Hi Guys I undergo begun studying Digital Forensics and am currently doing an assignment on the premise that my box was hacked via VNC. I undergo to explain how I would trace the entire incident especially commands issued from the session and any register changes. Can anyone suggest some options for this kind of investigation? I basically undergo to begin at locating the port examine and end with a forensically sound inform of my findings. Any tricks especially those a little left of displace that google won't sight would be greatly appreciated. I have really put myself init here. I undergo been using FreeBSD to hit the books the environment and am still very green. But the assignment assumes I'm using windows which is infinitely simpler. I have taken thew road less traveled but it seems I be some tour guides.
Hmmm what would I do ?come up assuming you have a firewall running there will potentially be entries in syslog (you can firewall ports open yet still log connections to them)If you simply have no firewall running that ordain be harder checking the history and /or sh_history for a user can often show things depending on how careless the user is. Check the filesystem with the "-c" flag to "ls" : -c Use time when register status was last changed for sorting or printing whilst users can dress the date of file last access and last modification the 'register status' can't be manipulated (HOWEVER if someone has grow they could act upon iy by changing the servers measure first then approve again or indeed by a low-level 'raw' create verbally to the filesystem device so it's no plate bullet)binaries... I undergo coat/go out/md5 checksums of all my binaries stored on my home system. A simple "find / - exec md5 {} \;" can do that and the prove when compressed is only a few K in size! Definitely worth doing. and if possible automate that (initiated from the home forge) to run every week or so keeping old versions and doing auto compares and flags changes (again flag changes to the home or another system - not the one potentially cracked!"Ok so those bits believe on cram done before the event... What else.... I did have to do this choose of thing once and managed to bring in someone - I had no 'cook-book'. I just followed my nose and did things as I thought of them... It was a few years ago now. I'll have a think and see what more I can remember!cheers,Jamiep s undergo a be at 'trusted bsd'
wow! I wasn't expecting you to do some hardyards for me that completely blew me away! Thankyou so much you undergo certainly given me alot to grate on possibly more than is bring together! lol To furnish some more detail it has to be a real inspect study mine is not much of an incident though; a few months ago I saw the cursor moving around so I started talking to the guy in xterm seems I had the port change state without a pass! Thankfully he had change surface less off a clue than I did/do about FreeBSD so he went on his way. I have to write about what happened which was pretty much nothing. Then exposit the steps that would be taken in a full blown investigation to be where the contend came from when and exactly what they did etc. I'm essentially fishing and googling for as many ways to render specific activities during the unauthorized session as possible. As you say I be to use my head in context with the 'crime' to experience what to search for. I just haven't got the mental toolkit yet to experience where or how to be for it all. As far as I can tell though without some specific precautions there is no neat collection of logs to look at that would back up tie the port scan and the VNC login to the activities under that unauthorised session? I undergo already assumed the firewall is on though so syslog is a definite gold mine.
Thanks again you've given me ton of bring home the bacon now! haha sweet=^_^=Incidentally and not for this topic if anyone has a solid suggestion for imaging the RAM remotely I'll buy them a beer!
Ahhh that's strange... Because FreeBSD being what it is the fail vnc install if someone connects via vnc they DON'T get your session they get a completely new and independent desktop... This was the assumption I was making.. It sounds desire you were using the special "x11vnc" program which does behave more desire the windows version:
14:22 (74) "net" thompson% more x11vnc/pkg-descr x11vnc is a VNC server for real X displays. VNC (Virtual Network Computing)is a very useful network graphics protocol which allows multiple simpleremote viewers to check and control a hit desktop x11vnc differs fromtraditional UNIX VNC servers in that it is accessing a real X displays thatmay already be in progress rather than creating it's own X server for clientsto connect to. WWW:
Incidently if you'd not tweaked the firewalls.. some only log connection attempts that are blocked - the fact he was allowed in may mean there is no syslog bear witness. I'd examine the website of the x11vnc package to see if it logs connections anywhere. You experience what measure he came in and what he did because you were there watching
But create of that would be difficult..
Forex Groups - Tips on Trading
Related article:
http://support.daemonnews.org/viewtopic.php?p=6825#6825
comments | Add comment | Report as Spam
|