Google Answers Logo
View Question
 
Q: How does one protect against + gather evidence to prosecute for server hacking ? ( No Answer,   1 Comment )
Question  
Subject: How does one protect against + gather evidence to prosecute for server hacking ?
Category: Computers
Asked by: druginteldotcom-ga
List Price: $50.00
Posted: 05 Jan 2005 07:11 PST
Expires: 04 Feb 2005 07:11 PST
Question ID: 452330
I've experienced a server intrusion that I can pin down to a five day
period, so far. The perp altered robots.txt and change the intrasite
search engine to search the competitor's site.  This had terrible
impact on search engine ranking, of course.

This is an updated Fedora Linux server. I'm publishing mostly with
Frontpage, but there is also ftp access going on to set up a phpbb2
bulletin board, other occasional accesses, usually using WS_FTP.  I
will go ahead with learning about and instituting some of the safety
precautions described here
http://answers.google.com/answers/threadview?id=166896 especially
answers from owain-ga and eiffel-ga

My questions (which are also posted as a fresh, pay-for-answer question):

1. Does Frontpage have similar vulnerabilities for hacking password?
2. Do I have hope of learning the ip address or other partial identity
of the hacker? Are there investigators recommended who do this
professionally?  I can narrow down my suspicion about who it was
pretty easily.
3. Is it worthwhile reporting the criminal intrusion, and if so, to whom?
4. I have looked for other security and monitoring software, and have
found Snort and Snorter.  Is this recommended?  http://www.snort.org/ 
Also Tripwire  http://www.linuxsecurity.com/content/view/110291/65/
5. What other files might have been vandalized by my competitor on my
server to prevent its being promoted? The site has just about
disappeared from search engines results, now, 20 days after the
attack.

The ftp logs on the server, furnished by my server administrator, have
been of little use, so far.

On the matter of civil litigation, the dollar value of damage is not
huge, this being a site for a non-profit group.  However, the
suspected perpetrator belongs to a major law informatics website (!)
so that the cost to them of a public conviction would be staggering. 
Financing an investigation would be a burden; I am not sure of the
forensic legitimacy of a "bounty hunter" type of operation.
Answer  
There is no answer at this time.

Comments  
Subject: Re: How does one protect against + gather evidence to prosecute for server hacking ?
From: d_whyte-ga on 06 Jan 2005 06:51 PST
 
1) Just a general tip - it's dependant on what language -> sql would
require you to connect to a database.

Presumably using frontpage i'm assuming you have either a javascript
login which has only a few usernames and passwords, even worse only
one. You could then find out the password through right click and view
source.

2) I don't know your server settings - but you can enable logging; or
even create your own logging script using a language such as PHP, this
is not very hard to do.

3) Realistically unless you can see any real damage, or find any
actual proof of IP there is little you can do. The internet isn't
really regulated - update your security.

4)Look around there are plenty to chose from - read reviews see what
suits your needs.

5) Your question isn't that specific, add more to it!

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy