|
|
|
Date Submitted:
08/05/05
Hits: 64 Rating: ![]() ![]() ![]() ![]() based on 0 votes
IDS Logs in Forensics Investigations: An Analysis of a Compromised HoneypotAdded by Papergrl
Description:
An attacker has compromised a Sun Solaris server on a production network using an exploit for the dtspcd service in CDE; a Motif-based graphical user environment for Unix systems. You are the senior security engineer of the Security Operations Center (SOC) for your company and are required to find out how the box was compromised and by whom. Using only a Snort binary capture file from the remote log server, you are to conduct a complete analysis of all IDS captures, log files, and an inspection of the file system.
Read the Complete Paper You don't have permission to post replies. Please login or register. |
