Skip to comments.
Freeper Tech Help Needed -- Have I Been HACKED?
Posted on 09/11/2002 11:33:50 AM PDT by Maceman
My Black Ice 3.5 just gave me a "data changed" red alert. What should I do about this? Can anyone explain this situation and appropriate action to me in language I can understand?
Here is what the Black Ice Advice Screen says:
Summary
An overlap in new TCP data with queued data has been observed, and the overlapping data has changed between the two packets.
Details
This technique is used by advanced hackers to hijack connections. They utilize IP spoofing and sequence number guessing to intercept a user's connection and inject their own data into the connection. If successful, the hacker can gain control of a system.
False Positives
This is may be a false positive. The intrusion is triggered if the TCP data has changed within two frames. In theory, this should never happen. However, some recent TCP implementations (Win 2000 and some Unix implementations) send "status" information after a RESET within the data part of the frame. This condition, which results in a false detection, has been addresed in the 3.0 release of BlackICE.
Your help will be GREATLY appreciated.
TOPICS: Miscellaneous; Your Opinion/Questions
KEYWORDS: datachanve; hacker
1
posted on
09/11/2002 11:33:51 AM PDT
by
Maceman
To: Maceman
What were you downloading/doing at the time?
If downloading a file, dump it, whatever it was.
2
posted on
09/11/2002 11:41:41 AM PDT
by
balrog666
To: Maceman
What version of Windows are you using? What type of internet connection do you have? Do you have a local area network, and do you intentionally offer any services over it? Are you publishing a web site from your system?
Try testing your IP connection security using the facilities at Gibson Research and DSL Reports
3
posted on
09/11/2002 11:43:30 AM PDT
by
sourcery
To: sourcery
What version of Windows are you using? What type of internet connection do you have? Do you have a local area network, and do you intentionally offer any services over it? Are you publishing a web site from your system? Try testing your IP connection security using the facilities at Gibson Research and DSL ReportsI am using Windows XP, with a broadband cable connection from RCN. I don't have a LAN. Just a stand-alone system with a single direct internet connection.
4
posted on
09/11/2002 11:47:49 AM PDT
by
Maceman
To: sourcery
I am not publishing a website from my system, and don't offer any services over the Internet. I only do surfing (including lots of Freeping) and e-mail.
5
posted on
09/11/2002 11:49:21 AM PDT
by
Maceman
To: Maceman
You might think of obtaining a hardware firewall that sits between the cable-modem and your confuser. I have one that does address translation, which obviates anyone's attempt to get to your machine directly through the IP addy...LinkSys makes one, so does Belden. It acts as a switch, too, so's I can share the connection - instead of only one machine froze up I now can have two...
To: Maceman
Windows XP
Found your problem right here.
Seriously, though. Make sure you have all of the updates available at
Windows Updates.
Then you'll want to make sure that you have the inherent firewall enabled on your machine (XP ships with it). Go to Help if you have questions about it.
Check out the other info posted, since it looks VERY helpful.
Chances are you haven't really been hacked, although someone might have attempted it. And the correct phrase is 'cracked' not hacked.
And to get your computer lingo straight, check out the
Jargon File.
Good luck.
To: Maceman
and don't offer any services over the Internet
Realize 'services' means Computer-based programs that 'do things' (i.e. serve web pages, send email)
You shouldn't have to worry, but sometimes, if you set up 'Personal Web Server' for example, you have a 'web service' running on your machine.
Simplistic answer, but it will suffice for now.
To: dyed_in_the_wool
" Seriously, though. Make sure you have all of the updates available at Windows Updates. "
Of course that's a problem in itself. Yes, you have to have all of the updates to get anywhere close to security on any system, especially a MS system. However, the End User License Agreement that you have to agree to says Microsoft can go on to your computer any destroy any programs or data they don't like. Will they? Probably not. I just don't like signing my rights over to Microsoft.
9
posted on
09/11/2002 12:21:15 PM PDT
by
mykej
To: Maceman
I advise following these recommendations from Gibson Research:
10
posted on
09/11/2002 1:04:29 PM PDT
by
sourcery
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson