[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAJBPpWC=HHSb29g9apNQ4sTng+q1Ntrqx-wDrC9VDp8RJ8F+yA@mail.gmail.com>
Date: Fri, 20 Jul 2012 10:53:38 -0700
From: Scott Solmonson <scosol@...sol.org>
To: Григорий Братислава <musntlive@...il.com>
Cc: "full-disclosure@...ts.grok.org.uk" <full-disclosure@...ts.grok.org.uk>,
Ali Varshovi <ali.varshovi@...mail.com>
Subject: Re: Linux - Indicators of compromise
It seems that English isn't your first language, so no problem with
the confusion-
"don't isolate, monitor spread tactics, perceptually contain and then analyse."
Isolation in an INFOSEC sense means actual measures to stop actual actions.
The short version looks like "we've got all the information we need,
it's time to seal this bitch in a cage".
Before that point is reached, the most important thing is to monitor
without damage to determine behaviors and tactics, hence "perceptually
contain"; in order to anticipate future actions.
Imagine thousands of VMs spun up on a fully simulated IP space with a
full suite honeypot profile-
Let the cows roam, see where they find grass...
Your analysis of my explanation:
> 1) Let hacker run amok so you can see them is run amok
> 2) Once hacker is run amok, steal your bread and is butter, wipe your
> systems, restore
> 3) Go back and is learn why they steal and delete.
1) an enemy can not be countered unless it can be understood
2) that bread and butter was put there, by me, on purpose
3) simple knowledge is power, motivational knowledge is godlike
4) ???
5) profit!
--
NUNQUAM NON PARATUS ☤ INCITATUS ÆTERNUS
On Thu, Jul 19, 2012 at 6:18 AM, Григорий Братислава
<musntlive@...il.com> wrote:
> On Wed, Jul 18, 2012 at 12:20 PM, Scott Solmonson <scosol@...sol.org> wrote:
>> Shortcutting other responses-
>
>> 2) assume the worst, don't isolate, monitor spread tactics,
>> perceptually contain and then analyse.
>
> This is make sense! Do not isolate. Let hacker run rampant in is your
> network. Because if they is damage your network in is process of not
> isolating them, is ok if they is steal and delete. You get to see what
> is they stole after is gone, and after they is wipe your system. This
> is good advice yes, help test your BC/DR! MusntLive like absurd and
> obscure approach!
>
>> Endgame is always close the hole, restore the data, learn from your
>> mistakes that allowed it to happen :)
>
> MusntLive is love your advice!
>
> According to you:
>
> 1) Let hacker run amok so you can see them is run amok
> 2) Once hacker is run amok, steal your bread and is butter, wipe your
> systems, restore
> 3) Go back and is learn why they steal and delete.
>
> MusntLive think answer for #3) is logic one: "Idiot admin allowed is
> this to happen"
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists