Go Back   Jemsite > Off-topic & Polls > Off-topic / Miscellaneous

Off-topic / Miscellaneous Talk about miscellaneous stuff off-topic and not related to music, guitars or bands. No music, gear or anything guitar related here please.



Registered Members don't see these ads. Register now it's free!

Reply
 
Thread Tools Display Modes
  #1  
Old 04-09-2005, 03:53 PM
30yroldpig 30yroldpig is offline
 
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374  -  iTrader: (0)
Unhappy

Hacked


Well my suspicions have been confirmed, my computer's been/is hacked.

2 months ago I decided I'd install a P2P program to preview some music. I also installed a BETA version of messenger.

Last week I get my internet bill and i have 23 gigs in uploads ( only allowed 10 per month).

I figured It's cause I left the P2P app running...my fault, I'll pay. Since then I've uninstalled the software.

Today I browsed my "internet consumption update" on my ISP's web site and it said I already have 6.8 gigs in uploads....

When I type netstat -a in DOS there are other ISP's connected...

Man this bites. Looks like i'm due for a re-install.

I dunno if I got hacked through MSN Beta (also now removed) or the P2P.

Anybody else get hacked? What did you guys do?

I feel a bit violated...I also do all my banking and transfers via the net. manoman.
Registered Members don't see these ads. Register now it's free!
Reply With Quote
  #2  
Old 04-09-2005, 07:19 PM
bizkit666 bizkit666 is offline
 
Join Date: Dec 2004
Location: Manchester, England
Posts: 105  -  iTrader: (2)

Re: Hacked


dont worry you havent been hacked, a P2P (peer to peer) is a program that lets the whole world share files, and u downloading files means your sharing them, so when you download a file, it auto shares it (you can turn this off so you dont share files) so sharing files means you are letting ppl download the files that you have downloaded from you, and this is why your upload bandwith is going up!

i hope tht made sence
Reply With Quote
  #3  
Old 04-09-2005, 07:35 PM
Artist Artist is offline
 
Join Date: May 2003
Location: London, England
Posts: 795  -  iTrader: (0)

Re: Hacked


have you scanned for spyware?
Reply With Quote
  #4  
Old 04-09-2005, 08:22 PM
bammbamm bammbamm is offline
 
Join Date: Dec 2000
Location: Chicagoland, IL.
Posts: 3,944  -  iTrader: (14)
Reviews: 1

Re: Hacked


You could have EASILY picked up a trojan and are being used as a slave to send out mass emailings unbeknownst to you.
Which P2P system did you install?
2ndly, I would get a firewall installed ASAP.
3rd, run all manor of virus and spyware scanning to detect any infiltration.
Another way to find some of these is look at the running processes and look up the ones that don't look familliar to you, normally you should see 25-no more than 40-ish (with a lot of apps open) I try to keep my total processes as low as possible just so I know when something new is running on my machine. I haven't had a cirus or reinstall in 2 years since I built my machine. (with the exception of when I swapped over to a raid 0 config.)

Hope this helps.
There are also bandwidth meters to see incoming and outgoing traffic on all ports.


Bamm
Reply With Quote
  #5  
Old 04-10-2005, 12:43 AM
Ralsch Ralsch is offline
 
Join Date: Mar 2005
Location: Maryland
Posts: 116  -  iTrader: (0)

Re: Hacked


Firstly,turn off all your active x updates as that is a major cause for hacker interference if you run xp...just get a firewall running and a program called zone alarm to alert and diable people from accessing your modem. run some anti-virus program and/or ad-aware , check the path if there is a problem and check it manually in your registry , if worse comes to worse just disable file sharing and reformat/defrag. . Like bam said you normally have a tagged section showing bandwith traffic and try to check whats running at startup. hope that helps
Reply With Quote
  #6  
Old 04-10-2005, 12:49 AM
microdmitry microdmitry is offline
 
Join Date: Sep 2002
Location: Bellevue, WA
Posts: 1,687  -  iTrader: (4)

Re: Hacked


1. Enable a firewall. Better yet, use hardware router if you have one.
2. Run full virus and spyware scan. Microsoft scanning tool is pretty good.
3. Do not use P2P clients that are not written in Java, .NET languages (C#, VB.Net, Managed C++) or other language that is fully protected against buffer overflows.

I'm actually surprised nobody actively targets P2P clients like emule, edonkey, gnutella, etc. They were written by hobbyists, they expose ports to the web, and they most likely have more holes than Swiss cheese. Best of all, source code is often available, so you don't have to guess.

Look for a client written in Java or for Microsoft .NET platform. This automatically prevents a whole bunch of attacks. Many attacks are simply not possible on the systems that use runtime buffer length checking. I run Azureus myself, and it works pretty darn good. Also, before installing P2P software, google on the web to make sure that stuff you install doesn't come with spyware. P2P programs often have spyware. Once you install this stuff on your machine the only safe way to remove it is to rebuild the machine.

Last edited by microdmitry; 04-10-2005 at 12:50 AM. Reason: typo
Reply With Quote
  #7  
Old 04-10-2005, 11:54 AM
30yroldpig 30yroldpig is offline
 
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374  -  iTrader: (0)

Re: Hacked


Hi guys thanks for the replies.

