Message boards : Number crunching : Attempted Hacking???
Author | Message |
---|---|
Gen_X_Accord Send message Joined: 5 Jun 06 Posts: 154 Credit: 279,018 RAC: 0 |
Has anyone noticed anything that resembles attempted hacking or unauthorized access to their personal computers since installing and running BOINC for Rosetta? I installed BOINC for the Rosetta project after reading about it a few days ago on Yahoo news and thought it a noble cause to dedicated my spare processing power to. When I get home from work at about 1 or 2 a.m. I turn on my pc, read then news, and go to bed, leaving my computer on for the time I am home to run the BOINC for Rosetta. I do not use the screen saver graphic, I just shut my monitor off to conserve power. The first morning I woke up, my web browser was open. I began to suspect unathorized entry then. I notices nothing amiss for the next two nights, but this morning when I woke up, I found I could not see any results on my BOINC manager and it gave me a message saying "Password not Accepted" and the Boinc manager was effectively locked out for me, I had to restart my pc to reset everything. Now...I am no security slouch. I have Norton Antivirus, Zonealarm Firewall, and two active spyware scanners all on at one time. Nothing gets through Zonealarm without my permission. The BOINC subsequently has permission, and I am wondering if someone is using it to try to access my computer. Has anyone else experienced problems like this??? Any suggestions outside of shutting off my internet connection while I am not online??? |
Dogbytes Send message Joined: 4 Dec 05 Posts: 37 Credit: 207,563 RAC: 0 |
Has anyone noticed anything that resembles attempted hacking or unauthorized access to their personal computers since installing and running BOINC for Rosetta? I installed BOINC for the Rosetta project after reading about it a few days ago on Yahoo news and thought it a noble cause to dedicated my spare processing power to. When I get home from work at about 1 or 2 a.m. I turn on my pc, read then news, and go to bed, leaving my computer on for the time I am home to run the BOINC for Rosetta. I do not use the screen saver graphic, I just shut my monitor off to conserve power. The first morning I woke up, my web browser was open. I began to suspect unathorized entry then. I notices nothing amiss for the next two nights, but this morning when I woke up, I found I could not see any results on my BOINC manager and it gave me a message saying "Password not Accepted" and the Boinc manager was effectively locked out for me, I had to restart my pc to reset everything. Now...I am no security slouch. I have Norton Antivirus, Zonealarm Firewall, and two active spyware scanners all on at one time. Nothing gets through Zonealarm without my permission. The BOINC subsequently has permission, and I am wondering if someone is using it to try to access my computer. Has anyone else experienced problems like this??? Any suggestions outside of shutting off my internet connection while I am not online??? I have seen peeps using the same AVP/Firewall setup as you've got and their computers were riddled with malware. BTW, Norton uses up CPU cycle like a pig at the county fair and many anti-spyware programms don't react to the latest invaders and/or detect them once they're entrenched. For starters you should be using some sort of router with a hardware firewall as a gateway. It is better to stop a thief down the street than at your front door. The only really effective AVP's run in rootkit like Kaspersky and BitDefender. Norton, McAfee, AVG, Avast, (and they only update Dat files once a week or once a day instead of hourly) are all junk and give their users a false sense of security. If you feel that your computer has been compromised, you should consider backing up your critical personal files, doing a destructive F&R, then installing a decent AVP and washing your backup disc first before reloading it. There is nothing known in Boinc that causes any specific security issues at this moment. Of all the AVP's on the market I recommend Kaspersky. It currently has 199,284 Dat files that cover all known bugs including mal/spyware up to 1 hour ago. It is better at detecting spyware than any anti-sypware program out there. Remember another thing, when it's free, you get what you paid for, i.e. nothing. Ad-aware is one of the biggest pieces of junk out there, BTW. |
Astro Send message Joined: 2 Oct 05 Posts: 987 Credit: 500,253 RAC: 0 |
I've been with boinc since day one, am a Boinc Alpha tester (I see the back channel talk). I've not heard of a boinc virus like you describe. I have heard on one user writing an install script which installed boinc on peoples computers under someone elses account. Last I heard that was stopped by Seti management and the users account zeroed. I suspect you need startpagedefender, and a toolbarcop. Some maleware is using your puter. tony |
Ethan Volunteer moderator Send message Joined: 22 Aug 05 Posts: 286 Credit: 9,304,700 RAC: 0 |
Also be aware there is a VNC vulnerability that will allow anyone to take over your desktop if you have VNC server running (it's something you have to install, so if you don't know what VNC is, you probably don't have it). I was sitting at my work computer and suddenly the mouse started jumping around the screen. Fun stuff :) |
Dogbytes Send message Joined: 4 Dec 05 Posts: 37 Credit: 207,563 RAC: 0 |
Also be aware there is a VNC vulnerability that will allow anyone to take over your desktop if you have VNC server running (it's something you have to install, so if you don't know what VNC is, you probably don't have it). I was sitting at my work computer and suddenly the mouse started jumping around the screen. Fun stuff :) Good point, LOL. |
Dogbytes Send message Joined: 4 Dec 05 Posts: 37 Credit: 207,563 RAC: 0 |
Also be aware there is a VNC vulnerability that will allow anyone to take over your desktop if you have VNC server running (it's something you have to install, so if you don't know what VNC is, you probably don't have it). I was sitting at my work computer and suddenly the mouse started jumping around the screen. Fun stuff :) @ Tony...I remember that...the Seti Zombie. Try to find that at Symantec. |
Feet1st Send message Joined: 30 Dec 05 Posts: 1755 Credit: 4,690,520 RAC: 0 |
BOINCs internet traffic all initiates from your PC. In other words, the project doesn't contact you, it's always the other way around. The BOINC Manager contacts the project to send results, or request work. So, your firewall should not have been impacted by your installation of BOINC, and therefore, your exposure not increased. If this is now happening consistently, suggest you exit BOINC (using File -> Exit) to shut everything down. Leave the PC on and see if same happens when BOINC is not running. What website does the browser land on? Add this signature to your EMail: Running Microsoft's "System Idle Process" will never help cure cancer, AIDS nor Alzheimer's. But running Rosetta@home just might! https://boinc.bakerlab.org/rosetta/ |
Gen_X_Accord Send message Joined: 5 Jun 06 Posts: 154 Credit: 279,018 RAC: 0 |
If Norton, Zonealarm, Windows Defender, Spybot S&D, and Adware SE can't catch all the problems, then I give up. I don't have VNC either, whatever it is. And I just downloaded a free version of Bitdefender. Maybe that will find what the others can't seem to. As far as toolbars go, I use Firefox and I don't allow toolbars of anykind to be installed on my I.E. browser. In fact, I hate toolbars. My Broswer was only open on my start page, which is Yahoo news. I'm a news junkie. |
Astro Send message Joined: 2 Oct 05 Posts: 987 Credit: 500,253 RAC: 0 |
If Norton, Zonealarm, Windows Defender, Spybot S&D, and Adware SE can't catch all the problems, then I give up. I don't have VNC either, whatever it is. And I just downloaded a free version of Bitdefender. Maybe that will find what the others can't seem to. As far as toolbars go, I use Firefox and I don't allow toolbars of anykind to be installed on my I.E. browser. In fact, I hate toolbars. My Broswer was only open on my start page, which is Yahoo news. I'm a news junkie. do you have a pet? I've seen animals playing with mice(no pun intended) Also, there's links to other software at how to get rid of a Start Page? |
Gen_X_Accord Send message Joined: 5 Jun 06 Posts: 154 Credit: 279,018 RAC: 0 |
