maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Off Topic (https://talk.maemo.org/forumdisplay.php?f=19)
-   -   [URGENT] Expert Hacker Needed. (https://talk.maemo.org/showthread.php?t=89510)

AMD 2013-03-18 14:16

[URGENT] Expert Hacker Needed.
 
Hey guys, I know this is the wrong place to discuss this but here I know the best people to help me..
Anyway, since 2 days my Facebook was getting hacked by an anonymous person. I didn't know who. But my email and password are being changed. I got my Facebook back yesterday and today it went away again. When I got it back my name was changed and lots of bad messages were sent to my friends. Also, my timeline won't open resulting with 'Page Not Found'.
Does anyone know how to prevent my Facebook to be hacked again? I changed my password A LOT of times. But to no avail.
Please help me. Please..

thedead1440 2013-03-18 14:34

Re: [URGENT] Expert Hacker Needed.
 
You may have been key-logged; try using a vkb for entering passwords preferably a vkb that's re-sized and not in the same place of the desktop where it opened.


Obviously it goes without saying change your email etc passwords too and do a thorough check of your system. Since you are using Windows, if no malware is found a re-format may be necessary...

AMD 2013-03-18 14:52

Re: [URGENT] Expert Hacker Needed.
 
Did that.. And basically once I change my password after 5 mins the account is hacked again.. Are you sure it's keylogged? I never allowed anyone to transfer files to my PC via Teamviewer or such. I have njRAT and I know how it works too. And no one sent me a renamed server.exe to be a victim. No one sent me a fake webpage to make my browser redirect to enter my credentials. Anyhow, my computer is 100% clean. There is something really fishy about this. I am ready to do anything to keep my laptop clean but I want to make sure of this first.

erendorn 2013-03-18 14:56

Re: [URGENT] Expert Hacker Needed.
 
use a linux live CD to change your password, that way you'll know it's clean.
maybe resecure your email account too.
Remove any facebook app that could be insecure.

AMD 2013-03-18 15:26

Re: [URGENT] Expert Hacker Needed.
 
All are secure.

AMD 2013-03-18 16:05

Re: [URGENT] Expert Hacker Needed.
 
And in case I didn't mention, I use Windows 8 Pro now

juiceme 2013-03-18 17:27

Re: [URGENT] Expert Hacker Needed.
 
I wonder how can you be so sure that your computer is secure? Having windows whatever is a risk, and once your box gets infected with nasty enough rootkit, there is nothing you can do to detect it.

The info erendorn gave you is valid; you need to run different OS from a secure boot media to be sure you can change your password securely. And remember, the first minute you boot back to your infected box and check your mail, then you are screwed again :(

sixwheeledbeast 2013-03-18 17:58

Re: [URGENT] Expert Hacker Needed.
 
It does sound like a keylogger, it could be a hardware or a software one.
Use a mobile device to change your password to prove this.

AMD 2013-03-18 18:14

Re: [URGENT] Expert Hacker Needed.
 
Okay, I will try. Thanks

AMD 2013-03-18 18:15

Re: [URGENT] Expert Hacker Needed.
 
Anyway, is there a way to find out who is trying to hack my account? If so, I can directly shut him down.

AMD 2013-03-18 18:31

Re: [URGENT] Expert Hacker Needed.
 
The hacker's ID is 63.216.126.1
And the location is in Milan, Italy.

juiceme 2013-03-18 20:04

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1329864)
The hacker's ID is 63.216.126.1
And the location is in Milan, Italy.

I don't think so... tracerouting from finland it appears that that IP address routes to lebanon.

stickymick 2013-03-18 20:27

Re: [URGENT] Expert Hacker Needed.
 
If it's a keylogger it'll be running as a background task. These are normally not scanned by an anti-virus or malware scanner.

You could give Avira Antivir Rescue System a try. This is a linux based boot CD that can scan the whole Windows installation because nothing in Windows is running at all.

minimos 2013-03-18 22:39

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1329864)
The hacker's ID is 63.216.126.1

Also to me it seems that the IP is located in Lebanon.
But anyway, a search with 'whois' reveals that it belongs to 'Beyond The Network America' which is a shady operator at best and a nest of spammers & spybots at worst.
Terminate their connections with extreme prejudice.

fongo 2013-03-18 23:43

Re: [URGENT] Expert Hacker Needed.
 
Disable all apps & sites that use your FB login; and definitely do not use the same login/email password on FB as your email.

Verssetti 2013-03-19 01:27

Re: [URGENT] Expert Hacker Needed.
 
How do you connect by wifi or ethernet?

AMD 2013-03-19 04:49

Re: [URGENT] Expert Hacker Needed.
 
I connect by both. But WiFi is faster so I use WiFi more frequently. And since I might be watched, I changed my pass yesterday to something that does not have any meaning from any language. And since that change nothing happened. And I think because my passwords were so simple, the hacker could trace the password easily but now no matter how much I type it he'll get lost.. Well, let's test it this time and when I come back from school I will leave a reply.

Verssetti 2013-03-19 05:07

Re: [URGENT] Expert Hacker Needed.
 
Enter in the portal of your router and change the name of your wifi and the password maybe sniffing your account by your wifi.

dadaniel 2013-03-19 11:07

Re: [URGENT] Expert Hacker Needed.
 
well, it could be a keylogger, but honestly, i dont think so ...


... first check your facebook login history to find out who logged into your account: https://www.facebook.com/settings?ta...ction=sessions

... then check your applications under facebook: http://www.facebook.com/settings?tab=applications

... a friend of mine and me once tried to spoof logins through fb applications and it worked!



oh yeah ... if the ip 63.216.126.1 is the right one - here's the whois query and some other checks:

Code:

zeus:~# whois 63.216.126.1
#
# Query terms are ambiguous.  The query is assumed to be:
#    "n 63.216.126.1"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=63...showARIN=false                                              &ext=netref2
#

NetRange:      63.216.0.0 - 63.223.255.255
CIDR:          63.216.0.0/13
OriginAS:
NetName:        BTN-CIDR5
NetHandle:      NET-63-216-0-0-1
Parent:        NET-63-0-0-0-0
NetType:        Direct Allocation
Comment:        ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate:        1999-12-09
Updated:        2012-03-02
Ref:            http://whois.arin.net/rest/net/NET-63-216-0-0-1

OrgName:        Beyond The Network America, Inc.
OrgId:          BNA-42
Address:        450 Springpark PL
Address:        Suite 100
City:          Herdon
StateProv:      VA
PostalCode:    20170
Country:        US
RegDate:        2004-05-25
Updated:        2012-05-24
Ref:            http://whois.arin.net/rest/org/BNA-42

OrgNOCHandle: PUN6-ARIN
OrgNOCName:  PCCW US NOC
OrgNOCPhone:  +1-703-621-1637
OrgNOCEmail:  usnoc@pccwglobal.com
OrgNOCRef:    http://whois.arin.net/rest/poc/PUN6-ARIN

OrgAbuseHandle: PAD13-ARIN
OrgAbuseName:  PCCW AUP Department
OrgAbusePhone:  +1-703-621-1637
OrgAbuseEmail:  abuse.ops@pccwglobal.com
OrgAbuseRef:    http://whois.arin.net/rest/poc/PAD13-ARIN

OrgTechHandle: PUN6-ARIN
OrgTechName:  PCCW US NOC
OrgTechPhone:  +1-703-621-1637
OrgTechEmail:  usnoc@pccwglobal.com
OrgTechRef:    http://whois.arin.net/rest/poc/PUN6-ARIN

OrgTechHandle: MCKAY9-ARIN
OrgTechName:  McKay, Ian
OrgTechPhone:  +1-703-673-1012
OrgTechEmail:  usnoc@pccwglobal.com
OrgTechRef:    http://whois.arin.net/rest/poc/MCKAY9-ARIN

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


zeus:~# nmap -PN -sS 63.216.126.1

Starting Nmap 4.62 ( http://nmap.org ) at 2013-03-19 12:15 CET
Stats: 0:05:37 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 97.38% done; ETC: 12:21 (0:00:09 remaining)
All 1715 scanned ports on 63.216.126.1 are filtered

Nmap done: 1 IP address (1 host up) scanned in 347.784 seconds


... when i check the IP on robtex.com it tells me:
Code:

63.218.12.1
       
Summary

Cr01.ldn01.pccwbtn.net point to 63.218.12.1.
Which servers does 63.218.12.1 use?

63.218.12.1 uses the reverse pointer cr01.ldn01.pccwbtn.net only.

It is not listed in any blacklists.


... so once again a whois against pccwbtn.net:

Code:

zeus:~# whois pccwbtn.net

  Domain Name: PCCWBTN.NET
  Registrar: GODADDY.COM, LLC
  Whois Server: whois.godaddy.com
  Referral URL: http://registrar.godaddy.com
  Name Server: NS-CORP.CAIS.NET
  Name Server: NS-CORP2.CAIS.NET
  Name Server: NS-CORP3.CAIS.NET
  Status: clientDeleteProhibited
  Status: clientRenewProhibited
  Status: clientTransferProhibited
  Status: clientUpdateProhibited
  Updated Date: 28-apr-2011
  Creation Date: 07-may-2001
  Expiration Date: 07-may-2014
  Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
  Domain Name: PCCWBTN.NET
      Created on: 07-May-01
      Expires on: 07-May-14
      Last Updated on: 27-Apr-11

  Registrant:
  PCCW-HKT DataCom Services Limited
  39/F PCCW Tower, Taikoo Place
  979 Kings Road
  Quarry Bay,  0
  Hong Kong

  Administrative Contact:
      Ralph, David  domain.admin@pccw.com
      PCCW-HKT DataCom Services Limited
      11/F East Exchange Tower
      38-40 Leighton Road
      Causeway Bay,  0
      Hong Kong
      +852.28836774      Fax -- +852.29625858

  Technical Contact:
      Ralph, David  domain.admin@pccw.com
      PCCW-HKT DataCom Services Limited
      11/F East Exchange Tower
      38-40 Leighton Road
      Causeway Bay,  0
      Hong Kong
      +852.28836774      Fax -- +852.29625858

  Domain servers in listed order:
      NS-CORP2.CAIS.NET
      NS-CORP3.CAIS.NET
      NS-CORP.CAIS.NET


after some googling - for me it looks like it's a torrent-server (or something similar - a kind of p2p network)

cheers!

stickymick 2013-03-19 11:53

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1329951)
And I think because my passwords were so simple, the hacker could trace the password easily......

Errrm... TBH, you were asking for trouble, then. A long as possible complicated combination of letters and numbers is always the best.

Something that means something to you...... even if it's 3 words typed as 1 with the date when it happened is a good combination for a password.

i.e: arrowin1066theeye.

AMD 2013-03-19 16:11

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by stickymick (Post 1330009)
Errrm... TBH, you were asking for trouble, then. A long as possible complicated combination of letters and numbers is always the best.

Something that means something to you...... even if it's 3 words typed as 1 with the date when it happened is a good combination for a password.

i.e: arrowin1066theeye.

I did it smth like T5Ls6zR8
Anyway, since I changed it to smth like this my account hasn't been hacked.

AMD 2013-03-19 18:12

Re: [URGENT] Expert Hacker Needed.
 
Found the guy, messed the **** up with his Facebook & burned his Hotmail :D No more worries :D No more Fb for him neither Hotmail :p

Dave999 2013-03-19 18:31

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1329864)
The hacker's ID is 63.216.126.1
And the location is in Milan, Italy.

I traced it and found this man behind the IP. He is called silvio berlusconi...

AMD 2013-03-19 19:29

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by Dave999 (Post 1330140)
I traced it and found this man behind the IP. He is called silvio berlusconi...

Well, it came out to be with me Hassan Reslan :p

myname24 2013-03-19 19:31

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by Dave999 (Post 1330140)
I traced it and found this man behind the IP. He is called silvio berlusconi...

he don't have time to do this , he's doing something else :p

AMD 2013-03-19 19:58

Re: [URGENT] Expert Hacker Needed.
 
btw when he changed my name to Ahmad Makdoushe it means he's100% Lebanese and I caught him red-handed ;)

AMD 2013-03-20 13:33

Re: [URGENT] Expert Hacker Needed.
 
Anyway, is there anyway to get my Timeline back?

erendorn 2013-03-20 14:23

Re: [URGENT] Expert Hacker Needed.
 
contact facebook? seems like a bug to me.

AMD 2013-03-20 14:45

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by erendorn (Post 1330295)
contact facebook? seems like a bug to me.

No; in fact you can only change your username which links to the timeline once. And the hacker used this chance to change it. I got back my old username somehow but it is invalid now thus my timeline won't open, resulting with 'Page Not Found.'

sifo 2013-03-20 21:40

Re: [URGENT] Expert Hacker Needed.
 
Nice Adventure AMD, Congrats getting your account back, it was funny reading the whole thread :p

erendorn 2013-03-20 21:57

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1330302)
No; in fact you can only change your username which links to the timeline once. And the hacker used this chance to change it. I got back my old username somehow but it is invalid now thus my timeline won't open, resulting with 'Page Not Found.'

I'd still try to contact them, explain it wasn't you, and all.
Not that you have many alternatives :/

AMD 2013-03-21 10:15

Re: [URGENT] Expert Hacker Needed.
 
I will see, thanks anyway guys for all your help :)
Edit: I contacted Facebook again with more details, waiting for response.

sunyakram 2013-03-21 17:37

Re: [URGENT] Expert Hacker Needed.
 
Try fb security code , when you login on fb,fb send you a 6 letter code every time on your mobile, any cracker cant crack it, hope it help

AMD 2013-03-21 17:54

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by sunyakram (Post 1330571)
Try fb security code , when you login on fb,fb send you a 6 letter code every time on your mobile, any cracker cant crack it, hope it help

It's not my account anymore. I secured it and accessed it. And I didn't leave any account which belongs to that cracker after I've traced him. The thing is that I can't access my timeline page, not account..

AMD 2013-03-22 18:18

Re: [URGENT] Expert Hacker Needed.
 
Guys can you trace this bastard for me? IP= 77.42.200.184

geektech 2013-03-22 18:53

Re: [URGENT] Expert Hacker Needed.
 
Beirut, Lebanon.

AMD 2013-03-22 18:55

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by geektech (Post 1330902)
Beirut, Lebanon.

I know, but I need his name.

geektech 2013-03-22 19:01

Re: [URGENT] Expert Hacker Needed.
 
you know that could be somebody else on an open network?

AMD 2013-03-22 19:03

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by geektech (Post 1330905)
you know that could be somebody else on an open network?

I don't know actually, but it happened when I was talking to my friend, he hacked his account and starting messing with my friend. I was trying to defend my friend then the crazy bastard got angry with me and started telling me that he'll hack me too. I really don't care if he hacks it but I'm afraid he'll send something bad to my friends. So, I want his name and the rest is on me..

Dave999 2013-03-22 19:21

Re: [URGENT] Expert Hacker Needed.
 
Quote:

Originally Posted by AMD (Post 1330896)
Guys can you trace this bastard for me? IP= 77.42.200.184


IP address: 77.42.200.184
ISP: LIBANTELECOM
Country: Lebanon (LB)
latitude: 33.8333
longitude: 35.8333


go to the coordinates and you will find him...the best way to surprise him would be to parachute during the night with nightvision and air support. If you need help just call me.


All times are GMT. The time now is 12:10.

vBulletin® Version 3.8.8