So from where I'm sitting, you got pwned, your flatmate found out about it one way or the other and chose to keep quiet until that conversation, either to test if the info he'd gotten elsewhere was right or to show off by slyly divulging his results. Even if you found Metasploit on his Mac, it proves nothing. The browsing history of IE might tell you something about when the hack may have occurred (or at least when the spyware snuck into your machine) but it would have to be recent and for all we know so far it might've been months ago.
Hi Cooper,
Sorry for my delays in responding. I am only have access to a computer intermittently at the moment as I organise a replacement for the one that was hacked.
Yeah I think as you say I got pwned. There is no other way it seems to me that he raises a topic out of the blue that he could only have known about if he was directly observing me one way or the other. Then I find meterpreter on my computer etc.
I confronted him about it and he denies it all. I don't believe him as I know his character. I'm evicting him at the moment.
One of the IP's connected had a remote address connecting in via local port 54829.
The other was his Mac, using a remote port 52066 connecting to local port microsoft-dns
There were various 'localhosts' established, but I presume these are no problem
i also have wiresshark logs that show his computer was consistently established to my computer. As I understand it this should not be the case? His computer should only have been connected to the modem we use, which also showed up in the DHCP list in the modem log?
Anyhow, he offered me the opportunity to scan his computer to prove it wasn't him. But correct me if I am wrong, it wouldn't be difficult to delete the offending programs. One other thing is that he uses a remote server to log into and use the internet and other programs. Beats me why the hell he does this, but he keeps saying he doesn't know much about computers, but knows enough to use a remote server for his applications.
Appreciate all your help and if there is anything else you can add, please feel free.
Thank you kindly - Papasmurf.