Who is accessing my modem and how do I stop them?

UncleWick

Commendable
Jul 29, 2016
24
0
1,510
Who is accessing my modem and how do I stop them?

I received an email stating I have downloaded a movie using BitTorrent (do not have). This is the second time they have sent me a similar message and are now warning they could denying me internet for 6 months. Below is a copy of part of the email (ip address redacted).

I ran Mbam, SpyBot S&D, and my paid antivirus Avast Internet Security, to make sure I was clean, I was/am.

I set each of my devices to a static ip address and reserved them, according to their mac address, in the LAN setup menu of my modem so I can tell at a glance what is accessing it.

I turn off UPnP. I do not have an Xbox.

I tried to apply some kind of MAC filtering but my modem (Netgear r6300v2) does not offer a means to do that. (not that I can find anyway)

I tried to renew my IP address but it kept applying the same one, called Cox and explained the situation and asked for a new IP to be assigned and they said it is renewed automatically every 24 hours. Well I still have the same one that was in the email so something is off there.
One thing that did come of the conversation was that some sites offering free streaming “could” do this as well. She mentioned a couple names but when I looked for them they all look legit.
---------------------------------------------------------------------------------------------------------------------------
Reason I am here...

Is there a way to block something like BitTorrent from using my router, I do not have another computer to put “in the dmz” between the world and the router.

Is there a way to apply some type of MAC filtering?

Is there a list of sites that offer free streaming of movies and television shows I can add to the “blocked sites” list in my router? I have monthly memberships to both Amazon Prime and Netflix, I have no use for any others.
----------------------------------------------------------------------------------------------------------------------------
Part of the received email. I have a copy of the modem's log but it is long and unless you need it cannot see wasting the space on the page.

XML:
---Start ACNS XML
<?xml version="1.0" encoding="UTF-8"?>
<Infringement xsi:schemaLocation="http://www.acns.net/ACNS http://www.acns.net/v1.2/ACNS2v1_2.xsd" xmlns="http://www.acns.net/ACNS" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">      <Case>
                <ID>222137573922</ID>
                <Status>OPEN</Status>
                <Severity>Normal</Severity>
                <Ref_URL></Ref_URL>
        </Case>
        <Complainant>
                <Entity>AMC Film Holdings LLC</Entity>
                <Contact>AMC Film Holdings LLC</Contact>
                <Address></Address>
                <Phone></Phone>
                <Email>Amc.antipiracy@ap.markmonitor.com </Email>
        </Complainant>
        <Service_Provider>
                <Entity>Cox Communications</Entity>
                <Contact>DMCA Agent</Contact>
                <Address>Cox Communications Inc.   1400 Lake Hearn Drive   Atlanta   GA   30313   US   </Address>
                <Phone></Phone>
                <Email>abuse@cox.net</Email>
        </Service_Provider>
        <Source>
                <TimeStamp>2017-01-18T15:09:03.14Z</TimeStamp>
                <IP_Address>**.**.**.***</IP_Address>
                <Port>37778</Port>
                <DNS_Name>ip**.**.**.***.hr.hr.cox.net</DNS_Name>
                <Type>P2P</Type>
                <SubType BaseType="P2P" Protocol="BITTORRENT" />
                <Number_Files>1</Number_Files>
                <IsSource>false</IsSource>
        </Source>
        <Content>
                <Item>
                        <TimeStamp>2017-01-18T15:09:03.14Z</TimeStamp>
                        <AlsoSeen Start="2017-01-18T15:08:41.24Z" End="2017-01-18T15:09:03.14Z"></AlsoSeen>
                        <Title>WALKING DEAD, THE</Title>
                        <Artist></Artist>
                        <FileName>The Walking Dead S07E05 INTERNAL 720p HDTV x264.mp4</FileName>
                        <FileSize>346847212</FileSize>
                        <Type>Video</Type>
                        <Hash Type="SHA1">33976E655BC3C2B8274EEC095A9F61D04E1DF45D</Hash>
                </Item>
        </Content>
<History></History>
<Notes></Notes><Type Retraction="false">DMCA</Type>
        <Detection>
                <Asset>
                        <OriginalAssetName>WALKING DEAD, THE</OriginalAssetName>
                </Asset>
                <ContentMatched Audio="true" Video="true" Text="false" Human="false"/>
                <HashMatched>true</HashMatched>
                <MetadataMatched>false</MetadataMatched>
                <VerificationID>Manual and hash verification</VerificationID>
        </Detection>
        <Verification>
                <VerificationLevel Type="DT">3</VerificationLevel>
        </Verification>
        <TextNotice><![CDATA[Cox Communications


Thank you for looking.
 
