Go Back   PCMech Forums > Help & Discussion > Computer Hardware

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 11-03-2000, 07:22 PM   #1
Member (9 bit)
 
jalbes's Avatar
 
Join Date: Jul 2000
Posts: 257
Just the other day, I decided to put up a server to share files with my friends. When I rebooted my pc I noticed something funny and ran my virus scan. Sure enough I had a trojen and I had to remove them and delete the load commands in my WIN.INI. How does a hacker get into my pc even though I have a firewall up? Appearently they got in through a backdoor. What is this backdoor? What can I do to prevent this in the future?

I thought that I'd ask you guys, because you's are always so helpful. Thanks again.
jalbes is offline   Reply With Quote
Old 11-03-2000, 07:49 PM   #2
Red-eyed Moderator
Staff
Premium Member
 
HAL9000's Avatar
 
Join Date: Dec 1999
Location: Regina, Saskatchewan, Canada
Posts: 17,525
To get in, one either needs a trojan to open a port, or there to be an existing port open. What services do you have running? FTP, Web server, do you have ICQ running? MSN instant messanger?
__________________
-At Ford, quality is job #1, job #2 is making them explode. ~Norm MacDonald, SNL News

-Switching to Glide..Balancing in my head..inside of me...
taking the glide path instead.
HAL9000 is offline   Reply With Quote
Old 11-03-2000, 10:28 PM   #3
Premium Member
 
Statica's Avatar
 
Join Date: Jun 1999
Posts: 9,231
Trojans can go through firewalls too .. the firewall can only prevent attacks from outside, not from within .. the trojan has basically openned up means of moving relevant traffic through ports.

  • Delete the files pertaining to the trojan
  • rebuild your IP stacks
  • Get your comp checked by at least 2 a.virus programs
  • research the trojan that affected you .. find out what port was used to allow traffic in.
  • set your firewall to trap and log traffic to the ports defined by that trojan. [make sure that u identify if any other progs use it]
  • contact system administrator of trojan user if possible
  • FIND OUT HOW YOU GOT INFECTED IN THE FIRST PLACE
  • Statica is offline   Reply With Quote
    Old 11-04-2000, 02:59 PM   #4
    Staff
    Premium Member
     
    mairving's Avatar
     
    Join Date: Jul 1999
    Location: Arlington, TN
    Posts: 5,538
    Probably not a bad idea to check your system at http://www.grc.com . You can probe ports and all kinds of stuff there.
    mairving is offline   Reply With Quote
    Old 11-05-2000, 10:45 AM   #5
    glc
    Forum Administrator
    Staff
    Premium Member
     
    glc's Avatar
     
    Join Date: May 2000
    Location: Joplin MO
    Posts: 36,453
    The Cleaner at http://www.moosoft.com has an active background trojan monitor and a monitor that alerts you when anything tries to write to certain registry keys.
    glc is offline   Reply With Quote
    Old 11-07-2000, 01:09 AM   #6
    Member (9 bit)
     
    jalbes's Avatar
     
    Join Date: Jul 2000
    Posts: 257
    Unhappy But....

    In response to HAL9000! All that I had open was my hotline server and client.

    So I'm assuming that someone used a program like "port sniff" or something like that to determine the open port. Is that correct? If so, can I somehow hide this information from being seen by a hacker?

    I find it hard to understand how someone can plant a trojen directly into my pc. Yet again, it makes me wonder what else a hacker can control on my PC.

    This is kinda starting to get scary!

    "Toto, I don't think that we're in Kansas anymore!"

    jalbes is offline   Reply With Quote
    Old 11-07-2000, 08:58 AM   #7
    Red-eyed Moderator
    Staff
    Premium Member
     
    HAL9000's Avatar
     
    Join Date: Dec 1999
    Location: Regina, Saskatchewan, Canada
    Posts: 17,525
    To reduce your risk in the future, take the advice from the other guys, go to http://www.zonelabs.com and get a firewall, it's free. Even without any programs running, NETBIOS (port 139) and IDENT (Port 113) will be open. You can go to http://www.grc.com for a quick report on what is open (it only tests a few) or you can go to http://www.dslreports.com for a more detailed scan. http://www.hackerwhacker.com will test your system pretty hard, but you can only do one scan before you have to pay for the scans.

    Trojans can get placed on your system quite easily, especially if you do a lot of downloading (from warez sites in particular).
    HAL9000 is offline   Reply With Quote
    Old 11-07-2000, 02:34 PM   #8
    Member (9 bit)
     
    jalbes's Avatar
     
    Join Date: Jul 2000
    Posts: 257
    Wink Thanx HAL9000

    I'm definately going to try out all of the links that you all posted.

    But one question that didn't get directly answered and I'm still currious about. On the night that I got hacked into, I didn't personaly download anything, I just had my server open for my friends. So how is a hacker able to upload a trojen into my Windows Directory when he shouldn't have access to that directory, let alone change my WIN.INI file? If he can already get in to upload this trojen, then can he do any other harm to my pc that I'm not already aware of?

    Thanx alot for your help. I really appreciate all the support.
    jalbes is offline   Reply With Quote
    Old 11-07-2000, 04:22 PM   #9
    Premium Member
     
    Statica's Avatar
     
    Join Date: Jun 1999
    Posts: 9,231
    Some thoughts:
  • Do you have adequate antivirus? Perhaps one of your friends uploaded something that was infected without knowing it.
  • Does it allow anonymous access??
  • It is also highly likely that the trojan has been on your system a lot longer than just the other day.
  • Statica is offline   Reply With Quote
    Old 11-07-2000, 06:59 PM   #10
    Red-eyed Moderator
    Staff
    Premium Member
     
    HAL9000's Avatar
     
    Join Date: Dec 1999
    Location: Regina, Saskatchewan, Canada
    Posts: 17,525
    As soon as you have a server open, you also have a port open. Either way, you need to lock that system down a little bit to keep intruders out.
    HAL9000 is offline   Reply With Quote
    Old 11-08-2000, 04:58 AM   #11
    Member (9 bit)
     
    jalbes's Avatar
     
    Join Date: Jul 2000
    Posts: 257
    Talking False Alarm

    I found out today on what had actually happened.

    It turned out that since my server was up, my roommate didn't want to disconnect me from the net, so he hopped onto my pc and added his ICQ# on to my PC so that he could talk to his friends.

    Well one of his friends told him to download this little program that he made at school. So my idiot of a retard of bonehead of a roommate downloadeded it. He tried to run it but it didn't work. (Obviously a trojen). So he told his buddy that it didn't work. Not much later my room mate said that my firewall asked pemission to connect somewhere. Fortunately my roomate said no and disconnected me from the net, but retard there only disconnected my pc so that he could connect with his pc in order to get the file from his friend on his own pc. Well, needless to say he infected his PC as well.

    Some peoples children, I tell you!

    But yeah, I ran all the tests on the links that all of you provided and my PC is supposedly safe. Thanx for all of the help and support.

    jalbes

    jalbes is offline   Reply With Quote
    Reply

    Bookmarks

    Still Need Help? Type Your Keywords Here:


    Thread Tools Search this Thread
    Search this Thread:

    Advanced Search
    Display Modes Rate This Thread
    Rate This Thread:

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is On
    Trackbacks are On
    Pingbacks are On
    Refbacks are On



    All times are GMT -5. The time now is 07:53 AM.
    Powered by vBulletin® Version 3.8.6
    Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
    SEO by vBSEO 3.6.0