Full Disclosure mailing list archives
Re: Linux - Indicators of compromise
From: Григорий Братислава <musntlive () gmail com>
Date: Thu, 19 Jul 2012 09:18:59 -0400
On Wed, Jul 18, 2012 at 12:20 PM, Scott Solmonson <scosol () scosol org> wrote:
Shortcutting other responses-
2) assume the worst, don't isolate, monitor spread tactics, perceptually contain and then analyse.
This is make sense! Do not isolate. Let hacker run rampant in is your network. Because if they is damage your network in is process of not isolating them, is ok if they is steal and delete. You get to see what is they stole after is gone, and after they is wipe your system. This is good advice yes, help test your BC/DR! MusntLive like absurd and obscure approach!
Endgame is always close the hole, restore the data, learn from your mistakes that allowed it to happen :)
MusntLive is love your advice! According to you: 1) Let hacker run amok so you can see them is run amok 2) Once hacker is run amok, steal your bread and is butter, wipe your systems, restore 3) Go back and is learn why they steal and delete. MusntLive think answer for #3) is logic one: "Idiot admin allowed is this to happen" _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Linux - Indicators of compromise, (continued)
- Re: Linux - Indicators of compromise valdis . kletnieks (Jul 26)
- Re: Linux - Indicators of compromise Григорий Братислава (Jul 26)
- Re: Linux - Indicators of compromise Scott Solmonson (Jul 28)
- Re: Linux - Indicators of compromise Григорий Братислава (Jul 30)
- Re: Linux - Indicators of compromise jerry (Jul 28)
- Re: Linux - Indicators of compromise coderman (Jul 16)
- Re: Linux - Indicators of compromise Григорий Братислава (Jul 19)
- Re: Linux - Indicators of compromise Scott Solmonson (Jul 23)
- Re: Linux - Indicators of compromise Benji (Jul 16)
- Re: Linux - Indicators of compromise coderman (Jul 16)
