Re: identifying the owner of an IP address.

"jdow" <[email protected]>
Newsgroups gmane.linux.redhat.release.guinness
Message-ID <02e901c26424$27ef4e30$1125a8c0@wednesday>
From: "Joel Thompson" <[email protected]>

> Thanks. The whois by IP worked great.
> 
> They are located in Bucharest, Romania.  Should I notify
> the FBI or what?  What kind of recourse do I have?

If it cost you or your company significant money or compromised credit
records notify the FBI. In practical terms you have no recourse.

1) Are you sure the cracker was located in Bucharest or was that
   Romanian computer itself cracked and used as a cutout.

2) If it was Romania do you think you have a prayer of carrying out
   a civil trial against the "perp" in Romania for less money than
   you could collect in damages?

3) Do you really think the Romanian ISP gives a damn about the perp's
   activities?

4) Why in heck did you leave your front door open?

> Anyone experienced this problem before - what did
>  you do?

I have not. But, FIRST OFF, I would disconnect the system from the
internet. Then WITHOUT CREATING OR DELETING ANY FILES I would create
backups of everything I could check as being legitimate. (Best, though,
is to go to a backup taken BEFORE the compromise.) Then if it involved
credit cards or significant financial loss on my part or my company's
pat I'd call the FBI and see if they were interested. If not I'd recycle
the disk by low level formatting it. Otherwise I'd put in a new disk and
save the old one as evidence.

Then I would reinstall completely. I would make sure that I ran no
services that I did not need. I'd further make sure no services were
exposed to the Internet that were not needed on the Internet. (I'd
also have those services running on their own NIC off the gateway
with specific forwarding instructions through the firewall to get
to those machines. I'd leave those machines VERY isolated from the
rest of the local machines denying all attempts to contact them from
inside or attempts for these exposed servers to contact the internal
network. I'd have one exception to this rule, one machine would be
able to install or remove files from the servers so attempts to contact
the exposed servers from that one machine would be allowed.

There's a lot more to it. But you should think through what you expose
to the Internet VERY carefully. Never expose more than you must. And
even then never expose to more addresses than you must.

{^_^}
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.