[Full-disclosure] Team Evil - Incident #2



Earlier this year, Beyond Security’s beSIRT released an incident response
forensic analysis of a defacement attack by Team Evil [Team Evil Incident
(Cyber-terrorism defacement analysis and response)]. The PDF itself can be
found here:
http://www.beyondsecurity.com/besirt/advisories/team-evil-incident.pdf

A follow up is being released today, on a second incident. Following what Team
Evil did, their methodology and how it changed since the first document was
released.

The aim of this document is more to show how such analysis is done, on an
educational note. The PDF can be found here:

http://beyondsecurity.com/besirt/advisories/teamevil-incident2.pdf

We hope you find this useful.

beSIRT, Beyond Security.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Team Evil - Incident #2
    ... Beyond Security’s beSIRT released an incident response ... forensic analysis of a defacement attack by Team Evil [Team Evil Incident ... (Cyber-terrorism defacement analysis and response)]. ...
    (Bugtraq)
  • Re: [Full-Disclosure] Reacting to a server compromise
    ... Incident Response Procedures ... Computer security incidents are occurring at an ever-increasing rate on the ... Since we, Company XYZ, depend on the Internet for our livelihood, ...
    (Full-Disclosure)
  • RE: [Full-Disclosure] Reacting to a server compromise
    ... "Computer Security Incident Handling Step-by-Step," ... Incident Response Procedures ... Since we, Company XYZ, depend on the Internet for our livelihood, ...
    (Full-Disclosure)
  • NT/2K/XP Incident Response Training
    ... Look at the lists, for example. ... which a Unix admin had to respond to an incident. ... I've created a Incident Response ... BlackHat Windows Security conference. ...
    (Incidents)
  • RE: IDS Incident Escalation Procedure
    ... Incident Response, called "On Incident Handling and Response: ... Subject: IDS Incident Escalation Procedure ... The structure of the core Incident Response Team ...
    (Focus-IDS)