No pets. And my mouse is trackball optical.(I hate having to move around regular mice.) As far as my start page, Yahoo news is my own preferred setting(Even thought Yahoo sucks and helped China track down a few people for voicing their opinions).And since they get their new mostly from the Associated Press anyway, I should make the AP my start page. The only problem I ever have with start pages it the stupid IE keeps wanting to open up to microsoft update even though Yahoo news is my default start page. Finding the browser open didn't really bother me, but having the BOINC client locked out and give me an "incorrect password" message made me think that somthing was fishy. I would just as soon let the Boinc run and the internet connection shut off, it is a low speed,256k, connection, but the Boinc doesn't seem to like to work without an internet connection. Oh well. And thank you to everyone for responding. Ohh, and this free version of Bit defender is finding infected stuff. So thanks for the heads up on better virus software. But I do like some of the features of of Norton Internet Security. Like the Parental Controls for internet site viewing. Their are things that I like to keep my kids, away from online. |
Snake Doctor Send message Joined: 17 Sep 05 Posts: 182 Credit: 6,401,938 RAC: 0 |
No pets. And my mouse is trackball optical.(I hate having to move around regular mice.) As far as my start page, Yahoo news is my own preferred setting(Even thought Yahoo sucks and helped China track down a few people for voicing their opinions).And since they get their new mostly from the Associated Press anyway, I should make the AP my start page. The only problem I ever have with start pages it the stupid IE keeps wanting to open up to microsoft update even though Yahoo news is my default start page. It sounds as though someone may have tried to use the remote monitoring feature of BOINC on your system. THis can be activated by use of the "Select Computer" option from the "Advanced" menu in BOINC version 5.4.9. If the person does not have the correct password, they would get the error message you describe, and it would leave the computer disconnected from the "Local Host". But it would have to have been activated from your computer. You can tell if the computer is disconnected from the local host by looking in the lower right corner of the BOINC Manager window. It will say one of three things 1) Disconnected 2) Connected to localhost (normal operating mode) 3) Connected to XXXXX (where XXXXX is another system) There is a password required to use this feature. It is there for "Farmers" who want to monitor and control many systems from one computer. In any case, if the manager is "Disconnected" the task window will appear as empty, as will all other tabs except the Message window. Usually you can reestablish the connection by use of the "Advanced" menu Select computer option. Failing that shutting down BOINC and restarting it will cause a reconnect. Your browser could have been loaded from the Project window in the BOINC manager, if someone had managed to make a remote connection. There is a way to prevent even an attempt to use remote control by creating a file that in effect locks out that feature in your BOINC Files directory. There is a lot more about all this in the BOINC WIKI. We Must look for intelligent life on other planets as, it is becoming increasingly apparent we will not find any on our own. |
Feet1st Send message Joined: 30 Dec 05 Posts: 1755 Credit: 4,690,520 RAC: 0 |
...but the Boinc doesn't seem to like to work without an internet connection. Oh, you've misunderstood. You have just pointed out another good Q&A item for me, so I've addressed this point there. Add this signature to your EMail: Running Microsoft's "System Idle Process" will never help cure cancer, AIDS nor Alzheimer's. But running Rosetta@home just might! https://boinc.bakerlab.org/rosetta/ |
BennyRop Send message Joined: 17 Dec 05 Posts: 555 Credit: 140,800 RAC: 0 |
I've run spybot S&D, Adaware, Ewido, TrojanHunter, bitdefender, Panda's online scan www.pandasoftware.com, and TrendMicro's scan. And I still find spyware/trojan/worm/malware traces on the 7th scan of heavily infected systems, no matter which app ends up being #7. With the unending list of vulnerabilities in Windows, I've recommended hardware firewall/Nat routers so you don't find out you're susceptible to attack from the internet from whatever the new vulnerability is that isn't protected by your software firewall. Make it harder.. :) If you're not currently using it, you might thing of using Spywareblaster to cut down on the number of infected sites you can visit with your browser. (Which really helps when the person infecting your system doesn't follow your security recommendations.) |
Dogbytes Send message Joined: 4 Dec 05 Posts: 37 Credit: 207,563 RAC: 0 |
No pets. And my mouse is trackball optical.(I hate having to move around regular mice.) As far as my start page, Yahoo news is my own preferred setting(Even thought Yahoo sucks and helped China track down a few people for voicing their opinions).And since they get their new mostly from the Associated Press anyway, I should make the AP my start page. The only problem I ever have with start pages it the stupid IE keeps wanting to open up to microsoft update even though Yahoo news is my default start page. Linksys routers (Cisco Systems) have a parental control next to none...but it takes some configuring, also you get the benefit of a real hard firewall as well. |
Moderator9 Volunteer moderator Send message Joined: 22 Jan 06 Posts: 1014 Credit: 0 RAC: 0 |
No pets. And my mouse is trackball optical.(I hate having to move around regular mice.) As far as my start page, Yahoo news is my own preferred setting(Even thought Yahoo sucks and helped China track down a few people for voicing their opinions).And since they get their new mostly from the Associated Press anyway, I should make the AP my start page. The only problem I ever have with start pages it the stupid IE keeps wanting to open up to microsoft update even though Yahoo news is my default start page. And they are not too expensive. Moderator9 ROSETTA@home FAQ Moderator Contact |
m.mitch Send message Joined: 10 Feb 06 Posts: 34 Credit: 1,928,904 RAC: 0 |
Also be aware there is a VNC vulnerability that will allow anyone to take over your desktop if you have VNC server running (it's something you have to install, so if you don't know what VNC is, you probably don't have it). I was sitting at my work computer and suddenly the mouse started jumping around the screen. Fun stuff :) That's one of those things were you wonder how long ago they found your web cam 8-O Click here to join the #1 Aussie Alliance on Rosetta |
Gen_X_Accord Send message Joined: 5 Jun 06 Posts: 154 Credit: 279,018 RAC: 0 |
...but the Boinc doesn't seem to like to work without an internet connection. I've read the Q&A you linked to, but that brins me to another question. If BOINC doesn't need the internet, even though my Zonealarm show the activity, why does the BOINC freeze up if I lock my internet connection with either my Zonealarm, or if I shut my internet connection off with the button on top of my cable modem??? |
Astro Send message Joined: 2 Oct 05 Posts: 987 Credit: 500,253 RAC: 0 |
I've read the Q&A you linked to, but that brins me to another question. If BOINC doesn't need the internet, even though my Zonealarm show the activity, why does the BOINC freeze up if I lock my internet connection with either my Zonealarm, or if I shut my internet connection off with the button on top of my cable modem??? There are three parts to Boinc; The Daemon, the Manager, and the Screensaver. The Daemon and the Manager communicate with eachother via an internal port (either 1043 or 31416, and is called "the Loopback address"), this is recorded as network traffic, even though it never leaves your computer. If you lock which ever port you're using, boinc will stop working. hope this helps tony Note: actually the Daemon should keep working(you can see this by the fact that "rosetta_5.15/5.22_windows_intelx86.exe is listed with a cpu percentage in your "task manager"), it's just that the Manager won't display any information, and you can't change anything with it. |
mnb Send message Joined: 15 Dec 05 Posts: 51 Credit: 69,458 RAC: 0 |
There is a way to prevent even an attempt to use remote control by creating a file that in effect locks out that feature in your BOINC Files directory. There is a lot more about all this in the BOINC WIKI. Could you provide a link to this file creation info? list of my results |
Astro Send message Joined: 2 Oct 05 Posts: 987 Credit: 500,253 RAC: 0 |
There is a way to prevent even an attempt to use remote control by creating a file that in effect locks out that feature in your BOINC Files directory. There is a lot more about all this in the BOINC WIKI. How to control remote computers in the Wiki |
Message boards :
Number crunching :
Attempted Hacking???
©2024 University of Washington
https://www.bakerlab.org