real-time forensic monitoring?

Rich Adamson <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <Chameleon.1098103267.adar0@vegas>
Got a location where we believe an isp ex-employee is accessing/reading 
private email, and that employee might be obtaining current passwords
(etc) from existing employees. We're going to use snort to monitor for
several very specific rules (specific to this need) to help detect the 
access, but we're not sure as yet how access is being obtained. We
also would like (as a secondary approach) to trigger other linux system 
audit functions (eg, logins, etc) to gather forensic evidence in this
case.

We've not yet seen or been into their systems (but will be shortly), so 
not sure how they are configured or what might be available to aid in 
this discovery process. We're about 90% sure their email system is
based on linux though.

Before heading to their site (clandestinely, under contract signed by
their president), any suggestions from anyone that has had to play this 
real-time role as to additional evidence-gathering mechanisms that should
best be addressed during a first visit?

On-list or off-list suggestions would be appreciated.


_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.