Jump to content

Someone hacked into all of our accounts right under our noses, and here is how

iamdarkyoshi

So we have had over $3000 spent on various crap ranging from itunes gift cards, computers, cell phones, and clothes.

 

How did this happen? Well, it all started with our Plex server which has RDP enabled, and is accessible from outside the network, it is port forwarded. My dad uses this machine as his PC, and had multiple accounts saved in chrome and IE. The best part? The PC's login password was 'p' and the password hint states this.

 

Now: someone's found the external IP that leads to this PC's RDP, and remoted into it. They changed the password, which is what confused us. This PC has had viruses and stuff on it in the past, so we just assumed that a virus was fucking with us, should have wiped it clean long ago but wanted to keep the purchased software. We just cracked it with ubuntu and left it alone, so we could continue watching movies from it.

 

BAD PLAN.

 

At this point, the hacker was on to something. So last night, he logged in again, changed the PC's password again, and made over 3 grand in purchases on lots of different sites.

 

To fix this, the mediaserver is no longer connected to the internet, the router has had a new firmware flashed that has logging support, and we are working with everyone that purchases have been made to get our money back. But the issue here is that the purchases have been made from the same PC as legitimate purchases, so ebay does not want to consider them fraudulent charges!

 

 

Now here is the "lucky" part. Stuff ordered here is obviously going to be shipped somewhere, and this "somewhere" is probably going to have the police waiting. Also, here is my favorite part: The hacker didn't delete ANY of the history here, it is ALL saved on the PC and is visible. What a dumbass. Actually we are probably the dumbass here.

 

So we are going to get the police involved here, but let this be a lesson to you:

 

Don't store autosaved passwords on a machine with a crude password, and ESPECIALLY not a machine with a crude password with port forwarding and DNS services!

Link to comment
Share on other sites

Link to post
Share on other sites

Fuck......

*goes to 192.168.0.1*

*disables all my port forwarding ports*

safe.

Ryzen 5 3600 stock | 2x16GB C13 3200MHz (AFR) | GTX 760 (Sold the VII)| ASUS Prime X570-P | 6TB WD Gold (128MB Cache, 2017)

Samsung 850 EVO 240 GB 

138 is a good number.

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, iamdarkyoshi said:

So we have had over $3000 spent on various crap ranging from itunes gift cards, computers, cell phones, and clothes.

 

How did this happen? Well, it all started with our Plex server which has RDP enabled, and is accessible from outside the network, it is port forwarded. My dad uses this machine as his PC, and had multiple accounts saved in chrome and IE. The best part? The PC's login password was 'p' and the password hint states this.

 

Now: someone's found the external IP that leads to this PC's RDP, and remoted into it. They changed the password, which is what confused us. This PC has had viruses and stuff on it in the past, so we just assumed that a virus was fucking with us, should have wiped it clean long ago but wanted to keep the purchased software. We just cracked it with ubuntu and left it alone, so we could continue watching movies from it.

 

BAD PLAN.

 

At this point, the hacker was on to something. So last night, he logged in again, changed the PC's password again, and made over 3 grand in purchases on lots of different sites.

 

To fix this, the mediaserver is no longer connected to the internet, the router has had a new firmware flashed that has logging support, and we are working with everyone that purchases have been made to get our money back. But the issue here is that the purchases have been made from the same PC as legitimate purchases, so ebay does not want to consider them fraudulent charges!

 

 

Now here is the "lucky" part. Stuff ordered here is obviously going to be shipped somewhere, and this "somewhere" is probably going to have the police waiting. Also, here is my favorite part: The hacker didn't delete ANY of the history here, it is ALL saved on the PC and is visible. What a dumbass. Actually we are probably the dumbass here.

 

So we are going to get the police involved here, but let this be a lesson to you:

 

Don't store autosaved passwords on a machine with a crude password, and ESPECIALLY not a machine with a crude password with port forwarding and DNS services!

Really sucks that this happened to you. This is why I never have weak passwords and save any information that could be used to make purchases on my pc. :) Good luck getting everything back and I hope the bitch that did this gets caught.

