Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: Once is happenstance.....

  1. #11
    I know you are not using WEP, right???

    Also proximity isn't that relevant. A dedicated attacker can have something like this

    http://www.cantenna.com/
    http://www.turnpoint.net/wireless/cantennahowto.html

    or just pull up in a car

    also it helps to check if the time on your systems isn't screwed (expired cert. problem)

    was the email legit ... not one of those made look like login screens which will re-mail your auth info to the attacker
    UNIX IS user friendly, it\'s just very choosy about who it calls a friend.

  2. #12
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    I'm beginning to think I was being paranoid.... ["What YOU" everyone shouts.... ].

    I have been through my ethereal captures on both the wireless sniff and the external.... There's lots of AV updates, some Windows updates, some scans etc but there isn't anything screwy in 10 hours of capture and I haven't had a repeat of either "oddity" either.... I'll run the ethereals overnight and see what pops up.....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  3. #13
    Regal Making Handler
    Join Date
    Jun 2002
    Posts
    1,668
    Originally posted here by Tiger Shark
    I'm beginning to think I was being paranoid.... ["What YOU" everyone shouts.... ].

    I have been through my ethereal captures on both the wireless sniff and the external.... There's lots of AV updates, some Windows updates, some scans etc but there isn't anything screwy in 10 hours of capture and I haven't had a repeat of either "oddity" either.... I'll run the ethereals overnight and see what pops up.....
    Paranoia is good,

    But when one is troubleshooting, should we all go for the extreem measures first or look at the more simple?

    That is rhetorical, as it should depend on the situation
    What happens if a big asteroid hits the Earth? Judging from realistic simulations involving a sledge hammer and a common laboratory frog, we can assume it will be pretty bad. - Dave Barry

  4. #14
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Jinx:

    Yeah, I like paranoia.... I see bogey men in the clouds....

    I would be more concerned if the behaviour was repeatable.... Since it isn't then there are two options:-

    i) coincidental glitches
    ii) the "attacker" has removed his harvesting system, (possibly in preference of a better system)

    As it is I gave away "nothing" passwords to date and have not been using hese boxes for anything other than the same stuff.... I will probably use an alternative way out if I _need_ to work fr a while to see what happens.....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  5. #15
    BIOS Bomber
    Join Date
    Jul 2003
    Location
    Michigan
    Posts
    357
    your not paranoid your old. by the way, make sure to forward the logs to a non web email account. not sure what isp you use but send an email to yourself with the logs as an attachment so you can look them thoroughly over if possible. from what i have heard your from michigan too. maybe its time for some tux + gore and tiger chats because your paranoid which is ok but you leaving work email open like that, not sure how id go about telling you bad boy. you have to know by now that michigan is hot for war driving. its almost disgusting. one thing though, gore may be ok with all that windows you got there, but damn man id bring a sawed off.
    "When in doubt, use Brute Force."

    Never argue with an idiot. They'll drag you down to their level, then beat you with experience.

  6. #16
    Elite Hacker
    Join Date
    Mar 2003
    Posts
    1,407
    Where the heck have you been mandraketux?

    Good luck solving the case TS. Hopefully it's nothing. But if it is nothing, that might be bad if you're paranoid because you'll always wonder. Perhaps it would be better if you find something wrong and fix it.

  7. #17
    The Doctor Und3ertak3r's Avatar
    Join Date
    Apr 2002
    Posts
    2,744
    "coincidence occurred i was about 5 mins away from my scheduled morning shower.....
    thats the trouble with coincidence and paranoia it wont even give you a chance to scratch your balls..

    There is a saying.. "Better safe than sorry"
    "Consumer technology now exceeds the average persons ability to comprehend how to use it..give up hope of them being able to understand how it works." - Me http://www.cybercrypt.co.nr

  8. #18
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    your not paranoid your old
    Well.... Don't beat around the bush old chap.... Say what you mean...

    Undies Old Man..... I agree entirely.... <LOL>

    As to a wardriver.... I have discounted that for the following reason:-

    1. If it were a wardriver he would have had to be sat in range on both occasions. That would mean he would have to have been there at 4:30ish in the evening and again at 5:10am the next morning. I would suggest that it would be unlikely that he would be there for that long or, coincidentally, on the two times I was on unless he had been stalking me for a long time to ascertain my habits.... I haven't lived there that long and my habits have only recenly become "established".

    I have discounted this being an installed system for the following reason:-

    2. If it were an installed system to harvest passwords it would have to have either be programmed to pick up on my specific connections that require a password or it should be able to recognize the fact that I am about to submit a password, form a copy of the page on the fly, submit the results to the wrong IP address and then return me to the password submission screen of the original web site. Is that _possible_? Yes, but it would take some significant programming and a certain amount of AI to accomplish and would, undoubtedly be quite buggy thus displaying other evidence of it's existence. Furthermore, in subsequent tests of sites, (both the ones that "glitched" and some that I haven't logged in to for a while or from my home network), where I am required to submit a password the symptom is not repeatable. An installed program would continue to display the symptom on web sites that have not been previously harvested - which would be illogical since it would be sensible to _always_ function in case the user has changed their credentials.

    Conclusion: I'm paranoid!!!!

    But, I have good news.... With all the sniffing I did I found a misconfiguration that leaks DNS information to the ISP's DNS servers which _could_ be sniffable to determine that I run an AD domain within my network. This issue is being fixed in a minute or two.... Oh, and I saved a bunch of money by switching to Geico......
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •