Re: identifying the owner of an IP address.
"jdow" <[email protected]>
| Newsgroups | gmane.linux.redhat.release.guinness |
|---|---|
| Message-ID | <02e901c26424$27ef4e30$1125a8c0@wednesday> |
From: "Joel Thompson" <[email protected]> > Thanks. The whois by IP worked great. > > They are located in Bucharest, Romania. Should I notify > the FBI or what? What kind of recourse do I have? If it cost you or your company significant money or compromised credit records notify the FBI. In practical terms you have no recourse. 1) Are you sure the cracker was located in Bucharest or was that Romanian computer itself cracked and used as a cutout. 2) If it was Romania do you think you have a prayer of carrying out a civil trial against the "perp" in Romania for less money than you could collect in damages? 3) Do you really think the Romanian ISP gives a damn about the perp's activities? 4) Why in heck did you leave your front door open? > Anyone experienced this problem before - what did > you do? I have not. But, FIRST OFF, I would disconnect the system from the internet. Then WITHOUT CREATING OR DELETING ANY FILES I would create backups of everything I could check as being legitimate. (Best, though, is to go to a backup taken BEFORE the compromise.) Then if it involved credit cards or significant financial loss on my part or my company's pat I'd call the FBI and see if they were interested. If not I'd recycle the disk by low level formatting it. Otherwise I'd put in a new disk and save the old one as evidence. Then I would reinstall completely. I would make sure that I ran no services that I did not need. I'd further make sure no services were exposed to the Internet that were not needed on the Internet. (I'd also have those services running on their own NIC off the gateway with specific forwarding instructions through the firewall to get to those machines. I'd leave those machines VERY isolated from the rest of the local machines denying all attempts to contact them from inside or attempts for these exposed servers to contact the internal network. I'd have one exception to this rule, one machine would be able to install or remove files from the servers so attempts to contact the exposed servers from that one machine would be allowed. There's a lot more to it. But you should think through what you expose to the Internet VERY carefully. Never expose more than you must. And even then never expose to more addresses than you must. {^_^}