Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 2 Weeks Ago   #1 (permalink)
Overclocker in Training
 
Weedvender's Avatar
 
amd nvidia

Join Date: Oct 2008
Posts: 1,634

Rep: 68 Weedvender is acknowledged by some
Unique Rep: 54
Trader Rating: 12
Default Nosy coworker constantly breaking into my computer.

I have a coworker who I used to trust my computer to. I've built him computers for, I've helped his family with everything computer related from security cameras to out of warranty repairs because I am a nice guy. And I love calculus.

I have a feeling that my coworker and his father (owners of the office I am at) are browsing through my computer through illegal means. I am self employed, not an employee. My coworker knows about key loggers but other than that, he is computer illiterate. I doubt any scripts are involved as I showed him what keyloggers were.

How can I detect that a keylogger has been installed?
A simple password change wont work as he would most likely go with OPHCrack or something to figure it out.

Second,
Whats the best thing I can do to keep these files safe and away from prying eyes?
*A ghost disk with a strong encryption?
*A VPN to my house via Open SHH?
*Can I change the loggin that it tells me when someone logged in and for how long?
*Should I try to setup an authentication server to my house and then handle everything locally?

What should I do? I dont know how to do anything of what I just describe but I want a effective method, apart from showing up to work with a carbine.

The reason why he might be doing this is because I've had a very good success rate with business for the past few months and some people are naturally asking what I am doing. What sucks the most is that he just goes through the day without feeling bad or anything. Sucks when your supposed friends are like this.
__________________
Want a 50% yearly return on your investment? PM me. (Im serious)

System: Spork117
CPU
720BE @ 3.6 Ghz
Motherboard
Gigabyte MA770
Memory
6GB Gskill 800Mhz
Graphics Card
PNY 9800GT
Hard Drive
WD 500GB Black
Power Supply
Asus 550W
Case
Antec P182
OS
Windows 7 Pro

Last edited by Weedvender : 2 Weeks Ago at 07:34 PM
Weedvender is offline   Reply With Quote
Old 2 Weeks Ago   #2 (permalink)
Extreme Cooler
 
LightsInTheDark's Avatar
 
amd nvidia

Join Date: Jan 2009
Posts: 249

Rep: 20 LightsInTheDark is acknowledged by some
Unique Rep: 18
Trader Rating: 2
Default

A remote-access seems like a sound idea, password change anyways, you should change it regularly anyway.

Prehaps you could invest in one of those hard-drives...that go in your front bay, and has a key hole on the front. At the end of the day, you slide the key in, unlock it, and just slide the entire hard-drive (in a protective aluminium casing) out of the front bay, effectively removing any access to it.

you can then just throw it in your computer at home every night, and bring it back in the AM.

Even just sliding the HD out, putting it somewhere in your office-space, and just keeping the key, so even if they wanted to, they couldnt access anything on it.

The financial business I work at use them regularly every day, to keep client data safe. All the data of that day gets dumped on the harddrive, then gets removed out of the computers every single night.



__________________
I did error10's Windows Challenge and Windows now runs me!

System: X-Blade Gaming Rig
CPU
AMD Athlon X2 2.7GHz Kuma B.E (OC 3.2GHz) AS5
Motherboard
ASUS M2N32-SLI Deluxe
Memory
G.SKILL 2GB, 2GB Generic DDR2
Graphics Card
EVGA 8600GTS AS5 Therm.
Hard Drive
Seagate Barraccuda 500GB
Sound Card
Onboard FTW!
Power Supply
Logisys 550W SLI
Case
X-Blade Gaming Case
CPU cooling
AC Freezer 64 Pro, AS5
GPU cooling
Stock with AS5
OS
Windows 7 Ultimate 32
Monitor
NEC 22" Widescreen
LightsInTheDark is offline   Reply With Quote
Old 2 Weeks Ago   #3 (permalink)
Overclocked and Underpaid
 
losttsol's Avatar
 
intel nvidia

Join Date: Feb 2007
Location: Virginia
Posts: 4,560

Rep: 354 losttsol is a proven memberlosttsol is a proven memberlosttsol is a proven memberlosttsol is a proven member
Unique Rep: 298
Hardware Reviews: 3
Trader Rating: 15
Default

