Re: identifying the owner of an IP address.

H Clive Robinson <[email protected]>
Newsgroups gmane.linux.redhat.release.guinness
Organization SilverPlatter Technical Support
Message-ID <[email protected]>
Just another thing,

It's not just services you need to remove, the recent Apache/OpenSSL
worm (Slapper/bugtraq) could only do it's stuff if,

  1, You had the vulnerable service
  2, The C compiler was available on the attacked machine.
  3, The Firewall did not check outbound packets and did not block
     unknown traffic from unexpected ports.

The moral be a good neighbour, do not leave Anything on an internet
facing machine that could be used to aid in the attack of your
machine or others...

In England many many years ago, although a village could not fend
off a Viking attack, they could however burn their boats to stop
them attacking another village...

Regards,

	Clive

jdow wrote:
> 
> From: "Joel Thompson" <[email protected]>
> 
> > Thanks. The whois by IP worked great.
> >
> > They are located in Bucharest, Romania.  Should I notify
> > the FBI or what?  What kind of recourse do I have?
> 
> If it cost you or your company significant money or compromised credit
> records notify the FBI. In practical terms you have no recourse.
> 
> 1) Are you sure the cracker was located in Bucharest or was that
>    Romanian computer itself cracked and used as a cutout.
> 
> 2) If it was Romania do you think you have a prayer of carrying out
>    a civil trial against the "perp" in Romania for less money than
>    you could collect in damages?
> 
> 3) Do you really think the Romanian ISP gives a damn about the perp's
>    activities?
> 
> 4) Why in heck did you leave your front door open?
> 
> > Anyone experienced this problem before - what did
> >  you do?
> 
> I have not. But, FIRST OFF, I would disconnect the system from the
> internet. Then WITHOUT CREATING OR DELETING ANY FILES I would create
> backups of everything I could check as being legitimate. (Best, though,
> is to go to a backup taken BEFORE the compromise.) Then if it involved
> credit cards or significant financial loss on my part or my company's
> pat I'd call the FBI and see if they were interested. If not I'd recycle
> the disk by low level formatting it. Otherwise I'd put in a new disk and
> save the old one as evidence.
> 
> Then I would reinstall completely. I would make sure that I ran no
> services that I did not need. I'd further make sure no services were
> exposed to the Internet that were not needed on the Internet. (I'd
> also have those services running on their own NIC off the gateway
> with specific forwarding instructions through the firewall to get
> to those machines. I'd leave those machines VERY isolated from the
> rest of the local machines denying all attempts to contact them from
> inside or attempts for these exposed servers to contact the internal
> network. I'd have one exception to this rule, one machine would be
> able to install or remove files from the servers so attempts to contact
> the exposed servers from that one machine would be allowed.
> 
> There's a lot more to it. But you should think through what you expose
> to the Internet VERY carefully. Never expose more than you must. And
> even then never expose to more addresses than you must.
> 
> {^_^}
> 
> _______________________________________________
> Guinness-list mailing list
> [email protected]
> https://listman.redhat.com/mailman/listinfo/guinness-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.