Bug 33628 - I think there is Security Breach in 141-elan i2c
Summary: I think there is Security Breach in 141-elan i2c
Status: RESOLVED INVALID
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: High major
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-10-09 16:52 CEST by Demos95
Modified: 2024-10-11 12:10 CEST (History)
1 user (show)

See Also:
Source RPM:
CVE:
Status comment:


Attachments

Description Demos95 2024-10-09 16:52:33 CEST
Description of problem:
I'm on linux
I reset my computer multiple times but I still have a security Breach on my laptop Cause someone succeed to access to my Mouse Controler
To move my mouse some time to time without my voluntee 

The problem is ... I can reinstall my computer
Change password but it's still occuring again

Problem also is it's possible hacker succeed to pass throught the protection Firewall of My House
But also Firewall of my Computer

I have Lenovo T490S 
Does this issue is occuring only with Lenovo Computer ?
I don't know if any one else have this issue

I found a Security Leak related to Firefox and Mouse Controler

I suspect people wait I connect on my Personal Website to connect and control my mouse
Otherwise it occure less often

So I Think
Possibly It can also be an error on PHP 
Security Leak on PHP I have Wordpress and KUBIO plugin

I have reported an issue on KUBIO PHP Template related to the Button

But I suspect once the PHP issue occured on the laptop
It can happen again after until I reset my laptop

So I suspect it's Trojan going through PHP KUBIO PHP Button or something in PHP 

Problem is 
it's Security Leak on PHP
But also LINUX cause Firefox let it pass on
Maybe not only Linux

I Mention to you all this information
Cause I don't know how to deal with it
And I think Some people are entering on my computer possibly to take all personal information

Version-Release number of selected component (if applicable):
I have MAGEIA : 9 last version updated 

Linux localhost.localdomain 6.6.52-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Thu Sep 19 20:27:15 UTC 2024 x86_64 GNU/Linux

How reproducible:

It's difficult to explain but I can Reset my Computer like Reinstall it
Renew all password
I Raise the priority cause it break all my Firewall Password Renewall
Maybe it can be also Brut Force Attack Going through PHP Code ? 

But I have asked my Host domain Provider they explain me everything is fine on there side
So I suspect only going through PHP a Trojan and Brut Force attack
That make my mouse doing strange movement

Go to reset my Router from my broadband provider
Then go to my personal website wordpress : 
www.healthinyourplanet.com

Edit the website
After few hours my mouse can start to move in different direction ...

I have reported this issue also to KUBIO Wordpress Plugin Application

Steps to Reproduce:
1.Go to Edit Wordpress Website
2.The mouse mouvement get strange
3.
Comment 1 Demos95 2024-10-09 16:55:07 CEST
Do not hesitat to create an other ticket from this one

I have Reported my issue to the following wordpress website also : 
https://kubiobuilder.com/contact/#support

I tried also to report it to the UK Digital Police
If you have any other advice to website to report this 

Please let me know

Thanks
Demos95

Priority: Normal => High

Comment 2 David Walser 2024-10-09 17:53:34 CEST
An issue with your particular system (especially with third party software) is not a Mageia bug.

Status: NEW => RESOLVED
Resolution: (none) => INVALID

Comment 3 Demos95 2024-10-09 17:57:06 CEST
Hello

I'm not sure it's External issue only

I suspect it's also Trojan issue
problem is Firefox and Mageia do not have protection against this issue

can we keep open maybe if we can keep trace of this ?
Cause it's quiet tiring to be on linux and having mouse moving in all direction
even after reseting computer

Broadband provider explain it's issue from Computer Software like OS
but problem you say it's external

I think there is an issue on Mageia if we cannot be protected just going on a website checking or Editing things...

What do you think ?
Comment 4 Demos95 2024-10-09 17:58:23 CEST
(*quite tiring) 
Sorry
Comment 5 Morgan Leijström 2024-10-09 18:38:39 CEST
(In reply to Demos95 from comment #0)

> To move my mouse some time to time without my voluntee 
> 
> The problem is ... I can reinstall my computer
> Change password but it's still occuring again

I have had mouse pointer randomly but seldom starting wandering.
It was a hardware problem in mouse sensor...
Depend on temperature, ambient light, surface...

Try:

1) use another mouse
Or simply unplug the mouse when it start moving by itself, and see if pointer stops.

2) Run another distro as live USB and see if problem occour.

CC: (none) => fri

Comment 6 Morgan Leijström 2024-10-09 18:42:15 CEST
It is the touchpad, not mouse?
Unplugging it requires opening the laptop, you may be inconvenient to do that.
Maybe it is possible to disable it in "BIOS" settings?
Or by not loading a kernel module, or use kernel parameter... not my cup of tea.
Comment 7 Demos95 2024-10-10 11:11:44 CEST
Hello Thanks for all this reply
( It's Touchpad from now I don't use Mouse)

I suspect it's Hacker that connect to my laptop... the mouse is just something giving me information they entered ... 


So I think multiple problem here

- Hacker succeed to access to my laptop in some point by a security leak exploitation ( but not sure how they do ) but at least my FAN is getting more active
even activating the Firwall as usual all the rules etc
I can reset my laptop they success to come back to it

- I generally notice by using two finger on the Mouse Pad and you can see the mouse is doing some ( soubresaut ) sort of movement very strange

- I also notice my mouse moving alone even without two finguer I think (80% sure) at a certain time for exemple it occured few days similarly
Comment 8 Demos95 2024-10-10 11:15:27 CEST
Generally it's visible when you use two finger 
the Idea PAD ( mouse Pad Lenovo ) is normally working perfectly when you Reset your laptop even with last update of Magiea all update etc

But then you connect to internet

you start to hear your FAN getting more active with more noise

So then when you use the Mouse Pad 

if you use two finguer as usual to scroll etc

The Pad mouse sometimes do strange movement
Like Up down quickly

Sometimes it's some turning 
sometimes it can be cross 

Sometimes also it get down quickly 
you notice it's something wrong

Status: RESOLVED => UNCONFIRMED
Ever confirmed: 1 => 0
Resolution: INVALID => (none)

Comment 9 Demos95 2024-10-10 11:25:09 CEST
Just to precise 
( If you do not connect to internet )
the issue with the Two finger on the Mouse Pad is not occuring

The Mouse is not doing Unstable Movement

Just to add
Comment 10 Demos95 2024-10-10 11:26:12 CEST
Also ( the mouse is not constantly instable even on Internet )
it occures sometimes to times ... That's also the problem ... 

Demos95
Comment 11 Demos95 2024-10-10 11:29:46 CEST
( I'm in Secure Mode also to precise )
Password Complex 
Firewal Activated with all rules

It's maybe Trojan inside my disto but on linux ?
But I do not think it's the case because I reset my Laptop few times
Even Keeping Save on Different partition I do not open or touche all files saved 

And the issue occured again

Because we can here the Fan
I think it's Security Breach Security Leak

So I notice with the Fan noise
But also Mouse 

The FAN occurs only once

Then the mouse is doing movement some time to time

With My broadband provider
We tried to capture Dump for the Connection But we didn't notice so much things wrong ... 
I might need to double check

Demos95
Comment 12 sturmvogel 2024-10-10 11:32:06 CEST
It‘s a common Thinkpad issue. Simply google it. Example
https://forum.thinkpads.com/viewtopic.php?t=124953

Status: UNCONFIRMED => RESOLVED
Resolution: (none) => INVALID

Comment 14 Demos95 2024-10-10 11:36:03 CEST
@morgan

Unplugging it requires opening the laptop, you may be inconvenient to do that.
Maybe it is possible to disable it in "BIOS" settings?
Or by not loading a kernel module, or use kernel parameter... not my cup of tea.

--- 

I think the mouse might be only a Symptom not the worsed problem
I have noticed also some modification on my online account ... Linkedin etc
Things like that ...
I suspect hacker profit of this access to stoll data

regarding your second comment :

Unplugging it requires opening the laptop, you may be inconvenient to do that.
Maybe it is possible to disable it in "BIOS" settings?
Or by not loading a kernel module, or use kernel parameter...

