Mai, intr-un fel sickness are dreptate, TU ca sa te conectezi la internet trebuie sa iei net de la provider, cum s-ar spune, pe romaneste, da? Cand iei acel abonament, automat, pentru tine se fac niste 'camere' speciale in care ti se logheaza activitatea, LOGURI da? Cand vrei sa intrii pe Gogu si ii ceri IP-ul unui DNS Server ca sa te poti conecta, treci prin mai multe nod-uri dar intai si intai treci prin routerele lor, in care se salveaza in log: "IP-ul xx.x.x.x.x.x.x, cu contul xxxxxxx -- detalii: str ,blah blah (optional probabil), a facut request la IP-ul <DNS SERVER> pe port-ul <plm> @ proto TCP" (un exemplu sa zicem, cam asa stau lucrurile si in realitate) iar apoi treci prin mai multe hop-uri, nod-uri de retea, unele sunt vizibile, altele nu, astea au scop la fel ca un router care salveaza loguri, ITI SALVEAZA CONEXIUNEA, sau ce ai facut tu la momentul respectiv. NU EXISTA A NU LASA LOGURI DIN START! Doar sa detii tu toate nod-urile,toate hop-urile, toate routerele,tot ce este Internet, si sa dezactivezi salvarea intr-un log a conexiunilor stabilite de IP-ul tau. Prin a nu lasa urme se inteleg urmatoarele: LA UN MOMENT DAT indiferent de activitatea pe care o ai, LASI URME! Dar! Le poti sterge apoi! Cum a spus si sickness, esti intr-un internet cafe, le "spargi" router-u, stergi log-urile si le dezactivezi, in momentul asta APROAPE nu sunt dovezi despre conexiunea ta, retineti ca orice calculator are un MAC UNIC de identificare (asa stiu, in caz ca eu gresesc, corectati-ma), si daca nu ma insel se salveaza si respectivul, deci ca tu sa stabilesti o anonimitate, mai intai trebuie sa te dezvalui, iar abia apoi sa iti stergi urmele, cu hop-urile/nod-urile sau cum naiba le-or spune, nu ai ce sa faci, asta este! Dar, daca esti bun si te duce capul, reusesti sa intrii in mai multe sisteme si te folosesti de tot ce poti, VPN-uri cu tunel de date criptat, socks, proxy, rdp-uri (ca s-a specificat din cate am vazut), radmin-uri (old school), botnet, iar daca ai un calculator la care ai acces care l-ai stabilit sa fie VPN aici pot intervenii mai multe tehnici de abordare, poti cripta hard-ul respectivului (fara cunostinta lui) ca in momentul recuperarii logurilor (daca sa zicem ajunge politia la el) sa nu poata face nimic! Si DA! NICIODATA sa nu uitati ca se pot recupera loguri, daca tu le-ai sters asta nu inseamna ca s-au dus DEFINITIV, o distributie de Linux Live CD legata de Forensics ( utilizarea testelor ?tiin?ifice pentru a rezolva crime - hallo.ro) ar rezolva imediat recuperarea datelor sterse, dar cu hard-ul criptat, ar fii mai greu asa ceva // LE: daca tot vorbim de loguri, uitati niste incercari esuate de logare pe un root: --------------------- SSHD Begin ------------------------ Failed logins from these: 4Dgifts/password from ::ffff:212.227.22.75: 1 Time(s) 911/password from ::ffff:212.227.22.75: 1 Time(s) Abuse/password from ::ffff:212.227.22.75: 1 Time(s) Braydon/password from ::ffff:212.227.22.75: 1 Time(s) Douglas/password from ::ffff:212.227.22.75: 2 Time(s) OutOfBox/password from ::ffff:212.227.22.75: 1 Time(s) TEACHER/password from ::ffff:212.227.22.75: 1 Time(s) Thiago/password from ::ffff:212.227.22.75: 2 Time(s) aaa/password from ::ffff:212.227.22.75: 1 Time(s) aart/password from ::ffff:212.227.22.75: 2 Time(s) abcd/password from ::ffff:212.227.22.75: 1 Time(s) abuse/password from ::ffff:212.227.22.75: 2 Time(s) activity/password from ::ffff:212.227.22.75: 1 Time(s) adamf/password from ::ffff:212.227.22.75: 1 Time(s) adamko/password from ::ffff:212.227.22.75: 1 Time(s) adamo/password from ::ffff:212.227.22.75: 1 Time(s) admfin/password from ::ffff:212.227.22.75: 2 Time(s) admin/password from ::ffff:212.227.22.75: 6 Time(s) admin2/password from ::ffff:212.227.22.75: 2 Time(s) administrator/password from ::ffff:212.227.22.75: 1 Time(s) admissions/password from ::ffff:212.227.22.75: 1 Time(s) adry/password from ::ffff:212.227.22.75: 1 Time(s) afonsobarroso/password from ::ffff:212.227.22.75: 1 Time(s) agent/password from ::ffff:212.227.22.75: 1 Time(s) agrarbal/password from ::ffff:212.227.22.75: 1 Time(s) aid/password from ::ffff:212.227.22.75: 1 Time(s) ajwisse/password from ::ffff:212.227.22.75: 1 Time(s) aklarena/password from ::ffff:212.227.22.75: 1 Time(s) akos/password from ::ffff:212.227.22.75: 1 Time(s) alang/password from ::ffff:212.227.22.75: 1 Time(s) alaska/password from ::ffff:212.227.22.75: 1 Time(s) albert/password from ::ffff:212.227.22.75: 2 Time(s) alech/password from ::ffff:212.227.22.75: 1 Time(s) alex/password from ::ffff:212.227.22.75: 1 Time(s) allen/password from ::ffff:212.227.22.75: 1 Time(s) alphabg/password from ::ffff:212.227.22.75: 1 Time(s) altairhq/password from ::ffff:212.227.22.75: 1 Time(s) am-staff/password from ::ffff:212.227.22.75: 1 Time(s) am-teacher/password from ::ffff:212.227.22.75: 1 Time(s) am-test/password from ::ffff:212.227.22.75: 2 Time(s) amadis/password from ::ffff:212.227.22.75: 1 Time(s) amandina/password from ::ffff:212.227.22.75: 1 Time(s) amy/password from ::ffff:212.227.22.75: 1 Time(s) anacristina/password from ::ffff:212.227.22.75: 1 Time(s) ancelot/password from ::ffff:212.227.22.75: 1 Time(s) anderson/password from ::ffff:212.227.22.75: 1 Time(s) andika/password from ::ffff:212.227.22.75: 1 Time(s) andreas/password from ::ffff:212.227.22.75: 2 Time(s) andreb/password from ::ffff:212.227.22.75: 2 Time(s) andrei/password from ::ffff:212.227.22.75: 1 Time(s) andres/password from ::ffff:212.227.22.75: 1 Time(s) angela/password from ::ffff:212.227.22.75: 1 Time(s) ani/password from ::ffff:212.227.22.75: 1 Time(s) anita/password from ::ffff:212.227.22.75: 1 Time(s) anne/password from ::ffff:212.227.22.75: 1 Time(s) apgilke/password from ::ffff:212.227.22.75: 1 Time(s) apollo/password from ::ffff:212.227.22.75: 1 Time(s) applelau/password from ::ffff:212.227.22.75: 1 Time(s) aptechplacements/password from ::ffff:212.227.22.75: 1 Time(s) arizona/password from ::ffff:212.227.22.75: 1 Time(s) arnhem/password from ::ffff:212.227.22.75: 2 Time(s) arwen/password from ::ffff:212.227.22.75: 1 Time(s) asdf/password from ::ffff:212.227.22.75: 1 Time(s) asdfgh/password from ::ffff:212.227.22.75: 2 Time(s) asdqwe/password from ::ffff:212.227.22.75: 1 Time(s) atesz/password from ::ffff:212.227.22.75: 1 Time(s) ati/password from ::ffff:212.227.22.75: 1 Time(s) attila/password from ::ffff:212.227.22.75: 1 Time(s) atul/password from ::ffff:212.227.22.75: 1 Time(s) auditor/password from ::ffff:212.227.22.75: 1 Time(s) ayala/password from ::ffff:212.227.22.75: 1 Time(s) babitha/password from ::ffff:212.227.22.75: 1 Time(s) backup/password from ::ffff:212.227.22.75: 2 Time(s) baldwin/password from ::ffff:212.227.22.75: 1 Time(s) balee/password from ::ffff:212.227.22.75: 1 Time(s) balikone/password from ::ffff:212.227.22.75: 1 Time(s) bangalore-ib/password from ::ffff:212.227.22.75: 1 Time(s) barta/password from ::ffff:212.227.22.75: 1 Time(s) bastiaan/password from ::ffff:212.227.22.75: 1 Time(s) bbuser/password from ::ffff:212.227.22.75: 1 Time(s) bcis1301/password from ::ffff:212.227.22.75: 1 Time(s) bcis1405/password from ::ffff:212.227.22.75: 1 Time(s) bcis1432/password from ::ffff:212.227.22.75: 1 Time(s) becc/password from ::ffff:212.227.22.75: 1 Time(s) bedelia/password from ::ffff:212.227.22.75: 2 Time(s) ben/password from ::ffff:212.227.22.75: 2 Time(s) bendene/password from ::ffff:212.227.22.75: 1 Time(s) benny/password from ::ffff:212.227.22.75: 1 Time(s) benobj/password from ::ffff:212.227.22.75: 1 Time(s) bernatp/password from ::ffff:212.227.22.75: 1 Time(s) bertha/password from ::ffff:212.227.22.75: 1 Time(s) bhagya/password from ::ffff:212.227.22.75: 1 Time(s) bharani/password from ::ffff:212.227.22.75: 1 Time(s) bialecki/password from ::ffff:212.227.22.75: 1 Time(s) bianca/password from ::ffff:212.227.22.75: 2 Time(s) biblio/password from ::ffff:212.227.22.75: 1 Time(s) bigi/password from ::ffff:212.227.22.75: 1 Time(s) billing/password from ::ffff:212.227.22.75: 2 Time(s) bizapp/password from ::ffff:212.227.22.75: 1 Time(s) blake/password from ::ffff:212.227.22.75: 1 Time(s) bmtrack/password from ::ffff:212.227.22.75: 1 Time(s) bmw/password from ::ffff:212.227.22.75: 1 Time(s) bo/password from ::ffff:212.227.22.75: 1 Time(s) bob/password from ::ffff:212.227.22.75: 3 Time(s) bogdan/password from ::ffff:212.227.22.75: 1 Time(s) bogdanus/password from ::ffff:212.227.22.75: 1 Time(s) bogie/password from ::ffff:212.227.22.75: 1 Time(s) boker/password from ::ffff:212.227.22.75: 1 Time(s) bozso/password from ::ffff:212.227.22.75: 1 Time(s) bpendle/password from ::ffff:212.227.22.75: Unde 212.227.22.75 este ip-ul atacatorului. Asa ca daca vreodata faci bruteforce, sa te asiguri 100% ca la un moment dat ai sa ii ghicesti parola si sa speri sa nu fie prea tarziu atunci, ca sa te apuci de "curatat" . // LE(2): Aparent, nea 212.227 face bruteforce sau dictionary attack din 2006, probabil dictionary, cu aceleasi usere si parole [click]