Finding the spammer?

Vyper28

Active Member
Reaction score
122
I have a client that is actually 100 clients.. it's a mobile home park that provides wireless internet to all tenants. One of their lines (they have 4 residential internet lines) has been blocked from sending emails because an infected computer is spamming.

I have managed to narrow it down to the ROUTER that is serving the client, but it is one of 11 routers and serves about 10-15 different small homes. It is a piece of junk actiontek router that was provided by their ISP.

Anyone have any advice on how to pin down which client in particular is responsible? If I could even get the exact internal IP of their computer I could cut their internet off and wait for the call "my internet doesn't worrrkkk" and then explain why and go from there. Help Please!!?
 
Last edited:
Wireshark would work but only if I had access to a monitor port or something on the router..As stated above this is a junk router that has most functions locked out by the ISP. How could I use it to capture traffic from all 10 machines on that router?
 
Thanks :) I found the culprit in a round about way.. The router was so handicapped by the provider we ended up changing the wireless password and waiting for the calls. We connected 1 person at a time and watched the activity.. 3 person connected sent 300+ emails in a matter of minutes. We restricted their access and are still waiting for them to notice they cannot send emails.

Eventually they will call us and we can let them know :)

I am going to try the wireshark thing anyway because I want to see how it works.. I was under the impression if I used it on my laptop it would onyl track traffic from my machine not everyone on the router!
 
Wire-shark if configured correctly can tell you everything about that network not the just node your are connecting to the infrastructure. You may need to do a small amount of research for the configuration settings you require, but it's a fantastic application to have in your arsenal if you now how to use it.
 
3 person connected sent 300+ emails in a matter of minutes. We restricted their access and are still waiting for them to notice they cannot send emails.

Eventually they will call us and we can let them know :)

It's likely they don't even know and their PC is infected :eek:
 
Back
Top