Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: First time security issue.

From: Chris Ess <azarin(at)tokimi.net>
Date: Tue Jul 22 2003 - 12:53:43 EDT

> Sorry if this post seems remedial, but I'm pretty new to security.

In a word: Yes.

Many people suggest reformatting after any compromise in security. In the world of my day job, that is sometimes not feasible. (Time-sensitive issues.) If you are unable to determine precisely what an attacker did and how they got in, your best bet is to reformat. If you can determine exactly and precisely what they have done (sometimes a hard task on unix systems and I imagine near impossible on some Windows installations), you can cleanse the system of their taint, restore any modified binaries, and go back to running like usual once you patch the hole.

Since it seems like you are unable to determine exactly what they changed or the breadth of the modification is so great, I would suggest a reformat. Backup any user data you may need and hope you have a recent backup of the registry from before the compromise.

Good luck.

Sincerely,

Chris Ess
System Administrator / CDTT (Certified Duct Tape Technician)



Received on Tue Jul 22 17:09:21 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:12 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library