I believe I'm being hacked
Sep. 3rd, 2009 11:03 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
Dear Friends Whom I've Only Cultivated For Free Technical Support: I seem to have a problem and request advice.
I've been getting some odd laptop grinding noises, performance hits and complaints from McAfee that I'm not protected ("click "Fix") so I checked the Internet Inbound Events log and found a bunch of these:
A computer at 79.67.95-79.rev.gaoland.net has attempted an unsolicited connection to UDP port 28432 on your computer.
Another one from dru3.neoplus.adsl.tpnet.pl (same port)
etc. (ETA: OMG I've found HUNDREDS of them)
I have the option to ban the IP... should I?
More technical info on request - I haven't a clue what's going on.
TIA
NEW INFO: Something appears to be trying to open my Wireless Network Adapater (which I have switched off because I don't use it at home)
I've been getting some odd laptop grinding noises, performance hits and complaints from McAfee that I'm not protected ("click "Fix") so I checked the Internet Inbound Events log and found a bunch of these:
A computer at 79.67.95-79.rev.gaoland.net has attempted an unsolicited connection to UDP port 28432 on your computer.
Another one from dru3.neoplus.adsl.tpnet.pl (same port)
etc. (ETA: OMG I've found HUNDREDS of them)
I have the option to ban the IP... should I?
More technical info on request - I haven't a clue what's going on.
TIA
NEW INFO: Something appears to be trying to open my Wireless Network Adapater (which I have switched off because I don't use it at home)
no subject
Date: 2009-09-03 03:17 pm (UTC)http://www.safer-networking.org/index2.html
no subject
Date: 2009-09-03 03:42 pm (UTC)no subject
Date: 2009-09-03 04:03 pm (UTC)no subject
Date: 2009-09-03 04:57 pm (UTC)no subject
Date: 2009-09-03 09:23 pm (UTC)Next, on your router, set it to drop incoming packets to that port - do this at the router, not the machine - once it has reached your laptop, you are already having to process it.
Lastly, update your scanner software, and do an audit - which includes re-checking your outgoing traffic.
If you have been compromised, consider re-installing - especially if the router logs show unexpected outgoing traffic, and your scanners come up clean.
no subject
Date: 2009-09-04 04:28 am (UTC)I don't have a router - just a wireless USB modem (which is included in the scanning system). New attempts come in as soon as I log in. I have a dynamic IP.
no subject
Date: 2009-09-04 04:45 pm (UTC)If you have a Telstra modem, ignore what I'm about to suggest. It Will Not Work.
If you have an Optus, 3, or Virgin USB modem, check the manufacturer - if it is a Huawei, then head down to your nearest 3 shop, and ask about the 3g-wifi router.
This is a little white or black box that you can plug aforementioned modem into, and it turns into a short-range access point. This can be configured to filter ports via a web interface - ie giving you a firewall.
It may offer that little extra layer of protection - but check the manual against your modem model for compatibility. Also, you will have to do a tiny bit of reconfiguration if you are not using 3 itself.
It also means that two of you can use the link at the same time :) Or more, if the cats are so inclined.
no subject
Date: 2009-10-25 01:58 pm (UTC)no subject
Date: 2009-09-04 12:42 am (UTC)If the bots are finding you even if your IP address changes, then try to find out whether there is something running on your machine that is attracting them.