Firstly I've been running zonealarm since I began surfing the web. I'm using an anti-virus (AVG FREE) and everytime i finnish surfing, i run add aware SE as well as Spybot-search & destroy. I know they're only freebee wares but I can't afford new software now and I don't believe in hacked software (no pun intended)

I understand the principle of P2P apps (was running shareazaa), what I don't understand is why, when I cleared ALL my shared files associated with shareazaa, there were 6.8 gigs in uploads. That's why I suspect that I've been hacked or as Bamm said had a trojan installed.

I'll look into all those options, Bamm, I have about 30 running processes, but to be perfectly honest, I don't really know what they all mean.

Once again, many thanks guys

Cheers
Pat
Reply With Quote
  #8  
Old 04-10-2005, 12:29 PM
fettouhi fettouhi is offline
 
Join Date: Aug 2003
Location: Odense S, Denmark
Posts: 9,937  -  iTrader: (2)

Re: Hacked


Get a program called hijackthis (use google to find it) and do a scan with it. The program will list the processes you are running then post the log file here.

Regards

André
Reply With Quote
  #9  
Old 04-10-2005, 01:42 PM
Jem7RB MK Jem7RB MK is offline
 
Join Date: May 2002
Location: Milton Keynes,UK
Posts: 2,329  -  iTrader: (20)

Re: Hacked


Quote:
Originally Posted by Pat knup
Hi guys thanks for the replies.

Firstly I've been running zonealarm since I began surfing the web. I'm using an anti-virus (AVG FREE) Cheers
Pat
Pat, Have used AVG for about 6 years now, after hearing of it on #UKMG and have never had a virus issue on the freeware version ... As for the P2P stuff, I rarely use Win*x and have never suffered unduley, Nor do i get spyware scans show up anything untoward.

Hope you get sorted out bro

Rob
Reply With Quote
  #10  
Old 04-12-2005, 09:20 PM
30yroldpig 30yroldpig is offline
 
Join Date: Feb 2001
Location: Montréal, Canada
Posts: 374  -  iTrader: (0)

Re: Hacked


Rob, thanks for the encouragement, but I'll steer clear from P2P software.

So far everything seems back to normal, although I havn't really kept my system running long enough to see if there was any more activity.

André check your inbox, I've emailed you a Hijack this log.

Many thanks everyone.

Cheers
Pat
Reply With Quote
  #11  
Old 04-12-2005, 09:39 PM
Serratus Serratus is offline
 
Join Date: Jan 2004
Location: UK
Posts: 479  -  iTrader: (4)

Re: Hacked


Go to this page:

http://www.answersthatwork.com/Taskl...s/tasklist.htm

It is a list of almost all the programs that could be running in your task list (what processes are running in ctrl-alt-del) and what they do, and whether you need/want them. It's worth checking out and comparing to your tasklist every now and again to make certain you've not picked up anything nasty (in addition to all the other advice above).
Reply With Quote
Comparison Shopping
Fender Baritone Special HH Black Rosewood Fretboard

As low as $970

at 7 sellers

Jacques FB-2 Fuse Blower Distortion Pedal

As low as $130

at 5 sellers

Members with more than 50 posts don't see this bar

Warwick Red Label Stainless Wound Medium 5-String Bass Strings

As low as $21

at 3 sellers

Hal Leonard The Allman Brothers Band - The Definitive Collection for Guitar - Vo

As low as $14

at 8 sellers

Members with more than 50 posts don't see this bar

Fishman AFX Delay Guitar Effects Pedal

As low as $179

at 22 sellers

Fender Vintage Reissue '65 Deluxe Reverb Guitar Combo Amp

As low as $850

at 12 sellers

Members with more than 50 posts don't see this bar

Dean Markley 2066A PhosBronze Medium Lt Acoustic Guitar Strings

As low as $6

at 7 sellers

DiMarzio Cliplok 2-Inch Strap

As low as $16

at 4 sellers

Members with more than 50 posts don't see this bar

Korg PitchBlack Pedal Tuner

As low as $10

at 90 sellers

Hal Leonard Rock Lead Techniques Book/CD Package

As low as $8

at 7 sellers

Members with more than 50 posts don't see this bar

Everly 9113 X Rockers Lo Tune Drop C Electric Guitar Strings

As low as $6

at 3 sellers

Seagull Entourage Series Dreadnought QI Acoustic-Electric Guitar Rustic Burst

As low as $429

at 3 sellers

Members with more than 50 posts don't see this bar

Levy's 2-1/2 Leather Strap with Cross Black

As low as $22

at 3 sellers

Luna Fauna Series Dolphin Folk Cutaway Acoustic-Electric Guitar Transparent Azur

As low as $399

at 8 sellers

Members with more than 50 posts don't see this bar

Reply

 
Similar Threads

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Sitemap:1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28
All times are GMT -4. The time now is 03:30 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
(c) jemsite.com
 
close
Sign up for free and join one of the largest communities of Jem guitar lovers!
Our members will be glad to help you with anything you need!

Join over 30,000 JemSite members!

Email

Email Confirm Email
Username
Password Confirm Password

I agree to the website rules