question ?

For beginners, flames not allowed...(just by the staff :P)
Post Reply
User avatar
devil_ducky666
Newbie
Newbie
Posts: 1
Joined: 27 May 2007, 16:00
16

question ?

Post by devil_ducky666 »

well there are a few questions that i have ..
1. my wifes email accounts keep getting hacked . it seems she has to make a new one every week. one day she asked me if i sent her an ecard .. i said no and she opened it a few days latter her password was changed ... now for the question ... could that "ecard" have something inbedede into it to steal a password? and if so what ?
2. on the same note i know that one way to get a password is with a keylogger ... could this person be getting it someother way like with a "remote" or going through a "backdoor" ect...
3. is there a way that i could find out that persons ip addy and report him?
i thank you ahead of time

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

1. definitely yes. pictures in emails can be linked to trojan downloaders for example....I always recommend to disable linked images in emails (can be done in most email clients or antivirus apps)....if a person you know want to send you a picture he'll simply add it as attachment and not link it, so linked images are always very suspicious.

2. sure, but usually the classic backdoors need a running service which can be accessed from the outside, like a webserver. in your case it's most likely either a keylogger/remote administration tool ("trojan") which has been downloaded by the ecard (or in others ways, at the moment instant messaging apps are very popular to distribute malware), or a browser hijacker which directs to a phishing site instead of the real one when entering the URL for the email account login. if your wife has used different email providers it's most likely a keylogger/trojan, if it was always the same provider (like hotmail for example) it's most likely a hijacker.

3. first the kind of infection needs to be identified, run full system scans with your AV (I hope there is one installed), also get Ad-Aware and Spybot:
http://www.safer-networking.org/en/download/index.html
http://www.download.com/3000-2144-10045910.html
when done let us know if anything was found, you can also get "hijack this" and post here the report it created:
http://www.merijn.org/files/HiJackThis_v2.exe
when we have identified the problem it might be possible to trace the data back to the source...

until this issue is solved no sensitive data should be transfered by this computer...
:wink:

User avatar
Lyecdevf
cyber Idi Amin
cyber Idi Amin
Posts: 1222
Joined: 16 Mar 2006, 17:00
18
Location: In between life and death.
Contact:

Re: question ?

Post by Lyecdevf »

devil_ducky666 wrote: 3. is there a way that i could find out that persons ip addy and report him?
Do not bet on it. If you want justice on the internet you got to hack him back. They do not call cyberspace of 2007 the Chicago of 1920 for nothing.
We will either find a way, or make one.
- Hannibal

Post Reply