How can I trace someone stealing ADSL username and password?

Viruses, hackers and crackers
Post Reply
Colin_69
Registered User
Posts: 378
Joined: 16 Nov 2004, 02:00
Location: Stellenbosch

How can I trace someone stealing ADSL username and password?

Post by Colin_69 »

Im sure that this question has popped up a few times before. So im sorry for the double post, but this is quite urgent.

ISP is one of our company's services, and one of our clients is threatening to sue us over this issue. So what would be the quickest and most efficient way of tracing the unauthorized usage of our ADSL usernames? Can this only be done through telkom?

*stealing for heaven sake! - jee*
ASUS P6T | Core I7 920 @ 3.4 |MSI 6950 Unlocked | 3x2048 Corsair Dominator @ 1600 8 8 8 24 (Corsair CMXAF1 Cooler) | Coolermaster HAF932 | Corsair TX850W | Logitech Z5500 | Logitech MX518 | X-FI Platinum | Samsung T260 | 8.5TB Storage
Colin_69
Registered User
Posts: 378
Joined: 16 Nov 2004, 02:00
Location: Stellenbosch

Post by Colin_69 »

I have the IP addresses assigned to the person on every sessions he used. Obviously the IPs change
ASUS P6T | Core I7 920 @ 3.4 |MSI 6950 Unlocked | 3x2048 Corsair Dominator @ 1600 8 8 8 24 (Corsair CMXAF1 Cooler) | Coolermaster HAF932 | Corsair TX850W | Logitech Z5500 | Logitech MX518 | X-FI Platinum | Samsung T260 | 8.5TB Storage
PsyCLown
Registered User
Posts: 6159
Joined: 16 Feb 2006, 02:00
Location: Johannesburg - Bryanston

Post by PsyCLown »

Hmm, so your company is an ISP and now your clinet is having someone stealing his bandwidth and is complaining to sue your company.

It might be his fault as he might now have changed the default password on his router.

But I think the only way to trace the people would be through Telkom or IS (depending on whos bandwidth you are reselling).
“The true bare of any man is his willingness to accept the consequences of his actions.” - iser0073

Image
Spoiler (show)
APPARENTLY 92% Of Teens Have Moved On To Rap Music.
If You Are Part Of The 8% That Still Listen to real music then put this in your signature.
Cameron_Losco
Moderator Emeritus
Posts: 2338
Joined: 30 May 2002, 02:00
Location: Out there somewhere

Post by Cameron_Losco »

And don't you have something in your TOS that states that you are not responsible for unauthorized usage? I'd contact Telkom but I have a feeling that you aren't going to get very far.
Colin_69
Registered User
Posts: 378
Joined: 16 Nov 2004, 02:00
Location: Stellenbosch

Post by Colin_69 »

Im not to worried about him suing us, we spoke to the client again and he just wants justice, cuz he paying for 5GB every month and this person is raping all the bandwidth. We just want to stop the abuse of our client's usernames, because this issue is beginning to blow up in our faces
ASUS P6T | Core I7 920 @ 3.4 |MSI 6950 Unlocked | 3x2048 Corsair Dominator @ 1600 8 8 8 24 (Corsair CMXAF1 Cooler) | Coolermaster HAF932 | Corsair TX850W | Logitech Z5500 | Logitech MX518 | X-FI Platinum | Samsung T260 | 8.5TB Storage
jPm
Registered User
Posts: 1009
Joined: 05 Aug 2005, 02:00
Location: Capetown
Contact:

Post by jPm »

Hmmm.

Your client says he's/shes bandwidth is being used by some-one else. Then It should def. come up on your systems(that is there IP address).

NB: This person doesnt necessarily need a Username and Password, they could be using the WiFi of this person which has nothing to do with your ISP.


Phone your client again ask them a few questions more.



Im with Webafrica and If there is more than one person logged in at any time the IPs come up. So if the IPs are not coming up, then its defnitely through Wifi or your client just uses up alot of bandwidth
Slasher
Registered User
Posts: 7525
Joined: 23 Aug 2003, 02:00
Location: 5th rock from the sun.

Post by Slasher »

Well, change the username and password of your client and send it to him/her. If this does not immediately stop this bandwidth you know it is not via username but via wlan.


Did the client change the default username/password?

Also, changing should stop the access. Either you have someone in your company selling usernames or you was hacked in the database if the guy's network is secure and he did not give it out. Any other clients give complaints?
My BF2142 Stats:
Image


Slasher : Former member of www.PCFormat.co.za
I have reached the end of my near 5 year forum life. Farewell good days...

slasher (at) webmail (dot) co (dot) za
User avatar
Stuart
Lead Forum Administrator
Posts: 38503
Joined: 19 May 2005, 02:00
Location: Home

Post by Stuart »

Slasher wrote:Well, change the username and password of your client and send it to him/her. If this does not immediately stop this bandwidth you know it is not via username but via wlan.


Did the client change the default username/password?

