Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 3 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Urgently need advice from Hacking experts
EH-Net
May 22, 2013, 03:27:41 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Urgently need advice from Hacking experts
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Urgently need advice from Hacking experts (Read 6587 times)
0 Members and 1 Guest are viewing this topic.
DeltaMacD3
Newbie
Offline
Posts: 3
Urgently need advice from Hacking experts
«
on:
October 16, 2011, 06:49:54 AM »
Hi all,
I only joined this site to ask for help regarding an odd issue i've just heard about.
A friend of my brothers has had her internet connection hacked apparently. She cannot go online at home and the hacker has called her repeatedly demanding £200 to reinstate her connection. Personally i've never heard of this kind of thing happening to a home network but i'm not really up to speed regarding this kind of attack.
Apart from contacting the ISP and authorities, can anyone recommend a course of action? (I'd really love to be able to wipe the smirk off the guys face!)
He called again at 0830 this morning to laugh at my brothers attempts to stop him. I only got the news via txt and have been unable to contact my bro to find out exactly what he tried but I will post more details as I obtain them.
Thanks to any and all who have advice on this.
Logged
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Urgently need advice from Hacking experts
«
Reply #1 on:
October 16, 2011, 08:34:57 AM »
Delta,
I think the best thing to do is contact the police. Remember..this website is called ETHICALhacker.net
Logged
OSCP in progress
DeltaMacD3
Newbie
Offline
Posts: 3
Re: Urgently need advice from Hacking experts
«
Reply #2 on:
October 16, 2011, 08:47:39 AM »
Hi Yuck,
I've been trying to find out if she has contacted the police etc but at present i've had no luck getting in touch.
The reason i posted here was BECAUSE the site is called Ethicalhacker.net. I was hoping someone with a decent level of morality and ethical standards would be able to assist in derailing the perpetrators attempts to extort a single mother.
Thank you for the reply and i'll try to explore other avenues in the meantime.
Cheers.
Logged
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Urgently need advice from Hacking experts
«
Reply #3 on:
October 16, 2011, 09:11:31 AM »
Believe me I understand what you are trying to say and the situation. But it doesnt mean fighting fire with fire is the answer.
Logged
OSCP in progress
DeltaMacD3
Newbie
Offline
Posts: 3
Re: Urgently need advice from Hacking experts
«
Reply #4 on:
October 16, 2011, 09:27:15 AM »
Hey Yuck,
I don't want to fight fire with fire, i'd love to sure, but i'm actually only interested in any tips or techniques to stop what is happening.
Sorry if I wasn't clear on that. I can see from my original post that the comment in brackets would probably lead you to think I want advice on hacking back, but that's not the case.
I also realise I haven't really given you anything to go on as I have no more info myself atm. I don't even know what kind of setup she has or how exactly this has come to pass.
I'll try to get the details and then perhaps I can ask here for advice on how to prevent further intrusions of this nature.
I'd be interested to know if anyone has heard of something like this happening before. It seems sort of personal to me and a lot of trouble to goto for £200, especially if the police become involved regarding 'cybercrime' or extortion, i'm not even sure what this would be classed as.
Thank you again for your input Yuck
Logged
YuckTheFankees
Sr. Member
Offline
Posts: 324
Re: Urgently need advice from Hacking experts
«
Reply #5 on:
October 16, 2011, 09:44:16 AM »
That is a little different. Try to get more information about her setup and maybe one of the more experience poster's can help. I'm probably not the best guy to troubleshoot this issue. But I can definitely try to help...within reason. I'm sure you understand.
Logged
OSCP in progress
chrisj
Hero Member
Offline
Posts: 1163
Re: Urgently need advice from Hacking experts
«
Reply #6 on:
October 16, 2011, 12:29:04 PM »
It should probably be claimed as extortion, but I haven't studied Cyber Law (yet).
Most likely, without more information on how the person is keeping her off line, and what services are affected I would guess guy has a proxy set up somewhere.
Start at the OS level. Have your brother download a copy of Ubuntu linux from home (or any other version of linux that can be ran from CD). Also print out a few sheets or take good notes on how to do some basic stuff. Like getting network configured.
See if that lets her on the internet.
If not, then move up to the next thing. check for a router or home access point. If possible pull that out of the mix. Using the computer running from the LiveCD, see if you an get on the internet.
If not, call the service provider and tell them about the problem and tell them to fix it or cancel the service and get something else.
Before new service is established, I would at the very least do a fresh install of the OS, and harden it (there are documents on the internet how to do that), and flash the router / access point.
You'll probably want to do that in any case. Don't trust and thing on the connection, and don't expose more boxes to it. Get everything remotely and then take them on CD (NOT RE-WRITEABLE), so they can't be messed with. Also if possible check the hash of the item downloaded so not to get bad versions.
