Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Hacked at home

Thread Tools
 
Search this Thread
 
Old 04 January 2006, 11:32 AM
  #1  
MattW
Scooby Regular
Thread Starter
 
MattW's Avatar
 
Join Date: Jun 2001
Posts: 8,021
Likes: 0
Received 0 Likes on 0 Posts
Default Hacked at home

Mate of mine has been hacked, hotmail account password changed and poker account emptied. Following ips possibly responsible, can anyone trace and provide more info than standard whois search.

86.137.180.26
86.137.179.24
Old 04 January 2006, 01:06 PM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

I'm pretty sure those are BT addresses. Have you contacted the police?
Old 04 January 2006, 01:08 PM
  #3  
Scooby-Doo
Scooby Regular
 
Scooby-Doo's Avatar
 
Join Date: Oct 2001
Location: X5 and MCS JCW country....London :)
Posts: 2,223
Likes: 0
Received 0 Likes on 0 Posts
Default

www.showmyip.com shows it as a BT IP address which is kind of good that its not columbia or such like.

Contact the police and let them take it up with BT.
Old 04 January 2006, 05:03 PM
  #4  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

TBH I think it's very unlikely that the source of the attack was actually the owner of the PC located at that IP at the times located in your logs.

It's extremely likely that the attacker was relaying off that PC (or indeed through several PC's) to launch the attack making it very difficult (of not impossible) to trace.

Hopefully your friend didn't lose too much money and his e-mails being taken over wasn't too much of an inconvienience.

You could report it to the police but TBH I wouldn't hold your breath.

Buy a new hard drive, remove the old one (incase the old bill need it), reinstall, Patch, anti-virus, firewall and away you go.

Sorry to be the bringer of bad news, but chalk it up to experience and move on.

/edit

If it were me who was hacked, I'd also:

Cancle any credit / debit card used online

Advise my bank(s) and suspend any on-line activity.

(on the new PC) change all passwords on any websites where I've registered that I care about.

Last edited by BlkKnight; 04 January 2006 at 05:15 PM.
Old 04 January 2006, 07:42 PM
  #5  
MattW
Scooby Regular
Thread Starter
 
MattW's Avatar
 
Join Date: Jun 2001
Posts: 8,021
Likes: 0
Received 0 Likes on 0 Posts
Default

Cheers Guys, friend has read replies and i'm round there tonight to install Hardware Firewall, update Virus protection etc.

FYI Betfair is where most of the money was taken, they have used a CC without matching the 3 digit security code and basically told him to go swivel.
Old 04 January 2006, 09:51 PM
  #6  
swaussie
Scooby Regular
 
swaussie's Avatar
 
Join Date: Jun 2002
Location: Switzerland
Posts: 643
Likes: 0
Received 0 Likes on 0 Posts
Default

That really sucks but I wonder if he was hacked or has had his traffic monitored? Was their any obvious signs of a break in (logs etc). I would highly advise him (and anyone else for that matter) to use secure login (https) where ever possible and if you are going to give out credit card info on the net make sure you are using a secure connection before you send any data. It may have happened that someone was scanning his traffic and if it wasnt being sent encrypted, then its a very easy crime to commit.

Oh and just to stay on my high horse I would also advise everyone to have a seperate password for internet usage to what you have as your logon password

Last edited by swaussie; 04 January 2006 at 09:53 PM.
Old 05 January 2006, 10:28 AM
  #7  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

i'm round there tonight to install Hardware Firewall, update Virus protection etc.
This is not good enough i'm afraid

You need to FORMAT & REINSTALL from scratch.

You have no idea what obsucre backdoors & trojans the attacker has put on (bespoke stuff that A/V software won't pick up).

I'm sure everyone else will agree with me to.

I know it's a PITA - but it's the best long term option.

Trending Topics

Old 05 January 2006, 11:11 AM
  #8  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by BlkKnight
You need to FORMAT & REINSTALL from scratch.
I'd chuck the disk personally.
Old 05 January 2006, 11:57 AM
  #9  
Alan C
Scooby Regular
 
Alan C's Avatar
 
Join Date: Jun 2003
Posts: 6,702
Likes: 0
Received 0 Likes on 0 Posts
Default

Not all hackers are relayers who can manipualte your pc as a Zombie. Might just be simple smash & grab.

I know it's a longshot, but I feel it's still worthwhile letting the Police know the IP's at least. If other people have done the same then BT logs could show the same user ID to other similar activity.

Throwing the Hard drive is, for me, OTT for 'normal' users, so a reformat will remove all OS / App rootkits if one is installed.

Once done, add one or all these prevention & detection measures to your Security layers..
  • AntiHook - prevention
  • RootkitRevealer from Sysinternals - detection
  • BlackLight from F-Secure - detection
Just three free RKD options to use. They're not 100% (nothing is) but it's one more step to keeping the bad guys out..
Old 05 January 2006, 12:04 PM
  #10  
Iain Young
Scooby Regular
 
Iain Young's Avatar
 
Join Date: Sep 1999
Location: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Posts: 6,956
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Alan C
Not all hackers are relayers who can manipualte your pc as a Zombie.
Very true. But there are also exceedingly talented hackers out there who can do this sort of damage. Unless you know the hacker personally, you cannot know which which category they belong in, and so I'd err on the side of caution and at the very minimum do a format and reinstall. Like Steve, I'd be tempted to bin the disc as well.
Old 05 January 2006, 12:10 PM
  #11  
Alan C
Scooby Regular
 
Alan C's Avatar
 
Join Date: Jun 2003
Posts: 6,702
Likes: 0
Received 0 Likes on 0 Posts
Default

Iain, I couldn't agree more. Plus, as I'm paid to be paranoid and cautious, I'd also err on that side and re-format as a minimum..
Old 05 January 2006, 04:27 PM
  #12  
MattW
Scooby Regular
Thread Starter
 
MattW's Avatar
 
Join Date: Jun 2001
Posts: 8,021
Likes: 0
Received 0 Likes on 0 Posts
Default

Hi Guys, I had to do a format anyway, so much crap on it I thought it safer.
Old 05 January 2006, 06:58 PM
  #13  
Iain Young
Scooby Regular
 
Iain Young's Avatar
 
Join Date: Sep 1999
Location: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Posts: 6,956
Likes: 0
Received 0 Likes on 0 Posts
Default

It's for the best
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
SilverM3
ScoobyNet General
8
24 February 2021 01:03 PM
XRS
Computer & Technology Related
18
16 October 2015 01:38 PM
BLU
Computer & Technology Related
11
02 October 2015 12:53 PM
Pro-Line Motorsport
ScoobyNet General
9
28 September 2015 09:48 PM



Quick Reply: Hacked at home



All times are GMT +1. The time now is 08:32 PM.