RE: tools to run on compromised linux box
- From: "Murda Mcloud" <murdamcloud@xxxxxxxxxxx>
- Date: Fri, 8 Aug 2008 07:29:48 +1000
Nikhil's suggestion of booting to another OS to do the investigation
is an important choice-otherwise you run the risk of further infection
or destroying potential evidence by writing over files that could be
recovered.
You'll run that risk one way or the other. If you do forensics on the
live system, the malware may become aware of what you're doing and try
to wipe its trails. If you cut the power you may lose volatile data
(from the RAM). However, if you have Firewire enabled on the machine in
question, you can dump the contents of the RAM before cutting the power.
You're right Ansgar-I should have clarified the 'steps' in order. Ie take
memory from the live machine first if you choose to or take an image after
killing the power and then running from another OS to do the investigation.
The either/or scenario you indicate is the decision that has to be made by
the investigator-depending on what is more important. Thanks for pointing
that out.
Another suggestion would be to image the compromised box. Then you can
take your time. Adepto on the Helix cd is great for this kind of op.
That should always be the first step after powering the machine off.
Right again.
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Ansgar -59cobalt- Wiechers
Sent: Thursday, August 07, 2008 11:12 PM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: tools to run on compromised linux box
On 2008-08-07 Murda Mcloud wrote:
Nikhil's suggestion of booting to another OS to do the investigation
is an important choice-otherwise you run the risk of further infection
or destroying potential evidence by writing over files that could be
recovered.
You'll run that risk one way or the other. If you do forensics on the
live system, the malware may become aware of what you're doing and try
to wipe its trails. If you cut the power you may lose volatile data
(from the RAM). However, if you have Firewire enabled on the machine in
question, you can dump the contents of the RAM before cutting the power.
BTW, never do a "normal" shutdown on an infected machine, as that may
erase evidence, either by the system overwriting/deleting something, or
by the malware doing some "cleanup".
Another suggestion would be to image the compromised box. Then you can
take your time. Adepto on the Helix cd is great for this kind of op.
That should always be the first step after powering the machine off.
Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq
- References:
- tools to run on compromised linux box
- From: lister
- Re: tools to run on compromised linux box
- From: Nikhil Wagholikar
- RE: tools to run on compromised linux box
- From: Murda Mcloud
- Re: tools to run on compromised linux box
- From: Ansgar -59cobalt- Wiechers
- tools to run on compromised linux box
- Prev by Date: Microsoft Exchange 2003, forensics and
- Next by Date: Pen testing for educational purposes
- Previous by thread: Re: tools to run on compromised linux box
- Next by thread: Re: tools to run on compromised linux box
- Index(es):
Relevant Pages
|