Slashdot Mirror


How Should One Respond to a Network Break In?

Jety asks: "I am the sole IT support for a medium sized residential real estate office. It has a network of one main server, 10 office workstations, and another 40 or so agent's personal computers. I discovered via logs that recently someone made about 50 remote login attempts to the server, guessing at passwords, but it would appear that they were not able to gain access. They did, however, leave an IP address in the logs. It turns out to be an Exchange server for another business in the same city. What is an appropriate response to this sort of failed break-in attempt? How seriously should one react? How should it be presented to management, and should you encourage them to over or under react? Should the other business, whose server was used to launch the attack, be informed? Should you try to surveil them first to learn about who is doing their tech work? With what tone should they be approached and/or accused? What would a suitable response from that company entail?"

4 of 96 comments (clear)

  1. It probably isn't even them by Stone+Rhino · · Score: 5, Informative

    You shouldn't start out accusatorily, because it's most likely that they're not the ones attempting the breakin. It's more likely that their box has been hijacked and is being used as a proxy to launch attacks against your computer for someone else.

    After all, who uses an exchange server as their terminal to log in to other computers? If it was one of the desktops, then it would make sense that they were attacking.

    --


    Remember, there were no nuclear weapons before women were allowed to vote.
  2. Simple by rylin · · Score: 5, Insightful

    You try contacting abuse@ the other company.
    If that fails, you call them up and ask for their tech-lead.

    You already have your logfiles, and reasonably secured server.
    What you can gain here is a partnership - or at least an exchange of favors every now and then - between your company and the remote one.

    That said, if the other company isn't responsive, you firewall them to hell and get on with your daily work.

    You'll want to give management a brief notice about what's happening before you do this, obviously.
    After you've talked to abuse@, you tell management what happened.

    Now is the time to see over your authentication schemes. Are your users logging in over SSH? With passwords instead of keys? (Hint: keys are nicer).

    After this is said and done, you paypal me $90 for doing your job.
    Cheers!

  3. Personally... by Anonymous Coward · · Score: 5, Funny

    I always celebrate. Oh wait, you mean as the victim? Hrm..

  4. Re:Don't overreact by Nos. · · Score: 5, Informative

    Speaking of which, I was just chatting with a buddy who has a Brute Force rule setup in IP tables. Too many connections from a single IP within a set amount of time creates a temporary ban of that IP.

    Here's what he wrote to an IRC channel we were on (this is untested but should be close):

    • iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -j SSH_Brute_Force
    • iptables -A SSH_Brute_Force -m recent --name SSH --set --rsource
    • iptables -A SSH_Brute_Force -m recent ! --rcheck --seconds 60 --hitcount 4 --name SSH --rsource -j RETURN
    • iptables -A SSH_Brute_Force -m limit --limit 3/min -j LOG --log-prefix "SSH Brute Force Attempt: "
    • iptables -A SSH_Brute_Force -p tcp -j REJECT
    Again, I haven't tried this yet, but generally speaking, 4 ssh connects within 60 seonds on eth0 will result in a 3 minute ban - I think.