Hello everyone. I am looking for some security advice for my home network. Today I discovered a strange computer had been discovered by Windows 7. I wasn't able to connect to it, nor could I resolve it's IP address. The only evidence of the connection was the name "Joshua-PC" was discovered by Windows 7. "Joshua-PC" is not a member of my LAN.
Here is what I discovered trying to track this down. My son admins a linux server on a RaspberryPI microPC. This box has Hamachi installed, and resides on a Hamachi VPN. He had allowed remote SSH access by members of his Hamachi VPN. One of his buddies on Hamachi owns a PC named "Joshua-PC", and had at some point connected to RaspberryPI via SSL. His computer appears to be the mystery computer discovered by my PC. However, my PC does not have Hamachi installed!
When we shutdown the RasberryPI machine, I could no longer discover "Joshua-PC". With RaspberryPI running, and Joshua-PC logged in by Hamachi/SSH, his machine becomes visible again. I spent some time on Skype with Joshua, and he claims that my machine is not discoverable to him. He can only see machines that are Hamachi VPN members.
I have asked my son to uninstall Hamachi from the RaspberryPI machine, and to disallow SSH outside our LAN. I have two questions:
1. How is it possible that a remote PC connected via VPN/SSH to RaspberryPI can become discoverable by non-VPN machines on the same LAN?
2. Is there anything else I should do?
I will provide a network diagram, in case it helps anyone. Hamachi is installed on 5 machines:
- MBP-MOBILE (Ubuntu)
- MBP-PC (Win7)
- JCP-MOBILE (Ubuntu)
- JCP-PC (Win7)
- RaspberryPI (Linux 3.6.11+ armv61)
My machine, which doesn't have Hamachi is MWP-PC (Win7). It is the machine that discovered "Joshua-PC". "Joshua-PC" is a VPN member, and is not on our LAN.
Here is what I discovered trying to track this down. My son admins a linux server on a RaspberryPI microPC. This box has Hamachi installed, and resides on a Hamachi VPN. He had allowed remote SSH access by members of his Hamachi VPN. One of his buddies on Hamachi owns a PC named "Joshua-PC", and had at some point connected to RaspberryPI via SSL. His computer appears to be the mystery computer discovered by my PC. However, my PC does not have Hamachi installed!
When we shutdown the RasberryPI machine, I could no longer discover "Joshua-PC". With RaspberryPI running, and Joshua-PC logged in by Hamachi/SSH, his machine becomes visible again. I spent some time on Skype with Joshua, and he claims that my machine is not discoverable to him. He can only see machines that are Hamachi VPN members.
I have asked my son to uninstall Hamachi from the RaspberryPI machine, and to disallow SSH outside our LAN. I have two questions:
1. How is it possible that a remote PC connected via VPN/SSH to RaspberryPI can become discoverable by non-VPN machines on the same LAN?
2. Is there anything else I should do?
I will provide a network diagram, in case it helps anyone. Hamachi is installed on 5 machines:
- MBP-MOBILE (Ubuntu)
- MBP-PC (Win7)
- JCP-MOBILE (Ubuntu)
- JCP-PC (Win7)
- RaspberryPI (Linux 3.6.11+ armv61)
My machine, which doesn't have Hamachi is MWP-PC (Win7). It is the machine that discovered "Joshua-PC". "Joshua-PC" is a VPN member, and is not on our LAN.