My CNC Machine was Hacked!

More
28 Aug 2022 04:15 #250602 by PhilCNC
When I walked into my garage, my lathe had Mozilla Firefox open and the mouse was moving across the screen! Hundreds of terminal windows were open and hundreds of application launchers were open. The hacker opened capital one banking online. I was shocked! I wanted my dad to see this so I shouted for him to look, but the hacker clearly understood what I said and therefore stopped what he was doing. I will remove the wifi card from the computer, and only periodically connect with a USB wifi adapter from here on out. Fortunately I have no sensitive information stored on this Linux install, but this is extremely concerning. What can I do to find out what this hacker accessed? I will include a few cellphone photos of what the hacker connected to, but I feel like there must be more that I'm not seeing.
Attachments:

Please Log in or Create an account to join the conversation.

More
28 Aug 2022 12:40 #250616 by rodw
Replied by rodw on topic My CNC Machine was Hacked!
Its always a worry this stuff.
I would be far more concerned about firewall security. How did he get in? What other PCs is he using on your network?
The following user(s) said Thank You: arvidb, pommen

Please Log in or Create an account to join the conversation.

More
29 Aug 2022 08:29 #250675 by robertspark
can you post some info of what Linux flavour you were running (Debian/whatever) and what version it was

hence was it kept up to date with security fixes etc?

I presume that it would have been a Firefox breach, something like or via this.

www.google.com/amp/s/www.forbes.com/site...-security-flaws/amp/

important to keep up to date on security patches.

I don't think it will be a linuxcnc issue.

Please Log in or Create an account to join the conversation.

More
29 Aug 2022 09:52 #250679 by tommylight
Screenshot shows Debian Wheezy or Buster.
Attack was through VNC or RDP running on the victims PC with weak password.
Hard to figure more from a screenshot.
The following user(s) said Thank You: robertspark

Please Log in or Create an account to join the conversation.

More
29 Aug 2022 23:34 #250739 by PhilCNC
Replied by PhilCNC on topic My CNC Machine was Hacked!
I'm certainly not up to date, I did the regular 2.8 LinuxCNC install that way I could use the probe basic GUI. I saved my configuration and I'm going to start over with a fresh install. I think I will use 2.9 and certainly remove the wifi card. This machine doesn't really need internet access and I can't risk hackers getting into other computers in the house.

Please Log in or Create an account to join the conversation.

More
30 Aug 2022 01:21 #250741 by JohnnyCNC
As Rod said I would be far more concerned about how they got past the firewall on your router. Of all of my PCs the CNC would be the least of my worries.

Please Log in or Create an account to join the conversation.

More
06 Sep 2022 21:12 #251353 by andypugh
Replied by andypugh on topic My CNC Machine was Hacked!
I had this happen once.
I had been using RDP but they only way that I could get it to work between the Mac and LinuxCNC was to do it without passwords.

I _assume_ that the attacker was linked to my WiFi, as I don't think that there was any link through the router to the larger internet.

I got rid of the RDP and changed my Wifi password (and security type., I think) and haven't seen it happen since.

Please Log in or Create an account to join the conversation.

Time to create page: 0.081 seconds
Powered by Kunena Forum