how is this being pulled off?

Discussions of applications and operating systems and any problems, tips or suggestions. Win XP, 9x/2k, Linux, NT, photo editing, Virus/Spyware help
Post Reply
MidnightSin
Senior Member
Posts: 268
Joined: Sat May 20, 2006 12:58 pm
Location: TEXAS

how is this being pulled off?

Post by MidnightSin »

I have a bud who was busted at work yesterday surfing on the net.

No big trouble or anything but we have yet to figure out how he got busted yet. so heres a basic rundown of the situation.

He totally reformatted and reinstalled everything on the comp in his lab at work 3 days ago. His pc is not on any local network and its net access is via Xanadoo wireless modem which only sends signal from the modem to the wireless tower 11 miles away. As far as he can tell (and he is pretty computer savvy) there are no programs installed to monitor his surfing in anyway. He cant find a single program on his comp that he himself did not install. But yet he was asked why he went to http://www.mousebreaker.com at 10:30 am 2 days ago.

Only thing we could think of was maybe someone went into his lab after hours with another key to his lab and actually looked back through his browser history. I personally have never had to deal with any monitoring software as I have always had a job where I could surf the net if I wanted.

Any of you guys got any ideas how this was pulled off?
Image
User avatar
wvjohn
Posts: 9238
Joined: Wed Nov 22, 2000 7:09 am
Contact:

Post by wvjohn »

keystroke logger?
<a href="http://www.heatware.com/eval.php?id=123" target="_blank" >Heatware</a>
User avatar
b-man1
Posts: 5201
Joined: Wed Nov 22, 2000 10:23 am

Post by b-man1 »

it's a company ISP? whoever pays the bill could be getting a usage report or easily request one at any time.

.02
Trench
Genuine Member
Posts: 49
Joined: Wed Feb 15, 2006 8:01 am
Location: Miami
Contact:

Post by Trench »

somebody probably saw him go there.
User avatar
nexus_7
Posts: 10306
Joined: Wed Nov 22, 2000 12:09 pm
Location: chicago land area.
Contact:

Post by nexus_7 »

there are plenty of hardware web trackers out there. we have one at work...cant remember the name though. Just hardware that sits between network and internet.

Greg
<a href="http://www.pcabusers.org" target="_new"> <img src="http://www.pcabusers.org/images1/banner.jpg" border="0"></a>
<a target=NEW href="http://setiathome.ssl.berkeley.edu/stats/team/team_87793.html">JOIN the PCA Seti Team!</a>
User avatar
nitro237
Posts: 3205
Joined: Wed Nov 22, 2000 7:14 pm
Location: Louisiana

Post by nitro237 »

proxy settings? hidden video camera?
Image


Image
User avatar
eGoCeNTRoNiX
Posts: 7362
Joined: Wed Oct 23, 2002 12:51 pm
Location: HELL

Post by eGoCeNTRoNiX »

Originally posted by nitro237
hidden video camera?


heh.. something about that just doesn't sound right, but possible!
PM before Email People!!
Image
Heat Under eGoCeNTRoNiX :)
Who Farted? BEANIE!!!
!Welcome to the United States of the Offended!
User avatar
nitro237
Posts: 3205
Joined: Wed Nov 22, 2000 7:14 pm
Location: Louisiana

Post by nitro237 »

Originally posted by eGoCeNTRoNiX
heh.. something about that just doesn't sound right, but possible!


Very possible. I am 100% positive it can be done.
Image


Image
User avatar
eGoCeNTRoNiX
Posts: 7362
Joined: Wed Oct 23, 2002 12:51 pm
Location: HELL

Post by eGoCeNTRoNiX »

Originally posted by nitro237
Very possible. I am 100% positive it can be done.


No No, not doubting it can be done.. I've done it myself.. Just wondering if it's possible in his buddies lab.. Depending on the type of lab, I'd suspect he'd probably have noticed one maybe kinda sorta.. I guess 99% of people who are being watched by one never know it's there though..

eGo
PM before Email People!!
Image
Heat Under eGoCeNTRoNiX :)
Who Farted? BEANIE!!!
!Welcome to the United States of the Offended!
MidnightSin
Senior Member
Posts: 268
Joined: Sat May 20, 2006 12:58 pm
Location: TEXAS

Post by MidnightSin »

Ok I talked with the ISP (We have the same ISP) They offer NO type of monitoring at all. He changed the locks on his lab and totally reformatted again. So we will see what happens now. Like I said he isnt in any kind of big trouble over the deal, its just he could find nothing other than what he installed on the machine running and we knew it wasnt coming from the ISP but had to double check. remember this machine is not on any of the companies networks. It has its own wired net connection to wireless modem that only serves that machine and is not connected to any type of router and the ISP wont provide any monitoring services of any kind.

So the bottom line is someone probably came into his lab and checked his bowser history.

IF and when I figure out how they did it. even if its just as simple is someone snuck in I'll let you guys know.
Image
canton_kid
Golden Member
Posts: 1400
Joined: Tue Mar 26, 2002 5:01 pm
Contact:

Post by canton_kid »

It has its own wired net connection to wireless modem


Could that be a clue? Is is possible the company or whatever can monitor the wireless part of the system?
Not sure what you meant by that, wireless modem? WIFI, Satalite....?
Canton_kid

spam bot food!
<A HREF="http://www.auditmypc.com/freescan/antispam.html">Anti-Spam</A>
MidnightSin
Senior Member
Posts: 268
Joined: Sat May 20, 2006 12:58 pm
Location: TEXAS

Post by MidnightSin »

By wireless modem I mean its actuallt wired via cat5 to the comp and has a power cord, but otherwise sends and recieves via wireless signal to a tower at the ISP 11 miles away.
Image
User avatar
wpublic
Senior Member
Posts: 350
Joined: Sun Jan 06, 2002 6:07 am
Location: nashville, tn

Post by wpublic »

what brand/model firmware version is the wireless device the comp is plugged into?

could it be using something like this??
http://www.navini.com/Website/Content/P ... MX_EMS.htm


there is a strong possibility that the device is logging activity and storing it locally in an EEPROM or forwarding the log to another IP or even email address.
MidnightSin
Senior Member
Posts: 268
Joined: Sat May 20, 2006 12:58 pm
Location: TEXAS

Post by MidnightSin »

Yep its the Navini MX modem. It's used by an ISP in our area named Xanadoo. I sold them the modem as our store is a reseller for Xanadoo. I called the ISP and asked them if we offered any monitoring packages for companies that wish to monitor thier employees and they said they did not.

As for software or something else installed on the system we know now for sure that there is nothing as my friend just completly reformatted the system. He alse changed the locks on his lab.

So we'll see what happens from here.
Image
Post Reply