Use this guide to fix text problems in your postGo here and here for all your power supply needs

 

New Build Currently Under Construction! See here!!!! -----> 

 

Spoiler

Deathwatch:[CPU I7 4790K @ 4.5GHz][RAM TEAM VULCAN 16 GB 1600][MB ASRock Z97 Anniversary][GPU XFX Radeon RX 480 8GB][STORAGE 250GB SAMSUNG EVO SSD Samsung 2TB HDD 2TB WD External Drive][COOLER Cooler Master Hyper 212 Evo][PSU Cooler Master 650M][Case Thermaltake Core V31]

Spoiler

Cupid:[CPU Core 2 Duo E8600 3.33GHz][RAM 3 GB DDR2][750GB Samsung 2.5" HDD/HDD Seagate 80GB SATA/Samsung 80GB IDE/WD 325GB IDE][MB Acer M1641][CASE Antec][[PSU Altec 425 Watt][GPU Radeon HD 4890 1GB][TP-Link 54MBps Wireless Card]

Spoiler

Carlile: [CPU 2x Pentium 3 1.4GHz][MB ASUS TR-DLS][RAM 2x 512MB DDR ECC Registered][GPU Nvidia TNT2 Pro][PSU Enermax][HDD 1 IDE 160GB, 4 SCSI 70GB][RAID CARD Dell Perc 3]

Spoiler

Zeonnight [CPU AMD Athlon x2 4400][GPU Sapphire Radeon 4650 1GB][RAM 2GB DDR2]

Spoiler

Server [CPU 2x Xeon L5630][PSU Dell Poweredge 850w][HDD 1 SATA 160GB, 3 SAS 146GB][RAID CARD Dell Perc 6i]

Spoiler

Kero [CPU Pentium 1 133Mhz] [GPU Cirrus Logic LCD 1MB Graphics Controller] [Ram 48MB ][HDD 1.4GB Hitachi IDE]

Spoiler

Mining Rig: [CPU Athlon 64 X2 4400+][GPUS 9 RX 560s, 2 RX 570][HDD 160GB something][RAM 8GBs DDR3][PSUs 1 Thermaltake 700w, 2 Delta 900w 120v Server modded]

RAINBOWS!!!

 

 QUOTE ME SO I CAN SEE YOUR REPLYS!!!!

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, iamdarkyoshi said:

So we have had over $3000 spent on various crap ranging from itunes gift cards, computers, cell phones, and clothes.

 

How did this happen? Well, it all started with our Plex server which has RDP enabled, and is accessible from outside the network, it is port forwarded. My dad uses this machine as his PC, and had multiple accounts saved in chrome and IE. The best part? The PC's login password was 'p' and the password hint states this.

 

Now: someone's found the external IP that leads to this PC's RDP, and remoted into it. They changed the password, which is what confused us. This PC has had viruses and stuff on it in the past, so we just assumed that a virus was fucking with us, should have wiped it clean long ago but wanted to keep the purchased software. We just cracked it with ubuntu and left it alone, so we could continue watching movies from it.

 

BAD PLAN.

 

At this point, the hacker was on to something. So last night, he logged in again, changed the PC's password again, and made over 3 grand in purchases on lots of different sites.

 

To fix this, the mediaserver is no longer connected to the internet, the router has had a new firmware flashed that has logging support, and we are working with everyone that purchases have been made to get our money back. But the issue here is that the purchases have been made from the same PC as legitimate purchases, so ebay does not want to consider them fraudulent charges!

 

 

Now here is the "lucky" part. Stuff ordered here is obviously going to be shipped somewhere, and this "somewhere" is probably going to have the police waiting. Also, here is my favorite part: The hacker didn't delete ANY of the history here, it is ALL saved on the PC and is visible. What a dumbass. Actually we are probably the dumbass here.

 

So we are going to get the police involved here, but let this be a lesson to you:

 

Don't store autosaved passwords on a machine with a crude password, and ESPECIALLY not a machine with a crude password with port forwarding and DNS services!

