Security Incidents mailing list archives

RE: hacked server, DDoS bin installed


From: "richardcg" <richardcg () comcast net>
Date: Wed, 7 Dec 2005 21:44:15 -0500

This also depends on the customer and what the server either housed (i.e.
Database of account - credit card #) or it's use(s) (i.e. Web Server with
Websites, web access points, portals, or web mail services) as to what
action(s) to take. The advice earlier given is perfect and should be
followed (document everything) but to add, if the possibility of identity
theft exists they should, as well, notify there customers and/or users to
let them know and take appropriate actions.

--- Rich

-----Original Message-----
From: naptime () gmail com [mailto:naptime () gmail com] 
Sent: Tuesday, December 06, 2005 4:33 PM
To: incidents () securityfocus com
Subject: hacked server, DDoS bin installed

a customers server got hacked.. binary in tact, seems like they were
DDoSing.. strings brings up the irc server, channel name, key.. where is the
fbi address where i can send this information to?

thanks


Current thread: