First I wanna say that I would never leave my personal stations in this level of neglect. The computer I'm talking about came as part of a business I and my gf purchased a few months ago. I've been a little swamped and never got around to protecting this computer.
Second, this is a busy salon, and if you know cosmetologists you'll know how they've been using the computer...
[aside: I was reading about a hack that used the NT Lan Manager to get past firewalls, etc. which is why I asked about NTLM Auth. Oh, and I'm not a programmer, thus the stupid question. :) ]
karmarec wrote:2. You can see live connection information for your XP machine by going to the command prompt and typing "netstat -a"
Nice. Thanks. I like to know stuff like this. :)
karmarec wrote:3. You ISP will almost certainly not provide you with any traffic info for your connection (they probably aren't doing anything more than setting bandwidth caps and using packet shapers....)
This boggles my mind. I know the storage would be insanely costly, but how exactly does the government catch good hackers? I assume they don't. With notebooks being essentially disposable...
karmarec wrote:So a few questions for you:
1. How do you connect to the internet (dial up, dsl, cable etc...)
2. Do you have a modem device for your connection
3. Do you have a wireless access point or router (or maybe both) on your home network?
1. The computer in question is using dsl on a dedicated line. Don't look at me that way. :) Lol. I didn't set it up.
2. Dsl modem with the wireless deactivated.
karmarec wrote:The information you provided is a little less than what would be needed to tell you much more. If you want to save off your event logs (system, application, security) and ship em over I'll have a look at them, but no telling if any info would be in there that would be useful.
That would be great. I have sys and app logs, and an empty security log. I'll email you soon. Very generous of you to offer. :)
karmarec wrote:On a very general note, it would take a long time to grab all the stuff from your hard drive over a typical internet connection, if you have cable you might be able to upload at 756Kbps (that's bits not bites), at best. So just getting a megabyte (8000 kbits) of data over would take some time. It's very unlikely someone actually was able to pull the contents of your hard drive over unless you were away from your machine for a long time....
Very good to know. I immediately was reminded of how long it takes for uploads on my wireless, so this makes prefect sense to me. The computer was on all the time, for a scheduling proggy that the girls use...
busbus wrote:NT Lan Manager? 1998 called and they want their OS back. I kid.
How's Madison this time of year? I understand it's a little brisk. :P :)
ChristopherM wrote:The whole reason that I asked about your firewall situation is because (if you had one) it really would be key here. Your local system log files aren't going to be a whole lot of help...and your ISP isn't going to give you jack shit. But, since it doesn't sound like you have anything set up (other than what is probably built into your modem) it's going to make it much more difficult to figure out if what you think happened actually did happen.
Yeah. You guys are painting a picture. I'm starting to think that under the circumstances someone actually came into the business and took the files that they wanted and deleted everything else. I was thinking about how I would delete a bunch of files, and I came up with a search for a string of file suffixes something like, '*.mp3,*.doc,*.xls,*.html...' selecting and deleting all found. I haven't tested it because I'm not entirely stupid. :) Lol. Just kinda stupid. It could be done inside 10 minutes right?
ChristopherM wrote:Does the version of NAV you have include a "personal firewall" feature? If so, have you checked those logs?
Nope. No firewall logs.
Today I'm installing Norton Internet Security, a key-logger, all proggy updates, all windows updates, etc. Gunna add 512 RAM, vista, and a wireless router. Gunna change the carrier too. Passwords, etc.
ChristopherM wrote:You would definitely have to give up some more info if you wanted any real help here, but with what you've said so far, I highly doubt someone hacked in from outside, copied and/or deleted all your files, etc. etc. I'd say it was someone that was physically there in front of the system. Any recently fired employees hanging around or anything? Haha!
Like I said, we just bought this salon, and we got it at a very good price. The previous owner is apparently experiencing seller's remorse. Also, she's not a very nice person.
Thanks guys! I'm starting to get a better picture here.