The accused seems to have done the following
- SSHed in with his user id and gained root access to a dev server. The DHCP address for the client IP was last assigned to his laptop
- Created a cron job that ran a script. The script checked whether it was January 31st, 2009. If so, it did the following
- Disable internal monitoring systems to disable alerts
- Create a list of all servers,walk through them and disable logisn and clear out logs
- Wipe out data by overwriting with zeros
- Uninstall software and turn off the machines
- Clear itself out and zero out the root filesystem
The 'smoking gun' seems tenuous at best- the person accused seems to use similar naming conventions for his personal temp files (the .x, .y format) which I agree is unconventional. I think the real smoking gun is the fact that his laptop and his login was used
Comments
Check out the FBI affidavit at http://blog.wired.com/27bstroke6/files/fannie_complaint.pdf.
The accused seems to have done the following - SSHed in with his user id and gained root access to a dev server. The DHCP address for the client IP was last assigned to his laptop
- Created a cron job that ran a script. The script checked whether it was January 31st, 2009. If so, it did the following
The 'smoking gun' seems tenuous at best- the person accused seems to use similar naming conventions for his personal temp files (the .x, .y format) which I agree is unconventional. I think the real smoking gun is the fact that his laptop and his login was usedI wish I could give you 20 karma for that. Nice sleuthing!
Do you think his attack would have worked?