Page 6 of 7 FirstFirst ... 4567 LastLast
Results 51 to 60 of 62

Thread: puzzled - tough security issue

  1. #51
    Member
    Join Date
    Sep 2005
    Posts
    77
    Did you say you switched ISP's?
    I am ashamed to say that yeeeears back I knew a sysadmin out of Brasil that
    didn't have the best of ethics. He tried giving me Telnet access to one of
    their mailservers in exchange for an account on a server that I ran.
    Needless to say, I don't think its benieth a weird sys admin at an ISP to pull a stunt like this.
    %42%75%75%75%75%72%70%21%00

  2. #52
    I think Eyecre8 already suggested this, but check out your friend's system. This seems to be an important peice of the puzzle. So far it seems to be the only unchanged variable.

    Your countermeasures, such as chaning ISPs, countries while obtaining a NEW laptop would thwart most hackers. You'd think someone with this "ability" or persistence would embark on larger endeavors than making you life hell. Not that you're not imprtant

    Back to what I was saying... It seems like her machine is the only constant and could very well be the hub for your troubles.

    Let us know about this.

  3. #53
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Wrong track guys......

    I thought about that too but that would require the target of the abuse to have the cooperation of any other female he has written to.

    If it is her monitoring his machine, (and I'm not counting that out entirely - he says it hasn't been physically compromised but, then again, he probably hasn't thought about the victim being the perpetrator - a situation where I spent 8 hours of a perfectly good night being interrogated by military CID once.... fun, fun, fun..... ), then the Glenn Close comment is right up the correct alley....

    Run Awaaaaaay....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  4. #54
    I'll go with the Boot CD idea too. I've tried Knoppix though and I didn't like it that much - I've got Mandriva Move coming in the post (yeah, I paid for it rather that download it, I'm like that!) which does a similar sort of thing.

    Some thoughts.

    The router - well, I don't know Linksys routers very well or their capabiltiies, but it is possible that the router has a logging function (my Netgear one has a limited logging function) and that remote management for the router has been enabled. With remote management, the hacker could basically open up any port they want remotely - they could have gained remote management through a previous successful intrusion.

    Wireless - maybe you don't use it but can you confirm that it has NO wireless or the wireless is defintely turned off.

    A question - on the email messages, does it seem that the hacker can read the whole email or just the message title? If they're just reading the message title, then maybe they have some sort of logging function enabled rather than a full compromise.

    Check your proxy and autoconfig settings in IE. Make sure that you're not using a strange, alien proxy that you don't recognise.

    Check your HOSTS file - now I personally have lots of entries in my HOSTS file but most normal people should have something like:

    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    ..blah blah blah..
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost
    Any other entries in the HOSTS file are highly suspect.

    As for TEMPEST - well, it's a way of snooping on electromagnetic radiation from computers. CRT monitors are the worst for leaking EM radiation. Laptops leak a lot less and are much harder to do a TEMPEST attack on. A patient amateur could probably do a TEMPEST snoop on a CRT, a laptop would probably require the CIA! It's unlikely though, but the whole scenario is a bit unlikely.

    Finally, and most disturbingly, the hacker could have access to your ISP logs. They could even work for your ISP. There's a limited amount you can do in these circumstances, but if your PC is clean (especially if you boot from Knoppix or Mandriva), your firewall is clean and there are no physical devices on the computer, then it could be a possibility.

    Another hint - use an external proxy service for your web browsing. I use Megaproxy. That should create a secure layer that will be very difficult to snoop on if your router or ISP is compromised.

  5. #55
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    So.... Where'd the OP go?????

    Hello.... Ropester.... You out there?
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  6. #56
    The ******* Shadow dalek's Avatar
    Join Date
    Sep 2005
    Posts
    1,564
    Maybe we were a little.......late

    The Glenn Close thing might be right on the mark!!!!
    PC Registered user # 2,336,789,457...

    "When the water reaches the upper level, follow the rats."
    Claude Swanson

  7. #57
    Senior Member
    Join Date
    Nov 2005
    Posts
    115
    ropester: Do you sit on your computer by a window? Maybe they are using a high powered telescope to record your every action and keystroke and hence compromising any accounts or other systems you use...

    *shrugs* well I thought it was funny...

  8. #58
    Member
    Join Date
    Sep 2005
    Posts
    77
    Originally posted here by alleyCat
    ...Maybe they are using a high powered telescope to record your every action and keystroke and hence compromising any accounts or other systems you use...
    Heheh.. just watched the movie SNEAKERS the other day. They acquired a guy's login/pass by filming his from a distance and watching his fingers and what keys they pressed

    Heheh... maybe our boy here is in deeper than he thinks! There something you aren't telling us? Are you on the receiving end of a 3 letter agency?
    %42%75%75%75%75%72%70%21%00

  9. #59
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Too late.... Glenn got him....

    Or he realized he messed up....

    I vote for the latter...

    But he might have realized that he was posting here from the spyed on box - and he realized that it might not be the best idea.....

    [EDIT]

    He was last here at about 2:25 am yesterday.... Daleks post scared him away.... <LOL>

    [/EDIT]
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  10. #60
    Senior Member
    Join Date
    Sep 2005
    Posts
    221
    Seems I'm reviving dead threads here, but I am kinda curious about what's happening to ropester nowadays...
    Definitions: Hacker vs. Cracker
    Gentoo Linux user, which probably says a lot about me..
    AGA member 14460 || KGS : Trevoke and games archived

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •