 | I assume that my system has been hacked - help pls on checking my network neighbourhood this morning I have identified a rogue network connection :-
"pro_connectivity on 212.250.57"
I am assuming that this is the result of some form of hack.
have reconnected my adsl line (i.e. changed my IP address) and confirmed with the latest version of Sophos that no viruses/trojans are identified.
two questions 1. how did they get in first time - according to dslreports my system could not be identified, and 2. what do I need to do to prevent re-occurrence |
|
 LiontaurLets Get Boincing AlreadyPremium,MVM,ExMod 2004-06 join:2001-11-03 Salmon Arm, BC | 1. Just cause DSLR says you are safe doesn't mean you are. and 2. Unplug your computer from the dsl modem, or hopefully a good firewall will do  -- Do you SETI |
|
 | reply to brianstanden point taken, although I am using a firewall on an xp system
clearly trade off between usefulness, and security risk (I have nothing particularly worth hacking into anyway !) |
|
 Time Out$Premium join:2002-04-28 North Myrtle Beach, SC | Are you using SonicWall or a VPN? |
|
 | reply to brianstanden
Try this close all connections you have. Wait a while. Then run (without quotas) "netstat -a" that should tell you about connections in/out of your computer then.
And GET a firewall, antivir and such...  -- My privacy related homepage & PGP keys:»www.markusjansson.net |
|
 WildcatboyPremium,Mod join:2000-10-30 Toronto, ON kudos:2 Host: Security Product V.. Security
| reply to brianstanden
Re: I assume that my system has been hacked - help pls If you see another computer in your Network Neighborhood it means that you have Netbios open and it's basically looking for other machines in your network and lists them. Any firewall would be able to fix the problem. whether you have something on your computer or not is irrelevant, Your computer and your bandwidth is valuable enough for someone to put a Trojan on your machine and use it as a zombie to hurt others. -- You can catch the Devil, but you can't hold him long. |
|
|
|
 SYNACKJust Firewall ItPremium,Mod join:2001-03-05 Venice, CA Host: Networking Virtual Private Ne.. Netgear ZyXEL
| The network neighborhood is populated automatically via local broadcasts. You and somebody else both run netbios over TCP/IP on an unsecured computer.
This is relatively risky behavior if your setup is not done with security in mind (e.g. if you share your HD with your household using weak passwords).
Run the shields up test ("test my shields" on »grc.com/x/ne.dll?bh0bkyd2 ) to see how much of your machine is visible to outsiders.
To see if somebody is actually connected, run netwatcher. Showing up in NN does NOT mean that computer has ever attempted to connect to your shares, most likely he is in a similar situation than you and probably uses the same default workgroup name. People that actively try to hack into shares usually have their system secured and you won't see anything in the NN, even if they are connected. -- Where is the world is LA/OC ? |
|
 | reply to brianstanden many thanks for all your assistance
shields up continues to give me a clean bill of health, not quite sure how I eliminate netbios from the options, I am on win XP home, could have (and did !) eliminate netbios from earlier versions of windows
I am currently monitoring the system to see if I can find anything abnormal - but remain a little concerned as if this can happen once, and I do not know why, I am unsure if it could happen again. |
|
 SYNACKJust Firewall ItPremium,Mod join:2001-03-05 Venice, CA | Another possibility: Do you have a home network with any wireless leg? |
|
 | reply to brianstanden yes I do, recognise that someone could have another wireless system in range, but it would be difficult unless they were trying to get close to my house, and why would they do that. (my portables only operate within the house, not the grounds |
|
 WildcatboyPremium,Mod join:2000-10-30 Toronto, ON kudos:2 | reply to SYNACK Good catch SYNACK.  |
|
 | reply to brianstanden there are antennas around that allow access much further than any PC Card / Antenna can... so really that's no barrier. -- ... and now I have cable. |
|
 | reply to brianstanden ok , point taken I will ensure that wifi system kept switched off when not directly in use,
still a little bizarre that anyone would be trying to probe for wifi in my residential neighbourhood without any reason to target it - would need to match my settings and network description
still if everest wasn't there no one would have tried climbing it ! |
|
 SYNACKJust Firewall ItPremium,Mod join:2001-03-05 Venice, CA Host: Networking Virtual Private Ne.. Netgear ZyXEL
| reply to ihaddsl You should tighten the wireless side with all available means:
(1) enable WEP, (2) hide SSID, (3) Use MAC filtering, etc.
I would suggest the wireless forum: »Wireless Networking
(Also see e.g. »Best Buy closes wireless registers ) -- Where is the world is LA/OC ? |
|
 | reply to brianstanden many thanks,
will turn to those immediately |
|
 Time Out$Premium join:2002-04-28 North Myrtle Beach, SC | Hack here
In November last year BBC News Online was shown just how easy it is to find and gain information about wireless networks.
People have made these antenna out of Pringles tubes, coffee cans and even old satellite dishes
Geoff Davis, i-sec These networks are rapidly becoming popular because they are cheap, easy to set up and replace the unsightly cables that many companies have used to link PCs together into networks.
»news.bbc.co.uk/hi/english/sci/te···0241.stm _______________________________________________________________________ Hacking wireless networks with a Pringles tube
»Hacking wireless networks with a Pringles tube
_______________________________________________________________________
War Driving...
I've read recently from a local paper that some hackers engage in what is called "War Driving". The article explained how hackers would drive around looking for wireless networks. I mention the article to my friend who has a wireless network. What steps can he take to make sure his home wireless network is secured?
»War Driving...
_______________________________________________________________________
Bestbuy, Walmart, Petsmart Security Issues For about 2 days, there has been alot of talk about how when you purchase at a Bestbuy, all of your information is sent out in cleartext across a wireless network. That information can be captured while transfering across the network.
»Bestbuy, Walmart, Petsmart Security Issues _______________________________________________________________________ |
|