---

I think The mouse not be the only problem and that's the thing

If My Fan is doing lot of Noise... there is probably somwhere Hacker exploit

Cause also I do not open the SSH SSL Access ...
I have Secure mode
but I don't think the SSH SSL port is open ..

Status: RESOLVED => UNCONFIRMED
Resolution: INVALID => (none)

Demos95 2024-10-10 11:36:16 CEST

Status: UNCONFIRMED => NEW
Ever confirmed: 0 => 1

Comment 15 Demos95 2024-10-10 11:39:37 CEST
Nice discovery Link

But I'm not sure it's related to BUG 
Cause 
The issue is stoping as soon I disconnect my Ethernet Wire Cable
I think it's External access 

I will double check the link again but not sure it's only stability like bug 

Also If I reset my laptop the issue do not occure even on the last version of mageia with all update 

Only after hearing Fan getting more active once ... then mouse get strange some time to times and only when I'm connected with internet
Comment 16 Morgan Leijström 2024-10-10 12:09:56 CEST
A hacker would not want to reveal himself by controlling the screen pointer.
Also, that would need extra work, for what?

- Or alternatively, if he gets access to see the screen then it would be in order to control it. So do you have high bandwidth usage up when this happens (screen mirrors)?  Does the self moving pointer actually move in some effective way, execute things?

The sensitivity to ethernet cable may be EMC/EMI interference, that affect the touchpad. (laptop becomes an "end/antenna" of the cable) If you have the indication it happens more with ethernet than with wifi, this points (slightly) toward touchpad hardware sensitivity/calibration problem.

What if you move your hand a couple centimetre around/over the touchpad when this happen?
Comment 17 David Walser 2024-10-10 15:08:07 CEST
Please do not reopen this bug.  This kind of discussion would be better held on the forums or discuss mailing list.

Status: NEW => RESOLVED
Resolution: (none) => INVALID

Comment 18 Demos95 2024-10-11 09:40:01 CEST
Sorry David before we close the Forum Case or Ticket
Can I just reply to morgan before  ?

Morgan you said :
A hacker would not want to reveal himself by controlling the screen pointer.
Also, that would need extra work, for what?

Ok I agree for revealing himself
But in any case it's quite tiring cause you see (Pointer Cursor) (you right) moving in lot of direction when you work
So ... Revealing identity ... it can be also tiring people .... 


Regarding "Extra Work" not sure what do you mean
I think this issue is not concerning only Linux
as your link were mentionning 

As you said extra work
I'm not sure what do you mean ?


Forum then ?

I think for me it Security Breach I report here cause I'm using Linux Mageia
But maybe it can help other company

I don't know... 
Linux for me is more central 
it can help every company more easily I would say ... no ?
I do not mean to fix it yourself
but you are more central than me to report it to other instance no ?


Regarding what you said After (Morgan) :
this points (slightly) toward touchpad hardware sensitivity/calibration problem.

ok yes .. it might be not really Stolling data so not very bad

But We are also in context of Microship Component crisis
What the point if you feel someone is able to move your mouse without your consent
You have impression constant someone read or modify what you do

also

The thing is the FAN turning I suspect Brut Force attack
But I do not see from which Port or App

cause I have not so much App install 
It's default distrib 
only one app add on top of it



Do you prefere we continue to the forum ?

For me it's security leak
There is brut force possibility and also Trust Questionise regarding your distrib
for me it's major security issue ..
What do you propose ?

I'm open to your decision
Available also if you have any question

Demos95
Comment 19 Morgan Leijström 2024-10-11 10:41:59 CEST
Forum.
Comment 20 Demos95 2024-10-11 12:10:32 CEST
Ok Thanks 

Forum Discussion : in Basic Topic
Title : "Thinkpad-trackpoint-moves-on-its-own-on-linux"

Thanks for your help in this Topic Discussion

Demos95

Note You need to log in before you can comment on or make changes to this bug.