Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Incident Response
My father is hacking me?!
EH-Net
May 25, 2013, 07:15:12 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Incident Response
(Moderator:
don
) >
My father is hacking me?!
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: My father is hacking me?! (Read 8822 times)
0 Members and 1 Guest are viewing this topic.
littleblondenerd
Newbie
Offline
Posts: 2
My father is hacking me?!
«
on:
October 09, 2010, 01:11:29 PM »
Hello everyone,
My father, a (potentially) former NSA cracker, has been hacking my laptop computer ever since I left for college this year. I do not, however, have any concrete evidence or proof. From conversations that we have had, I am 99.9% certain that he has access to my computer (he set up an SSH on my computer, which I think that I have effectively disabled, but as I know almost nothing about SSH servers and how they work, I am not sure) through who knows how many programs and backdoors. I just installed the professional trial of eEye and ran a scan which showed that I have 5 high risk, 5 medium risk, and 14 low risk security issues. Here are the descriptions of a few of these:
Microsoft Windows contains a vulnerability in the SSL and TLS protocols when renegotiating session handshakes that could allow man-in-the-middle attackers to inject arbitrary data into encrypted TLS/SSL sessions.
The current MS RAS (Remote Access Server) is not encrypting data transfers. It is recommended to encrypt all transfers between client and server.
The current MS RAS (Remote Access Server) is not logging connections. It is recommended to log all RAS connection information.
It is recommended to enforce MSCHAP V2; this forces the server to drop any VPN (Virtual Private Network) connections that do not use MSCHAP V2 authentication.
By default, users are permitted to make RAS connections without any sort of authentication. It is recommended that you require users to authenticate themselves.
ICMP Timestamp request is allowed from arbitrary hosts.
Structured Exception Handling Overwrite Protection (SEHOP) is disabled on the target system. SEHOP is a mitigation that attempts to prevent an attacker from using the Structured Exception Handler (SEH) overwrite exploitation technique.
NTFS has the ability to support backwards compatibility with older 16 bit apps. It is recommended not to use 16-bit apps on a secure server since it could allow attackers to bypass access restrictions for files with long file names.
POSIX and OS2 should not be enabled. Enabling the POSIX or OS/2 subsystem can allow a process to persist across logins.
Can anyone help, please?
Logged
ElCapitan
Newbie
Offline
Posts: 28
Unanimous FTP: the #1 threat to copyrights!
Re: My father is hacking me?!
«
Reply #1 on:
October 09, 2010, 02:13:29 PM »
I don't think a vulnerability scanner will help you in this instance. If he was a true "NSA cracker", it is likely the backdoor is sophisticated enough to avoid detection though common security software.
Your best bet is to wipe the disk on the laptop completely (or find someone you trust to perform this if you are unsure how to). Reinstall the operating system, update and secure it (e.g. firewall, security software, disable unnecessary services, etc.).
Then just communicate with your Dad via phone and pen/paper.
P.S. Why is the MS RAS (Remote Access Server) enabled? Do you use this functionality? It is typically not enabled by default.
P.P.S. Did he give you the laptop or at anytime have physical access to it? If that is the case, I would put it on Ebay if you are truly concerned about him "hacking" your laptop.
Logged
CISSP, Security+, CEH, OPP, et alii
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: My father is hacking me?!
«
Reply #2 on:
October 09, 2010, 03:11:13 PM »
There are a couple of solutions:
A) Buy a new harddisk and replace the old physically with the new one. Then install an operating system fully up2date. (Install a good firewall and anti-virus system too like Kaspersky, Symantec Norton 2010, or similar.)
If you're into computers, install Linux and configure it in a secure way.
B1) Your father may have installed a rootkit which does not get wiped by a regular Windows re-format. If you're not going for a new harddisk to be sure you don't got a hard2remove rootkit installed, get a "harddisk eraser" from IBAS or similar. (It's just a special magnet messing up the bits on the magnetic harddisk, in case it's not an SSD disc.)