Found this...
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http:///www.quora.com/Can-I-block-p2p-software-on-my-router

"Block Bittorrent ports on your router:
The well known TCP port for BitTorrent traffic is 6881-6889 (and 6969 for the tracker port). To completely block BT, block UDP port 1024-65534, too."

------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
but I have VoIP, Skype, Messenger, FB, a few android games (CoC and boombeach) I play with my nephew, RaidCall, Ventrilo, and OneDrive, that i do not want to block. Will blocking these ports block what i have listed?
 
Change your WIFI password to a 12-15 character phrase. Change the admin password on the router (different than WIFI). Disable WPS on the router. Disable UPNP on the router. Disable remote administration on the router. Disable WIFI admin on the router. Use only WPA2 encryption on your router.

This will require that anyone that wants to mess with the router has to use a wired LAN port to do it. It will set the security on your router to maximum practical.
 


I think you meant WPA2, not WPS2.
 


Thanks. I fixed my post ... "S" and "A" right next to each other ....
 
Make sure you keep a copy of this so if have any stupid friends that think they will never get caught torrentling stuff you can show them. Be extremely careful who you trust on your network. I have gotten to the point I do not even always trust relatives....especially if they are under 18.

Take this extremely serious. I have seen people get cut off on the second offense...at least until they called the office. Because of the legal stuff involved they can be very sure who was using what IP at any period of time. The ISP is getting requests from places like the RIAA. If they are ignored the do actually take legal action especially if this is a company or business account.
 


avid reader of this site, passwords were all changed when the router was first installed and again when i was sent the previous email.

security set to WPA2-PSK [AES] from day one.

never had remote management but i do have 2 android devices of my own and my son, nephew, and sister visit with theirs as well, not disabling wifi.

disabled UPnP this time,,, see above.

thank you for your suggestions.
 


Then it may well have come through your router.
Ask them.
 
I was a mechanic, what I know about computers and networking wouldn't count as much more than laughable, but I know how to “google” lol.

I have been googling all day it seems and have compiled a list of sites I believe might be helpful to block. I there a way to “packet” these or do I need to add them to the block list one by one?

1337x.org
1337x.to
1iwc.com
abmp3.com
ahoy.one
alluc.com
beemp3s.org
bitsnoop.com
bitsoup.me
bittorrent.am
bomb-mp3.com
btdigg.org
btloft.com
bts.to
cartierloveonline.com
coolmoviezone.org
cmovieshd.com
cucirca.eu
demonoid.ph
demonoid.pw
dl4all.com
emp3world.cc
extratorrent.cc
extratorrent.com
extra.to
etmirror.com
etproxy.com
extratorrentonline.com
extratorrentlive.com
eztv.ag
eztv.it
fenopy.eu
filecrop.com
filestube.com
film-club.net
filmlinks4u.to
firstrow1.eu
free-tv-video-online.me
h33t.com
heroturko.me
hotcartierwatch.com
icefilms.info
iptorrents.com
isohunt.to
iwannawatch.to
iwatchonline.to
iwcwatchtop.com
kat.cr
kat.ph
limetorrents.cc
limetorrents.com
losmovies.me
losmovies.tv
lozoly.com
megashare.info
mininova.org
monova.org
montblancpensonlineuk.com
movie25.ag
movie25.cm
movie2k.to
movie4k.to
movienight.ws
mp3juices.com
mp3lemon.org
mp3raid.com
mp3skull.com
newalbumreleases.net
newfreemoviesonline.com
newzbin.com
newzbin.es
nowtorrents.com
only4pirates.com
openbit.se
picktorrent.com
piratebaymirror.eu
piratesbay.pe
pirateportal.xyz
pirateproxy.vip
primewire.ag
putlocker.is
putlocker.plus
putlocker.today
radiotimes.com
rapidlibrary.com
rapidmoviez.com
rarbg.com
rarbg.to
replicawatchesiwc.com
scenesource.me
seedpeer.eu
seedpeer.me
seventorrents.re
sumotorrent.in
solarmovie.ac
solarmovie.so
sumotorrent.sx
thepiratebay.org
thepiratebay.se
thepiratebay.red
thepiratebay.run
thepirate.zone
torlock.com
tormovies.org
torrent.cd
torrentbit.net
torrentbox.sx
torrentbutler.eu
torrentbytes.net
torrentcrazy.com
torrentday.com
torrentdb.li
torrentdownload.ws
torrentexpress.net
torrentfreak.com
torrentfunk.com
torrenthound.com
torrenting.com
torrentproject.se
torrentreactor.com
torrentreactor.net
torrentroom.com
torrents.fm
torrents.net
torrentsdownload.org
torrentus.eu
torrentz.cd
torrentz.eu
torrentz.in
torrentz.pro
torrentzap.com
tubeplus.is
tubeplus.me
tv-series.me
tvchaosuk.com
ukmontblancoutlet.co.uk
vertor.eu
viooz.co
vitorrent.org
vodly.to
vumoo.ch
warez-bb.org
watch32.com
watchfree.to
watchfreemovies.ch
watchseries.lt
watchseries.to
watchtvseries.to
wolowtube.cc/
xmovies8.tv/
yidio.com
yourbittorrent.com
zmovie.co

thank the computer nerds for the copy paste option or I would have carpal tunnel.

Thanks for looking an any suggestions you have.
 


how do i find out how or block it from happening again?
 
Your ISP sent you an email.

The question is, is the torrent trangression from someone known or unknown.

If an unknown person, not in your household...change your WiFi and other router passwords. As outlined above.
If someone known. (son/nephew/etc)...talk to them.
"Yo dude...you can't do that anymore. Cox sent us a nastygram, and they will cut us off next time."

Actively blocking torrent activity is near impossible at the consumer level. There is always a different torrent client, or a different torrent IP address or port used.
 
i asked them if they could provide anything beyond the IP of my router and they said no... so it could be someone has hacked my router i guess. it is impossible for me to have done it, i do not have a torrent.

i live alone and no one was here during the time the download was done. if i read the email correctly it happened around 3pm yesterday, i wasn't even home.
 
Maybe to just repeat and be sure you just forgot to confirm. Did you disable WPS. This can be cracked in a short time and once it is cracked there is nothing you can do it can not be changed. Some routers actually generated the WPS key from the mac so there are some routers that can be cracked in less than 1 second.

This is a massive security hole that most security professionals think should be be removed from routers....but there are SO many lazy people that feel keying in a password is too much effort.
 
no idea

EyHBNFzaN62guo3m6

https://goo.gl/photos/EyHBNFzaN62guo3m6

maybe you can tell me.
 
It says the pin is off. This is really stupid way to do this because technically the router must take the pin if the WPS button is not also disabled. Hard to say it appears to be off.

Maybe use the feature on your router to only have the wifi on when you are at home.
 


 
if you are asking if i (or anyone connecting via wifi) have to inter a password then yes, 15 chars long... numbers, upper case and lower case letters and a symbol, otherwise please look at the image i linked and see if that is what you mean
 
If you are going to try crazy solution like putting huge lists of IP in I would try a more simple crazy thing.

Turn off the DHPC...this is going to make it painful to a point. Assign a not commonly used ip block. There is a fairly new block that is designed for cell phone providers to use so they do not have to use the more common blocks like 10.x.x.x that will conflict with customers.

You can use 100.64.0.1 as your router. You can then manually assign IP to all your devices. This is the painful part.

This means even if someone where to connect to your network they would not get a IP. They would be extremely unlikely to guess you are using this non standard ip block so they could not assign themselves a IP.
 


i assigned static IP to all my devices and reserved them in the router so i could name them by device, if that is what you mean by "manually assign IP to your devices" then that is done... now... if you could dumb down the rest of it a little i might follow you...

i think i have an idea what you are saying though. are you suggesting to assign a static IP to the router? isn.t that assigned by the ISP?
 


The time was 2017-01-18T15:08:41.24Z -- Z for ZULU or London time. You local time is probably 5 or 6 hours EARLIER depending on what time zone you are in. Since the notice came from COX in GA, I am assuming US Eastern which would be 10AM local ...
 


You would think if the black-hat programmers can make these torrents, then the white-hat programmers could make something to block them or at least more accurately track the user.

I know my nephew is not downloading a movie onto his iphone in the few hours he is visiting. My sister is only here long enough to drop him off or pick him up so she is out too... that leaves 3 options.

Either I am downloading TV shows illegally that I can watch for free legally or, one of my neighbors is a pro hacker and using his/her talent to break into my modem to steal a zombie show LOL, or there is something wrong with their tracking system.

I think the later.

Tried to put all those sites in the block list but there seems to be a limit to how many you can put. I am at my wits end... BTW, what I have read says not to turn off DHCP. Can you link me something that says I should?
 

TRENDING THREADS