Help:Unauthorised User on My Internet account

Thanks, Router password changed, account password changed and wireless key changed. Hopefully all will be OK for a while. Have had to purchase extra cap but we live an learn. To all who helped many thanks :)
 
I had same problem

Have now implemented IPCOP (Linux Distribution) with "Router" switched to Bridged mode
Authentification on IPCOP Firewall.
 
Can your account be hacked if your account info is not stored on the router.. I assume it can be but with more difficulty?
 
I Must say that MWEB technical were very helpfull, many phonecalls from them and assistance. Only problem is price and fact that I will probably not get my stolen bandwidth back but a very helpfull bunch. Can recommend them!
 
I Must say that MWEB technical were very helpfull, many phonecalls from them and assistance. Only problem is price and fact that I will probably not get my stolen bandwidth back but a very helpfull bunch. Can recommend them!

That is exactly the reason why I have gone this route.

Hacker would have to hack two hardware devices.

The Router/Bridge Logon.
Then the ISP Account details on the Linux Firewall.

My Reasoning is that you will never STOP a determined Hacker, just make it more difficult for him/her
 
One of my accounts this month uploaded 1.9gigs, there is apparently one of those anoyying trojans again. I made my friend that uses it format his pc!
 
Can your account be hacked if your account info is not stored on the router.. I assume it can be but with more difficulty?

It can, especially if you use a virtual firewall. A hardware, or dedicated, firewall will make things more difficult for them.

A Linux distro aimed specifically at firewalling, such as Smoothwall or IPCop has no extra bells and whistles, it is a distro aimed at being a dedicated firewall.

Refer to this thread.

Regards

Libs
 
I Checked with MWEB and they provided detailed records that indicate my account was accessed from two separate telephone lines so don't think its a trojan. All PCs scanned and malware tested all firewalls on and router firewall on :)
 
I Checked with MWEB and they provided detailed records that indicate my account was accessed from two separate telephone lines so don't think its a trojan. All PCs scanned and malware tested all firewalls on and router firewall on :)

Will you be opening a case of fraud and theft with the police? Or what will you do now?
 
When trying to fix issues like this it's best to disconnect from the Internet completely and do the anti virus and password changes offline.
If there is a key logger installed on your PC and you're connected to the Internet it can just send your new passwords to someone every time you update them.

Isolate, repair and then reconnect.
Or just dump Windows if you can and use something that doesn't collect every bit of trash off Internet.
 
Ive just had my account details hijacked aswell of late. (8GB stolen) What i did was phone the ISP and have them lock our ADSl account onto our NASPORT ID, so that it can only be used from our adsl telephone line.

Also obtain the ID that the person accessed it from, then open a case with the Police under FRAUD and give them this information. They will then supina(sp) SAIX for the person that access ur account, and then you can lay charges.
 
Yes, Thanks for Info. I need to have access when I'm away from home and the kids need access as well, so unfortunately I cannot lock down to one line. I have taken the other precautions as well. Have also put the kids 2 PCs onto auto schedule for Virus Scanner and Spyware. I now keep careful tabs on account.
 
Ah rgr, Im not to fond of PPPoE tbh its to prone to password hijacking comppared to PPPoA where you can only use it from a prefixed line.
 
Hi, I discovered when I checked my user stats both with SASA and with my ISP that some one had been using my account downloaded 935 mb between 11 and 12 this morning (Sat 16 sep). I have subsequently changed my passsword on the account, on my ADSL modem and rebooted modem as well. I also ran a virus scan on all PCs connected to modem. I found one with a Trojan Horse virus which has been deleted. Are there any other precautions or actions I should take. I have the firewall activated on modem and all PCs are running software firewalls.
Thank you

No Use in changing the Passwords if you have employees. This is the root problem of your cause. You have someone that has a few cells more than you thought.

Best would be to add an admin Password to all pc's on your server. Wouldn't keep the smart employee out for to long but trace his/her IP would be a good idea, him/her will try and crack the password from his/her work station

The employee checks the password or uses a Trojan to get hold of the password. and log-on remotely. Easy as Pie. I only need to be @ your office for 8 hours and i'll be able to do the same.

It would probably be best to start there.....
 
Thanks for replies.
1. I have only had one unauthorised access, I change passwords monthly.
2. I use wiresless but it iis secured access using WPA
3. I have 2 other PCs connected to router used by my kids software firewalls in place Windows and Zone Alarm. They are prevented from accessing certain sites via firewall and router.
3. Passwords are not written or kept in lists on PC. Written down in my organiser in locked briefcase.

Seeing that it's wireless also outside your building on the side-walk. wipe out any strange marking on the pavement, looks like you could have some midnight surfers....:rolleyes:
 
"downloaded 935 mb between 11 and 12 this morning" hmmmmm

That must be a "upto 4mbit" user that got yur pass/login. Since 512K adsl can only get around 160mb - 180mbper hour. at max.

If your using IS, u can even see on the usage website, wich area that login was made from. (it says Durbanville 2, or Parow 3)
*nice to see, cause maybe one of your buddies zife'd your account when coming for a quick visit*

I'm not sure if Saix Usage website shows similar stats

Another midnight surfer.....:rolleyes:
 
Top
Sign up to the MyBroadband newsletter
X