The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Security Question? How Do I Read My Logs?

    Discussion in 'Networking and Wireless' started by therock, Mar 13, 2007.

  1. therock

    therock Notebook Evangelist

    Reputations:
    1
    Messages:
    310
    Likes Received:
    10
    Trophy Points:
    31
    Me Thinks someone is using my bandwidth?
    I went into my logs and put some of the IP numbers into my browser and they open some sites I have not visited. Huh?

    I have a WRTG54. A Version 2.0 with the latest Firmware.
    I configured it to allow my laptop to use my Comcast cable internet via a Motorola SB5100 cable modem.
    I have WPA2 Personal, AES,A Shared Key, and a Group Key renewing every 3600 seconds.
    I can't get all the numbers to open a site as I have never entered webb addresses this way "72.14.207.99".

    I need to learn how use my logs to see if I am being hacked.
     
  2. WackyT

    WackyT Notebook Deity

    Reputations:
    906
    Messages:
    1,389
    Likes Received:
    1
    Trophy Points:
    56
    Are you using a complex long password for your WPA2?

    The number you reference is called an IP address. When you type in a URL like www.google.com, your computer contacts another computer called a DNS server to look up what you typed in to find the corresponding IP address, which is used to find websites on the internet. Your router logs IP addresses being visted, and not URLs.

    You visit a lot more websites than you think. Like on this page, you're also hitting Google for the ads in the left frame.
     
  3. therock

    therock Notebook Evangelist

    Reputations:
    1
    Messages:
    310
    Likes Received:
    10
    Trophy Points:
    31
    Thanks WackyT.

    I'll look at the password thing.
    Can you point me at somthing I do or use to detect when a second party has gotten into my network?
     
  4. BaNZ

    BaNZ Notebook Consultant

    Reputations:
    13
    Messages:
    172
    Likes Received:
    0
    Trophy Points:
    30
    Check how many clients is connected to the router and see if you identify any unknown or duplicates.
     
  5. WackyT

    WackyT Notebook Deity

    Reputations:
    906
    Messages:
    1,389
    Likes Received:
    1
    Trophy Points:
    56
  6. Chutsman

    Chutsman Notebook Evangelist

    Reputations:
    6
    Messages:
    609
    Likes Received:
    1
    Trophy Points:
    31
    Change your SSID name then disable its broadcast.
     
  7. blue68f100

    blue68f100 Notebook Virtuoso

    Reputations:
    1,020
    Messages:
    3,439
    Likes Received:
    0
    Trophy Points:
    105
    Use truly random generated keys, all printable chr's. Use the max number allowed, always. I use http://www.grc.com key generators. Just Copy and Paste. If you can remember the keys it's to easy and not long enough. If the keys are good you will need to copy and paste them.
     
  8. therock

    therock Notebook Evangelist

    Reputations:
    1
    Messages:
    310
    Likes Received:
    10
    Trophy Points:
    31
    Good Stuff Guys,

    I had a "Cable Guy" friend over today and he went through my setup and said I am good to go.
    The GRC thing will be implemented tonight.

    For fun I connected to one of (many) my neighbors network and entered the Linksys isp and got in under Linksys, Admin, and moved around in his router setup.
    How can I anonymously leave him word in his setup he needs to secure it?
     
  9. skagen

    skagen Notebook Deity

    Reputations:
    278
    Messages:
    885
    Likes Received:
    0
    Trophy Points:
    30
    Changing SSID is fine but disabling broadcast tends to cause problems in XP and you yourself may struggle to get on your LAN then.

    MAC filtering and a strong password is as much as you can do really.

    If you find that the person could still get on you can trying limiting the number of IP addresses allowed to one.
     
  10. blue68f100

    blue68f100 Notebook Virtuoso

    Reputations:
    1,020
    Messages:
    3,439
    Likes Received:
    0
    Trophy Points:
    105
    Hidden SSID causes no problems, I do find it easier to do the setup then hide it when every thing is working.

    The notion of MAC filtering is a JOKE. Any sniffer can give you that info. All broadcast includes it in the header. Run a copy of netstumbler if you want to see them. Beside you can take any router or network hardware and they provide a way to clone your mac address.

    therock, some router have problem with the " chr, if you have a problem, remove them from the string.
     
  11. RedSensiStar

    RedSensiStar Notebook Deity

    Reputations:
    178
    Messages:
    897
    Likes Received:
    0
    Trophy Points:
    0
    Eh, no:

    1. OS problems like XP
    2. Also there is a neat little exploit for those who hide the SSID. Which in turn gives up a lot more network traffic information than if it had just been broadcasted!
     
  12. grumpy3b

    grumpy3b Notebook Evangelist

    Reputations:
    270
    Messages:
    683
    Likes Received:
    0
    Trophy Points:
    30