This forum has been archived. All content is frozen. Please use KDE Discuss instead.

Where with my "Attacked, Konqueror went beserk" video?

Tags: None
(comma "," separated)
MRovis
Registered Member
Posts
4
Karma
0
OS
I didn't meddle, as I wouldn't anyway be able to meddle (not a programmer, intermediate user only).
This video shows how my system was under attack:
http://vimeo.com/33561248
I actually studied hard various security related issues for weeks afterwards, and hopefully solved my systems' vulnerabilities by hardening my Gentoo installations.
But that did happen.
And I thought it was honest to report it in KDE forums.
My systems are growing increasingly out of date.
I am not using mainstream KDE installations anymore, but openbox/slim based installation, as Gentoo is an awful lot of compilation and my systems are some six yrs old based tech.
But I do keep and use various KDE programs, notably I never would like, nor could I do it easily (like old dogs and new tricks as the saying goes, right?), notably I wouldn't like to have to move away from using Konsole, the queen of all the Gnu Linux X-Windows console applications!
So... in hindsight, where do I post this question on my attacker exploring Konqueror vulnerabilities, exaclty?
Or, if some admin thinks a better section then this one applies for it, she/he can move it right into that more appropriate section.
So, which Konqueror vulnerabilities did my attacker make use of here?

Last edited by MRovis on Wed Dec 14, 2011 3:44 pm, edited 1 time in total.
User avatar
Mamarok
Manager
Posts
6071
Karma
16
OS
How about being a bit more specific about your KDE version?


Running Kubuntu 22.10 with Plasma 5.26.3, Frameworks 5.100.0, Qt 5.15.6, kernel 5.19.0-23 on Ryzen 5 4600H, AMD Renoir, X11
FWIW: it's always useful to state the exact Plasma version (+ distribution) when asking questions, makes it easier to help ...
MRovis
Registered Member
Posts
4
Karma
0
OS
Mamarok wrote:How about being a bit more specific about your KDE version?

Sorry, I should've figured out that was necessary.
My Gentoo is recently all up to date, testing version (with ACCEPT_KEYWORDS="~amd64" in /etc/make.conf).
But that video was taken before I took refuge with hardened Gentoo (grsecurity/pax based).
It is not the case anymore, all those popping windows. My konqueror is now normal. Yes, it is. I just rechecked.
That video I made back on the day 2011-09-04, I was able to check now, because I make my screencast something like this:
Code: Select all
# ffmpeg -f x11grab -s xga -r 25 -i :0.0 Screen_`date +%y%m%d_%H%M`_`hostname`.mpg

and it had, before I "bloated" it (in the positive way, to make it nearly HD resolution for easier viewing, original reso being miserable... only 640x480 and vimeo maybe would reduce it further, Youtube would...)...
And, I was saying, before I "enlarged" it, it had:
"110904" for 2011-09-04, in the name...
Current kde in my system:
Uuhrgh...
That may even not be helpful.. But that is what there is now, after the event...
Code: Select all
 # emerge -s kde
Searching...   
[ Results for search key : kde ]
[ Applications found : 90 ]

...[snip]...

*  kde-base/kde-env
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 0 kB
      Homepage:      http://www.kde.org/
      Description:   Environment setting required for all KDE4 apps to run.
      License:       as-is

*  kde-base/kde-l10n
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 17,040 kB
      Homepage:      http://www.kde.org/
      Description:   KDE internationalization package
      License:       GPL-2

...[snip]...

*  kde-base/kdebase-kioslaves
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 5,885 kB
      Homepage:      http://www.kde.org/
      Description:   kioslave: the kde VFS framework - kioslave plugins present a filesystem-like view of arbitrary data
      License:       GPL-2

*  kde-base/kdebase-menu
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 5,885 kB
      Homepage:      http://www.kde.org/
      Description:   KDE Menu query tool.
      License:       GPL-2

*  kde-base/kdebase-menu-icons
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 5,885 kB
      Homepage:      http://www.kde.org/
      Description:   KDE menu icons
      License:       GPL-2

...[snip]...

*  kde-base/kdegraphics-meta
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 0 kB
      Homepage:      http://www.kde.org/
      Description:   kdegraphics - merge this to pull in all kdegraphics-derived packages
      License:       GPL-2

*  kde-base/kdegraphics-strigi-analyzer
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 41 kB
      Homepage:      http://www.kde.org/
      Description:   kdegraphics: strigi plugins
      License:       GPL-2

*  kde-base/kdelibs
      Latest version available: 4.7.3-r11
      Latest version installed: 4.7.3-r11
      Size of files: 11,788 kB
      Homepage:      http://www.kde.org/
      Description:   KDE libraries needed by all KDE programs.
      License:       LGPL-2.1

...[snip]...

