[08:32] Morning folks [08:53] morning elacheche [08:58] good morning fellows [08:58] morning praisethemoon :D [08:58] How is it going son? [09:00] as usual dad, working and drinking coffee x) wbu? [09:01] o/ [09:04] nzoueidi, Like father like son [09:04] XDDDDDDD [09:04] elacheche, o/ [09:04] nzoueidi, i bet like grand father elacheche too :p [09:07] * pavlushka is praising the moon. [09:08] Moon is a good reflector of the Sun during the night :) [09:14] xD [09:14] o/ pavlushka [09:17] \o/ [09:17] pavlushka, Good \o/ [11:14] nzoueidi: o/ === ichihi is now known as ichihi|call [12:38] nzoueidi oussemos praisethemoon interesting review → #33C3 #Infrastructure Review https://youtu.be/m6dw3AMrOw0 [12:44] Hello elacheche :) [12:44] wbb [12:46] Hey pavlushka :) [16:20] thx for the link elacheche ;-) [17:44] :) [18:15] hello [19:11] elacheche, are u there? [21:24] Dro: o/ [21:25] ahla elacheche ! ça va? [21:25] Yep, u? [21:26] hmd [21:27] kont bech nes2lek 3la 7kaya [21:27] How can I help [21:28] elacheche, its a 'strange' problem as always :D [21:28] well I have openvpn running automatically on startup [21:28] We learn from that, so I'm thankfull for sharing stange issues :) [21:28] and connecting to an IP that I never used [21:29] and I don't know [21:29] bref, kol ma n7el el pc nal9a l'ip mta3i mel suede ! [21:29] And you wanna stop that? [21:30] ce qui est bizarre ma femma 7atta connexion vpn actif fel connections manager [21:30] chaque fois je dois faire un sudo killall openvpn fel terminal [21:30] Did you checked your cron jobs? [21:30] bon mouch i want to stop it, mais n7eb na3ref chnia l'origine mta3 la7keya hethi [21:31] bref choft les programmes eli yetlansaw fel démarrage [21:31] Did you checked your cron jobs? [21:31] w fe9t de passage eli 3andi un RAT .jar dra mnin jeni haha :D [21:31] oops x) [21:31] oui oui [21:31] You must installed it :) :D [21:32] 93ad rbo3 sa3a bloqué hahahaha [21:32] wait [21:32] bech nwarik kifech l9itou bethabt [21:32] voila, j'avais cette commannde qui s'execute auto au démarrage [21:33] .. /usr/lib/jvm/java-7-oracle/jre/bin/java -jar /home/ubuntu/.Qjytmqba/Nezqzwta.jar [21:33] w msammih Torzm Duuif [21:33] bref avec une ptite recherche sur google j'ai trouvé que c'est un RAT esmou AdWind [21:34] x) [21:34] mais j'ai pas pu savoir si il est en cours d'execution ou pas [21:34] auccune trace sur le Systeme monitor [21:34] et aucune trace sur 'top' [21:34] en tt cas na77itou w t3adit 3la rou7i :D [21:35] After you removed it you rebooted and you still connect to the vpn? [21:35] mais je sais pas si 3andou 3ala9a b7kayet el serveur openvpn eli 9a3ed nconnecti 3lih chaque stratup ou pas [21:35] ou bien c'est un truc à part [21:35] no ma 3maltech reboot [21:36] tawa je cherche comment je peux vérifier tt les scripts qui s'executent au démarrage [21:36] bech nefhem 7kayet el openvpn mnin jet [21:36] Try a reboot and check, maybe the jar just execute openVPN with the good config file.. If you still have the jar we probably can debug it and see what it is doing [21:36] btw, ynejem ykoun mizel 9a3ed y'executi tawa el RAT :D vu que j'ai pas rédemarré [21:38] What ubuntu verson do you have? [21:38] 16.04 [21:38] + j'ai déjà cherché bcp dessus [21:39] aslan ma net'hanna ken ma nlawej w n'analysi mli7 w nefhem ech 9a3ed ya3mel bethabt :D [21:39] systemctl list-unit-files | grep enabled [21:39] bref j'ai trouvé qu'il se connecte à une IP turc apparement [21:39] w comme chaque RAT il donne un accés total sur la machine [21:39] :/ [21:39] Yep :/ [21:40] oui je l'ai déjà vu [21:40] cette commande ta3tik juste les noms de services [21:41] et openvpn existe bel et bien et je peux le désactiver [21:41] openvpn.service enabled [21:41] Best thng to do right now is to reboot, then check if the OpenVPN still connected, if so try to list the enabled services via systemctl, and check all your users crontabs (a basic for loop, I can share it if you like) [21:41] mais je veux savoir mnin jet la7keya w l'ip heki [21:41] probablement femma script wella 7aja [21:42] Dro: Check the content of openvpn.service.. It uses a cfg file to start it? if so you'll find the path [21:42] bon normalement c pas un nom de fichier [21:42] well i guess :P [21:43] eh donc comment trouver le conf si ça existe [21:43] c pas le conf par défaut de openvpn zeda [21:43] i guess 2 :P [21:43] Hold on, let me check [21:45] Dro: Check if the service file is in here → ls /usr/lib/systemd/* [21:48] elacheche, bon j'ai trouvé qq .service sous /usr/lib/systemd/user , mais le openvpn.service mouch ghadi [21:48] 1 sec let me try locate [21:49] * elacheche don't use systemd :/ [21:50] hmm [21:50] i feel a bit stupid [21:50] well, I found 2 openvpn.service files [21:51] nothing interested in both of them [21:51] except the "configDir=" variable [21:51] "/etc/openvpn" [21:51] I checked it out [21:52] I found that I have some files .crt .pem .key .conf .... etc [21:52] that I "maybe" tried it i dunno when :| [21:52] x) [21:52] finally it seems it me who added these files [21:52] hahaha :D [21:53] its me* ! :| [21:53] x) [21:53] ema ça doit pas marcher [21:54] 5ater el vpn heka a déja expiré :| [21:54] en tt cas je vais les supprimer , faire un reboot et voir [21:54] dans les 2 cas j'ai rien perdu.. par contre fe9t que j'avais un RAT [21:54] sodfa 5ayron men alfi mi3ad :D [21:55] x) [21:56] OK then,, let me go back to my Gentoo :p [21:57] ok, see u tomorrow! :D [21:58] :) [21:59] thanks for ur help, good night! (F)