DISQUS

Scobleizer: My brother on what to do after you get hacked

  • Anona · 3 years ago
    #1 Look at your computer for the last time.

    #2 Get a Mac.

    #3 There's no step #3.
  • Michiel · 3 years ago
    My guess is for 99% of the admins out there step 11: 'blow the operating system away, reinstall from scratch, and focus on preemptive security. ' would be the only step. Time pressure, stretched budgets, it'd be lovely to have the time to go on a forensics safari but I sure don't.
  • Jeff O'Hara · 3 years ago
    Ok, patch your systems daily and run IDS's and you will not get hacked, I really hate it when an admin says "We have to test the patches first", Well that's the vendor's job wether it be MS, Redhat, etc...

    If you do get hacked,
    1. don't blow it away, remove the box from the network,
    2create a snapshot of the system (for legal reasons.)
    3. blow away and reinstall, or better yet, pull the drives and install new drives and rebuild the system.
  • J. Random Poster · 3 years ago
    Simple: dump your windows infrastructure, and go with a securable system instead. If you have windows apps you can't get rid of, run them under VMWare on Linux, BSD, Solaris, or (coming soon), Mac OS X. They'll still get pwn3d, but you can trivially restart them from a pristine image.
  • Chris · 3 years ago
    Definitely agree patching is a necessity, but so is change management. You cant have people making arbitrary changes without documentation.

    In response to the above post, IDS are reactive...they do not prevent anything....they are not designed to. It is the vendors job to test that patch to make sure it doesnt cause issues with the OS. It is the administrators job to test the patch to make sure it doesnt interfere with other applications / modifications made since it was a fresh OS. Just throwing on the latest patch blindly is going to cause more problems that it will fix. You have to test patches, no matter the source.

    --C
  • Balakumar Muthu · 3 years ago
    Quite interesting steps... thanks for points us their!!

    --
    Balakumar Muthu