Domain attacked

furnic

Expert Member
Joined
Oct 15, 2006
Messages
1,033
Reaction score
0
One of my domains that I run a web store from appears to have been attacked since yesterday afternoon. I suddenly started receiving a ton of returned emails like the domain is being used for mass mailings.
I then had issues logging into my site and have since found some coding errors which I am busy sorting out (or trying to), also after looking I found that the DSL usage on my account spikes certain days by at least a third extra, about 30mbs extra on certain days. I also couldn't get into my ADSL router via the standard password, so I had to reset everything to factory default.
I also found on my PC a network connection to unisa of all places? where did that come from?
So what can I do - re my telkom account I contacted Telkom to change passwords, I have also chaged the admin password on the router, which ok, my fault, that should have been done from day one. Telkom are now also going to send me my daily usage figures via email.
I have contacted my hosting company and busy changing all the login passwords for my various domains and I am busy slowly formatting my PC's because the telkom dude said I may have spyware or other issues on my side.
I had basic antivirus but it would mainly pick up viruses If I did an actual scan but it wouldn't stop the viruses from penetrating the PC - and it keeps on finding various trojans and worms, so I thought it best to just format the PC's.
So anyhow is my domain lost? can I prevent it from being used for mass mailings and could someone have hacked into my router or Adsl account?
Man oh man, I have so much work to do now trying to format and salvage stuff :mad::mad:
 
Sounds like somebody managed to hack into your PC and used it as phishing site/spam site.

Best to format and reinstall tho.

Yes, they can hack into your router if it's not properly secured, and sniff your adsl username/password for exploitation.

My suggestion : put a proper dedicated firewall (Smoothwall, IPCop etc) put up strong passwords, block SMTP outgoing (if SMTP is not neccessary) and the hackers' life will be more difficult.

Did you had VNC/Remote Desktop enabled?

Should you require remote access to this PC, better look at a VPN solution instead of opening a VNC port to the Internet...
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X