Comparison Shopping
Reviews
Gallery
Jemsite Blog
Forums
Home
Jemsite
>
Off-topic & Polls
>
Off-topic / Miscellaneous
Hacked
User Name
Remember Me?
Password
Register
FAQ
Calendar
iTrader
Mark Forums Read
Off-topic / Miscellaneous
Talk about miscellaneous stuff off-topic and not related to music, guitars or bands.
No music, gear or anything guitar related here please.
Go to Page...
Thread Tools
Display Modes
#
1
04-09-2005, 03:53 PM
30yroldpig
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374 - iTrader: (
0
)
Hacked
Well my suspicions have been confirmed, my computer's been/is hacked.
2 months ago I decided I'd install a P2P program to preview some music. I also installed a BETA version of messenger.
Last week I get my internet bill and i have 23 gigs in uploads ( only allowed 10 per month).
I figured It's cause I left the P2P app running...my fault, I'll pay. Since then I've uninstalled the software.
Today I browsed my "internet consumption update" on my ISP's web site and it said I already have 6.8 gigs in uploads....
When I type netstat -a in DOS there are other ISP's connected...
Man this bites. Looks like i'm due for a re-install.
I dunno if I got hacked through MSN Beta (also now removed) or the P2P.
Anybody else get hacked? What did you guys do?
I feel a bit violated...I also do all my banking and transfers via the net. manoman.
30yroldpig
View Public Profile
Visit 30yroldpig's homepage!
Find all posts by 30yroldpig
#
2
04-09-2005, 07:19 PM
bizkit666
Join Date: Dec 2004
Location: Manchester, England
Posts: 105 - iTrader: (
2
)
Re: Hacked
dont worry you havent been hacked, a P2P (peer to peer) is a program that lets the whole world share files, and u downloading files means your sharing them, so when you download a file, it auto shares it (you can turn this off so you dont share files) so sharing files means you are letting ppl download the files that you have downloaded from you, and this is why your upload bandwith is going up!
i hope tht made sence
bizkit666
View Public Profile
Visit bizkit666's homepage!
Find all posts by bizkit666
#
3
04-09-2005, 07:35 PM
Artist
Join Date: May 2003
Location: London, England
Posts: 795 - iTrader: (
0
)
Re: Hacked
have you scanned for spyware?
Artist
View Public Profile
Find all posts by Artist
#
4
04-09-2005, 08:22 PM
bammbamm
Join Date: Dec 2000
Location: Chicagoland, IL.
Posts: 4,134 - iTrader: (
16
)
Reviews: 1
Re: Hacked
You could have EASILY picked up a trojan and are being used as a slave to send out mass emailings unbeknownst to you.
Which P2P system did you install?
2ndly, I would get a firewall installed ASAP.
3rd, run all manor of virus and spyware scanning to detect any infiltration.
Another way to find some of these is look at the running processes and look up the ones that don't look familliar to you, normally you should see 25-no more than 40-ish (with a lot of apps open) I try to keep my total processes as low as possible just so I know when something new is running on my machine. I haven't had a cirus or reinstall in 2 years since I built my machine. (with the exception of when I swapped over to a raid 0 config.)
Hope this helps.
There are also bandwidth meters to see incoming and outgoing traffic on all ports.
Bamm
bammbamm
View Public Profile
Visit bammbamm's homepage!
Find all posts by bammbamm
#
5
04-10-2005, 12:43 AM
Ralsch
Join Date: Mar 2005
Location: Maryland
Posts: 116 - iTrader: (
0
)
Re: Hacked
Firstly,turn off all your active x updates as that is a major cause for hacker interference if you run xp...just get a firewall running and a program called zone alarm to alert and diable people from accessing your modem. run some anti-virus program and/or ad-aware , check the path if there is a problem and check it manually in your registry , if worse comes to worse just disable file sharing and reformat/defrag. . Like bam said you normally have a tagged section showing bandwith traffic and try to check whats running at startup. hope that helps
Ralsch
View Public Profile
Find all posts by Ralsch
#
6
04-10-2005, 12:49 AM
microdmitry
Join Date: Sep 2002
Location: Bellevue, WA
Posts: 1,687 - iTrader: (
4
)
Re: Hacked
1. Enable a firewall. Better yet, use hardware router if you have one.
2. Run full virus and spyware scan. Microsoft scanning tool is pretty good.
3. Do not use P2P clients that are not written in Java, .NET languages (C#, VB.Net, Managed C++) or other language that is fully protected against buffer overflows.
I'm actually surprised nobody actively targets P2P clients like emule, edonkey, gnutella, etc. They were written by hobbyists, they expose ports to the web, and they most likely have more holes than Swiss cheese. Best of all, source code is often available, so you don't have to guess.
Look for a client written in Java or for Microsoft .NET platform. This automatically prevents a whole bunch of attacks. Many attacks are simply not possible on the systems that use runtime buffer length checking. I run Azureus myself, and it works pretty darn good. Also, before installing P2P software, google on the web to make sure that stuff you install doesn't come with spyware. P2P programs often have spyware. Once you install this stuff on your machine the only safe way to remove it is to rebuild the machine.
Last edited by microdmitry; 04-10-2005 at
12:50 AM
. Reason: typo
microdmitry
View Public Profile
Find all posts by microdmitry
#
7
04-10-2005, 11:54 AM
30yroldpig
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374 - iTrader: (
0
)
Re: Hacked
Hi guys thanks for the replies.
