Firewall Wizards mailing list archives

RE: Hackers left open door to my server..


From: Don Benack <DonB () fool com>
Date: Tue, 25 Jan 2000 09:11:11 -0500

I believe SANs formed giac (global incident analysis center) for just this
purpose.
Try http://www.sans.org/giac.htm

Foolishly,
Don

--
Don Benack
The Motley Fool
Don't be a fool, be a Fool at www.fool.com!

-----Original Message-----
From: James Hepworth [mailto:jhepworth () jcllc com]
Sent: Friday, January 21, 2000 11:31 PM
To: 'firewall-wizards () nfr net'
Subject: Hackers left open door to my server..


Someone tried to get into one of our boxes here and left a door (rcp) to one
of their hacked servers.  They also left quite a few files on the server,
large list of servers, IP addresses, usernames and root passwords + their
toolbox of toy scripts. Our system did not let them delete these files, but
they thought they had.  I also have the console log with them chatting to
each other & the commands they issued.

Is there any one place to report this type of violation or should I just
clam up and clean up the box?  The connection (rcp) is still up (not for
long I suspect tho), I would like to catch these buggers.....

Thanks
JAMES  

Tired of bad Internet search results?
Try http://www.muckymuck.com
Cut Through the Muck!



Current thread: