Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

I think we were hacked, what do you think.

Status
Not open for further replies.

mhaff

Technical User
Jan 31, 2003
55
US
On Jan 20th people came to work and shortly found out
that they could not receive email. They COULD send email and surf
the web. I'm the "psuedo" IT guy here and I wasn't in the office. So someone called our computer/IT service dealer to check it out. He wasn't able to log on to our Netopia(R7200) router which led him to believe that the login and password had been changed by me. I didn't change it. As a temporary work around we set up some people with a yahoo mail account and had it pull mail from our pop address. To our amazement, one user, who typically gets about 25 emails a day, got about 500, and then 1000 the next day. Our DSL provider was telling us that without the log in and password we would have to buy a new router. Then on thurday evening, I came into the office and all of the sudden I could get email. The next day, everyone else was getting their mail. And, the user that was getting 500 to 1000 mails, after a couple of days, told me that his incoming email had tapered down to it's normal volume.

I think we were hacked from the outside. I suspect someone logged in to our router with the default login and password and changed the settings(I understand that there is a setting the won't allow incoming email). I'm not sure how to relate it to the flood of emails the one guy was getting, but I think it is related.

Does anyone have comments? Agree or disagree?

Also, since then, I found that it is quite simple to restore the Netopia to original factory settings. I'm quite upset with our DSL provider for telling us we needed a new one.

One more thing, every now and again, I have to power down the router because we lose DSL access. When I power it up again, we regain access. Our provider can't figure out what the problem is. Suggestions?

Thank you to everyone who had the patience to read this long winded post.
 
One word to the wise... ALWAYS change your login and password to anything you did not set. And most providers cannot tell you anything about the routers they sell you, better to check out the manufacturers website. Netopia has very good support... Thanks,

Matt Wray
 
As to the powering up and down of your router... I had a similar problem with SBC DSL, and it turned out that shortening the cable from the wall to the modem solved things (went from ~25 feet to ~6 feet).

-Rob
 
It doesn't really sounds like a hacking session, more like a communications failure somewhere along the line.

If you have forgotten/lost/had changed the routers password you can reset it back to factory defaults (I've never seen a router without this function).
 
Netopia R7200 is a good router.

1. check your connection about the sync going up and down.
2. what kind of dsl? sym or adsl?
Is your speed setting to high for what distance you are from the co? although you will probably have to ask your ISP provider for that info. If you have a sunset tester you can test providing you have the right adsl or sdsl card to test to the dslam.

3. change that password and keep the IP secure so someone cannot telnet into it.
and finally who is the ISP you have? that said you needed a new router? what a sham they are.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top