Darkwind - Viewing Topic: ** Not DW related **
Welcome Guest! » Darkwind » Operating Systems » Mac OSX » ** Not DW related **

Pages: << prev 1 next >> Reply to Topic Create New Topic Create New Poll
** Not DW related **, Hijacked E-Mail
*Grograt*
Grograts Gonads
Darkwind Guru

Renegade

Avatar

Member Level

Group: Marshals
Posts: 8,377
Joined: Oct 5, 2008

Send an email to *Grograt* Send a personal messsage to *Grograt* Reply with a quote from this post Go to the top of the page

I know we have some techs here B) i need some advice, our internet provider ( sky ) cut our connection yesterday, when we contacted them they stated that there had been a complaint that an e-mail account here ( possibly my partners ) had been hijacked and was being used to spam addresses due to a virus. Now my partner uses a Mac and entourage and the rest of us mere mortals use pc's ( thats 1 mac 1 pc 1 laptop xbox and ps3 ) she has the only e-mail account that is used on a regular basis, the kids have hotmail but don't use it for mailing and i have a googlemail account which is hardly used for e-mails and i don't receive much spam, Where as her account has suffered with spam for quite a while. Now my question is " what can we do to try and purge this spam forwarding via one of our accounts" i have posted here due to the main user being on a mac...... i know we have a lot of tech guys playing who just waiting to start a debate B)
.........................
vet marshal wv community

Posted Mar 30, 2009, 9:48 am Last edited Mar 30, 2009, 9:50 am by *Grograt*
*sam*
The Salthill Sluggerz
Darkwind Guru

Renegade

Avatar

Member Level

Group: Lead Developer
Posts: 16,780
Joined: Jan 19, 2006

Send an email to *sam* Send a personal messsage to *sam* Reply with a quote from this post Go to the top of the page

Change the password?
.........................
marshal vet deathrce1 paintladder combat1 wv ped1 cont slay2013

Posted Mar 30, 2009, 11:19 am
*Grograt*
Grograts Gonads
Darkwind Guru

Renegade

Avatar

Member Level

Group: Marshals
Posts: 8,377
Joined: Oct 5, 2008

Send an email to *Grograt* Send a personal messsage to *Grograt* Reply with a quote from this post Go to the top of the page

Could it really be that simple lol, we have had Sky ( blah ) contact us this morning stating we should be re formatting our hard drives ( oh of course im going to do that, not ) it was a category one breach ( OMG we are a category )
.........................
vet marshal wv community

Posted Mar 30, 2009, 11:54 am
lordbam
Nephilim Rising
Darkwind Guru

Anarchists Faction

Member Level

Group: Members
Posts: 1,410
Joined: Dec 9, 2007

Send an email to lordbam Send an ICQ messsage to lordbam Send a personal messsage to lordbam Reply with a quote from this post Go to the top of the page


i don't know how tech savvy you are, but the solution lies in monitoring traffic to find wich computer is infected.
Wireshark is a program that will capture all traffic going in and out of your computer. (including passwords :-))

youtube movie on how to use wireshark

you will need to filter out traffic with destination port 25

cleaning:
On windows
Change passwords
Install kaspersky or another GOOD virus scanner. (not norton)
scan with hitman pro to remove remainder of virusses.


For the mac:
Install chkrootkit:
Scan the computer with clam av

.........................
vet wv zom0,3,0

Posted Mar 30, 2009, 12:10 pm
*Lugal*
Luna Sea
Darkwind Guru

Renegade

Member Level

Group: Marshals
Posts: 2,246
Joined: Jan 27, 2008

Send an email to *Lugal* Send a personal messsage to *Lugal* Reply with a quote from this post Go to the top of the page

*Grograt* said:
the kids have hotmail

I'd stop using these cheap browser emails.  Gmail should be fine but hotmail, yahoo, etc have all sorts of issues, not simply with security.