*  kde-base/kdepim-common-libs
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 15,801 kB
      Homepage:      http://www.kde.org/
      Description:   Common libraries for KDE PIM apps
      License:       GPL-2

*  kde-base/kdepim-icons
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 15,801 kB
      Homepage:      http://www.kde.org/
      Description:   KDE PIM icons
      License:       GPL-2

...[snip]...

*  kde-base/kdepim-runtime
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 1,177 kB
      Homepage:      http://www.kde.org/
      Description:   KDE PIM runtime plugin collection
      License:       GPL-2

...[snip]...

*  kde-base/kdepimlibs
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 3,157 kB
      Homepage:      http://www.kde.org/
      Description:   Common library for KDE PIM apps.
      License:       LGPL-2.1

...[snip]...

*  kde-base/kdesu
      Latest version available: 4.7.3
      Latest version installed: 4.7.3
      Size of files: 5,885 kB
      Homepage:      http://www.kde.org/
      Description:   KDE: gui for su(1)
      License:       GPL-2

...[snip]...

*  kde-misc/polkit-kde-kcmodules
      Latest version available: 0.98_pre20101127
      Latest version installed: 0.98_pre20101127
      Size of files: 25 kB
      Homepage:      http://www.kde.org
      Description:   PolKit agent module for KDE.
      License:       GPL-2

...[snip]...

*  sys-auth/polkit-kde-agent
      Latest version available: 0.99.0
      Latest version installed: 0.99.0
      Size of files: 33 kB
      Homepage:      http://www.kde.org
      Description:   PolKit agent module for KDE.
      License:       GPL-2
 # which konqueror
/usr/bin/konqueror
 # equery belongs /usr/bin/konqueror
 * Searching for /usr/bin/konqueror ...
kde-base/konqueror-4.7.3 (/usr/bin/konqueror)
 #

I could go and search if I may be able to find what I had of kde installed back at and around the time of the event. I *may* be able to find those versions...
I sure wish I reported Konqueror going beserk earlier...
But... Back then I was certain that I was under attack, and so I am now that I that which can be seen in the video was an attack...
And I was confident that I needed something, and grsecurity/pax would was what I found did the protection... So I think...
I am hopeful that my report is still helpful in the way of improving things.
I really was very concerned to firstly protect my system, and studied really hard...
Take a look how it did take me loooonngg occasionally:
https://forums.gentoo.org/viewtopic-t-903218-highlight-.html
Dear Mamarok, thanks for your insight! I'm not so much into music, but I did use Amarok earlier.
This I snipped too much in the # emerge -s kde above.
And it is the program that I use almost all of the time in my systems, and I'd like to thank here the developers for the magic of it:
Code: Select all
 # equery belongs /usr/bin/konsole
 * Searching for /usr/bin/konsole ...
kde-base/konsole-4.7.3 (/usr/bin/konsole)
 #
MRovis
Registered Member
Posts
4
Karma
0
OS
It's a parallel discussion on Gentoo Forums. Not really cross posting. No same texts!
I thought it would be honest to let you people from KDE know.
http://forums.gentoo.org/viewtopic-p-69 ... ight-.html
(already went to sleep. but then I thought, if I get to read more replies, I gotta give sufficient info, up to what my abilities and capabilities permit me).
Thanks!
MRovis
Registered Member
Posts
4
Karma
0
OS
Here is more.
And it is brand new video. Just happened (plus the time to add my voiceover, and wait inline for vimeo to allow it on).
http://vimeo.com/34150417
I suppose someone is misusing some imperfections in the Konqueror code to make some unwelcome fun, or to some other effect, but I cannot tell.
Here is the version:
Code: Select all
# konqueror --version
Qt: 4.7.4
KDE Development Platform: 4.7.4 (4.7.4)
Konqueror: 4.7.4 (4.7.4)

Any more info on this issue?
I don't guess it's common to have this nuissance.
As I say in the video, I didn't have anything to do with it, other than passively diagnosing the malaise.
I don't even remotely have the knowledge to do this, and neither to figure out what it is and how to deal with it.
I repeat, it didn't happen back with Konqueror 4.7.3
But, I suppose (I do not claim), because my attacker couldn't do it at the time, almost 10 days ago, IIRC.
Thanks if anyone introduce a little more light in this matter.


Bookmarks



Who is online

Registered users: bancha, Bing [Bot], Evergrowing, Google [Bot], lockheed, mesutakcan