LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2024, 04:25 AM   #1
linuxuser371038
Member
 
Registered: Jan 2024
Posts: 56

Rep: Reputation: 1
How to check 2nd hand hardware does not contain malware?


I do like the idea of picking up bargains 2nd hand and bringing them back to life.

I don't like the idea that none store bought hardware is more likely to be compromised.

Are there ways to check to a reasonable level of confidence that devices you buy are clean?

If so how?

Also must it be done on an airgapped, none internet connected, machine or would booting into a vm/livecd suffice?
 
Old 05-13-2024, 05:18 AM   #2
hazel
LQ Guru
 
Registered: Mar 2016
Location: Harrow, UK
Distribution: LFS, AntiX, Slackware
Posts: 7,661
Blog Entries: 19

Rep: Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483Reputation: 4483
In the old days I used to zero out the drive and then repartition it. You can do that with a UEFI machine too if you have an independent boot device, but you will have to create a new ESP, put elilo or grub onto it and use efibootmgr to store the new details into nvram. It's easier (but obviously less secure) to keep the ESP in place, and that's what I did when I bought my current machine.
 
1 members found this post helpful.
Old 05-13-2024, 05:36 AM   #3
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,998

Rep: Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338
yes, if it is a disk drive just repartition it and format. Use smartctl to check it first. you can put it into any host, just do not try to boot from it and do not [auto]momunt it.
 
1 members found this post helpful.
Old 05-13-2024, 06:05 AM   #4
linuxuser371038
Member
 
Registered: Jan 2024
Posts: 56

Original Poster
Rep: Reputation: 1
Quote:
Originally Posted by hazel View Post
In the old days I used to zero out the drive and then repartition it. You can do that with a UEFI machine too if you have an independent boot device, but you will have to create a new ESP, put elilo or grub onto it and use efibootmgr to store the new details into nvram. It's easier (but obviously less secure) to keep the ESP in place, and that's what I did when I bought my current machine.
The item in this case is a 4g dongle which doesn't have official storage unless you add an sdcard but does have some firmware.

This thread seems to have some good general guidance. Checking activity before and after plugging in usb device.
 
1 members found this post helpful.
Old 05-13-2024, 06:15 AM   #5
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,998

Rep: Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338
that answer is a simple no. You cannot detect. Or it is too late.
 
Old 05-13-2024, 07:40 AM   #6
linuxuser371038
Member
 
Registered: Jan 2024
Posts: 56

Original Poster
Rep: Reputation: 1
Quote:
Originally Posted by pan64 View Post
that answer is a simple no. You cannot detect. Or it is too late.
So, never buy 2nd hand? I am unable to find the device new though...
 
Old 05-13-2024, 08:08 AM   #7
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,998

Rep: Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338Reputation: 7338
Quote:
Originally Posted by linuxuser371038 View Post
So, never buy 2nd hand? I am unable to find the device new though...
Most probably there will be no problem, but you cannot be sure.
 
Old 05-14-2024, 03:37 AM   #8
___
Member
 
Registered: Apr 2023
Posts: 155
Blog Entries: 1

Rep: Reputation: Disabled
Maybe usbguard https://www.zdnet.com/article/how-to...ck-protection/


Or maybe an old (pre-UEFI) PC with no HDD, running a minimal Linux Live from cd-rom.

IF a USBkiller *burns* it up, you're in luck (you win): the PC was worth <$10 & the USBkiller is worth >$100!

Last edited by ___; 05-14-2024 at 03:49 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Arch Linux AUR Repository Found to Contain Malware ChuangTzu Arch 7 07-13-2018 08:44 AM
Arch Linux AUR Repository Found to Contain Malware ChuangTzu Linux - News 0 07-10-2018 05:24 PM
LXer: Why Microsoft's Linux lovefest goes hand-in-hand with its Azure cloud strategy LXer Syndicated Linux News 0 07-17-2016 07:06 PM
[SOLVED] How to find files that contain one string, but don't contain another. PatrickDickey Linux - Newbie 2 09-11-2011 06:00 AM
LXer: Linux Training and Laptops Go Hand in Hand at LinuxCertified LXer Syndicated Linux News 0 01-31-2006 12:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:48 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration