• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

Teamviewer may have been compromised

Status
Not open for further replies.
OK alternatives for remote desktop software between Windows 10 and iPhone:

Chrome Remote Desktop
Splashtop
Windows Remote Desktop

Any others to try?

I get pretty good results with Citrix' product, GoToMyPC.

I had good experiences with DameWare too but that's PC only.
 
I had this happen to me a few weeks ago.

Granted, TeamViewer had (at the time) one of my weaker passwords, so I figured it might have come from the LinkedIn leak or something. And yeah, they went straight to the browser and tried to send themselves damn near a thousand dollars through my Paypal account. Thankfully, the transaction didn't go through, so I'm not out anything except some stress and the hassle of basically resetting every damned password I have.

Two-factor EVERYTHING. Even with something like this, they never would have gotten into my Paypal if I'd had two-factor turned on (on Paypal, I mean) at the time (which I didn't then, but I sure as hell do now).

And yeah, the first thing I did afterwards was change my Teamviewer password, set up two-factor authentication, then completely uninstalled the software from my computer. They even had the balls to ask me why I was uninstalling it, I was happy to tell them.
 
Assuming this scenario is accurate and this is happening to users, it means that instead of compromising users' individual accounts, someone has gotten access to something that allows them to remotely connect directly to systems running TeamViewer from TV's own servers. If that's happening it wouldn't matter what authentication people had since their on accounts are never even being touched.

So.. they log into a system and then go to the Amazon website which has all the info saved in the browser. The hackers then make a purchase controlling the victims own computer/browser/saved info?
 
Sadly I was a victim to this too. Someone logged into my computer while I was asleep. Bought cheats for games, purchased instagram followers, tried to steal my money, etc. He then went onto my Facebook (since it was already logged in) and left creepy messages to my wife. Talk about a bad time. It took me a good couple months to fix my checking account.

In the end, I didn't just uninstall Team Viewer, I threw that computer away! Now I'm on a new computer waiting in fear that one day this could happen again.

P.S. : I did call the police and did as much as I could on my end (to be honest, the hacker was either sloppy or leaving a red herring but at least we had somewhere to start). In the end, I haven't heard of anyone getting caught....*sigh* we need a cyber police squad.
 
Damn, and I have always liked TeamViewer too since I could never get Remote Desktop to work. Sad I'm going to have to uninstall it
 
Check out this guy's post over at reddit.com titled "Best Practices". He has some good tips for tightening up security for TV such as disabling One Time Password (default is a 4 digit pin) and to setup a whitelist.
 
OK alternatives for remote desktop software between Windows 10 and iPhone:

Chrome Remote Desktop
Splashtop
Windows Remote Desktop

Any others to try?

Any solution for Win XP? yeah, yeah..... I know, but some of my costumers are still stuck in it for the foreseable future...
 
I thought team viewer was free, why would you have PayPal info hijacked? Unless it was for business use.


Edit: ooohhhhh you guys are leaving your PCs on.


Yes I only ever run it one time use and delete it.
 
I thought team viewer was free, why would you have PayPal info hijacked? Unless it was for business use.

Teamviewer is a remote access app. If it has been compromised, people are remote accessing your system, which might have all your account and purchase data saved on your system. That's what's happening.
 
Teamviewer is a remote access app. If it has been compromised, people are remote accessing your system, which might have all your account and purchase data saved on your system. That's what's happening.


I mean I know what it is.....but never realised some people completely install it, instead of using a one time run use on the program.
 
Hm, I'm not convinced. How would that work with a strong password and 2FA?

Amazon is pretty good about timing out sign ins and asking for your credit card number before making digital purchases like gift cards, credits, etc. but I used paypal recently and the sign in persisted for quite a while and never asked to re-input my password even when transferring money or using other functions on the site directly.

If they have direct access to all your logins that is pretty bad. Some people store personal information like plaintext passwords and tax documents on their computers as well.
 
Yes but if it's not running how are you going to remote into your system on the go?


