Reclaiming a compromised system

Last Updated : Apr 28, 2014 |

About this task

Unfortunately, there is no way to find with assurance all of the modified files and backdoors that might have been left without a complete re-install. Trying to patch up a compromised system risks a false sense of security and might actually aggravate an already bad situation.

Use this procedure to reclaim a compromised system.

Procedure

  1. Turn off the server and disconnect it from the network.
  2. Back up Communication Manager translations, but do not include any system files or system configuration files in the backup.

    For more information, see Secure backup procedures. Translation are safe to back up because they contain internal consistency checking mechanisms.

  3. Reformat the drive before re-installing software to ensure that no compromised remnants are hiding. Replacing the hard drive is a good idea, especially if you want to keep the compromised data for further analysis.
  4. Re-install Communication Manager (30+ minutes).
  5. Reconfigure the server using the Web configuration wizard or the Avaya Installation Wizard (AIW).

    This takes 30+ minutes.

  6. Apply all software updates as appropriate.
  7. Restore the Communication Manager translations (see Viewing and restoring backup data files).
  8. Re-examine your system for unnecessary services (/proc/*/stat | awk ’{print $1, $2}’).
  9. Re-examine your firewall and access policies.
  10. Create and use new passwords.
  11. Re-connect the system to the network.