Re: compromised network

jamesworld_at_intelligencia.com
Date: 12/30/03

  • Next message: erisk: "Re: compromised network"
    Date: Mon, 29 Dec 2003 19:35:58 -0600
    To: Dana Rawson <absolutezero273c@nzoomail.com>
    
    

    Dana,

    What the rest of the group has posted so far (12/29/2003- 1900 CST) has
    been great and hopefully should show you that there are many things you can do.

    What I am about to say might seem alarmist and could be construed as an
    insult by some. It is neither and it is not my intention to do either.

    I applaud you for your work thus far at locking down the nodes as best as
    you can. Great job. As far as legal...you are too late. Unless you have
    COMPLETELY documented EVERYTHING that you discovered and what you have done
    to fix it along with having a complete image of the machines in a 'hacked'
    state... your actual chances at a successful prosecution are gone. You
    are obviously not a security expert. You need one to validate your changes
    and HELP you (not do it for you while you are in another room and come back
    and say it's done). IF your network and servers are valuable to you or
    your business (assumed that they are) get the budget approval to get an
    expert consultant to assist you.

    You owe it to yourself. The time to learn is not in battle. Get
    help. Once this situation is remediated, then start learning on the side.

    Best of luck and let me know if I can help.

    -J

    At 13:21 12/26/2003, Dana Rawson wrote:

    >Not sure where to start except by saying that my servers and router were
    >compromised. Have locked down both servers and routers (at least I have
    >attempted to do so) but what is the best way to verify that there is
    >nothing rogue left active on the servers? Also, is there any legal action
    >I should take (i.e. Do I alert any authorities)? It appears that my
    >network was targeted by a server in california and individuals from
    >Australia, Netherlands and the US were connecting using it as an ftp
    >server. Was actually named "Revenge Server".
    >
    >I just installed Ethereal and am currently capturing packets but am not
    >really sure how to read this or if there is any easier way to monitor all
    >things. ...And to actually know how to read it.
    >
    >Will I be able to retrieve ip addresses from packets to match activity on
    >my syslog and identify rogue traffic?
    >
    >This is all new to me so I apologize if my questions don't make sense or
    >my approach is illogical.
    >
    >---------------------------------------------------------------------------
    >----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: erisk: "Re: compromised network"

    Relevant Pages

    • Re: compromised network
      ... First off, from what you've provided in your post, it doesn't seem at all that your network or your routers were compromised. ... You stated at the end of your post that this is all new to you, so it might be helpful if you could describe what it is that makes you think that your router was compromised, as well as your servers. ... Are you capturing packets of the "Revenge Server" being used by someone? ... of what use would syslog be if you already have the packet captures? ...
      (Security-Basics)
    • Re: Dcidag errors
      ... Port blockage between servers ... Other sorts of networking issues (lack of connectivity between the points ... These errors are typically a result of a network connectivity issue of some ... > replicating this nc. ...
      (microsoft.public.windows.server.active_directory)
    • Re: I need Job Blobb
      ... > Windows and Network administratation. ... > In a job I would like to administrate servers, ... > Title: ISP Network Administrator ... > o Building, installation, configuration and tuning ...
      (microsoft.public.cert.exam.mcse)
    • Re: I need Job Blobb
      ... > Windows and Network administratation. ... > In a job I would like to administrate servers, ... > Title: ISP Network Administrator ... > o Building, installation, configuration and tuning ...
      (microsoft.public.cert.exam.mcse)
    • Event Viewer Networking Connectivity
      ... What we need is a very solid working network. ... Here's what lead up to this scenario of BDC replacement. ... On the corporate side I can see our servers. ... Registration of the DNS record ...
      (microsoft.public.windows.server.networking)