Also, changing should stop the access.
My thoughts exactly. If someone is using his username and password, change said username and password, and tell him to protect the new details better.
Image
KillerByte
G3AR Staff Member
Posts: 5790
Joined: 08 Mar 2003, 02:00
Location: PCFormat HQ
Contact:

Post by KillerByte »

this is why people should have their AP's encrypted using WPA. Or else you get Wardrivers getting your cap and your files. Believe me, I know, cause I am one.
What I type has nothing to do with the people that employ me.
Futs
Registered User
Posts: 1565
Joined: 23 Oct 2003, 02:00
Location: Pretoria

Post by Futs »

KillerByte wrote:this is why people should have their AP's encrypted using WPA. Or else you get Wardrivers getting your cap and your files. Believe me, I know, cause I am one.
So you get peoples cap and files? (illegally of course)
Image
User avatar
Ron2K
Forum Technical Administrator
Posts: 9050
Joined: 04 Jul 2006, 16:45
Location: Upper Hutt, New Zealand
Contact:

Post by Ron2K »

This is KB we're talking about here. He wouldn't know what "legal" meant, even if he had to look it up in a dictionary, Google, or Wikipedia. :P
Kia kaha, Kia māia, Kia manawanui.
SBSP
Registered User
Posts: 3124
Joined: 09 May 2006, 02:00
Location: Centurion

Post by SBSP »

Or there could be a nasty application on his machine consuming bandwidth.
don't forget about that.
Sojourn
Registered User
Posts: 5649
Joined: 02 Sep 2004, 02:00
Location: Still looking...

Post by Sojourn »

o_O
You are offering a service as a provider, but dont know how to limit usage to only the MAC's provided by your customers?

Once you have limited the usage to that MAC and the usage stays the same you can tell your suing client where to go.

Pls tell me who your co is so I can avoid them.

s
User avatar
Ron2K
Forum Technical Administrator
Posts: 9050
Joined: 04 Jul 2006, 16:45
Location: Upper Hutt, New Zealand
Contact:

Post by Ron2K »

That's odd - I'm sure I replied to SBSP's post; no idea where it is. Must have navigated away from the page before I pressed "Submit". :oops:

It's entirely possible, given that most users don't have the full picture as to what their PC is doing. There could well be some sort of nasty on the client's PC that's causing excess bandwidth usage. Of course, it's also just as likely that a legitimate update process is responsible.

Given the circumstances of this case, bandwidth theft seems more likely than an app hogging the bandwidth, but that's not to say it's not a possibility.

EDIT: Sojourn, it probably wouldn't help much, given how easily a MAC address can be spoofed. :P
Kia kaha, Kia māia, Kia manawanui.
zerubabel
Registered User
Posts: 909
Joined: 08 Nov 2006, 02:00
Location: Durban

Post by zerubabel »

KillerByte wrote:this is why people should have their AP's encrypted using WPA. Or else you get Wardrivers getting your cap and your files. Believe me, I know, cause I am one.
Someone ban this fool plz.
You 'wardriver', you probably don't even know the first thing when it comes to accessing other people's routers etc, you just use a program and you think you are so clever and cool.
You are nothing more than a script-kiddie, and a criminal one at that.

You're lucky you are leaving soon, or i'd have you beaten at the next Uberlan/fraglan/etc.
Last edited by zerubabel on 23 Aug 2007, 18:13, edited 1 time in total.
Fut Fut Fut Freestailo!
zerubabel
Registered User
Posts: 909
Joined: 08 Nov 2006, 02:00
Location: Durban

Post by zerubabel »

@ Colin69, phone telscum and tell them you think someone is stealing bandwidth from this user.
They have a service to check this out... You just need to give them the username/email of the user, and which ISP it is, and they have a database to see who accessed that username when.

If they find its someone else, criminal charges can and will be pressed, otherwise it's your client who is having his internet raped via wi-lan.
Fut Fut Fut Freestailo!
RobThePyro
Registered User
Posts: 1210
Joined: 04 Dec 2006, 02:00
Location: Durbz!
Contact:

Post by RobThePyro »

LOL

zerubabel you forgot your <FlameON> and </FlameOn> Tags :wink: :lol: :twisted:

lol... kb...


Rob.
Image
PCF Dumbass of the Month Award!
"My lungs are in SLI :P"
Anthro
Moderator Emeritus
Posts: 5547
Joined: 21 Dec 2002, 02:00
Processor: i7 3770k
Motherboard: ASUS P8P67-Pro
Graphics card: 2xNvidia GTX670
Memory: 16 GB Gskill Sniper
Location: In SQL Space inserting 'null' on purpose
Contact:

Post by Anthro »

Killerbyte your are SUCH a **** - you need to seriously rethink posting stuff like "I wardrive.." - but I dont steal bandwidth - I only warn them :?

Owning yourself on Gmail is also not neccesary mmkay ?
Saying stuff like "Hacked into M&B wireless network" as a Gmail status is just incriminating.
So why dont you take that carrot up your bottom and leave ?
Temporary Absence
Screeper
Registered User
Posts: 3692
Joined: 04 Apr 2003, 02:00
Contact:

Post by Screeper »

I definitely think a long chat with the client is needed. You need to make sure his wlan (if he has one running) is either disabled (doesn't need it) or properly encrypted.
Once that is assured then give the client a new password (make it a good one) to login.
Ensure that he/she tells no one else the password and see if the bandwidth consuming continues - if it does then you will know that there is an evil app running on his pc(s) or he is lying and is trying to leech as much content as possible and claim it wasn't him.
There are 10 types of people in this world.
Those who understand binary and those who do not.
Post Reply