Need a consultant

2010-02-16 Thread James Finstrom
Greetings, Hello all a customer contacted me today and they appear to have a root kit or some other software placed on their system that is causing it to act as a proxy used in attacks on other servers causing their ISP to kill em. They prefer to clean and recover over re-install. There system is

Re: Need a consultant

2010-02-16 Thread JD Austin
My 2 cents :) It may be a simple web form exploit or something more serious and they have no guarantee that it won't be exploited again and again. I'm not a security expert but used to hang out with hackers back when it was just starting to be illegal and have a good understanding of how they

Re: Need a consultant

2010-02-16 Thread Eric Cope
I'm gonna wait for Lisa to chime in, and then say, yeah, what she said :) On Tue, Feb 16, 2010 at 2:37 PM, JD Austin j...@twingeckos.com wrote: My 2 cents :) It may be a simple web form exploit or something more serious and they have no guarantee that it won't be exploited again and again.

Re: Need a consultant

2010-02-16 Thread Craig White
On Tue, 2010-02-16 at 14:37 -0700, JD Austin wrote: My 2 cents :) It may be a simple web form exploit or something more serious and they have no guarantee that it won't be exploited again and again. I'm not a security expert but used to hang out with hackers back when it was just starting to

Re: Need a consultant

2010-02-16 Thread James Finstrom
Any monkey could probably clean it or re-install it and put it on line. The reason I used the term consult is because I would hope whoever goes in to correct this would be able to educate them and secure them so they are not repeating their mistakes. :) On Tue, Feb 16, 2010 at 3:25 PM, Craig

Re: Need a consultant

2010-02-16 Thread Eric Shubert
I agree with JD. I wouldn't (knowingly) buy a used car that had been fixed after a crash either. -- -Eric 'shubes' James Finstrom wrote: Any monkey could probably clean it or re-install it and put it on line. The reason I used the term consult is because I would hope whoever goes in to