RE: compromised network

From: Francisco Mário Ferreira Custódio (fcustodio_at_eda.pt)
Date: 12/29/03

  • Next message: Shawn Jackson: "RE: Firewall Hardware Recommendations"
    To: Dana Rawson <absolutezero273c@nzoomail.com>, security-basics@securityfocus.com
    Date: Mon, 29 Dec 2003 16:30:39 -0100
    
    

    Hello Dana.

    All questions make sense!

    If your network has been compromised, you should alert the authorities. You
    should collect as much informations as possible in order to track the bad
    guys. According to your e-mail...it looks like the bad guys used your
    systems to make a dump site. It seems you have been attacked by some "warez"
    freaks trying to get space for dumping files.

    To check for any rogue stuff, you should check all the processes running on
    each box, you should check the traffic for layer 4 information (tcp/udp
    packets and ports) to figure out what's running in and out. Finnaly you
    should check for layer 3 information (Ip addresses) destinations and
    origins, check for suspicious IP addresses.

    Ethereal provides you useful information, when you finnish your
    captures..Ethereal organizes the packets in a very reading friendky way. You
    can see all the information I was talking. Check all this informations with
    your syslog.

    You will be doing forensics work at this time.

    I strongly advise you to deploy a Network IDS (Snort is a good choice). The
    nIDS will alert you of any suspicious activity within your network.

    Good luck.

    FC

    -----Original Message-----
    From: Dana Rawson [mailto:absolutezero273c@nzoomail.com]
    Sent: sexta-feira, 26 de Dezembro de 2003 18:22
    To: security-basics@securityfocus.com
    Subject: compromised network

    Not sure where to start except by saying that my servers and router were
    compromised. Have locked down both servers and routers (at least I have
    attempted to do so) but what is the best way to verify that there is nothing
    rogue left active on the servers? Also, is there any legal action I should
    take (i.e. Do I alert any authorities)? It appears that my network was
    targeted by a server in california and individuals from Australia,
    Netherlands and the US were connecting using it as an ftp server. Was
    actually named "Revenge Server".

    I just installed Ethereal and am currently capturing packets but am not
    really sure how to read this or if there is any easier way to monitor all
    things. ...And to actually know how to read it.

    Will I be able to retrieve ip addresses from packets to match activity on my
    syslog and identify rogue traffic?

    This is all new to me so I apologize if my questions don't make sense or my
    approach is illogical.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Shawn Jackson: "RE: Firewall Hardware Recommendations"

    Relevant Pages

    • RE: Misc Large ICMP Packets(snort)
      ... packets for communication between clients and daemons. ... Your server was being ping'ed as part of our ... Digital Island's intelligent network service offering. ... Sandpiper Networks merged with Digital Island in Dec 1999, ...
      (Focus-IDS)
    • Re: DNS Configuration Problem
      ... > With a network sniffer I sniff my network and when I configure IP address ... > server for the server destination, ... > on the nic interface you do not get out anymore this kind of DNS request, ... How many total packets did I capture on the ...
      (microsoft.public.windows.server.sbs)
    • Re: Awful performance and millions of packets transferred
      ... I ran the same test on a separate network and found ... >that normally around 4000 packets were transferred for that perticular ... >The PC, switches, routers and the server were all checked for network ... The client was passing requests to the server and the ...
      (comp.databases.ms-access)
    • Re: subnets and subnetting
      ... I'm *also* trying to better understand a network that I ... >main subnet, only 3 of which happen to need to talk to a certain server ... the packets will ...
      (comp.os.linux.networking)
    • Re: Mysterious file - WINXPINIT.EXE
      ... >> Although I have not found this file on any machines on my network, ... When I plugged our W2K Server into ... The server was sending out tcp packets to random adddresses ...
      (microsoft.public.security.virus)