Telkom account being hijacked ?

fading_fast

Member
Joined
Mar 11, 2005
Messages
13
Reaction score
0
Location
Somewhere in the Cape
Hi,

The place I work for has 3 lines and 3 accounts. All with Telkom. 2 of these are being actively used. 1 of these is not even plugged into a modem/router. It's been like that for almost a month.

On Wednesday we found that someone/something did 200+ MB of traffic on an account that we don't use. The for that account is dangling in mid-air in our cabinet. 300MB in total for 2 days was used.

I think that perhaps someone has 'stolen/borrowed' our login details.

Has this happened to anyone else before ?

Thanks.
 
It happens to us quite a bit, we resell account and have about 100 accounts awalys sitting idle incase of a sale, we have implemented a policy of changing password weekely.
 
I have seen a bunch of ADSL forum threads mentioned this - effectively theft of bandwidth on capped ADSL ISP accounts, there was mention that Telkomonopoly employees see your usename & password on their screens in cleartext, and speculation that they are the primary culprits. I don't know if that's true, but I had already decided that if I endup going the ADSL route, I will be changing my password as often as possible - I don't know how effective that will be though if Telkomonopoly can see exactly what I have changed it to.
 
fading_fast said:
I'm so glad I chose MWEB for my personal ADSL account I use at home. That extra R59 is worth it :)
I have been wondering about this - if MWEB & other ISPs are merely resellers of ADSL ISP accounts, then Telkomonopoly would still be able to see the username & password for the account that they resell to you, correct...?
 
My understanding is that the Telkom equipment proxies the authentication request to mweb which replies with either a yes or a no.

...then again, I know very little of ADSL in SA, so I'm probably wrong. I've been living a life sheltered by diginet and ISDN :)
 
Changing the password often definitly helps, my account was hijacked 3 months in a row, i then changed the passwords very regularly after that and have had no sketchy business since then(2 months later)

I complained to Telkom about the problem; i was then told to email abuse@telkom and they would sort it, LOL, ha, no such luck....
 
I just phoned Telkom to get our password changed and the guy read back the current password to me without even trying to find out who I was. No wonder accounts are getting hijacked.
 
Very secure by the sounds of it.. aai..

Welkom by Teldom.
 
Same thing happened to a few of my clients, traced it to the telkom router which still had the default password and WAN http access enabled (by default). Someone must have found port 80 open on the current IP, logged in using the default username / pass to the router and ripped the ADSL account's details from the router. Changed the admin password for the router & turned off WAN side admin access to the router, never had it hijacked since!

btw, the new telkom routers all come by default with WAN side admin access disabled. At least they did something about the problem.

B.
 
Happened to me this month. How oh how did i download 9 gigs in a day???

May also be a worm... :(
 
Happened to me this weekend. User stats clearly show that there are two sessions logged in concurrently. One my normal light use, the other almost three gigs in a couple of hours.

Can't Saix see which ADSL line is being logged in with? simple matter then to identify the culprit and lay criminal charges (fraud)??

Oh yeah, as to my router, WAN side access is disabled and I have an alphanumeric password. So it's not that.
 
Last edited:
Yes they could, but do you think they would.

Change your password, and make sure that you do not have snmp enabled.
 
Not without a court order.

Maybe worth looking at though.

I'm pissed off enough to spend a couple of grand hunting the little weasle down.
 
Top
Sign up to the MyBroadband newsletter
X