RetroPie forum home
    • Recent
    • Tags
    • Popular
    • Home
    • Docs
    • Register
    • Login
    Please do not post a support request without first reading and following the advice in https://retropie.org.uk/forum/topic/3/read-this-first

    Pi3 rebooted by it's own (HACKED)

    Scheduled Pinned Locked Moved Help and Support
    pi3 rebootedupdate failed
    13 Posts 6 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mahcneto
      last edited by mahcneto

      Pi Model or other hardware: model 3
      Power Supply used: 5v 2.5amp
      RetroPie Version Used 4.3.3
      Built From: Pre made SD Image on RetroPie website
      USB Devices connected:
      Controller used: 2 8bitDo SNES30pro
      Error messages received: none

      I was playing snes Star Fox and then all of a sudden it restarted the game, then the Pi3 itself rebooted and it never worked again, i mean, it's been almos 15 mins since it's trying to download something but I don't see any progress? Will record a video with this if possible. What might have happened? The only kinf of message i get is when I power it and it says something about a dirty bit is set?

      0_1529468550405_35659937_10212203276666290_1352235741219913728_n.jpg

      mituM 1 Reply Last reply Reply Quote 0
      • mituM
        mitu Global Moderator @mahcneto
        last edited by

        @mahcneto It's not downloading anything. Because the previous restart was not a clean one, it checks the files on the card to make sure they're not corrupted. If your sd card is large, it could take a while.

        1 Reply Last reply Reply Quote 0
        • M
          mahcneto
          last edited by

          My SD card is 64gb. I recorded this, is this normal? Its taking almost 30 mins so far

          1 Reply Last reply Reply Quote 0
          • mituM
            mitu Global Moderator
            last edited by

            @mahcneto said in Pi3 rebooted by it's own, then started to update something:

            My SD card is 64gb. I recorded this, is this normal? Its taking almost 30 mins so far

            Based on your video, I'd say your installation has been 'hacked' and your system has a rootkit installed, acting as a SSH brute-force attacker.
            Save your ROMs and re-install from scratch. Don't expose the RPI directly into the internet and make sure you change the default password for the pi user.

            ClassicGMRC PokeEngineerP 2 Replies Last reply Reply Quote 0
            • ClassicGMRC
              ClassicGMR @mitu
              last edited by

              @mitu said in Pi3 rebooted by it's own, then started to update something:

              Based on your video, I'd say your installation has been 'hacked' and your system has a rootkit installed,

              Wow... didn't even know this was a "thing" outside Windows or some Mac viruses. Good to know.

              Growing older is mandatory. Growing up is optional!
              Enjoy the ride!

              1 Reply Last reply Reply Quote 0
              • M
                mahcneto
                last edited by

                it seems that i'm screwed? I tried accesing from FTP and my password has been changed. Is there any other way to backup my ROMs and Ports section & configs? this seems like a real pain in the ass, I can't belive there're peeps doing this, why for anyways, this sucks :/

                FruitybitF mituM 2 Replies Last reply Reply Quote 0
                • FruitybitF
                  Fruitybit @mahcneto
                  last edited by

                  @mahcneto Did you open up ports on your router to the Pi, or just no firewall? I ask as I use the Kodi port as my media server around the home, but it doesn’t have any extra access to the Internet other than when it needs to update the library, so I leave the Ethernet cable plugged in all the time.

                  M 1 Reply Last reply Reply Quote 0
                  • mituM
                    mitu Global Moderator @mahcneto
                    last edited by

                    @mahcneto said in Pi3 rebooted by it's own (HACKED):

                    I can't belive there're peeps doing this [..]

                    Unless you've been living under a rock, you must have heard about the rampant malware/spam/data breaches/hacked home appliances that are more and more prevalent and becoming more sophisticated each day.
                    It sucks, but you've been affected. Disconnect your PI from the internet and try to connect with file shares from a local connected PC - as mentioned in the docs. Make sure you only copy the ROMs and not some executables/other files.

                    1 Reply Last reply Reply Quote 0
                    • M
                      mahcneto @Fruitybit
                      last edited by mahcneto

                      @fruitybit I just opened one port for it.

                      @mitu I mean, I know there're malware and stuff but why with the Pi3, dang.

                      1 Reply Last reply Reply Quote 0
                      • PokeEngineerP
                        PokeEngineer @mitu
                        last edited by PokeEngineer

                        @mitu

                        Don't mind me, but this is my first time seeing Linux get infected, let alone a Raspberry Pi getting infected. Fascinating...

                        Don't sweat it.
                        When in doubt, take a BYTE out of life.

                        😎

                        mituM cyperghostC 2 Replies Last reply Reply Quote 1
                        • mituM
                          mitu Global Moderator @PokeEngineer
                          last edited by

                          @pokeengineer This is not the first time it's been reported in the forums:

                          • https://retropie.org.uk/forum/topic/16184/help-malware-and-or-backdoors-in-retropie
                          • https://retropie.org.uk/forum/topic/11260/issue-with-retopie-boot-emulationstation-not-starting
                          1 Reply Last reply Reply Quote 1
                          • cyperghostC
                            cyperghost @PokeEngineer
                            last edited by cyperghost

                            @pokeengineer said in Pi3 rebooted by it's own (HACKED):

                            @mitu

                            Don't mind me, but this is my first time seeing Linux get infected, let alone a Raspberry Pi getting infected. Fascinating...

                            This is not an "infection" via a virus. It's an open system and everybody who scans port 22 and got's a ping can try user pi and Password raspberry.

                            Voila... install whatever you want ... a php server with a full set of bitcoin mining user interface or a bot network, a porn blackbox, a torrent server, a hidden ftp file server, a hidden email server, a jabber network, irc servers .... endless possibilities... Nothing that's really fascinating ... just meat for underground damn dogs

                            You can follow @mitu's links and you will see consequences of spreaded open systems.

                            PokeEngineerP 1 Reply Last reply Reply Quote 0
                            • PokeEngineerP
                              PokeEngineer @cyperghost
                              last edited by PokeEngineer

                              @cyperghost said in Pi3 rebooted by it's own (HACKED):

                              @pokeengineer said in Pi3 rebooted by it's own (HACKED):

                              @mitu

                              Don't mind me, but this is my first time seeing Linux get infected, let alone a Raspberry Pi getting infected. Fascinating...

                              This is not an "infection" via a virus. It's an open system and everybody who scans port 22 and got's a ping can try user pi and Password raspberry.

                              Voila... install whatever you want ... a php server with a full set of bitcoin mining user interface or a bot network a porn blackbox a torrent server a hidden ftp file server endless possibilities... Nothing that's really fascinating ... just meat for underground hounds

                              Well, yeah, I knew that. It's just fascinating to me, because I'm into computer junk like that. Though, I never said it was virus that infected it.

                              Don't sweat it.
                              When in doubt, take a BYTE out of life.

                              😎

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post

                              Contributions to the project are always appreciated, so if you would like to support us with a donation you can do so here.

                              Hosting provided by Mythic-Beasts. See the Hosting Information page for more information.