site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
970
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

brianstanden

join:2001-07-14
uk

I assume that my system has been hacked - help pls

on checking my network neighbourhood this morning I have identified a rogue network connection :-

"pro_connectivity on 212.250.57"

I am assuming that this is the result of some form of hack.

have reconnected my adsl line (i.e. changed my IP address) and confirmed with the latest version of Sophos that no viruses/trojans are identified.

two questions
1. how did they get in first time - according to dslreports my system could not be identified,
and
2. what do I need to do to prevent re-occurrence


Liontaur
Lets Get Boincing Already
Premium,MVM,ExMod 2004-06
join:2001-11-03
Salmon Arm, BC

1. Just cause DSLR says you are safe doesn't mean you are. and 2. Unplug your computer from the dsl modem, or hopefully a good firewall will do
--
Do you SETI


brianstanden

join:2001-07-14
uk

reply to brianstanden
point taken, although I am using a firewall on an xp system

clearly trade off between usefulness, and security risk (I have nothing particularly worth hacking into anyway !)



Time Out$
Premium
join:2002-04-28
North Myrtle Beach, SC

Are you using SonicWall or a VPN?



jansson_mark
Markus Jansson
Premium
join:2001-08-05
Finland

reply to brianstanden

Try this

close all connections you have. Wait a while. Then run (without quotas) "netstat -a" that should tell you about connections in/out of your computer then.

And GET a firewall, antivir and such...
--
My privacy related homepage & PGP keys:»www.markusjansson.net


Wildcatboy
Premium,Mod
join:2000-10-30
Toronto, ON
kudos:2
Host:
Security Product V..
Security

reply to brianstanden

Re: I assume that my system has been hacked - help pls


If you see another computer in your Network Neighborhood it means that you have Netbios open and it's basically looking for other machines in your network and lists them. Any firewall would be able to fix the problem. whether you have something on your computer or not is irrelevant, Your computer and your bandwidth is valuable enough for someone to put a Trojan on your machine and use it as a zombie to hurt others.
--
You can catch the Devil, but you can't hold him long.


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

The network neighborhood is populated automatically via local broadcasts. You and somebody else both run netbios over TCP/IP on an unsecured computer.

This is relatively risky behavior if your setup is not done with security in mind (e.g. if you share your HD with your household using weak passwords).

Run the shields up test ("test my shields" on »grc.com/x/ne.dll?bh0bkyd2 ) to see how much of your machine is visible to outsiders.

To see if somebody is actually connected, run netwatcher. Showing up in NN does NOT mean that computer has ever attempted to connect to your shares, most likely he is in a similar situation than you and probably uses the same default workgroup name. People that actively try to hack into shares usually have their system secured and you won't see anything in the NN, even if they are connected.
--
Where is the world is LA/OC ?


brianstanden

join:2001-07-14
uk

reply to brianstanden
many thanks for all your assistance

shields up continues to give me a clean bill of health, not quite sure how I eliminate netbios from the options, I am on win XP home, could have (and did !) eliminate netbios from earlier versions of windows

I am currently monitoring the system to see if I can find anything abnormal - but remain a little concerned as if this can happen once, and I do not know why, I am unsure if it could happen again.



SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA

Another possibility: Do you have a home network with any wireless leg?


brianstanden

join:2001-07-14
uk

reply to brianstanden
yes I do, recognise that someone could have another wireless system in range, but it would be difficult unless they were trying to get close to my house, and why would they do that. (my portables only operate within the house, not the grounds



Wildcatboy
Premium,Mod
join:2000-10-30
Toronto, ON
kudos:2

reply to SYNACK
Good catch SYNACK.


ihaddsl

join:2001-12-05
/dev/hda0

reply to brianstanden
there are antennas around that allow access much further than any PC Card / Antenna can... so really that's no barrier.
--
... and now I have cable.


brianstanden

join:2001-07-14
uk

reply to brianstanden
ok , point taken I will ensure that wifi system kept switched off when not directly in use,

still a little bizarre that anyone would be trying to probe for wifi in my residential neighbourhood without any reason to target it - would need to match my settings and network description

still if everest wasn't there no one would have tried climbing it !



SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA
Host:
Networking
Virtual Private Ne..
Netgear
ZyXEL

reply to ihaddsl
You should tighten the wireless side with all available means:

(1) enable WEP, (2) hide SSID, (3) Use MAC filtering, etc.

I would suggest the wireless forum:
»Wireless Networking

(Also see e.g. »Best Buy closes wireless registers )
--
Where is the world is LA/OC ?


brianstanden

join:2001-07-14
uk

reply to brianstanden
many thanks,

will turn to those immediately



Time Out$
Premium
join:2002-04-28
North Myrtle Beach, SC

Hack here

In November last year BBC News Online was shown just how easy it is to find and gain information about wireless networks.

People have made these antenna out of Pringles tubes, coffee cans and even old satellite dishes

Geoff Davis, i-sec
These networks are rapidly becoming popular because they are cheap, easy to set up and replace the unsightly cables that many companies have used to link PCs together into networks.

»news.bbc.co.uk/hi/english/sci/te···0241.stm
_______________________________________________________________________
Hacking wireless networks with a Pringles tube

»Hacking wireless networks with a Pringles tube

_______________________________________________________________________

War Driving...

I've read recently from a local paper that some hackers engage in what is called "War Driving". The article explained how hackers would drive around looking for wireless networks. I mention the article to my friend who has a wireless network. What steps can he take to make sure his home wireless network is secured?

»War Driving...

_______________________________________________________________________

Bestbuy, Walmart, Petsmart Security Issues
For about 2 days, there has been alot of talk about how when you purchase at a Bestbuy, all of your information is sent out in cleartext across a wireless network. That information can be captured while transfering across the network.

»Bestbuy, Walmart, Petsmart Security Issues
_______________________________________________________________________

Monday, 04-Jun 09:02:09 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics