Log in

View Full Version : Catching ISP browsing with my password...


ukb008
13th March 2010, 02:19
Hi, PROs.

The problem:

In my Internet Usage Portal page where Internet usage details (start/stop times, data uploaded/downloaded, duration of usage and dates) are given by my ISP, I can see that data transfers are logged at times when I wasn't home and my computer wasn't on. Those transfers were for durations like 20, 30, 47 minutes, and data transfers were like 79493 KB in 47 minutes.

Additionally, my password was given by my ISP after I had once forgotten mine, but I never changed it because there was never any problem. Now that there is, I attempted to change the password, but discovered that I can't. This is what my Firefox says about the password change page of the site:

"You have asked Firefox to connect securely to ... (IP address) but we can not confirm that your connection is secure.

If you usually connect to this site without problems (my own internet browsing is never any problem), this error could mean that someone is trying to impersonate the site, and you shouldn't continue.

If you understand what's going on, you can tell Firefox to start trusting the site's identification. Even if you trust the site, this error could mean that someone is tampering with your connection.

Don't add an exception unless you know there is a good reason why the site does not use a trusted identification. Legitimate banks, stores, public sites will not ask you to do this."

My ISP is a government-owned company.

What I have done so far:

1. I have checked the Firefox history logs for the dates and time of those ghostly uses. There were no pages logged. Means, Firefox wasn't used.

I don't use IE, so nothing was logged in IE either.

2. I have checked the event log of my computer, and saw that, indeed, TCPIP Remote access was activated exactly like when I start browsing, and sessions started during those "ghost" times.

My simple questions are:

1. Is my ISP browsing the internet on my time and with my password? How can I KNOW and PROVE it if that is so?

2. If my ISP browses the internet with my password sitting in his office, will it be logged in my own computer's Event Viewer?

3. What's happening?

:confused:

Thanks and regards.

mariush
13th March 2010, 02:40
Your ISP has no need to browse the Internet with your username and password, after all they GIVE you the Internet.
Most likely, someone found the password of your router or modem and use it.

If you have a wireless router / modem then someone may have tried thousands of combinations until they found your user name and password and then configured his computer to use your wireless router, so he gets Internet from you.
If it's a cable modem, someone may have detected the MAC address of your modem and set his modem to the same MAC address, so when he uses the Internet, the traffic he does gets logged into your account.

Also, based on the traffic you see (80 MB in 47 minutes) it may be just random computers on the Internet scanning your Internet connection to see if your computer is vulnerable. Even if one runs a ping command, that's data coming towards your computer, powered on or not, so it may be recorded as traffic.

ukb008
13th March 2010, 03:17
Thanks, mariush.

Mine's not a cable modem. It is a wireless model, but I am using it with USB and phone connection-wires. My IP address is dynamic.

Because my ISP is a government agency, the guy who gave me my password may have leaked it and my username to someone...maybe one of his own relatives even.

1. But will windows log the usages made in a different computer in my own particular computer's event log ?

2. Why can't I change the password?

3. One of the things you have said is quite scary: my Internet will record traffic even when switched off, if someone pings my computer.

I want to clarify the issues in my own mind before taking them up with my ISP.

Regards.