B2) Perhaps, if there is a rootkit on your computer, a simple re-partitioning and format of the harddisk in Linux may erase everything. You can get LiveCD's in case you're not familiar with the linux console, and such a tool could be QTParted or GParted. I'm not sure how well Norton Partition Magic would work in this case.
B3) Do one of those Government Clearing of your harddisk where the data is wiped +5 times. (Depending on the method you choose, one of them will erase the data more than 30 times on your harddisk. It's a quite cool tool but I forgot the name unfortunately.)
C) Your father may have installed a rootkit in the BIOS, if so you need to replace the BIOS chip if possible. Otherwise buy a new motherboard or get a new computer. (Since it's a laptop, there isn't very much you can replace.)
Anyway, when you've done that and installed an Operating System do a FULL DISC ENCRYPTION!
Install TrueCrypt, and do a full disc encryption and set a good, long password with mixed upper and lower-case letters, numbers and symbols.
When you've done that set a password in the BIOS and make sure it is not possible to boot up on anything besides the harddisk. (Set the harddisk to be the first device in the boot order.)
Then you could set a password for booting up the computer as well.
There is however a reset jumper on most computers nowadays, which is able to reset the BIOS password. If you want to disable that functionality you need to do some hardware modifications to the motherboard in your laptop which I cannot recommend.
But if you follow most of what I wrote above, you'll be fine.
When you've installed your operating system and a firewall and an anti-viral system, don't visit websites your father suggests you
(He may be a rogue hacker too.)
Avoid using instant messaging programs except IRC.
Use HTTPS (ssl) whenever it is possible and encrypted protocols as well.
Now we're on the paranoid path, but depending on how well you want to hide everything from your father and anyone else, you're getting pretty close.
If you just want to confirm whether he's spying on you or not, do the following:
1. Set up a LAN where NAT is enabled. (A simple network with local ip-addresses, a router and another computer.)
2. Set up the second computer to log all communication from your computer to the Internet.
3. Don't use the laptop for anything but browse to a few websites you visit and then check the second computer if there's traffic that shouldn't be there.
This is NOT something that's easy, but it's fun
Good luck and have fun
PS: This reply was quite "brief" in how to do the above suggestions and these do not reflect my entire view on the possibilities on confirming whether your father has hacked your computer or not nor does it confirm how many ways there is to lock your computer down entirely. (In short, there's more to it than what I just said.)
«
Last Edit: October 09, 2010, 03:15:22 PM by MaXe
»
Logged
I'm an InterN0T'er
littleblondenerd
Newbie
Offline
Posts: 2
Re: My father is hacking me?!
«
Reply #3 on:
October 09, 2010, 04:18:10 PM »
The laptop caught a trojan last year that required completely wiping the disk - my dad spent the summer reprogramming and reinstalling everything. So, yes, he had physical access to it.
And the MS RAS is enabled because that's what he uses to debug computers or fix technical issues when he's not around.
Logged
dante
Jr. Member
Offline
Posts: 58
Re: My father is hacking me?!
«
Reply #4 on:
October 09, 2010, 06:07:24 PM »
Quote from: MaXe on October 09, 2010, 03:11:13 PM
B3) Do one of those Government Clearing of your harddisk where the data is wiped +5 times. (Depending on the method you choose, one of them will erase the data more than 30 times on your harddisk. It's a quite cool tool but I forgot the name unfortunately.)
Windows - SDelete, Eraser
Unix based OS - shred command should do
Logged
impelse
Hero Member
Offline
Posts: 565
Re: My father is hacking me?!
«
Reply #5 on:
October 09, 2010, 07:00:55 PM »
This would be a very interesting movie
Logged
CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training
Website:
http://blog.thehost1.com/
chrisj
Hero Member
Offline
Posts: 1163
Re: My father is hacking me?!
«
Reply #6 on:
October 09, 2010, 09:29:36 PM »
I have to agree with some of what the others said.
1) download Ubuntu work from that for a while. See if your dad still knows things you don't think he should.
2) buy a second cheap box, run linux on it, get an old school hub (not a switch), and then look at the traffic going out of your network.
Depending on where you go to school, you might be able to find someone to do it for you. For the price of a 6pack or 2.
