|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (9 bit)
Join Date: Jul 2000
Posts: 257
|
Just the other day, I decided to put up a server to share files with my friends. When I rebooted my pc I noticed something funny and ran my virus scan. Sure enough I had a trojen and I had to remove them and delete the load commands in my WIN.INI. How does a hacker get into my pc even though I have a firewall up? Appearently they got in through a backdoor. What is this backdoor? What can I do to prevent this in the future?
I thought that I'd ask you guys, because you's are always so helpful. Thanks again. |
|
|
|
|
|
#2 |
|
Red-eyed Moderator
Staff
Premium Member
Join Date: Dec 1999
Location: Regina, Saskatchewan, Canada
Posts: 17,525
|
To get in, one either needs a trojan to open a port, or there to be an existing port open. What services do you have running? FTP, Web server, do you have ICQ running? MSN instant messanger?
__________________
-At Ford, quality is job #1, job #2 is making them explode. ~Norm MacDonald, SNL News -Switching to Glide..Balancing in my head..inside of me... taking the glide path instead. |
|
|
|
|
|
#3 |
|
Premium Member
Join Date: Jun 1999
Posts: 9,231
|
Trojans can go through firewalls too .. the firewall can only prevent attacks from outside, not from within .. the trojan has basically openned up means of moving relevant traffic through ports.
|
|
|
|
|
|
#4 |
|
Staff
Premium Member
Join Date: Jul 1999
Location: Arlington, TN
Posts: 5,538
|
Probably not a bad idea to check your system at http://www.grc.com . You can probe ports and all kinds of stuff there.
|
|
|
|
|
|
#5 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 36,453
|
The Cleaner at http://www.moosoft.com has an active background trojan monitor and a monitor that alerts you when anything tries to write to certain registry keys.
|
|
|
|
|
|
#6 |
|
Member (9 bit)
Join Date: Jul 2000
Posts: 257
|
In response to HAL9000! All that I had open was my hotline server and client.
So I'm assuming that someone used a program like "port sniff" or something like that to determine the open port. Is that correct? If so, can I somehow hide this information from being seen by a hacker? I find it hard to understand how someone can plant a trojen directly into my pc. Yet again, it makes me wonder what else a hacker can control on my PC. This is kinda starting to get scary! "Toto, I don't think that we're in Kansas anymore!" |
|
|
|
|
|
#7 |
|
Red-eyed Moderator
Staff
Premium Member
Join Date: Dec 1999
Location: Regina, Saskatchewan, Canada
Posts: 17,525
|
To reduce your risk in the future, take the advice from the other guys, go to http://www.zonelabs.com and get a firewall, it's free. Even without any programs running, NETBIOS (port 139) and IDENT (Port 113) will be open. You can go to http://www.grc.com for a quick report on what is open (it only tests a few) or you can go to http://www.dslreports.com for a more detailed scan. http://www.hackerwhacker.com will test your system pretty hard, but you can only do one scan before you have to pay for the scans.
Trojans can get placed on your system quite easily, especially if you do a lot of downloading (from warez sites in particular). |
|
|
|
|
|
#8 |
|
Member (9 bit)
Join Date: Jul 2000
Posts: 257
|
I'm definately going to try out all of the links that you all posted.
But one question that didn't get directly answered and I'm still currious about. On the night that I got hacked into, I didn't personaly download anything, I just had my server open for my friends. So how is a hacker able to upload a trojen into my Windows Directory when he shouldn't have access to that directory, let alone change my WIN.INI file? If he can already get in to upload this trojen, then can he do any other harm to my pc that I'm not already aware of? Thanx alot for your help. I really appreciate all the support. |
|
|
|
|
|
#9 |
|
Premium Member
Join Date: Jun 1999
Posts: 9,231
|
Some thoughts:
|
|
|
|
|
|
#10 |
|
Red-eyed Moderator
Staff
Premium Member
Join Date: Dec 1999
Location: Regina, Saskatchewan, Canada
Posts: 17,525
|
As soon as you have a server open, you also have a port open. Either way, you need to lock that system down a little bit to keep intruders out.
|
|
|
|
|
|
#11 |
|
Member (9 bit)
Join Date: Jul 2000
Posts: 257
|
I found out today on what had actually happened.
It turned out that since my server was up, my roommate didn't want to disconnect me from the net, so he hopped onto my pc and added his ICQ# on to my PC so that he could talk to his friends. Well one of his friends told him to download this little program that he made at school. So my idiot of a retard of bonehead of a roommate downloadeded it. He tried to run it but it didn't work. (Obviously a trojen). So he told his buddy that it didn't work. Not much later my room mate said that my firewall asked pemission to connect somewhere. Fortunately my roomate said no and disconnected me from the net, but retard there only disconnected my pc so that he could connect with his pc in order to get the file from his friend on his own pc. Well, needless to say he infected his PC as well. Some peoples children, I tell you! But yeah, I ran all the tests on the links that all of you provided and my PC is supposedly safe. Thanx for all of the help and support. jalbes |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|