Re: I've been hacked...tips for a postmortem?

From: Michael Erskine (osiris@deltaville.net)
Date: 11/14/02


From: osiris@deltaville.net (Michael Erskine)
Date: 13 Nov 2002 20:06:34 -0800

It has been my consistent observation that the most pain I can inflict
upon a cracker is facilitated by:

1) Reboot the affected host...
2) Sniff and log (from a clean host) all traffic that enters or leaves
the suspect host for a period of 4 hours.
3) Analyze the sniff logs.
4) Contact the network admins of the networks from whence he enters
your box and provide them complete copies of the sniffer dumps. Do
this via voice (contact) and ftp/scp on an arranged schedule.

This proceedure will allow you to provide them (the other network
admins) the information necessary to take the crackers tools and toys.
 Crackers get really pissed when you take their toys.

-m-



Relevant Pages

  • Re: Detecting Sniffers?
    ... Sniff Host A from Host B. Have Ethereal capture on Host ... Since Ettercap poisons the ARP tables, ... > sniffer on the network. ...
    (Security-Basics)
  • Re: [?] DYNDNS host vulnerability
    ... it's convenient to use a DYNDNS domain name like myhost.dyndns.org. ... I guess, though, that the host myhost.dyndns.org would be much ... more vulnerable as for crackers there is no need to watch out ... I guess, many systems worldwide are wide, wide open in this respect.... ...
    (comp.os.linux.networking)
  • [?] DYNDNS host vulnerability
    ... it's convenient to use a DYNDNS domain name like myhost.dyndns.org. ... I guess, though, that the host myhost.dyndns.org would be much ... more vulnerable as for crackers there is no need to watch out ... caring for IP changes. ...
    (comp.os.linux.networking)
  • Re: No ebay, no amazon,
    ... Sniff. ... Helped me one day when my own host had blocked my IP. ... Nope, still can't reach ebay. ... Odd, isn't it? ...
    (alt.internet.search-engines)

Quantcast