*edit:
Or you could just ask him about your concerns.
«
Last Edit: October 09, 2010, 09:54:06 PM by chrisj
»
Logged
OSWP, Sec+
ziggy_567
Sr. Member
Offline
Posts: 361
Re: My father is hacking me?!
«
Reply #7 on:
October 09, 2010, 10:36:23 PM »
@chrisj
Let's not get crazy! Ask?!?! I think MaXe's suggestions are the most down to earth!
The only thing I'd add to MaXe's is not to use Truecrypt for whole disk encryption as the "Evil Maid" attack is pretty easy with physical access. I'd use whatever is native (that is, unless you're running XP)...pretty much every Linux distro will have native whole disk encryption, though...
Logged
--
Ziggy
eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
former33t
Full Member
Offline
Posts: 226
Re: My father is hacking me?!
«
Reply #8 on:
October 10, 2010, 03:15:33 PM »
Reading comprehension ftw:
So the computer has RAS enabled so dad can help out when he's not around... he doesn't need to be an NSA cracker. He doesn't even need to be able to hack his way out of a paper bag. He has access to the machine. Full disk encryption won't fix that. It won't even help.
If you are worried about him on the computer, get tech support somewhere else.
Edited: fixed copy paste error induced by writing response from my droid....
«
Last Edit: October 11, 2010, 10:28:31 AM by former33t
»
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
hayabusa
Hero Member
Offline
Posts: 1633
Re: My father is hacking me?!
«
Reply #9 on:
October 10, 2010, 08:14:20 PM »
Quote from: former33t on October 10, 2010, 03:15:33 PM
To be able to hackReading comprehension ftw:
So the computer has RAS enabled so dad can help out when he's not around... he doesn't need to be an NSA cracker. He doesn't even need to be able to hack his way out of a paper bag. He has access to the machine. Full disk encryption won't fix that. It won't even help.
If you are worried about him on the computer, get tech support somewhere else.
Agreed with former33t.
It doesn't take rocket science, if you've got RAS enabled. If dad has access, and is logged in as you, he's got access to whatever you have access to. Assuming you've already mounted filesystems, or accessed the encrypted disks, there's nothing for dad to crack. And if you haven't, all he needs to do is standby, until you do,
I held off on this thread response for a while now. Sometimes, threads just don't feel right, and IMHO, IF your dad is truly current or 'almost former' NSA cracker, or however you want to term it, I'd think your computer is very possibly / likely the least of your worries, regarding your privacy. Additionally, if you think he's watching you, or snooping, you'd know he very likely is watching everything you post to this thread, etc, and that, alone doesn't help your case, in terms of believability to me. Either you're incredibly naive, or just looking for some attention, as to ask these questions openly, VIA a computer, under said circumstances (dad being 'Big Brother',) to me, simply doesn't compute.
Additionally, who pointed you to eEye's software? How did you just stumble on that one, as there are plenty of malware detection and other programs out there, and in general, eEye's isn't the first one to come up via a simple Google search... I suppose it's possibly the same naivety, and please don't take offense, if that's the case. I just find it difficult to believe that you were searching on 'vulnerability scanning software,' if you're suspect of your father snooping on you. If you thought he had access, I'd assume you'd be looking for things about detecting and disabling remote access / connections, etc., not for 'vulnerability scanners.'
I'm personally sort of curious as to the thought process that led from Googling on, for instance:
"parents snooping on computer"
"ssh how to"
"disable remote access"
...
...
...
"vulnerability scanners"
Again, I mean, maybe, so don't take offense. And if so, tell me the search you used, that led you that route, as I'm interested. But the logic flow isn't quite as clear to me, as, perhaps, it was to you.
Sorry for doubting, but I'm doubting...
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
putosusio
Newbie
Offline
Posts: 26
Re: My father is hacking me?!
«
Reply #10 on:
November 08, 2010, 12:34:26 AM »
reformat and be done with it.
simple and effective.
p.s. if your dad was a NSA cracker, you're screwed.
Logged
Its not the fixing that's the hard part, its knowing what needs fixing.
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.