Reply to topic  [ 10 posts ] 
Er WTF...hax0rz issues 
Author Message
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
OK, here's the scenario.

A friend of mine has fallen out with his girlfriend. She has a friend who's fairly techy, but not really more so than most.

Anyway, his girlfriend has been able to re-produce his MSN conversations and what websites he has visited. She says her friend (who lives in Oz) is getting the info. My friend runs Kaspersky Internet Security (although he has previously run Avira free edition in addition to Zonealarm) on Windows XP SP3. Now, a virus scan turns up nada. Spybot et al turn up nada.

How is he/she doing this? :?

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Tue Aug 11, 2009 11:42 am
Profile
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
Manual searching over logmein or msn remote assist?

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Tue Aug 11, 2009 11:52 am
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
He definitely doesn't have logmein installed. Remote assistance is a possibility, but I don't think he's stupid enough to just accept a request.

I'm thinking possibly malware/rootkit distributed via MSN?

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Tue Aug 11, 2009 11:55 am
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:36 pm
Posts: 5150
Location: /dev/tty0
Reply with quote
Does MSN log conversations to the server? If so has he changed his MSN password recently?

Does he have a Google account? If so does that log his search history? Has he changed that password recently?


Tue Aug 11, 2009 12:08 pm
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
forquare1 wrote:
Does MSN log conversations to the server? If so has he changed his MSN password recently?

Does he have a Google account? If so does that log his search history? Has he changed that password recently?


His password for both is fairly complex, although you've just raised a good point - I'm not sure how easy his secret questions are to guess, especially for someone as close as his girlfriend.

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Tue Aug 11, 2009 12:13 pm
Profile
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
If she's got access to his machine she can get the logs easily

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Tue Aug 11, 2009 1:16 pm
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
saspro wrote:
If she's got access to his machine she can get the logs easily


What's the best course of action then?

So far we've wiped the machine (boot and nuke ftw!) and re-installed Windows (despite my insistence of using Linux). We've got Kaspersky et al up and running. He's now going to change passwords and secret answers to his account.

Is there anything else we should be doing?

EDIT: I should also make clear that any access to his machine would only be possible remotely. I don't think she'll be remaining his girlfriend anymore either. :|

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Tue Aug 11, 2009 1:20 pm
Profile
Spends far too much time on here
User avatar

Joined: Thu Apr 23, 2009 11:36 pm
Posts: 3527
Location: Portsmouth
Reply with quote
Have you nailed down the firewall on the router? Have you also left the modem off for a few hours so he gets a new IP?

That should help to shake off the guy in Oz, if it is actually him who is somehow getting the info.

He hasn't done something monumentally stupid like leave default access codes for the router and set it to accept connections from the internet? The guy could have got in that way if he has.

_________________
Image


Wed Aug 12, 2009 10:39 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
Nick wrote:
Have you nailed down the firewall on the router? Have you also left the modem off for a few hours so he gets a new IP?

That should help to shake off the guy in Oz, if it is actually him who is somehow getting the info.

He hasn't done something monumentally stupid like leave default access codes for the router and set it to accept connections from the internet? The guy could have got in that way if he has.


Er, it's a BT Home Hub so I have no idea, it doesn't let you keep the defaults though.

Thanks for the firewall/turning router off tip, I'll pass it on.

As it happens, she's now ex-gf, so hopefully that's problem solved. :lol:

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Wed Aug 12, 2009 10:44 pm
Profile
Occasionally has a life

Joined: Fri Apr 24, 2009 4:56 pm
Posts: 306
Reply with quote
Well the msn conversations.. do you mean ALL of them with everyone?

Or just ones with her (in which case they would be saved on her hard drive, as MSN gives the option to save all conversations you have).

Also... you sure it wasnt just a cookie that is tracking her website visiting.. could be transmitted easily enough...


Wed Aug 19, 2009 12:09 am
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 10 posts ] 

Who is online

Users browsing this forum: No registered users and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.