Install an anti-keylogger on the machine.
__________________

System: Low Tide
CPU
Q9650 @ 4.3GHz 1.36v
Motherboard
Asus Rampage Formula X48
Memory
G. Skill 2x2GB PC2 8500
Graphics Card
EVGA GTX 295 Plus
Hard Drive
150GB Raptor X + 320GB Barracuda
Sound Card
X-Fi XtremeGamer
Power Supply
Corsair TX850W
Case
Lian Li Armorsuit PC-P50
CPU cooling
D-Tek FuZion v1, MCR320-QP, MCP655
GPU cooling
Stock Fan + Backplate
OS
Windows 7 Ultimate RC
Monitor
Acer 22" AL2223Wd
losttsol is offline Overclocked Account losttsol's Gallery   Reply With Quote
Old 2 Weeks Ago   #4 (permalink)
New to Overclock.net
 
HuffPCair's Avatar
 
intel nvidia

Join Date: Apr 2009
Location: Kansas City, Mo
Posts: 15

Rep: 4 HuffPCair Unknown
Unique Rep: 4
Trader Rating: 0
Default

You can also go to msconfig and see if you can you find the program under the startup file

Then find the location and delete all that stuff or show proof of what they are doing kind of thing.
__________________
System: Boobs (.)(.)
CPU
Q6600
Motherboard
eVGA 680i SLI
Memory
DDR2 800 @ 1000MHz
Graphics Card
9800GTX+
Hard Drive
500GB
Power Supply
Cooler Master 500W
Case
Cooler Master ATCS 840
CPU cooling
Corsair H50
GPU cooling
Stock
OS
Windows 7
Monitor
Acer 19 inch
HuffPCair is offline   Reply With Quote
Old 2 Weeks Ago   #5 (permalink)
Overclocker in Training
 
Weedvender's Avatar
 
amd nvidia

Join Date: Oct 2008
Posts: 1,634

Rep: 68 Weedvender is acknowledged by some
Unique Rep: 54
Trader Rating: 12
Default

Quote:
Originally Posted by LightsInTheDark View Post
A remote-access seems like a sound idea, password change anyways, you should change it regularly anyway.

Prehaps you could invest in one of those hard-drives...that go in your front bay, and has a key hole on the front. At the end of the day, you slide the key in, unlock it, and just slide the entire hard-drive (in a protective aluminium casing) out of the front bay, effectively removing any access to it.

you can then just throw it in your computer at home every night, and bring it back in the AM.

Even just sliding the HD out, putting it somewhere in your office-space, and just keeping the key, so even if they wanted to, they couldnt access anything on it.

The financial business I work at use them regularly every day, to keep client data safe. All the data of that day gets dumped on the harddrive, then gets removed out of the computers every single night.



The HDD sounds like a very good idea. But I would prefer sending the info to my nas @ home via VPN/ ssh tunneling. Im going to let the HDD idea grow on me for a bit.

Quote:
Originally Posted by losttsol View Post
Install an anti-keylogger on the machine.
Got any in mind that are good?

Quote:
Originally Posted by HuffPCair View Post
You can also go to msconfig and see if you can you find the program under the startup file

Then find the location and delete all that stuff or show proof of what they are doing kind of thing.
I will try this
__________________
Want a 50% yearly return on your investment? PM me. (Im serious)

System: Spork117
CPU
720BE @ 3.6 Ghz
Motherboard
Gigabyte MA770
Memory
6GB Gskill 800Mhz
Graphics Card
PNY 9800GT
Hard Drive
WD 500GB Black
Power Supply
Asus 550W
Case
Antec P182
OS
Windows 7 Pro
Weedvender is offline   Reply With Quote
Old 2 Weeks Ago   #6 (permalink)
4.0 GHz
 
SniperXX's Avatar
 
intel nvidia

Join Date: Sep 2008
Location: So-Cal
Posts: 1,090

Rep: 67 SniperXX is acknowledged by some
Unique Rep: 60
Trader Rating: 6
Default

Use TrueCrypt to create a hidden encrypted volume. No need to wait for stuff to upload or download to/from home.

Or even keep all your stuff on a USB hard drive.
__________________
Want to get ~25,000PPD folding on your i7 running a Virtual Machine?

EVGA 680i FOR SALE

i7 920 @ 4.2Ghz
HT off for now, still testing.

HEATWARE

O o
/Ż/___________________________ _\
| BBBBBAHHHHHHHHHHHHHHHHH
\_\ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ Ż/

System: LAN Rig
CPU
i7 920 (D0) @ 4.0GHz HT ON
Motherboard
Asus Rampage II GENE
Memory
6GB Crucial Dominators
Graphics Card
2x BFG GTX285
Hard Drive
~5TB (Raid 0 w/ backup drives)
Power Supply
Corsair TX750
Case
Antec 300
CPU cooling
Coolermaster V8 (WC gear is here)
GPU cooling
Stock
OS
Windows 7 Ultimate
Monitor
Samsung Syncmaster 2233RZ (120hz)
Overclock.net - 2009 Chimp Challenge Champions
SniperXX is offline   Reply With Quote
Old 2 Weeks Ago   #7 (permalink)
New to Overclock.net
 
intel ati

Join Date: Sep 2009
Location: Casa Grande, Arizona
Posts: 379

Rep: 21 scottsee is acknowledged by some
Unique Rep: 16
Trader Rating: 0
Default

Quote:
Originally Posted by Weedvender View Post
The HDD sounds like a very good idea. But I would prefer sending the info to my nas @ home via VPN/ ssh tunneling. Im going to let the HDD idea grow on me for a bit.
I used a removable hard drive tray for a couple years, It works great, all you have to do is setup diffrent hardware profiles.. It's kinda bulky though..

You could use a BIOS password.. That will frustrate him, you'll know if he bipasses it by clearing the CMOS. Orphcrack works great aginst the SAM, but it's not that good aginst special key "$$#%" stuff. You could just up the password character size to 12-15 adding in some specal characters. The rainbow tables need for somthing like that is HUGE!!! I doubt he'd use a linux boot utility to overwrite SAM files, that would give him away, besides, If you do enable BIOS password he won't be able to get into the boot options anyway.

A network SSH or VPN is just opening up your home network to an already agressive person with to much time on his hands.. Don't give him anything else to get excited about..
__________________
ATX PSU design standerds (V2.2) recomend psu fans orentation is to draw intake air from the case as an exhaust.

System: Toy
CPU
i7 920 D0 #3919A704
Motherboard
Bloodrage
Memory
6g ocz 1600mhz gold
Graphics Card
Sapphire 4870 1gb
Hard Drive
barricuda 7200.11 1.5T
Power Supply
OCZ StealthxStream 700W
Case
Cool Master RC 690
CPU cooling
Mugen-2
OS
Win7/vista
Monitor
LCD 22" 5MS X223WBD
scottsee is offline   Reply With Quote
Old 2 Weeks Ago   #8 (permalink)
Overclocker in Training
 
I AM TEH LAW GIVAH's Avatar
 
amd ati

Join Date: Jul 2008
Location: California?
Posts: 2,850

Rep: 112 I AM TEH LAW GIVAH is acknowledged by manyI AM TEH LAW GIVAH is acknowledged by many
Unique Rep: 105
Trader Rating: 12
Default

i hate those nosy coworkers
__________________
Quote:
Originally Posted by CL3P20 View Post
..he is teh law.. you know what happens if you get on the wrong side of teh law!
HARDER STYLEZ OF OCN CLUB


System: FOUR WHEELS OF FURY!
CPU
AMD Phenom II x3 710 @2.9
Motherboard
Gigabyte 780g S2H
Memory
4GB Corsair XMS
Graphics Card
Sapphire 4890
Hard Drive
Seagate 500gb raid 0
Sound Card
X-Fi XtremeMusic
Power Supply
550W Antec Trio
Case
Antec 900
CPU cooling
Tuniq Tower
OS
Windows 7
Monitor
22" Viewsonic
I AM TEH LAW GIVAH is offline   Reply With Quote
Old 2 Weeks Ago   #9 (permalink)
GH0
Pineapple please!
 
