Learnsecurity
Aug 7 2004, 04:47 PM
hi,
first of all sorry for my english.
nearly daily one hears messages over compromite computers in all world, times small companies or also unix-project-server or also still much different one.
the aggressors will be mostly determined never.
Which are all measures around a break-down to determine, log files naturally, but which exactly. That depends naturally on the services and the infrastructure. But perhaps generally which is everywhere possible and which can be possible.
In the log files it stands ip's and time-entered with which one identify a hacker. Naturally only if itīs the real IP. This is kept anonymous usually with proxy or socks. But as these 2 possibilities are safe, and give it perhaps more ?.
would be grateful over each experience and assistance by you
gman24
Aug 7 2004, 10:33 PM
Honeypots and honeynets can reveal more info about the attacker and thier activities. Sometimes revealing a handle you can start tracing.
If something on your network has already been compromised you can use that to your advantage by making it into a honeypot and watching his activities.
Any type of IDS system would help.
Sometimes files dropped and other things can lead to clues on who he is. He may brag about it to his friends as well.
Sorry, this normally would be alot longer and detailed but I am really tired today.
nackas
Aug 8 2004, 01:37 AM
Check the event log if a windows system was compromised. A few programs create logs in the event log with some detailed information on the attacker, such sa Dameware Mini Remote Control which is a popular tool. But as gman24 said, setting up a honeypot on your network is the ultimate "venus trap" in catching out unwanted access.
tuby
Aug 14 2004, 07:15 AM
U can log all lan/wan activity , it's another good source of informations. U can use Tcpview from
Sysinternals.com .
U never find the ip of your attacker, except it's a newb', but u can observe which ports are compromized.
Enjoy !
MadMaddy
Aug 20 2004, 04:58 AM
| QUOTE |
Which are all measures around a break-down to determine, log files naturally, but which exactly. That depends naturally on the services and the infrastructure. But perhaps generally which is everywhere possible and which can be possible.
In the log files it stands ip's and time-entered with which one identify a hacker. Naturally only if itīs the real IP. This is kept anonymous usually with proxy or socks. But as these 2 possibilities are safe, and give it perhaps more ?.
would be grateful over each experience and assistance by you |
Pretty much as gman24 said, you can use an IDS such as snort. When you think you've captured some packets from your 'hacker', snort will be able to tell you such information as what program the packet is going for, origionation IP, plus many times you will also be able to tell if the person is using a proxy. With this information you will possible be able to tell which part of your system has been comprimised, what he's executing on your computer and where the commands are coming from (either the hackers or proxy's ip)
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.