I dont really have this problem, as any remote access I do is done through openvpn or l2tp

My native language is C++

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, themctipers said:

Fuck......

*goes to 192.168.0.1*

*disables all my port forwarding ports*

safe.

https://gyazo.com/88122af24c70a0b171f7db7df7344b13

erm..

 

Ryzen 5 3600 stock | 2x16GB C13 3200MHz (AFR) | GTX 760 (Sold the VII)| ASUS Prime X570-P | 6TB WD Gold (128MB Cache, 2017)

Samsung 850 EVO 240 GB 

138 is a good number.

 

Link to comment
Share on other sites

Link to post
Share on other sites

That's why all my passwords are atleast 12 characters with all sorts of symbols and I have no saved purchasing information on any of my systems. Just make sure to not make the same mistakes in the future :P

Sergeant, United States Marine Corps

Network Administrator, Comptia A+, Security+, Cisco Certified Networking Associate

From a G3258 to dual Xeon E5-2670's

Link to comment
Share on other sites

Link to post
Share on other sites

Some of the insecurity may have been caused by us trying to make it so things connected to the network can access it's files which worked only HALF the time...  

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Jacktastic-Mofo said:

That's why all my passwords are at least 12 characters with all sorts of symbols and I have no saved purchasing information on any of my systems. Just make sure to not make the same mistakes in the future :P

And that is what history is for!

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, themctipers said:

Fuck......

*goes to 192.168.0.1*

*disables all my port forwarding ports*

safe.

speaking of which...

Link to comment
Share on other sites

Link to post
Share on other sites

why was that enabled by default netgear is getting  a strongly worded letter

 

Link to comment
Share on other sites

Link to post
Share on other sites

saving passwords is a baaaaddd idea

where ever you happen to be

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

Good point,lol I'm just learning wireless networking though if I ever get an ethernet port on my cellphone,or unlimited data again .I'm running a wired only setup.mom can deal with it laptops suck lol

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, themctipers said:

Fuck......

*goes to 192.168.0.1*

*disables all my port forwarding ports*

safe.

 

7 minutes ago, Mitchell 3 said:

why was that enabled by default netgear is getting  a strongly worded letter

 

1. Port forwarding is not the issue here. It is a combination of many seriously bad ideas that happened.

 

2. You knowingly used a computer that has had virus infections? And on top of that, you entered personal information knowing that it was infected/knew had been infected before? Anything short of a complete wipe will not guarantee removal of a virus.

 

3. You noticed strange behavior and ignored it because you assumed it was a virus? So you also chose to ignore viruses?

 

4. You don't go to each individual retailer to dispute fraudulent purchases. You contact the credit card company and they take care of it.

 

5. Weak password on a remotely accessible device. Enough said.

Link to comment
Share on other sites

Link to post
Share on other sites

Well that sucks, I guess if I ever made a file server and set up my network and server to SSH into that server, I might want to look at ways of hardening that link from the outside world to that server. My Wifi network is pretty basicsauce and might want to look into hardening that connection too even though I use a pretty long password string for the wifi router.

 

I mean I use pretty good passwords and don't download things at random but still good idea to try to reinforce your network(s).

 

a Moo Floof connoisseur and curator.

:x@handymanshandle x @pinksnowbirdie || Jake x Brendan :x
Youtube Audio Normalization
 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

So I called it?

Thats that. If you need to get in touch chances are you can find someone that knows me that can get in touch.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, iamdarkyoshi said:

Someone is pretty stupid, they signed into our google account WITHOUT A VPN. WE HAVE HIS IP ADDRESS.

Hopefully they are in the US so his parents can give them a stern talking to, otherwise it sucks that nothing will really happen to him. :(

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

Man that must have been devastating but I guess rewarding. Well one thing that anyone can take from this is KEEP CLOSE EYES ON THINKS THAT CONTAINS MONEY, CONTAINS VIDAL DATA or PASSWORDs.

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, iamdarkyoshi said:

Someone is pretty stupid, they signed into our google account WITHOUT A VPN. WE HAVE HIS IP ADDRESS.

