D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Help!

 

On Wed, May 15, 2013 at 2:27 PM, Viv Griffin wrote:
> The reason I think it is being hacked is that the opendns report files are showing 
> web sites accessed that have not been accessed by the computers in this house, and 
> activity at times when the internet was not in use at all.

There are many reasons why devices connected to the network (that
includes the router!) will make DNS requests (which is what openDNS
registers), even when they are not being used. Programs and operating
system checking for updates, for instance.

> Additionally, here is an except from my router log. I am not sure if these kernel 
> intrusions may be someone trying to log into the network, unsuccessfully.

I'd wait for someone with more experience with routers and router logs
to be absolutely certain, but as I read it, it merely means someone on
the Internet tried to connect to your network, probing for some kind
of vulnerability. That may sound scary, but that happens a lot if
you're connected to the Internet.

What matters here (and this is what I'd like to have confirmed by
someone else) is that the attempts were unsuccessful.

Ah, Gordon has now confirmed this. :-)

Good point about the open resolver.

Martijn.

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq