Score:0

How do I prevent browser tampering from outside sources?

vi flag

in the past; I have had severe intrusion issues. Previously before moving to Linux, my internet was being throttled and browsers were being tampered with. So, I moved to Linux. I used arp -a to view CACHE logs of connected devices and found 4 attackers. I then tweaked the UFW settings to deny all & default to deny all incoming, but then opted towards reject all...afterwords, I installed tripwire & fail2ban, set the jail config to ban 5 failed request attempts for over 1000 thousand days; and an additional waiting period of over 1000 thousand days. I then used arp -a and ip addr/ip addr show and revealed that there were 0 connected IP's other than my own. So it looks like on that end, it had been a success. But there was still a problem --- my browser tabs were still being killed & browsers being tampered periodically, I determined that the internet throttling was in relation to the browsers directly, as after my internet throttles, I get a prompt that (x) browser is having issues [terminate/wait]....so, I stripped all browser downloads & installed 4 browsers - brave, firefox (pre-installed), chrome, tor. I then configured the browsers with these pre-sets/extensions here and here. That fixed the browser tabs from being killed, but not the throttling. So, I installed EtherApe and snort. I discovered that a massive amount of internet traffic was going through internet UNTIL I enabled my VPN...after I enabled my VPN, there were certain nodes that appeared periodically seemingly to receive packets, but...I just now experienced the throttling/browser failure WHILE there were no additional nodes present. No traffic was going through my network on EtherApe's end. I did receive 1 warning for potentially bad traffic on snort, but i'm not entirely sure if this was in relation to the exact event time, since I saw no other nodes present. I even installed suricata and have it running.

But the browser failure/throttling still happens. I have memory saver for tabs enabled on each browser as well. It doesn't just happen randomly. The browser's turn into lagged state and freeze my PC ONLY when I go to make specific posts or do specific things, after having used the browsers/internet just fine for several hours before the event....It doesn't appear to be a matter of switching between tabs fast, and follows a pattern of causation that shows an attacker is remotely viewing the activity in some mannerism, despite the fact that I have Remote Desktop disabled on Ubuntu settings AND have incoming ports set for reject all...does anyone have any clue on how to remediate this issue?

ar flag
Welcome to Ask Ubuntu. One possibility is you are visiting malicious sites. This may explain why only browsers are affected and it does not matter which browser you use. If the sites you visit are bad firewall and closing ports won't help. Identify which sites are bad and don't visit them.
Jess el avatar
vi flag
I can certainly assure you that this is not the case. I have HTTPS only enabled on [All] browsers, as well as two antivirus extensions as mentioned in the guide AND I use a security practice of never visiting sites I don't visit myself. I made a rule to never open link URL's in my primary browsers as well; in the scenario that I do click on a hyperlink/URL, it is isolated from my primary browser that I login to identifiers on; as my default browser is a separate one. Additionally; the other extensions I have both scan & prevent malicious sites from being opened. Also thank you for welcoming me
Jess el avatar
vi flag
Additionally: some of the extensions I have scan & prevent blacklisted/infected url's from being opened. I also block scripts in some cases. For all intensive purposes, the only webpages i've been visiting are the big name's....Facebook, devientart, other social media and big name companies, etc...
ar flag
Sometimes the extensions are the cause of slow-downs, freezes, and crashes. Try disabling them one by one and see if that helps. If you have multiple extensions doing similar things, having them all active may be the problem.
Jess el avatar
vi flag
Hey again @user68186. So, the problem is that I go hours without any issues or lag/freezing off and on. Also; but more importantly, this issue existed prior to me installing any extensions. Actually, as I mentioned, there was browser stalling/OS freezing due to the stalling ALONG with constant tab killing prior to me adding any extensions. This almost indefinitely means that it isn't extension-based; adding the extensions has only remediated the issue to certain extents. ----
Jess el avatar
vi flag
--- But if you would like to verify any stalling concerns with my extensions, you can view the list of all the extensions I use here: https://www.facebook.com/permalink.php?story_fbid=111959098567678&id=100092607645058 They are all very reputable and I don't see why they would stall my browser only at moments that would show patterns of Remote monitoring. Again, I had a major intrusion prior to this; and it appears to be a symptom of my being a large target for attacks; not a user-error fault via extensions & malicious webpage visits. This has been an issue with & without extensions.
Jess el avatar
vi flag
~ As well as on Windows OS and Linux OS. But overall it would be impossible for me to test if extensions are causing it by disabling them one at a time, as the issue occurs without them AS WELL as over a period between several hours. It would take extensive amounts of time; but again ---> The issue persists without extensions as well.
ar flag
Clearly the problem lies elsewhere, as you say it happens in both Windows and Ubuntu. Maybe your computer is overheating. Maybe your internal disk is failing. Maybe component card inside your computer is loose. There are thousands of possibilities. Whatever it is, it is not a Ubuntu problem. I am voting to close this question as the problem cannot be reproduced.
Jess el avatar
vi flag
Nope, i've not gotten a warning about CPU overheating, it's normal temp/my internal disk appears in good health, and nothing seems loose. That wouldn't explain why I go HOURS without it happening; and why it ONLY happens when I do something my attackers don't like. 100%, this is a backend attack. I just don't know how to remediate something like that. Check this post out for more info: https://askubuntu.com/questions/1469119/apparent-packet-transfer-inquiry-qa Post should not be closed because that is clearly not the answer and is clearly not the problem. I'm still up for more help. Thanks.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.