Since you have kids, depending on their ages, you might look into some restrictive software or system setting that prevents them from downloading anything, to include opening email attachments.
.........................
vet marshal wv

Posted Mar 30, 2009, 4:56 pm
*Grograt*
Grograts Gonads
Darkwind Guru

Renegade

Avatar

Member Level

Group: Marshals
Posts: 8,377
Joined: Oct 5, 2008

Send an email to *Grograt* Send a personal messsage to *Grograt* Reply with a quote from this post Go to the top of the page

Thanks Bam, have used the mac apps found nothing, changed passwords, Lugal i say kids when there 17 and 15 with a passing through 21 year old, they use hotmail for msn (pah) i already restrict on the main pc ( its amazing what a 17 year old wants to download these days, and its not just porn lol ). Hopefully once ive cleaned up main pc with Bams apps ( have done my lappy ) we should be good, no way of knowing till sky moans again i suppose, or the spammer gets fed up with bounced mail and goes elsewhere
.........................
vet marshal wv community

Posted Mar 30, 2009, 5:51 pm
BWGunner
DriveByRomance
Autodueller

Renegade

Member Level

Group: Storytellers + IP
Posts: 413
Joined: Mar 22, 2008

Send an email to BWGunner Send a personal messsage to BWGunner Reply with a quote from this post Go to the top of the page

I feel like I owe Bam for an hour of consulting. That's good info for a cross-platform house. I let our IT Guru here at work deal with this stuff, but I have to admit my home network is not well monitored...yet!

Thanks, great thread.
.........................
vet wv cont

Posted Mar 31, 2009, 7:11 pm
lordbam
Nephilim Rising
Darkwind Guru

Anarchists Faction

Member Level

Group: Members
Posts: 1,410
Joined: Dec 9, 2007

Send an email to lordbam Send an ICQ messsage to lordbam Send a personal messsage to lordbam Reply with a quote from this post Go to the top of the page

Although it is hard, the most important test is the wireshark test.
If the virus or rootkit isn't detected by the scanners, wireshark will pick up the network traffic.
.........................
vet wv zom0,3,0

Posted Mar 31, 2009, 10:22 pm
*Tinker*
BibleThumpers Anonymous
Darkwind Guru

Mutants Faction

Member Level

Group: Marshals + Contributors
Posts: 4,546
Joined: Aug 1, 2008

Send an email to *Tinker* Send a personal messsage to *Tinker* Reply with a quote from this post Go to the top of the page

For the Mac, i Urge you to get Little Snitch, a tiny but best peace of software I ever pirated got for my mac, it monitors in the background all outgoing communications and a pop-up asks you if you trust it or not and set a rule to block or allow it, for ever.


The evaluation is for a month, and well worth the price
.........................
vet marshal wv pvp3 zom circuit2 pvp1 cont

Posted Apr 1, 2009, 11:13 pm Last edited Apr 1, 2009, 11:15 pm by *Tinker*
*Grograt*
Grograts Gonads
Darkwind Guru

Renegade

Avatar

Member Level

Group: Marshals
Posts: 8,377
Joined: Oct 5, 2008

Send an email to *Grograt* Send a personal messsage to *Grograt* Reply with a quote from this post Go to the top of the page

cheers tink, my mrs is trying evaluation copy right now ( cant be bothered with demonoid yet lol )
.........................
vet marshal wv community

Posted Apr 2, 2009, 9:24 am
lordbam
Nephilim Rising
Darkwind Guru

Anarchists Faction

Member Level

Group: Members
Posts: 1,410
Joined: Dec 9, 2007

Send an email to lordbam Send an ICQ messsage to lordbam Send a personal messsage to lordbam Reply with a quote from this post Go to the top of the page

Looks like a firewall application.
This will not stop all outgoing mail because some mail viruses on windows use outlook (which will be approved) to send mail.

It is however better then nothing
.........................
vet wv zom0,3,0

Posted Apr 2, 2009, 10:46 am
Reply to Topic Create New Topic Create New Poll E-mail me when replies are made to this topic View Printable
» Darkwind » Operating Systems » Mac OSX » ** Not DW related **

0.1396 seconds - 21 queries - 0.65 load