Computer hacked, Please Help

SoulWinner

Commander
Joined
Apr 16, 2002
Messages
2,423
Hi everybody. My dad's cmputer had three hack attempts. My wife was working on it and discovered the attempts, I'm not sure how, but anyway, is there anyway I can backtrack and find ISP/IP address info on the machine to find who hacked it? I already know that it was my dirtbag POS nephew (my sisters "Special Little Guy.") What I want is something that I can print out to proove he did it to present to her when I deal with the little bastid. Any help?? <br /><br />His machine is a Dell, a couple of years old with the latest Windows OS. I sure do appreciate any help. I am not in a hurry to bring any of my son's hacker freinds over to look at the machine because they might hack it while their at it.
 

JB

Honorary Moderator Emeritus
Joined
Mar 25, 2001
Messages
45,907
Re: Computer hacked, Please Help

Non-boating Tech topic
 

Bob_VT

Moderator & Unofficial iBoats Historian
Staff member
Joined
May 19, 2001
Messages
26,023
Re: Computer hacked, Please Help

Get an IP trace program. http://www.tialsoft.com/ <br /><br />Increase your security first.<br /><br />Bob
 

SoulWinner

Commander
Joined
Apr 16, 2002
Messages
2,423
Re: Computer hacked, Please Help

Hey Bob, thanks for the link! The first thing we did was to install all the Norton goodies.
 

Paul Moir

Admiral
Joined
Nov 5, 2002
Messages
6,847
Re: Computer hacked, Please Help

Don't get too excited. I help run a little linux box that isn't publicly available, and we get probably 1 or 2 crack attempts each day. About 90% of them come from zombies. These are oblivious people's home computers that are infected with a "virus" or "spyware" that allows another person to control their computer without their knowlege, making it a 'zombie'. They do brute force attempts over blocks of ISP adresses. These rarely succeed - the attempt is more to find a computer that has a serious security hole.<br />Keep your updates up and don't use IE.
 

jsfinn

Lieutenant Junior Grade
Joined
Nov 26, 2003
Messages
1,093
Re: Computer hacked, Please Help

Like Paul said - attempts are really really common. Do you think there was any damage done? Do you have more detail about the attempts?
 

SpinnerBait_Nut

Honorary Moderator Emeritus
Joined
Aug 25, 2002
Messages
17,651
Re: Computer hacked, Please Help

SW, if your running XP, make sure the firewall is up to date and on and that will stop the attempts.<br />I hear all this stuff about IE and I have run IE all my computer life on 3 machines hooked on a router and on 24/7 and have never had any trouble.<br />Just my .02 worth.<br />________________________________________________<br />Here SW, from someone that knows, it's not me.<br /><br />
Well, basically you can not track it unless you installed a tool for it<br />BEFORE the incident. It doesn't build a log as default but depending on<br />the operating system, there may a log of the pc use (in Win2k rightclick<br />My Computer/Administer/Logbook), but this only logs events on the pc. It<br />tells who was logged on to the pc when a certain process was executed, but<br />if the guy in question was logged on as one of the usual users, it will<br />show nothing useful.<br /> <br />If the puter is running Win9x there is an in general very poor security<br />and no log whatsoever.<br /> <br />A firewall would have blocked all traffic not initiated from the pc.<br /> <br />There is a lot of 'parental' software around, and these provide the<br />ability to review each and every screen shown on the puter. That would<br />have been helpful in this case.<br /> <br />It also emphasizes the need for strict policies regarding computer use. If<br />this familiy did not allow the youngster to use the pc, or had a user<br />account for him top login to, in the first place it would not have<br />happened.<br /> <br />Next thing to consider is how to 'close the door' permanently on this pc<br />and to investigate what harm has really been done. A (true) hacker most<br />likely have left a backdoor open for future visits! Do we know if the<br />offended gentleman is at all capable of detecting a hacking or is it<br />merely a first shot at something, on the pc, he doesn't know what is (he<br />talks about 'attempts'?) More than often users shout VIRUS at any event -<br />even selfmade ones!<br /> <br />My suggestion is to get an up-to-date operating system as security is<br />hugely improved in the latest versions. By reformatting the harddrive and<br />setting it up all from scratch, any hacking stuff will be removed.<br />Use a firewall. Either the built-in (XP) or Zonealarm. Set it up before<br />the first Internet connection (set the pc up without even a network/modem<br />cable connected as setup procedures like to make the first<br />internetconnection as part of the install).<br />Set up user accounts for each user, with user names and passwords and<br />restricted rights, to be managed by the house master only.<br /> <br />These tasks should be made no matter what the future use is going to be.<br /> <br />If he likes, set up a parental control software (mind you, it can log his<br />own use as well!!).<br /> <br />Ultimately, set up an old pc for guests' internet browsing. Isolate it<br />from the family pc (logically or by DMZ on the router). This way they can<br />browse it to death, get attacked, be infected or whatever. By Ghosting the<br />fresh pc it can be restored in ~20 minutes. This task makes the former<br />setup important as being sent to an old pc will make the primay computer<br />very interesting to the youngster and the lack of an account to login to<br />becomes a major security point. User accounts in Win2k & XP are extremely<br />safe and unless the user chose a too easy password, he is definately<br />locked out.<br />
 

