Penetration Testing mailing list archives

Re: [PEN-TEST] eMail auditing problem


From: Mathew Bevan <listhandler () NTLWORLD COM>
Date: Wed, 13 Sep 2000 21:31:05 +0100

Note,

If you reinstall ANYTHING be sure that you have forensically frozen the
scene. Make backups of everything, generally if you just go ahead and
reinstall your prosecution would fail.

- the mail server is hacked => reinstall it, try to prosecute the hacker

- the boss box is compromised (BO2K), and all his keystrokes are logged
- surely some others ...

Unlikely but there are some nifty devices which clip between the keyboard
and computer. Great fun in physical tests I assure you.. 8-)

Mathew Bevan


Current thread: