My brother on what to do after you get hacked
My brother is an IT guy and writes for ComputerWorld. He gives a list of what to do after your servers get hacked.
My brother is an IT guy and writes for ComputerWorld. He gives a list of what to do after your servers get hacked.
Powered By WordPress
April 7th, 2006 at 3:10 am
#1 Look at your computer for the last time.
#2 Get a Mac.
#3 There’s no step #3.
April 7th, 2006 at 6:42 am
Got hacked? 11 things to do next
Before I start in on things to do after you get hacked, I recommend a read of a previous article I did on logging what goes on in your network.
If you don’t do what needs to be before an attack, many of the steps detailed in 11 things to do after a ha…
April 7th, 2006 at 7:48 am
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
April 7th, 2006 at 11:26 am
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
April 7th, 2006 at 2:09 pm
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
April 7th, 2006 at 5:55 pm
[...] 11 Things To Do After A Hack (via Scobes) [...]
April 8th, 2006 at 8:19 am
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
–C
April 11th, 2006 at 8:10 am
Got hacked?
Alex Scoble cites best practices preventing and pinpointing hacking (or cracking, or whatever more appropriate term we may call such intrusions) attacks on servers. The steps involve setting up adequate logging and auditing, and at the unfortunate even…
April 14th, 2006 at 7:27 am
Quite interesting steps… thanks for points us their!!
–
Balakumar Muthu