SoulWinner

Commander
Joined
Apr 16, 2002
Messages
2,423
Re: Computer hacked, Please Help

Thanks guys. Lester, that was a good and thorough message. Dee is handling this. She installed all the security goodies as well as a program that will log any attempts to hack the machine and give all kinds of info about the hackers ISP/IP and geographic location. I just know it was my nephew. He is real POS.
 

Ralph 123

Captain
Joined
Jun 24, 2003
Messages
3,983
Re: Computer hacked, Please Help

SW, unless your nephew is a GOOD computer hack, the odds are slim it was him. He'd have to know what the IP address was and hope it had not changed since the last time he determined it. Or installed a Trojan on the machine at some point. Very few ISPs issue static (non changing) IPs. One big reason is they don't want customers setting up web servers w/o paying a premium for a static IP.<br /><br />Hackers typically scan every IP for every known ISP every day. They know the range of address issued for the ISPs (it's public) and they scan one after the other looking for vulnerabilities. When I had an Earthlink DSL line I'd have dozens of attempts each day. My firewall logged the hacker's IPs and I used to report them all the time until it became such a PIA I just stopped. Most of the hacker IPs were coming out of eastern Europe or Asia.<br /><br />Look through the help file in your firewall software and find out if it logs the IP addresses of the attacks. Often you have to turn on logging. Then you can run a "whois" to find out who owns the IP and you can report them.
 

Twidget

Commander
Joined
Jun 16, 2004
Messages
2,192
Re: Computer hacked, Please Help

SBN, Im not so sure about the XP firewall. Gibson research has a leak test and 'shields up' test that get past my stock XP Pro firewall.<br /><br />I use a Linksys router and get invisible results from them. Still have the firewall activated, I just dont really trust it.
 

SpinnerBait_Nut

Honorary Moderator Emeritus
Joined
Aug 25, 2002
Messages
17,651
Re: Computer hacked, Please Help

Just did the test also Twidget and it could not connect because I also run a linksys router, but I also have the firewall up to date.<br /><br />Hey SW, that might be a good investment also is a Linksys router. Mine is a 3 port with a printer port too so all 3 of my computers can share the same printer.
 

SpinnerBait_Nut

Honorary Moderator Emeritus
Joined
Aug 25, 2002
Messages
17,651
Re: Computer hacked, Please Help

P.S. just did it again, and my Norton caught it before my firewall and router did.
 

Mark42

Fleet Admiral
Joined
Oct 8, 2003
Messages
9,334
Re: Computer hacked, Please Help

If it's your nephew, he may be useing the Win XP Remote Desktop or Support features that let someone access your computer legitimately from a remote location.<br /><br />My Mcafee firewall shows that someone tries to gain access to my PC about once every 10 minutes. The ISP trace shows they often come from China or middle east or that huge black hole of humanity: Newark, New Jersey.
 

SoulWinner

Commander
Joined
Apr 16, 2002
Messages
2,423
Re: Computer hacked, Please Help

Thanks for info guys. You guys know a whole lot about computer stuff, and I unfortunately do not. The reason I think it was my nephew is that he has been a hacker for years, and on a few occasions has had access to my dad's computer. Also, the hack attempt correspond with times when my dad went to ebay and it acknowledged him as being my nephew. Don't know anything yet, but we are gonna do the router thing in addition to the other security steps we have taken. Thanks again for your help.
 

Mark42

Fleet Admiral
Joined
Oct 8, 2003
Messages
9,334
Re: Computer hacked, Please Help

hack attempt correspond with times when my dad went to ebay and it acknowledged him as being my nephew.
Sounds a lot like remote access to me!
 

CATransplant

Admiral
Joined
Feb 26, 2005
Messages
6,319
Re: Computer hacked, Please Help

Well, if you're sure it's your nephew, a little private conversation with him might go a long way toward keeping him from doing it again. You know the words.
 

Scoop

Lieutenant Junior Grade
Joined
Jul 19, 2002
Messages
1,158
Re: Computer hacked, Please Help

SW, it sounds like it was your Nephew to me. He is not the best hack out there since he logged into Ebay from your machine and did not clear the cookie which would have taken an experienced (or even inexperienced) person 10 seconds.<br /><br />I would do a couple things.<br />Don't make it too complicated, but protect yourself. There is a lot of good information here. My advice, (although since I have been in management I have lost a lot of tech knowledge.)<br /><br />1. If your do not run Windows, then make sure it is Win2K or XP. If not, dump your old operating system and upgrade.<br />2. Patch system with operating system patches and virus scan/Firewall patches<br />3. Look at all your user accounts. Delete the ones that are not used and change any open account password<br />4. Make sure your main account is an adminstrator account so you can access and change the admin password. <br />5. Change the Admin password, reboot and login under the true administrator account to make sure you can.<br />6. Change your main account password<br /><br />This does not eliminate any backdoors he may have put on the machine, but if he just guessed a password, this should take care of it.<br /><br />7. Clear all cache and cookies on internet Explorer <br /><br />8. Create a "Guest" account (can be named anything) with no rights to install software, etc. That should be the only account he can use. <br />9. After he is done or has been near the computer go in as the main account and look at recent docs folder, check IE history for all accounts and cookies. If you have succesfully removed his access, then only the guest account will have new information.<br /><br />10. Secure externally. Linksys router with Firewall is a must (other kinds are good too, make sure it is quality). It is very secure out of the box, but make sure firewall is turned on. This will eliminate most Zombies hitting your machine as a matter of course. Will not eliminate someone trying your IP directly, but they will not get through unless they already have software installed on your machine or you click on something to install their software on your machine.<br /><br />I run Dual Firewalls, but it is not necessary to be redundant, but it also prtects me if my son's computer on my home network gets a virus etc.<br /><br />11. Set your Virus scan to auto update unless you are on dialup. Mine updates every 12 hours<br />12. Set your virus scan to scan your machine periodically. Mine does a full scan weekly. It is also set up to scan all incoming and outgoing emails and attachments even if they are many many layers deep.<br />13. Download a couple Spyware scanners. Spybot: Search and Destroy and Adaware are free for home use and work fairly well and scan yur machine with them ona schedule, Mae sur eyou click the update before the scan.<br />14. Have Windows Auto-update your machine or set a schedule to do this yourself, but don't be lax.<br />15. If you have to surf sites, that you are not sure of their safety, Use Firefox browser. At least for the time being it is a little safer than IE, but this will not continue in the future as the install base gets bigger so it is more worthwhile for hackers to hack it.<br /><br />I run Windows XP Professional SP2, IE 6.0, Firefox, Trend Micro internet suite with firewall enabled and have a Linksys firewall with wireless which has WEP 128bit enabled.<br /><br />I have used Zonealarm to check for programs that may try to access the net, but do not regularly run it.<br /><br />When I went to the Linksys router, from the one that came with my broadband, that eliminated the Zombie hits that were coming at 2 an hour.
 

Xcusme

Commander
Joined
Apr 21, 2003
Messages
2,888
Re: Computer hacked, Please Help

Lots of good info, but one more step can help to secure the user accounts. Password protect the bios of the machine. A bootup password will stop most users. If your nephew can boot the machine, he can boot a utility CD and reset,clear or change the user account passwords in Xp and Win2K.
 

Scoop

Lieutenant Junior Grade
Joined
Jul 19, 2002
Messages
1,158
Re: Computer hacked, Please Help

Xcuse, Your absolutely right. I have one of those CD's running Linux. Don't use it, but it was given to me to show me that it was possible.
 

Xcusme

Commander
Joined
Apr 21, 2003
Messages
2,888
Re: Computer hacked, Please Help

Yup...that's the one....(there are others too!)
 
Top