Re: Chasing down an attacker.

From: Shawn (greyhat@attbi.com)
Date: 05/09/02


From: "Shawn" <greyhat@attbi.com>
Date: Thu, 09 May 2002 00:41:39 GMT


> Here is a question for everyone. I've been attacked. I have the logs.
> So what is the next logical step. I called the ISP security guru. No
> answer and his voice mail is full. No response on the generic Abuse
> E-mail listing. Something tells me that they either don't care or can't
> keep up.

By attacked, do you mean someone has made hacking attempt against your
computer or has it been comprised (rooted)?

> What would be the next step?

Unfortunately, if their ISP isn't responding to your email, there's not a
whole lot you can do about an attack. You could bug the hell out of them
with emails until they respond. Or check the ip block for the ISP
www.geektools.com, see if they answer the a high authority, email the ISP's
provider.

> Who can I go to for results?

You might try www.incidents.org for starters. Hope this helps.

--
Shawn
www.intrusiondefense.com



Relevant Pages

  • Re: Question about rsync
    ... server, through your switches and gateways on to your ISP, through the ... internet infrastructure, and back out at the other side" ... methodof attack as you. ... - the idea that you *always* need strong encryption for any transfer can ...
    (comp.os.linux.networking)
  • Re: Web site being attacked!
    ... My advice is to contact the ISP that owns the IP address of the attacker ... block the attacks, until the attack patterns change again. ... Yes, you want "IISlockdown" which contains URLscan, install all microsoft ... The Netscreen 5XP is a real commercial grade firewall with the same features ...
    (microsoft.public.win2000.security)
  • Re: Dealing with script kiddies
    ... If I get a repeated attack ... and if I'm pissed because the bagel place was out of garlic ... >> to law enforcement networks, including the FBI, so I can let the ISP ... > security, not the technical side, so I'm not always _au courant_ with the ...
    (microsoft.public.inetserver.iis.security)
  • Re: Dealing with script kiddies
    ... If I get a repeated attack ... and if I'm pissed because the bagel place was out of garlic ... >> to law enforcement networks, including the FBI, so I can let the ISP ... > security, not the technical side, so I'm not always _au courant_ with the ...
    (microsoft.public.win2000.security)
  • RE: Disassembling botnets
    ... Well it isn't your job to disable the botnet and close down irc servers. ... ISP hosting the IRC network. ... little further into the attack source. ... I found the DNS name of the IRC server ...
    (Incidents)