Firstly I've been running zonealarm since I began surfing the web. I'm using an anti-virus (AVG FREE) and everytime i finnish surfing, i run add aware SE as well as Spybot-search & destroy. I know they're only freebee wares but I can't afford new software now and I don't believe in hacked software (no pun intended)
I understand the principle of P2P apps (was running shareazaa), what I don't understand is why, when I cleared ALL my shared files associated with shareazaa, there were 6.8 gigs in uploads. That's why I suspect that I've been hacked or as Bamm said had a trojan installed.
I'll look into all those options, Bamm, I have about 30 running processes, but to be perfectly honest, I don't really know what they all mean.
Once again, many thanks guys
Cheers
Pat
30yroldpig
View Public Profile
Visit 30yroldpig's homepage!
Find all posts by 30yroldpig
#
8
04-10-2005, 12:29 PM
fettouhi
Join Date: Aug 2003
Location: Odense S, Denmark
Posts: 9,937 - iTrader: (
2
)
Re: Hacked
Get a program called hijackthis (use google to find it) and do a scan with it. The program will list the processes you are running then post the log file here.
Regards
André
fettouhi
View Public Profile
Find all posts by fettouhi
#
9
04-10-2005, 01:42 PM
Jem7RB MK
Join Date: May 2002
Location: Milton Keynes,UK
Posts: 2,341 - iTrader: (
20
)
Re: Hacked
Quote:
Originally Posted by
Pat knup
Hi guys thanks for the replies.
Firstly I've been running zonealarm since I began surfing the web. I'm using an anti-virus (AVG FREE) Cheers
Pat
Pat, Have used AVG for about 6 years now, after hearing of it on #UKMG and have never had a virus issue on the freeware version ... As for the P2P stuff, I rarely use Win*x and have never suffered unduley, Nor do i get spyware scans show up anything untoward.
Hope you get sorted out bro
Rob
Jem7RB MK
View Public Profile
Find all posts by Jem7RB MK
#
10
04-12-2005, 09:20 PM
30yroldpig
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374 - iTrader: (
0
)
Re: Hacked
Rob, thanks for the encouragement, but I'll steer clear from P2P software.
So far everything seems back to normal, although I havn't really kept my system running long enough to see if there was any more activity.
André check your inbox, I've emailed you a Hijack this log.
Many thanks everyone.
Cheers
Pat
30yroldpig
View Public Profile
Visit 30yroldpig's homepage!
Find all posts by 30yroldpig
#
11
04-12-2005, 09:39 PM
Serratus
Join Date: Jan 2004
Location: UK
Posts: 491 - iTrader: (
4
)
Re: Hacked
Go to this page:
http://www.answersthatwork.com/Taskl...s/tasklist.htm
It is a list of almost all the programs that could be running in your task list (what processes are running in ctrl-alt-del) and what they do, and whether you need/want them. It's worth checking out and comparing to your tasklist every now and again to make certain you've not picked up anything nasty (in addition to all the other advice above).
Serratus
View Public Profile
Visit Serratus's homepage!
Find all posts by Serratus
#
12
04-12-2005, 10:02 PM
Jemwielder
Join Date: Apr 2005
Location: Rochester, NY/Boston, Mass
Posts: 999 - iTrader: (
1
)
Reviews: 6
Re: Hacked
Get yourself a nice mac that runs OS X. I got one thru school and I hate PCs now, viruses/hacking isn't an issue. The new mac mini is only 500-600 bucks and it works great. Personally i'd recomend a good G4 if you can afford it. I've got a powerbook. It works great.
Jemwielder
View Public Profile
Find all posts by Jemwielder
#
13
04-15-2005, 06:49 PM
30yroldpig
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374 - iTrader: (
0
)
Re: Hacked
Quote:
Originally Posted by
Jemwielder
Get yourself a nice mac that runs OS X. I got one thru school and I hate PCs now, viruses/hacking isn't an issue. The new mac mini is only 500-600 bucks and it works great. Personally i'd recomend a good G4 if you can afford it. I've got a powerbook. It works great.
Thanks but no thanks. I work with G4's and G5's at the studio and I don't find OSX all that stable.
30yroldpig
View Public Profile
Visit 30yroldpig's homepage!
Find all posts by 30yroldpig
«
Previous Thread
|
Next Thread
»
Thread Tools
Show Printable Version
Email this Page
Display Modes
Linear Mode
Switch to Hybrid Mode
Switch to Threaded Mode
Show/Hide
Posting Rules
You
may not
post new threads
You
may not
post replies
You
may not
post attachments
You
may not
edit your posts
BB code
is
On
Smilies
are
On
[IMG]
code is
On
HTML code is
Off
Show/Hide
Similar Threads
Thread
Thread Starter
Forum
Replies
Last Post
Jemsite Hacked?
caprile
Forum Announcements and Member Help
6
04-02-2005
03:43 PM
Sitemap:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
All times are GMT -4. The time now is
12:44 PM
.
-- Default Style
---- Mobile Default
-- Mobile Alabama
Contact Us
-
Jemsite.com: Ibanez JEM/UV guitars & more
-
Archive
-
Privacy Statement
-
Top
Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
(c) jemsite.com