Tracert it and RDP the IP. Chances are if they tried to RDP you, their ports are forwarded by the router on their side accordingly.

If nothing happens and it times out, best to just forget about it :)
 
Reset router to get a new public IP, close the open ports on your router, change admin password on router just to make sure, change your system password, just to make 100% sure.

To check if they could get in check the log files:
Code:
sudo cat /var/log/auth.log
-or-
sudo less /var/log/auth.log     // I do not have patience for less :-(
If they got to your system, all the commands will be listed there that were issued. If they are thorough they would have erased the file. If that file is not there, now is the time to worry.

Then check for:
Code:
cat ~/.bash_history
sudo cat /root/.bash_history
to see if they got to your system and what commands were issued by the normal user and sudo.
If those files are not there you can pretty much assume they got access to the PC.

Now will be the time to trace what they did. Report back and we will help with tracing what they did.

PS: You are not the first to have had this happen:
http://ubuntuforums.org/showthread.php?t=1387938

REMEMBER:
Any system is only as secure as its user, so tighten up your security a bit.
 
Last edited:
Thanks MyWorld.
They didn't seem to get access. I checked auth.log and no one but me was on. I'm using an 8ta modem, so no access to router etc.
I did notice that Desktop Sharing was enabled, but set to need me to grant permission. I disabled it, and the pop vanished so I lost the *****er's address. Not sure why that was enabled in the first place.

Anyway, I'll keep a watch from now on. All seems fine though.

It seems whoever this was, isn't the brightest hacker. I surely wouldn't try connect to a remote desktop as it usually pops up?
 
There should be a log somewhere with his address on, I do not know what app Ubuntu uses for remote desktop, but it should be fairly easy to trace and find the log file.
 
There should be a log somewhere with his address on, I do not know what app Ubuntu uses for remote desktop, but it should be fairly easy to trace and find the log file.

Thats what I thought, but apparently it doesnt ...
 
This is remote desktop for Ubuntu. It looks like your remote desktop is publicly available so automated bots do try get in all the time. Install a VM and mess with them :D Oh yeah, and you would have had to have configured the default client to behave like this. It doesnt automatically happen. You have to enable it.
 
This is remote desktop for Ubuntu. It looks like your remote desktop is publicly available so automated bots do try get in all the time. Install a VM and mess with them :D Oh yeah, and you would have had to have configured the default client to behave like this. It doesnt automatically happen. You have to enable it.

Agreed. I would also install a VM and mess them around a lot :D

Easiest would be to install Windows and Ultr@VNC - you can use Win7 without any product keys for up to 30 days before it'll start to nag you. Poor hacker probably won't understand Linux, but Windows ... oh yes... :D
 
I would have just opened up the most extreme hairy gay porn vid I could find...play it full screen and then accepted his request! /wicked grin
 
This is remote desktop for Ubuntu. It looks like your remote desktop is publicly available so automated bots do try get in all the time. Install a VM and mess with them :D Oh yeah, and you would have had to have configured the default client to behave like this. It doesnt automatically happen. You have to enable it.

Yeah, I'm pretty sure I enabled it. Not sure why :D

I would have just opened up the most extreme hairy gay porn vid I could find...play it full screen and then accepted his request! /wicked grin

Ah BRILLIANT!
 
Can someone advise how efiling's online consultant works ?
SARS now provides taxpayers with an online consultant when you eFile, who is able to view your return.

I have a suspicion that this involves remote desktop sharing. If so I suppose one would need to install something like teamviewer ?
I would never feel comfortable doing that and am just posing this question for interest sake.
 
Top
Sign up to the MyBroadband newsletter
X