OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: How to Track a hacker
From: Ryan Yagatich (ryagatichCSN1.COM)
Date: Tue Nov 07 2000 - 18:24:02 CST


<< a) fire logs onto another computer (so they need to break into that to)
>>
well, with my many attempts at doing this i have not yet found a way to get
this to work 100% of the time because the user who is following where the
logs go, they access that machine with the same credentials as the "logger".
say for example syslog points logs to machine B, it uses the username of
syslog, and password of syslog. well, the attacker just reads the script
that calls "the upload" or write to that disk, and has the same rights as
the person syslog.

my question is: how would you accomplish this, because my attempts have all
failed miserably.

thanks,
ryan