Logged
OSWP, Sec+
millwalll
Guest
Re: Urgently need advice from Hacking experts
«
Reply #7 on:
October 17, 2011, 03:39:49 AM »
I agree its very hard to give any advice if you know a bit about computers start to look at settings on the machine. Make sure there is no proxy set have your tried her machine on another network like yours does it work on that ? if it does not work good chance there a problem with the machine if it does work its her line rather than machine. It just case of trying identify what maybe causing the problem.
That all you can really do..
Logged
eth3real
Sr. Member
Offline
Posts: 309
Re: Urgently need advice from Hacking experts
«
Reply #8 on:
October 18, 2011, 12:26:31 PM »
My first thought about this was that maybe she had an unsecured wifi network, and the first step might be just hitting the reset button on the back. Or plugging the computer directly into the modem to see if it gets a connection that way.
Just a thought.
Edit: I don't recommend leaving the computer plugged directly into the modem if this is the case, just a test to see that it works.
«
Last Edit: October 18, 2011, 12:29:31 PM by eth3real
»
Logged
Put that in your pipe and grep it!
don
Editor-In-Chief
Administrator
Hero Member
Online
Posts: 4165
Editor-In-Chief
Re: Urgently need advice from Hacking experts
«
Reply #9 on:
October 19, 2011, 04:16:03 PM »
I agree with eth3real. First thing that came to mind is to simply tell her to unplug the wireless router. Simple things first.
Secondly, if you really want to attack him back without breaking the law, how about this ballsy idea. Tell the extorter that you'd be more than happy to pay. Then ask for their contact info including name, address, phone, email address, bank acct number, SS#... whatever you can get to turn over to authorities. Nothing like a social engineering attack. ;-)
Good luck,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
3xban
Hero Member
Offline
Posts: 608
Re: Urgently need advice from Hacking experts
«
Reply #10 on:
October 24, 2011, 11:50:06 AM »
+1 to Don's idea! Some of these types are just script kiddies and may not be too bright.
Also additional info on utilizing a bootable linux CD. If you can get online using that OS, then the configuration is with the main OS and not the actual ISP/modem/router equipment. Meaning, the guy somehow got remote control over the computer and configured the OS with some redirects or proxies. Another item to document is what happens when they try to go to the internet? Do they simply get a "Page cannot be displayed..." message or do they get redirected to a website that they can't seem to get past?
Logged
Certs: GCWN
(@)Dewser
p0et
Full Member
Offline
Posts: 197
Re: Urgently need advice from Hacking experts
«
Reply #11 on:
October 24, 2011, 03:43:49 PM »
Take as much as you can out of the equation. (remove any router/wireless setup) and plug your internet straight from the internet box/modem to your computer. You could try what was already suggested of a LiveCD (ubuntu), just toss it in the drive and boot to it or reboot into safe mode with networking. See if you can get online there. If not, open up a command prompt and see if you can ping any website such as "ping google.com" and see if you get any "replies". Just a guess, but it may be a trojan.
Logged
GCIH, Security+, Network+, A+, MCP, DCSE
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Urgently need advice from Hacking experts
«
Reply #12 on:
October 27, 2011, 04:22:54 PM »
Quote from: chrisj on October 16, 2011, 12:29:04 PM
It should probably be claimed as extortion, but I haven't studied Cyber Law (yet).
There's no direct cyber law related to this kind of extortion (that I'm aware of, but there are of course other laws to protect people from extortion), but let me just check my notes..
U.S. Code Title 18, §1362: Communication lines, stations or systems
http://www.law.cornell.edu/uscode/usc_sec_18_00001362----000-.html
U.S. Code Title 18, §2701 et seq: Stored wire and electronic communications and transactional record access.
(If the hacker has acquired access to data which he is not the intended recipient of.)
U.S. Code Title 18, §1029: Fraud and related activity in connection with access devices.
(If he has gained unauthorized access to a system.)
Most prosecutions in the USA goes into the U.S. Code Title 18, Section 1029 and 1030 (Fraud).
These only applies to the United States of course, and these are not all the laws that may apply in this case, but just a few of the common cyber laws.
A website that may interest you:
http://www.cybercrime.gov//
Side-note: Mother of god, I should've never begun reading my notes, now I want to read all of them to catch up on topics I apparently forgot about xD
Extra Side-note: In case you wonder why I have these notes, you need to know about common cyber laws in various countries if you're going to do the GPEN certification. Other certifications such as CEH includes cyber laws too.
«
Last Edit: October 27, 2011, 04:26:42 PM by MaXe
»
Logged
I'm an InterN0T'er
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.