GH0's Avatar
 
intel nvidia

Join Date: Jan 2008
Location: 0.0000 , 0.0000
Posts: 4,316
Blog Entries: 3

Folding Team Rank: 117
Trader Rating: 2
Default

I would concor with the TrueCrypt idea. Having a hidden partition that he can't see would be a great idea.

You can also do an online virus scan every now and then to see if he continuously plants something.

I would suggest changing the administrator password to something extensive like:

")J4WD*9w%@#634#(*y9H&U(&hI#$H3onefa98)nawd90W @#0-9#ERPj8cj3akj3e9"

This would take an extremely long time to crack using OphCrack, and your password could be changed to something of an equal yet less constrictive value. This will allow him to get frustrated and hopefully give up.

You could also check the process list using Process Explorer to see if anything in paticular is being run like Syncroneyes. This program is not going to pop up as a flagged program, but it is a monitoring program that allows the host to watch the clients. Or if he is running a VNC program of any type.
__________________
Diligite Iustitiam Qui Iudicatis Terra | Love righteousness, ye that are judges of the earth! "We're not God. Not only are our powers limited, we sometimes are driven to become the devil himself." "Gather at the Archeron, prisoners of Charon."
"While the mother holds her child, watches them die, Hands to the sky crying, "Why, oh why?" Cause I need to watch things die...from a distance, Vicariously I live while the whole world dies, You all need it too, don't lie."
Please, help me out!

System: Dataslum
CPU
Q6600 @ 3.2
Motherboard
EVGA 780i Motherboard
Memory
OCZ Blade PC-9600
Graphics Card
2x EVGA 9800GTX+ 512 MB (SLI)
Hard Drive
4 Hard Drives
Sound Card
Auzuntech Prelude 7.1
Power Supply
Corsair 1KW
Case
Lian-Li
CPU cooling
Xigmatek
GPU cooling
Stock
OS
Windows 7 Ultimate
Monitor
2x ASUS 23.6" VH242H
1 Million+ Folding at Home points
GH0 is offline I fold for Overclock.net Overclocked Account GH0's Gallery   Reply With Quote
Old 2 Weeks Ago   #10 (permalink)
Overclocker in Training
 
Weedvender's Avatar
 
amd nvidia

Join Date: Oct 2008
Posts: 1,634

Rep: 68 Weedvender is acknowledged by some
Unique Rep: 54
Trader Rating: 12
Default

Quote:
Originally Posted by GH0 View Post
I would concor with the TrueCrypt idea. Having a hidden partition that he can't see would be a great idea.

You can also do an online virus scan every now and then to see if he continuously plants something.

I would suggest changing the administrator password to something extensive like:

")J4WD*9w%@#634#(*y9H&U(&hI#$H3onefa98)nawd90W @#0-9#ERPj8cj3akj3e9"

This would take an extremely long time to crack using OphCrack, and your password could be changed to something of an equal yet less constrictive value. This will allow him to get frustrated and hopefully give up.

You could also check the process list using Process Explorer to see if anything in paticular is being run like Syncroneyes. This program is not going to pop up as a flagged program, but it is a monitoring program that allows the host to watch the clients. Or if he is running a VNC program of any type.
Nah. No VNC what so ever. Strictly keylogger. Thats all he knows. We are talking about a kid who listens to rap & reaggueaton and burns a windows xp cd now and then.

I will give TrueCrypt a try. On the VPN part, he wouldn't know what it was if it hit him slap on the face. I come to you guys because I have a lot of ideas but there might be an easier implementation with a guided hand.
__________________
Want a 50% yearly return on your investment? PM me. (Im serious)

System: Spork117
CPU
720BE @ 3.6 Ghz
Motherboard
Gigabyte MA770
Memory
6GB Gskill 800Mhz
Graphics Card
PNY 9800GT
Hard Drive
WD 500GB Black
Power Supply
Asus 550W
Case
Antec P182
OS
Windows 7 Pro
Weedvender is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 11:27 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright İ 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.16978 seconds with 9 queries