Love how stupid people are. It seems to me that they never thought someone would notice stuff going on. :P I wonder how many others they have done this to with out them noticing? 

 

IDEA!

You should use this to make a guide on how to protect you network! Make sure it's idiot and stupid person proof though......

Use this guide to fix text problems in your postGo here and here for all your power supply needs

 

New Build Currently Under Construction! See here!!!! -----> 

 

Spoiler

Deathwatch:[CPU I7 4790K @ 4.5GHz][RAM TEAM VULCAN 16 GB 1600][MB ASRock Z97 Anniversary][GPU XFX Radeon RX 480 8GB][STORAGE 250GB SAMSUNG EVO SSD Samsung 2TB HDD 2TB WD External Drive][COOLER Cooler Master Hyper 212 Evo][PSU Cooler Master 650M][Case Thermaltake Core V31]

Spoiler

Cupid:[CPU Core 2 Duo E8600 3.33GHz][RAM 3 GB DDR2][750GB Samsung 2.5" HDD/HDD Seagate 80GB SATA/Samsung 80GB IDE/WD 325GB IDE][MB Acer M1641][CASE Antec][[PSU Altec 425 Watt][GPU Radeon HD 4890 1GB][TP-Link 54MBps Wireless Card]

Spoiler

Carlile: [CPU 2x Pentium 3 1.4GHz][MB ASUS TR-DLS][RAM 2x 512MB DDR ECC Registered][GPU Nvidia TNT2 Pro][PSU Enermax][HDD 1 IDE 160GB, 4 SCSI 70GB][RAID CARD Dell Perc 3]

Spoiler

Zeonnight [CPU AMD Athlon x2 4400][GPU Sapphire Radeon 4650 1GB][RAM 2GB DDR2]

Spoiler

Server [CPU 2x Xeon L5630][PSU Dell Poweredge 850w][HDD 1 SATA 160GB, 3 SAS 146GB][RAID CARD Dell Perc 6i]

Spoiler

Kero [CPU Pentium 1 133Mhz] [GPU Cirrus Logic LCD 1MB Graphics Controller] [Ram 48MB ][HDD 1.4GB Hitachi IDE]

Spoiler

Mining Rig: [CPU Athlon 64 X2 4400+][GPUS 9 RX 560s, 2 RX 570][HDD 160GB something][RAM 8GBs DDR3][PSUs 1 Thermaltake 700w, 2 Delta 900w 120v Server modded]

RAINBOWS!!!

 

 QUOTE ME SO I CAN SEE YOUR REPLYS!!!!

Link to comment
Share on other sites

Link to post
Share on other sites

19 minutes ago, 8uhbbhu8 said:

Love how stupid people are. It seems to me that they never thought someone would notice stuff going on. :P I wonder how many others they have done this to with out them noticing? 

 

IDEA!

You should use this to make a guide on how to protect you network! Make sure it's idiot and stupid person proof though......

I might just do that! And yes, it is a USA IP

Link to comment
Share on other sites

Link to post
Share on other sites

In this case the problem wasn't really with your router, or your firewall but with your computer. port forwarding is totally safe providing that your protect any device you port forward to or you could just a non standard destination port and convert it to the correct port when you hit your router/NAT.

There are plenty of ways to protect yourself while keeping your system available and accessible.

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, iamdarkyoshi said:

Someone is pretty stupid, they signed into our google account WITHOUT A VPN. WE HAVE HIS IP ADDRESS.

Is there a way to tell that someone wasn't using a VPN that I don't know about? Because he could have just VPN'd into another "hacked" system and did everything from there. I'm pretty sure there is no way of knowing.

 

Also, even if you have his IP, it likely won't do you any good unless he has a static IP and you can find some information online pointing that back to him. You need a lot of pull and proof to get an ISP to give up the exact customer whom had that specific dynamic IP on that date. Its unlikely that would happen for relatively measly $3,000 in stolen goods. Just call the credit card company, claim fraud, protect your computers better, and be on your merry way. May as well power cycle your router and pick up a new IP as well or call and ask for one.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×