It's a customer thing for work, we always use single use on the program with ourselves and customers. I never physically left it running or ever installed it. I was already paranoid enough. But the fact that even during a single use shit can be hijacked scares me.


Is there any good alternate to this? I mean team viewer allowed me to even use a tablet and fix families computers when needed which was awesome.
 
It's a customer thing for work, we always use single use on the program with ourselves and customers. I never physically left it running or ever installed it. I was already paranoid enough. But the fact that even during a single use shit can be hijacked scares me.

Yes but that's not the only use of the app. Lots of people use it as a means of remoting into their own systems while outside, or remoting into their work system from home. Well, hopefully not anymore though! :P
 
When it happened to me a couple weeks ago I figured it was all me. But by having seen so many report it within weeks of it happening to me makes me think there is more to it.
 
When it happened to me a couple weeks ago I figured it was all me. But by having seen so many report it within weeks of it happening to me makes me think there is more to it.

Was talking to my sis about this and she said that even with 2FA and a strong password, she noticed an intruder accessing it at work recently, in real time, and shut it down. It's pretty hard to believe Teamviewer's claims that they haven't been compromised at all imo.
 
Yes but that's not the only use of the app. Lots of people use it as a means of remoting into their own systems while outside, or remoting into their work system from home. Well, hopefully not anymore though! :P


Yes. Sucks it was so easy to use........god hope no one else here gets effected. That shit sucks. I've had my debit card hijacked thanks to card readers at debit machines and that's bad. This could compromise anything if people leave anything saved in their browsers, files on the computer. God taxes.........



Blows my mind these guys are acting like nothing's even fucking going on.
 
A GAFer had someone get onto his laptop through Teamviewer while I was playing CSGO with him either yesterday or the day before, I can't remember. The 'hacker' loaded up PayPal in the browser just as he noticed and he turned the laptop off so he was fortunate we'd called an accidental timeout in the game or he may not have noticed :P
 
I had some emails lately about web access, but i've uninstalled teamviewer from my PCs years ago, so didn't pay it any mind.

Password was unique and very strong, though.

.. I also don't let paypal remember the password.
 
This is a costly demonstration of why having Paypal, Ebay and Amazon passwords and credit cards saved in the browser autofill isn't a good idea.
 
Sadly I was a victim to this too. Someone logged into my computer while I was asleep. Bought cheats for games, purchased instagram followers, tried to steal my money, etc. He then went onto my Facebook (since it was already logged in) and left creepy messages to my wife. Talk about a bad time. It took me a good couple months to fix my checking account.

In the end, I didn't just uninstall Team Viewer, I threw that computer away! Now I'm on a new computer waiting in fear that one day this could happen again.

P.S. : I did call the police and did as much as I could on my end (to be honest, the hacker was either sloppy or leaving a red herring but at least we had somewhere to start). In the end, I haven't heard of anyone getting caught....*sigh* we need a cyber police squad.

LOL you seriously threw a computer away? Even if you're paranoid, just put Dban on a flash drive and wipe all the drives.
 
Amazon is pretty good about timing out sign ins and asking for your credit card number before making digital purchases like gift cards, credits, etc. but I used paypal recently and the sign in persisted for quite a while and never asked to re-input my password even when transferring money or using other functions on the site directly.

If they have direct access to all your logins that is pretty bad. Some people store personal information like plaintext passwords and tax documents on their computers as well.

I meant TeamViewer. How are they connecting to the victims PCs if they had 2FA on?
 
I meant TeamViewer. How are they connecting to the victims PCs if they had 2FA on?

It seems increasingly likely that TeamViewer themselves have been compromised, and this isn't just a case of someone logging in using compromised usernames and passwords.
 
It seems increasingly likely that TeamViewer themselves have been compromised, and this isn't just a case of someone logging in using compromised usernames and passwords.
If that's the case if you always lock your pc and have a different password for that you should be OK right?
 
Removed it from my pc almost 6 months ago, but still had it on my phone. Just uninstalled it. I switched to using Chromes remote desktop since it was so much faster. This shit here has me shook.
 
Status
Not open for further replies.
Top Bottom