The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    somebody trying to steal my wifi?

    Discussion in 'Networking and Wireless' started by sublime313, May 23, 2010.

  1. sublime313

    sublime313 Notebook Evangelist

    Reputations:
    190
    Messages:
    563
    Likes Received:
    0
    Trophy Points:
    30
    i like turtles

    so i use WPA-PSK2 security enabled, and had my SSID broadcast turned OFF. twice today on my router log i noticed sequences like the following (from unrecognized mac address):

    [INFO] Sat Jul 25 15:23:04 2009 home11: Wireless system with MAC address 0xxxxxxxxxxx disconnected for reason: Received Deauthentication
    [WARN] Sat Jul 25 15:22:06 2009 xxxx was assigned the IP address of 192.168.0.196.
    [INFO] Sat Jul 25 15:22:06 2009 home11: Wireless system with MAC address 0xxxxxxxx secured and linked
    [INFO] Sat Jul 25 15:22:06 2009 home11: Wireless system with MAC address 0xxxxxxxx associated


    from what i can tell, this means they successfully got into my network then voluntarily disconnected soon after. my passkey is a series of letters and numbers that i'm pretty sure nobody would guess.

    i tried to replicate this process by entering my own network and i noticed that when i successfully got in, it actually gave me the following sequence, which includes the BOLDED notification which was NOT present during the earlier intrustions. does this mean that the intruder never actually got in?


    [INFO] Sat Jul 25 15:23:04 2009 home11: Wireless system with MAC address 0xxxxxxxxxxx disconnected for reason: Received Deauthentication
    [INFO] Sat Jul 25 15:22:30 2009 Allowed configuration authentication by IP address 192.168.0.196
    [WARN] Sat Jul 25 15:22:06 2009 A network computer (home) was assigned the IP address of 192.168.0.196.
    [INFO] Sat Jul 25 15:22:06 2009 home11: Wireless system with MAC address 0xxxxxxxx secured and linked
    [INFO] Sat Jul 25 15:22:06 2009 home11: Wireless system with MAC address 0xxxxxxxx associated


    any ideas?
     
  2. sublime313

    sublime313 Notebook Evangelist

    Reputations:
    190
    Messages:
    563
    Likes Received:
    0
    Trophy Points:
    30
    I'M AN IDIOT! i just remember i used my wireless printer twice today lol
     
  3. Tinderbox (UK)

    Tinderbox (UK) BAKED BEAN KING

    Reputations:
    4,745
    Messages:
    8,513
    Likes Received:
    3,823
    Trophy Points:
    431
    You made me laugh +REP :D
     
  4. Kuu

    Kuu That Quiet Person

    Reputations:
    765
    Messages:
    968
    Likes Received:
    18
    Trophy Points:
    31
    It seems that your printer is out to steal your NBR login... or maybe it has already.
     
  5. turqoisegirl08

    turqoisegirl08 Notebook Evangelist

    Reputations:
    1,617
    Messages:
    505
    Likes Received:
    260
    Trophy Points:
    76
    LOL :D

    I needed the laugh- thanks! Sounds like something I would have done too :)
     
  6. lie495fc

    lie495fc Notebook Consultant

    Reputations:
    72
    Messages:
    144
    Likes Received:
    0
    Trophy Points:
    30
    All she wants is your attention. let's take a closer look at your signature.

    "dv7t-1270|W7U-64|P8600 2.4GHz|4GB RAM|9600mGT|320GB|AGN+Bluetooth|LightScribe Blu-Ray|24" ViewSonic 1080p LCD|HP Bluetooth Stereo Headphones|HP QuickDock|MS5000 BT Mouse|HP 2.1 50w Speakers|HP Elite Wireless Keyboard|Notepal Infinite Cooler| and some other crap"

    you listed her as "some other crap." it all make sense now.
     
  7. blue68f100

    blue68f100 Notebook Virtuoso

    Reputations:
    1,020
    Messages:
    3,439
    Likes Received:
    0
    Trophy Points:
    105
    I would assign your printer a fixed IP outside of your DHCP range. Then it would not show up on your dhcp logs.

    Now unless your pass key is >20 chrs it can be broken almost as easy as WEP with the correct tools. I would recommend you to switch over to WPA(2) AES with the key random generated using all printable chr with a length min 20 chr. I use Home of Gibson Research Corporation random key generator and just copy to a notepad. Then copy and paste so it works the first time. Also turn back on SSID. Being hidden does not really hide it if there is any traffic flowing. The WPA works best with SSID open being broadcasted.

    If your pc are old before XP it may not support WPA, the same can be said about the older routers.

    As a rule any key you can remember is not a very strong key.
     
  8. LaptopNut

    LaptopNut Notebook Virtuoso

    Reputations:
    1,610
    Messages:
    3,745
    Likes Received:
    92
    Trophy Points:
    116
    You could have sparked an FBI investigation only to find out that your printer was the perpetrator. I guess you can't be too careful nowadays though.
     
  9. newsposter

    newsposter Notebook Virtuoso

    Reputations:
    801
    Messages:
    3,881
    Likes Received:
    0
    Trophy Points:
    105
    yah, let's all pull the trigger on panic and suspicion before we check or understand our own setups.....
     
  10. sublime313

    sublime313 Notebook Evangelist

    Reputations:
    190
    Messages:
    563
    Likes Received:
    0
    Trophy Points:
    30
    solved.

    this does not appear to be sound advice, but ok...



    [INFO] Mon May 24 01:53:08 2010 Administrator logout

    ok, who is "Administrator"? and if he logged out that must mean he was once logged in.. dun dun DUN.