one more suggestion... this may be a good opportunity to get your
employer to pay for a security audit and threat analysis.  most
eployers won't even consider it till it's too late, and I would say
it's that time for you right now.

would be a great learning opportunity for you and it would benefit
your employer as well!

-cameron

On 3/2/07, Yves Arsenault <[EMAIL PROTECTED]> wrote:
> Thanks for the replys guys....
>
> The IP could be spoofed... possible.
>
> I was thinking of reporting it to the ISP.
>
> I'm certainly not gonna spend a whole lot of time chasing anyone down.
>
> As for damages..... I'd estimate it lower the 5k for sure.
>
> Yves
>
>
> On 3/2/07, Heald, Timothy J <[EMAIL PROTECTED]> wrote:
> >
> > What was the monetary value of the damage done?  If it wasn't over 5000
> > (I think) the feds won't look at it.  Other options include contacting
> > the company that owns the IP address, contacting the host government, or
> > do nothing at all.  For your own time, money, and sanity I suggest you
> > whipe the box and don't report it.
> >
> > Figure out how the malicious user gained access, then patch or repair
> > whatever the fault was, then forget about it.
> >
> > --
> > Timothy Heald
> > Senior Developer/Architect
> > HR/EX/SDD, SA-1, H808F
> > Desk: 202-663-2752
> > Fax: 202-261-8299
> > Cell: 703-300-3911
> >
> > -----Original Message-----
> > From: Yves Arsenault [mailto:[EMAIL PROTECTED]
> > Sent: Friday, March 02, 2007 12:56 PM
> > To: CF-Community
> > Subject: Server has been hacked: Question
> >
> > Hey there!
> >
> > (Question way at the box.... context follows)
> >
> > I had quite a time these last couple of days.
> >
> > Yesterday morning, I discovered that one of my employer's linux servers
> > was
> > down... tried a few things to get some services up and running... but,
> > misteriously I could no longer log in. (an old Linux Mandrake 10
> > server...)
> >
> > So, I decided to reboot.
> >
> > After rebooting, I noticed that a couple of errors presented
> > themselves....
> >
> > An error stating that a file couldn't be found... I was unshure what
> > this
> > file was... and I later found out.
> >
> > After that error, the "logger" service crashed. Weird.
> >
> > Anyways, after trying several things to log in without success... . I
> > rebooted the box again using Knoppix on CD to boot up...
> >
> > I then proceeded to hack my password file. I changed the password to
> > blank
> > (as soon as I logged in, I changed it).
> > I then created the files that were missing.... these files were used by
> > the
> > logger service to write to log files.. when I tried checking my logs...
> > they
> > were all blank.
> > I was puzzled.
> >
> > I then booted up, logged in and started checking the server out... I
> > quickly
> > noticed that MANY files had simply vanished....
> > Apache that was running on this box was GONE! As was some of Webmin and
> > other stuff....
> >
> > I suspected from the start that maybe this box had some unwelcomed
> > visitor....
> >
> > This morning... I checked the logs again....
> >
> > And there was some evidence.
> >
> > In my auth.log file... I saw a user (who previously didn't exist on the
> > box)
> > log in from an external IP. (From Romania to be precise)
> >
> > A user was created on this box.....
> >
> > Anyways... this box doesn't have much on it.... a couple of small sites
> > I'm
> > gonna move over and a few emails.
> >
> > So.. it seems this person hacked this box, disabled my logging services
> > to
> > hide his trail and had fun deleting stuff...
> >
> > Now... my question:
> > Since I have this user's IP address how do I or can I report this?
> >
> > Anyone had an experience like this??
> >
> > Thanks CFers....
> >
> > --
> > Yves Arsenault
> >
> > "Love is the only force capable of transforming an enemy into a friend".
> > --Martin Luther King, Jr.
> >
> >
> >
> >
> >
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Deploy Web Applications Quickly across the enterprise with ColdFusion MX7 & 
Flex 2. 
Free Trial 
http://www.adobe.com/products/coldfusion/flex2/

Archive: 
http://www.houseoffusion.com/groups/CF-Community/message.cfm/messageid:229362
Subscription: http://www.houseoffusion.com/groups/CF-Community/subscribe.cfm
Unsubscribe: 
http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=11502.10531.5

Reply via email to