Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 2 members online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Malware
Mad cracker following my every move on the web
EH-Net
May 22, 2013, 09:54:03 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Malware
(Moderator:
don
) >
Mad cracker following my every move on the web
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Mad cracker following my every move on the web (Read 6951 times)
0 Members and 1 Guest are viewing this topic.
axm80
Newbie
Offline
Posts: 1
Mad cracker following my every move on the web
«
on:
May 04, 2012, 11:11:09 AM »
Hi all,
I am positive that some severely obsessed dude, whose identity I am certain of, has managed to hack into my mother's and sister's accounts to read my emails to them (which either never arrive or arrive open before they've actually read them) somehow also has access to at least the titles of my (several) email accounts and to my activity log on facebook, amazon and other sites.
He's also managed to do weird things like remotely getting my current housemate to subscribe to his best friend's facebook profile, for instance - if this doesn't sound too clear, her fb wall shows she subscribed to his best friend's fb profile in March, which she never did, nor does she recall ever receiving or accepting an invitation to become friends with him. He seems to still be enabled to follow my visits on the internet in spite of my 'clearing' of cookies, and there's a chance he might be reading this.
I have strong suspicions that he has also managed to hack into my work computer after an unexplainable series of emails and documents disappearing unexplainably (now this certainly doesn't tend to happen to me, and definitely not on the scale it recently has).
He is an IT professional and his computer knowledge is obviously more advanced to that of most people.
My initial questions are, what tools/means allow him to do what I mention above, is there a way (other than paying a computer specs to do it) to identify the computer from which he is doing this so I can get some tangible evidence, and what would you advise, technically speaking, in the meantime?
Logged
sil
Hero Member
Offline
Posts: 549
Re: Mad cracker following my every move on the web
«
Reply #1 on:
May 04, 2012, 11:23:58 AM »
My suggestion is to file a stalking and harassment report with your local authorities. They will (theoretically) be in a better position to assist you. Anything anyone does will likely tamper with potential evidence should you want to go to the legal system so if your ultimate goal is to that (somehow seek prosecution), then literally call the cops.
Because there is so much that could be done to remotely take over your machine, anyone can write a booklong response which will likely leave a non-technical person confused. If you don't seek to go the legal route, hire someone to figure out how the investigatory work. Your best best, copy any information you deem "sacred/holy/worthy" onto a storage device and rebuild your machine. This ensures you have a clean machine. Apply patches,etc., then change your passwords to something worthwhile.
Logged
http://www.infiltrated.net/mgz/puppylecter.jpg
MaXe
Hero Member
Offline
Posts: 669
I've just upgraded myself to a cyborg muahahaa!!1
Re: Mad cracker following my every move on the web
«
Reply #2 on:
May 04, 2012, 11:38:01 AM »
Seems like someone forgot to:
- Log out of facebook at a public place including any school, job, café, etc.
- Choose strong passwords (at least 8 ciphers, containing lower- and upper-case letters, numbers and at least one special character, and of course none of it should relate to: Years, Places, Towns, Cities, Zipcodes, Personal things, Names, and Birthdays, or any other known word that can be found in a dictionary or book.)
- Even MORE important is to make up a secret question and answer, that has absolutely no relation to you or only you know. Something you have never told anyone, otherwise even the best password won't protect you, if the "I forgot my password"-question is weak, which it usually is. The secret question(s) and answer(s) are just like your passwords, and they should be equally strong.
- NEVER use the same password across several websites. Use at least different passwords for: E-mail, your computer, social networking sites such as facebook, and especially at work or school.
- Never open attachments in e-mails, unless you are 200% sure you know who the sender is.
- Never open e-mails or allow scripts and images in them to be loaded, if you do not know the sender.
- Use an up2date firewall and antivirus program
- Never use anyone else's USB keys, avoid using your USB key in other computers than your own if possible.
- Don't allow people to use your computer if you don't trust them fully.
- Never log into facebook, your e-mail, etc., at a computer you don't know the security of. The attacker could've compromised this in case it's a school, workplace, etc. The attacker could also be eavesdropping on traffic on public networks.
- Always use WPA2/TKIP on a wireless network with a strong password. If you can, avoid using wireless networks, especially public ones.
- Avoid browsing to links you have no idea what contains, a lot of e-mail spam recently contains links to infected websites that automatically infects your computer.
If you follow all these guidelines, you should generally be quite safe.
Furthermore, you may have to reinstall your computer or just Windows in case you suspect this has been infected.
Last but not least, keep in mind, that if your e-mail gets compromised, everything it's attached to, facebook, twitter, etc., is potentialyl compromised as well, as an attacker can just use the "I forgot my password" feature then, just like you would if you had lost your password.
It's a lot of things to remember, but most of it is common sense and can be every day use quite easily if you're just willing to do so.
Naturally you should try to use "HTTPS" everywhere you can.
Logged
I'm an InterN0T'er
DragonGorge
Jr. Member
Offline
Posts: 83
Re: Mad cracker following my every move on the web
«
Reply #3 on:
May 07, 2012, 05:41:15 PM »
Personally, I don't think it's worth the effort to hunt down evidence proving this person's guilt. Sure it's an invasion of privacy and a serious nuisance, but I would think the authorities have higher priorities than prosecuting unauthorized facebook friending.
Unless this crosses over into monetary theft, bullying, or you're a celebrity, I doubt the police would be of much help.
As for tools this person may have used? Could be any number of things, up to an including absolutely nothing. Take the hacker who was recently busted for hacking into Scarlet Johanssen's phone and stealing/posting nude photos of her. As I understand it, the majority of his hacking came from simple guesswork on usernames and passwords.
Cleaning up your systems (system restore to factory defaults if necessary) and changing all of your local and online passwords (mother's & sister's too) is probably your best bet.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.