Security Basics mailing list archives

Re: computer with rootkit?


From: Predrag Petrovic <pedjap () gmail com>
Date: Wed, 28 Sep 2011 22:42:44 +0200

Hi Francois,

Well usually its the best procedure to reinstall the operating system,
you never know what is modified. But if you want to investigate
further I would do the following:
- Isolate the computer from rest of the network
- Forward all traffic from infected machine to an IPS/IDS station to
detect the possible rootkit/worm/trojan
- Perform cold backup of user data (and user data only) on a system
which has up to date definitions. This requires to detach the hard
drive from workstation and attach it to a new one which has up to date
definitions and is not a critical workstation-server in the network.
- Format the drive and install fresh operating system
- Install security patches and antivirus software
- Restore user data

Best regards,

P.

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: