Re: OpenBSD machine was hacked

2015-07-29 Thread Stuart Henderson
On 2015-07-29, Wong Peter wrote: > Where to find log files regarding pf rule was flushed out using carp or > pfsync? pfsync can only sync firewall state tables (pfctl -ss). carp can't change anything to do with PF settings - not rules, not states. There is no mechanism to sync or flush rules wi

Re: OpenBSD machine was hacked

2015-07-29 Thread Peter J. Philipp
On 07/29/15 03:33, Wong Peter wrote: > Q:why do you believe that your machine was hacked? > A: My pf rules was flushed.This can prove using pfctl -sr. The whoe > firewall was not usable anymore. NO NAT nor packet filtering. Hi Peter, Can you let us know the version and architecture of OpenBSD you

Re: OpenBSD machine was hacked

2015-07-28 Thread Martin Brandenburg
On Wed, 29 Jul 2015, Wong Peter wrote: > Q:why do you believe that your machine was hacked? > A: My pf rules was flushed.This can prove using pfctl -sr. The whoe > firewall was not usable anymore. NO NAT nor packet filtering. > > Q: You say that whatever happened was done by your ISP even though

Re: OpenBSD machine was hacked

2015-07-28 Thread Wong Peter
Q:why do you believe that your machine was hacked? A: My pf rules was flushed.This can prove using pfctl -sr. The whoe firewall was not usable anymore. NO NAT nor packet filtering. Q: You say that whatever happened was done by your ISP even though you had no Internet connection.Why do you believe

Re: OpenBSD machine was hacked

2015-07-28 Thread Joel Rees
One question at a time. On Tue, Jul 28, 2015 at 6:17 PM, Wong Peter wrote: > Dear All, > > Recently, I'm realized that my openbsd firewall router was not usable > anymore What symptoms? > due to pf rules had changed Can you show the configuration, the rules before the undesired changes, and th

Re: OpenBSD machine was hacked

2015-07-28 Thread Daniel Boulet
There is all sorts of information that you could provide: - why do you believe that your machine was hacked? You seem to think that someone at your ISP did whatever was done. Why do you believe that to be true? Why would someone at your ISP want to do this? Why would someone at you ISP be bette

Re: OpenBSD machine was hacked

2015-07-28 Thread Wong Peter
What information you all require? On Tue, Jul 28, 2015 at 10:28 PM, Giancarlo Razzolini wrote: > Em 28-07-2015 06:17, Wong Peter escreveu: > > Dear All, > > > > Recently, I'm realized that my openbsd firewall router was not usable > > anymore due to pf rules had changed by using carp and pfsync

Re: OpenBSD machine was hacked

2015-07-28 Thread Peter N. M. Hansteen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/28/15 11:17, Wong Peter wrote: > Recently, I'm realized that my openbsd firewall router was not > usable anymore due to pf rules had changed by using carp and pfsync > mechanism. It would be a lot easier to offer assistance if you offer some fa

Re: OpenBSD machine was hacked

2015-07-28 Thread Giancarlo Razzolini
Em 28-07-2015 06:17, Wong Peter escreveu: > Dear All, > > Recently, I'm realized that my openbsd firewall router was not usable > anymore due to pf rules had changed by using carp and pfsync mechanism. > > Here is my prove. > > I'm tried to reinstall the whole machine and plugged in the modem LAN c

Re: OpenBSD machine was hacked

2015-07-28 Thread Wong Peter
; insecure mode. man 1 chflags is your friend. > > If this doesn't help it is beyond my knowledge. > > Good luck! > STEFAN > > > *Gesendet:* Dienstag, 28. Juli 2015 um 11:17 Uhr > *Von:* "Wong Peter" > *An:* misc@openbsd.org > *Betreff:* OpenBSD machine

OpenBSD machine was hacked

2015-07-28 Thread Wong Peter
Dear All, Recently, I'm realized that my openbsd firewall router was not usable anymore due to pf rules had changed by using carp and pfsync mechanism. Here is my prove. I'm tried to reinstall the whole machine and plugged in the modem LAN cable to NIC card. All my written pf rules was flush and