identify your system the best way to protect you against computer attack irvan

30
Identify Your System The best way to protect you against computer attack Irvan http://irvan.or.id

Upload: berniece-richardson

Post on 17-Jan-2016

221 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Identify Your System The best way to protect you against computer attack Irvan

Identify Your System The best way to protect you against computer attack

Irvan

http://irvan.or.id

Page 2: Identify Your System The best way to protect you against computer attack Irvan

Agenda

• Introduction

• Identifying anomalies on Linux Based System

• Identifying anomalies on Windows Based System

• Discuss?

Page 3: Identify Your System The best way to protect you against computer attack Irvan

Introduction

• Sometimes we don’t know whether our computer is being attacked or not.

• Most people doesn’t know how to recognize anomalies on their system, even though they are so familiar with their own system.

• Users often underestimate about security audit things.

• But for common they are really don’t know how to recognize it.

• I am a Linux user, what should I do?• I am a Windows user, what should I do?

Page 4: Identify Your System The best way to protect you against computer attack Irvan

Identifying anomalies on Linux Based System

Page 5: Identify Your System The best way to protect you against computer attack Irvan

The “/var/log/messages”

Page 6: Identify Your System The best way to protect you against computer attack Irvan

Seeing process through “ps”

Page 7: Identify Your System The best way to protect you against computer attack Irvan

Watching your “httpd log”

Page 8: Identify Your System The best way to protect you against computer attack Irvan

Knowing error message from “httpd” activities

Page 9: Identify Your System The best way to protect you against computer attack Irvan

Watching out your “door” trought “netstat” command

Page 10: Identify Your System The best way to protect you against computer attack Irvan

Take time to see “lastlogin”

Page 11: Identify Your System The best way to protect you against computer attack Irvan

More detail with “lsof –i”

Page 12: Identify Your System The best way to protect you against computer attack Irvan

Sniff your network with “tcpdump”

Page 13: Identify Your System The best way to protect you against computer attack Irvan

Get process detail with “top”

Page 14: Identify Your System The best way to protect you against computer attack Irvan

Who is online, and what they do?

Page 15: Identify Your System The best way to protect you against computer attack Irvan

Is there any “uninvited” guest?

Page 16: Identify Your System The best way to protect you against computer attack Irvan

Identifying anomalies on Windows Based System

Page 17: Identify Your System The best way to protect you against computer attack Irvan

Check your connection with “netstat”

Page 18: Identify Your System The best way to protect you against computer attack Irvan

The “Task Manager” things

Page 19: Identify Your System The best way to protect you against computer attack Irvan

The “Task Manager” things

Page 20: Identify Your System The best way to protect you against computer attack Irvan

The “Task Manager” things

Page 21: Identify Your System The best way to protect you against computer attack Irvan

The “Task Manager” things

Page 22: Identify Your System The best way to protect you against computer attack Irvan

Who is online?

Page 23: Identify Your System The best way to protect you against computer attack Irvan

What is running on your system?

Page 24: Identify Your System The best way to protect you against computer attack Irvan

Find the “unusual” key on your registry

Page 25: Identify Your System The best way to protect you against computer attack Irvan

Find the unusual things on your “c:\windows”

Page 26: Identify Your System The best way to protect you against computer attack Irvan

Find the unusual things on your “c:\windows\system32”

Page 27: Identify Your System The best way to protect you against computer attack Irvan

Is there any “uninvited” groups?

Page 28: Identify Your System The best way to protect you against computer attack Irvan

Is there any “uninvited” users?

Page 29: Identify Your System The best way to protect you against computer attack Irvan

Discuss?

Page 30: Identify Your System The best way to protect you against computer attack Irvan

Thank You

Happy Hacking..!!