| You are here: | About>Computing & Technology>Internet / Network Security> Advanced Security> Incident Response> Incident Response> Help! I Think I've Been Hacked!! |
![]() | Internet / Network Security |
Elsewhere on the WebFedCIRC: Incident ResponseIncident-Response.orgBugtraq Mailing Lists Help! I Think I've Been Hacked!!From Tony Bradley, CISSP-ISSAP, Your Guide to Internet / Network Security. FREE Newsletter. Sign Up Now! ~ Continued ~On Windows systems you can also view the Task Manager or the Event Viewer for more clues. The Task Manager will show you all running applications. You can check this to see if there are programs running that you dont know about. Many hacker tools and utilities will not show up as an application, but may show up on the Processes tab. Click the Processes tab to see all running processes along with the username that initiated each process. Often the applications and processes are intentionally named to look like normal system files so you need to look closely.
The Event Viewer most likely wont offer much in the way of valuable evidence because logging the sort of information you really want would have required preparation (See Plan Ahead to Catch an Intruder). But, it cant hurt to look. By default there are three logs maintained on a Windows system- Application, Security and System. If you have certain services enabled like DNS or IIS or use some third-party applications you may have Event Viewer logs for those as well. You can look through the logs to see if any entries were made at odd times when you know you werent using your computer or if there were errors cause by programs you know you havent used. OK. So youve scanned through the computer looking for the clues and evidence you need to try and figure out who hacked your system, when and how. Now its time to move on to phase 4 (clean system and patch vulnerabilities) and get your system back into non-hacked operational status. There are steps you can take and tools you can use to be relatively sure the system is cleaned and secure. However, the tools rely on knowledge of existing hacker tools and techniques. There is always the possibility that your hacker did something different that wont be picked up and you may miss a backdoor, Trojan or other trick that may allow him to infiltrate your system again. If you have backups of your critical data your best bet is to completely format your hard drive and reinstall your entire system from scratch and then patch and secure it. If you dont have backups of your data or that sounds too extreme for your taste you need to do what you can to make sure the system is clean. If you have not previously unplugged the Internet connection now would be the time to do that, but, if the hacked computer is your only computer, you may need to download some of the tools and updates you will need before disconnecting. If your system is too damaged or you feel better disconnecting it from the Internet you will need to find a second computer to download the software you will need. Elsewhere on the WebFedCIRC: Incident ResponseIncident-Response.orgBugtraq Mailing Lists |
Las Vegas on a BudgetFind a BargainHotel DealsCheap EatsFree AttractionsEntertainment for Less |
All Topics | Email Article | | | ![]() |
| Advertising Info | News & Events | Work at About | SiteMap | Reprints | Help | Our Story | Be a Guide |
| User Agreement | Ethics Policy | Patent Info. | Privacy Policy | ©2008 About, Inc., A part of The New York Times Company. All rights reserved. |


