Bandwidth theft - procedure and contacts to solve

Yesterday 350 MB of bandwidth were stolen from my MWEB account within 2 hours of purchasing a new Gig. What must I do?
 
Theft of bandwidth

A while back I posted this on Pcformat..

PHP:
I did something the past two days , I scanned remote IP's, for open ports - came to some router login screens - strangely enough out of the 250 open ports - I found people with the standard usernames and passwords still on their routers Rolling Eyes
I had one lady that left her
1.ID book on her FTP directory,
2.Her usernames for all her ftp directories + websites and emails +
3. Bank account numbers and pins Shocked Shocked Shocked Shocked Shocked <<THIS WAS SCARY

Boys and girls of PCF - secure your stuff, because I am just a friendly reminder of what some script kiddie can do if he needs to get his /her daily fix.
1. I vote all the security experts of PCF recommend some tips / trick to secure your stuff
2. I vote I not be banned , because I warned you Smile
This was not a "hugely complicating procedure - it was VERY easy
How secure are you ???
Just a quick Q, why the hell do people not change their standard passwords..
I literally went through a couple HUNDRED reouters with standard usernames + pw ?
PCFORMAT.co.za*
 
Just a quick Q, why the hell do people not change their standard passwords..

Because they do not have the vaguest clue about the risks and do not know how to.

I believe it should be the ISP's responsibility to check on this for new clients and to assist them to do so.
 
What to do ?

Hi too you all, i need some advice, i got a sms from Mweb telling me that i have none of my cap left, this is funny, i thought, since i'm not home not is any of my pc's on or my modem. I need help on how and what i should do ?

Kind regards
 
Most important thing to do first is to change your password (this can be done probably from your ISP's website, or you might need to call them.
Secondly - log into your router, you will need to change your standard username + password on there ASAP.
What I can recommends is to maybe post the router / modem type here so we can direct you to change some settings to block external pining to your IP, also to let the people that do ping your IP and login to it does not get your login screen for router, but rather a "not responding"
 
Because they do not have the vaguest clue about the risks and do not know how to.

I believe it should be the ISP's responsibility to check on this for new clients and to assist them to do so.

I fully agree with you, all the ISP's should warn clients about the default passwords, maybe stick a note on modem box, might help:eek:
 
The only possible security risk is that I have had to replace the modem twice, which entails returning the router to telkom and collecting a new one. this means that I couldn't access the routers to change the setting on them. since they are non functional.

Have you tried the "reset" button at the back of the router yet? It's supposed to reset everything to factory default values.
 
Has anyone got ANYWHERE in reporting bandwidth theft?
This thread gets longer and longer but I dont see any resolutions from ISP's (or the Law)
 
@ Ricard - at this moment we are left to fend for ourselves.

Shop around and select an ISP (for example Axxess) who allows you to lock your ADSL account to your ADSL line.

Stay away from TelkomISP (and other ISP's) who doesn't have this sort of security feature.
 
Most important thing to do first is to change your password (this can be done probably from your ISP's website, or you might need to call them.
Secondly - log into your router, you will need to change your standard username + password on there ASAP.
What I can recommends is to maybe post the router / modem type here so we can direct you to change some settings to block external pining to your IP, also to let the people that do ping your IP and login to it does not get your login screen for router, but rather a "not responding"
Anthro.... how do i prohibit ppl from pinging my IP ?
 
Anthro.... how do i prohibit ppl from pinging my IP ?

You can't stop someone pinging you but if you turn off all ICMP responses on your firewall, you will not respond to their pings.

Alternatively, get your chainsaw, locate the source of the pings ( Russia, Indonesia, next-door ) and go carve them into a bloody mess. ;)
 
Most modern firewall distros also have the feature to disable ICMP pings.

Use it.

I've disabled mine, so they can ping my firewall for all they want, they won't get one ping back from it. :D

Further, if your firewall allows it, tells it to drop malformed packets, and not to reject it. Reject means it sends an response back to the attacker. Dropping it means that no response is sent back. I've set mine to drop any offending packets. :D

Will play with Snort and see if I can get it to drop all malformed stuff, and allow only the good stuff in :D

Saves a few k of bandwidth... :D
 
1) they should make local bandwidth cheaper. I think R130 for 30 gig local is good, if they made intl. cheaper, the need for people to steal bandwidth is reduced.
2)the manufacters of the routers and the ISP's (as mentioned before) should step up the security on the routers and have a standard to change the default password on first install.
3)people need to be made aware of the risks of hackers/crackers. The more people protect themselves, the harder it is to try, so many wont bother.

k
 
someone showed me how its done, to scan ip addresses for port 80 and 21. if the routers have default passwords, then its easy to steal the accounts.
i know it works, so i know how to protect myself from it happening to me and my friends and family. knowledge is power.
 
yes, even then.
these guys stealing accounts are doing so because its piss easy to scan for routers open ports and access them via the default password.
other ways are possible (hacking into the pc) but its much harder and time consuming.
 
Top
Sign up to the MyBroadband newsletter
X