SAIX-based accounts compromised?

titanium

Well-Known Member
Joined
Jun 13, 2005
Messages
278
Reaction score
1
According to the Telkom userstats, I've transferred more data than my ADSL router has recorded. For example, yesterday it showed that I had transferred 648 Mb, but I had nothing running on my machine (already checked for viruses/spyware/etc), didn't have any P2P or bittorrent apps running and was out of the office all day. Therefore it can only mean that my account has been compromised AGAIN. I'm starting to wonder if it's someone who has access to the Axxess authentication database.

I have already changed my password several times before, using a combination of numbers and letters, and this doesn't seem to have solved the issue. It is frustrating because this is eating away at my cap. The only way I can track this down is to find out from Telkom the IP address associated with my user accounts, eliminate the IP addresses that were assigned to me, then take a LART to the luser stealing my account.

Has anyone had similar problems?
 
I can't speak for Axxess, but I know that we can track the DSLAM port that has been using a specific username - ask them to give you a report on that.

---
Pedantic
www.saol.com
 
Thanks Pedantic - have mailed Axxess asking for a report on DSLAM ports associated with my username.
 
Out of interest, what would the potential effect of the latest virus outbreak (or any virus activity at all) be for ADSL bandwidth utilisation? Even if your machine and network is safe, is it possible for the virus to use up your bandwidth purely because the path is available?

An analogy. Even though your front door is locked and barred, people can still walk up and down your driveway. Can this happen?

Juice
 
Yep, it would chew up your bandwidth. So if you're undergoing a DoS attack, unplug your ADSL router and let the upstream provider deal with it. But this is a totally separate issue from someone using your ADSL account.
 
Juice, *one* infected windows machine can nuke a 3GB cap in one day. *one* !! I've seen this many times at clients (mostly the ones who cling for dear life to Norton....

Most routers allow you to setup firewall rules. A general good practise is to setup a two rules in the following order.

1. Allow outgoing connections to port 25 to IP address of your smtp server (smtp.saix.net - 196.25.240.94 for adsl)
2. Deny all outgoing connections to port 25 to any IP address

This will prevent any virusses from mailing themselves out, should you get infected.

The same applies for other types of traffic you need to put out. Allow the things you want to do, and deny every thing else. If you use something like Kerio's personal firewall you can see what connects to where and on which ports.
 
Top
Sign up to the MyBroadband newsletter
X