02
Oct
08

10 Sign of Compromise……..

SANS put out a good article last week on signs that you’ve had your network or data compromised:

  1. Your logging server hasn’t logged any events or you haven’t received alerts in the last 12 hours
  2.  Your FTP server/user hard drives etc. are suddenly out of disk space or maybe logs increase in size more than your normal variation
  3. Your competition’s products looks just like yours, but have a prettier color scheme
  4. Your customers start receiving spam on email addresses they used only to sign up for your service
  5. You get machine acts “funny” report from users (i.e. windows closing by themselves, browser homepage changed, etc.)
  6. Someone needs help connecting to the company’s wireless access point, you don’t have a wireless access point
  7. Complaints that software (payment processing software, web browser, etc) keeps crashing
  8. Complaints from user(s) that passwords/logins aren’t working
  9. Computer systems running unusually slow
  10. Visitors to your website complain that they get redirected to another site or one that just doesn’t “look” right

Another one we’ve seen – spikes in CPU usage, usually from dictionary attacks or DoS attacks.

October is Cyber Security Awareness month, so hopefully other organizations will be publishing other useful tips and information.

http://isc.sans.org/diary.html?storyid=5095&rss


0 Responses to “10 Sign of Compromise……..”



  1. Leave a Comment

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s


Follow

Get every new post delivered to your Inbox.