Before I start in on things to do after you get hacked, I recommend a read of a previous article I did on logging what goes on in your network.
If you don’t do what needs to be before an attack, many of the steps detailed in 11 things to do after a ha…
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
Alex Scoble cites best practices preventing and pinpointing hacking (or cracking, or whatever more appropriate term we may call such intrusions) attacks on servers. The steps involve setting up adequate logging and auditing, and at the unfortunate even…
#1 Look at your computer for the last time.
#2 Get a Mac.
#3 There’s no step #3.
#1 Look at your computer for the last time.
#2 Get a Mac.
#3 There’s no step #3.
#1 Look at your computer for the last time.
#2 Get a Mac.
#3 There’s no step #3.
Got hacked? 11 things to do next
Before I start in on things to do after you get hacked, I recommend a read of a previous article I did on logging what goes on in your network.
If you don’t do what needs to be before an attack, many of the steps detailed in 11 things to do after a ha…
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
My guess is for 99% of the admins out there step 11: ‘blow the operating system away, reinstall from scratch, and focus on preemptive security. ‘ would be the only step. Time pressure, stretched budgets, it’d be lovely to have the time to go on a forensics safari but I sure don’t.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Ok, patch your systems daily and run IDS’s and you will not get hacked, I really hate it when an admin says “We have to test the patches first”, Well that’s the vendor’s job wether it be MS, Redhat, etc…
If you do get hacked,
1. don’t blow it away, remove the box from the network,
2create a snapshot of the system (for legal reasons.)
3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can’t get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They’ll still get pwn3d, but you can trivially restart them from a pristine image.
[...] 11 Things To Do After A Hack (via Scobes) [...]
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
–C
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
–C
Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.
In response to the above post, IDS are reactive…they do not prevent anything….they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.
–C
Got hacked?
Alex Scoble cites best practices preventing and pinpointing hacking (or cracking, or whatever more appropriate term we may call such intrusions) attacks on servers. The steps involve setting up adequate logging and auditing, and at the unfortunate even…
Quite interesting steps… thanks for points us their!!
–
Balakumar Muthu
Quite interesting steps… thanks for points us their!!
–
Balakumar Muthu
Quite interesting steps… thanks for points us their!!
–
Balakumar Muthu