What To Do If Your Hacked

Pages: 1, 2
free web hosting
Free Web Hosting > Computers & Tech > How-To's and Tutorials > MISC (no matching category)

What To Do If Your Hacked

Downlinker
QUOTE(develCuy @ May 15 2007, 05:26 AM) *
My question is: how to know when you are hacked??

WARNING! I don't necessary agree with the following concepts. Read with caution -->

First I will share to you an ancient hacker philosophy.
"You are not talking about to be infected by a trojan or worm. Hacking is about open ports and capturing of services. A hacker don't want to delete your files or kill your HD, that is another kind of attack. The original purpose of a hacker is "to hack your system". Find security holes and then break the security, but nobody must know. Only after the "attack".
People commonly think about hackers like criminals that want to kick Buss ass and get access to the White House cameras and avoid terrorist be detected when they put an antrax bomb. Criminals are criminals, hackers are people that help in security. Now, if some hacker 'makes sin' then must be named a sucker..."

This kind of philosophy is named "subtility", Christians think that a subtility is an strategy used by the evil. A mix of true and lie, then, an absolute lie. Make some kind of invasion to private content, system or service is not a good action, this means "sin" and then "die". Christians know what kind of die.

<-- WARNING END


SECURITY ON YOUR DESKTOP

A Desktop Computer is the most vulnerable kind of system, . The principal virus, is normally the user. Is like the Earth. Our planet is destroyed by humans. The security of a system depends of the user. In Windows Systems, You ONLY need a good antivirus(avast!, antivir, etc...), also a firewall, an anti-spyware, install Windows Security Updates.... You know the history. Internet does not mean: download & install me. Is like the real world, be careful, something bad will happen if you visit warez sites, or open files containing attachments with the extension: .src, .com, .pif. You must also use this logic: "You read the manual for your TV, for your Cellphone, then use your computer's manual". Drive with care in the signals.
SECURITY ON SERVERS

Securing a server means be in control of everything, have an up to date system and take fast actions in the crisis. By example, for a common LAMP server, you have to configure the firewall, allow connections only via HTTP, HTTPS, FTP, SMTP, POP3 and SSH. Everyone of these services have a common port. If a hacker knows your Apache and OS version, then he will look at bug reports to find some hole and then take control of your Web server. To avoid vulnerability you have to keep an update kernel and apache server. The same for the other services, by example: Postfix, tftp, OpenSSH. You have to be in control of your system, what users, what services, what hostnames/IPs, what ports, what schedules, what kind of rights for every service.... and more in low level: what size of TCP/IP packages, what amount of packages, what amount of lost packages and their frequency.

Some kind of variation, something that makes you think: "this looks strange", must be enough to start your security test routine.
TURN OFF YOUR COMPUTER IS NOT ENOUGH

Hackers are intelligent people, they know: "He will turn-off the computer, just what I need!! I will put my trojan in the boot tasks". Please!!! Just pray, unplug your Internet connection, copy your important files, pray again, turn of your computer and call 911, the police office and FBI. Maybe your hacker is a terrorist spy using your as bridge to hack the Federal Bank. In the real life, a normal user will never know that was hacked, and how many times. Are you waiting for Fire games on your computer, and a Windows Message: "WARNING Your computer is being hacked!!!".
ARE YOU FILLING INSECURE?

Please, I don't want to start the red alert in your mind. Only be sure to have your system up to date. Let the security experts think in their servers and don't do thinks that your mother will not.

Blessings!


hehe, i was thinking about the same, good question!

 

 

 


Reply

dserban
I would like to add to that:
- If at all possible, and if you don't plan to advertise your services to the whole world, do not run them on well-known ports.

"Security by obscurity", so to speak.

Configure your FTP server to listen to e.g. port 7777 instead of 21, give Apache a port number of 9595, etc.

I was recently hacked by a random person through a string of bad decisions and negligence on my part.

I had configured my desktop PC to work as the default DMZ server, in other words, the one host that by default receives all port forwarding requests for port numbers greater than 1024. I had done that a while ago and this detail had slipped my mind.
Then one day I installed VMWare Player on my desktop and was playing around with a virtual live Knoppix environment.
The VMX file I had downloaded from somewhere was configured to allow remote VNC access on port 5900 with no password.
So far so good, but apparently there are hackers who port scan ranges of IP addresses just with port 5900, so I learned my lesson now and I treat 5900 as a well-known port.

So anyway, I was typing away at the root shell in my virtual Knoppix environment when suddenly I start noticing some strange behavior: random characters being output in the shell window, obscure Knoppix configuration applets popping up for no apparent reason, etc.
First I thought it must be a bug in the VMWare player, maybe because my PC was running low on memory, but then I saw something else: this person pasted into my root shell a very well conceived ftp script the purpose of which was to connect to a site with a user name and password and download a .exe file into the WINDOWS directory.
The name of the file was honeypot.exe or pothon.exe or something along those lines.
Obviously, the script failed miserably because the Knoppix ftp utility does not understand the same switches as its Windows couterpart, but I was curious whether or not the username and password for that site were a valid combination ... and they were!
In the end, I got a good laugh out of it, because I imagine this must have been a script kiddie who had not seen a Linux command prompt in his entire life, and even if he had, he couln't have caused any permanent damage to my environment, seen as the Knoppix iso file is handled in read-only mode by VMWare player.
But this small incident served to remind me that the threat from hackers who do this stuff for fun or in order to have something to brag about in their obscure black hat forums ... is REAL.

It also served to make me a little bit more paranoid and check three things at least once a day:
- what processes are running on my PC? Do I know what each one of them does?
- what ports are open on my PC, which ones have established connections with a remote host, and which applications have opened those ports?
- what are the attached devices on my wireless router? Has anyone managed to break the three layers of security (WPA, strong password, MAC filtering)?

 

 

 


Reply


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

Pages: 1, 2
Recent Queries:-
  1. what can i do if my ethernet connection on my desktop pc has been hacked - 5.08 hr back. (1)
  2. how to know ur computer is being hacked - 6.89 hr back. (1)
  3. check if pc is hacked - 14.81 hr back. (1)
  4. virus your computer is being hacked - 21.23 hr back. (1)
  5. how to find out if someone hacking your pc - 24.16 hr back. (1)
  6. how to know being hacked - 27.64 hr back. (1)
  7. how to see if anyone hacked your pc - 27.70 hr back. (1)
  8. what to do if someone hacks your email - 29.28 hr back. (1)
  9. how would you know if someone hack your pc - 30.04 hr back. (1)
  10. what to do if you think someone has hacked your email - 35.42 hr back. (1)
  11. my pc got hacked what can i do - 39.02 hr back. (1)
  12. how do you know when your pc is being hacked into - 44.65 hr back. (1)
  13. how to know if your photos have been hacked - 44.91 hr back. (1)
  14. what to do if people hack to your router? - 54.69 hr back. (1)
Similar Topics

Keywords : Hacked


    Looking for hacked






*SIMILAR VIDEOS*
Searching Video's for hacked
advertisement




What To Do If Your Hacked