Re: cuebot-d infection method

Harlan Carvey <[email protected]>
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
Jayson,

> One other possibility is that the attacker went
> straight through the
> firewall using an atypical packet....... unlikely,
> but should be placed
> on an all-inclusive roster of post-mortem
> investigations. 

I'm a forensic analyst/engineer, and would be very
interested to know more about your above statement.  I
think that knowing where to look during a post-mortem
investigation for evidence of an "atypical packet"
would be extremely valuable.  

Can you elaborate on this, providing specific
information?  How about examples?

Thanks,

Harlan
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.