RE: First time security issue.

From: Bojan Zdrnja (Bojan.Zdrnja_at_LSS.hr)
Date: 07/23/03

  • Next message: ben_at_benbailey.net: "Re: First time security issue."
    To: <incidents@securityfocus.com>
    Date: Wed, 23 Jul 2003 14:58:11 +1200
    
    

    > -----Original Message-----
    > From: Harlan Carvey [mailto:keydet89@yahoo.com]
    > Sent: Wednesday, 23 July 2003 8:56 a.m.
    > To: incidents@securityfocus.com
    > Subject: Re: First time security issue.
    >
    > What about the "how"? If the original poster (OP)
    > never discovers how the original compromise occurred,
    > then rebuilding the system does nothing but wastes
    > time. Rebuilding and updating the patches may help,
    > but there are great deal of things that patching
    > doesn't protect against, such as misconfigurations and
    > weak passwords.

    I'd agree with Harlan here.

    However, the process itself depends upon the business needs in front of the
    OP.

    In any case, my suggestion would be to reinstall the system and apply all
    patches on it. Also, before this, OP should make a HDD image copy so he can
    do forensics on it and eventually find out what happened with it.

    According to what the OP wrote, and as Harlan said as well, I doubt this is
    related to any Windows NT rootkit. Most of the cases I had experience with,
    and which had ServU/IRC-bot being setup, are related to script kiddies which
    just want to collect more machines and use public well-known exploits (or
    weak passwords etc.).

    Best regards,

    Bojan Zdrnja

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: ben_at_benbailey.net: "Re: First time security issue."

    Relevant Pages

    • Re: releng_source_question
      ... I have installed FreeBSD 6,2 and now just finished rebuilding world. ... Patches are mainly used in order to provide security updates to otherwise ...
      (comp.unix.bsd.freebsd.misc)
    • Re: sata_sil24 broken since 2.6.23-rc4-mm1
      ... It's not rebuilding the RAID at that point. ... Have you tested 2.6.23-rc4 without mm patches? ... but I have 4 good boots with one part of the mm-patches. ...
      (Linux-Kernel)
    • Re: I have a virus that uses "anti virus software" downloads as a cover up
      ... You're rebuilding a duhfault install with duhfault ... To me rebuilding also means applying all patches. ... a router or a FW device is nescessary before connecting ...
      (microsoft.public.security.virus)
    • Re: Outlook 2001 with Tiger
      ... twice and then cannot send mail. ... Harlan ... very annoying that there seems no logical way to fix it. ... Any other ideas out there besides rebuilding our image from scratch and hoping that works? ...
      (microsoft.public.outlook.mac)
    • Installing MS Patches
      ... modify so I can install multiple ms patches for windows ... Basicially I'm rebuilding a PC and want to install all ...
      (microsoft.public.windowsxp.security_admin)

    Loading