Web Server Compromise
Background:
Help! I was creating a blog to talk about my research and I think it was hacked! It is now advertising free essay papers. All I had done is install WordPress and and a few plugins.
Assignment:
This is a group project where you will work as a team of incident responders. You will be placed into teams of three. Working with your partner, you will use the logs and site directory to figure out what happened and when. The deliverable for this assignment is an incident report.
Steps:
We will be teaching using Splunk, but if you are more comfortable using Elastic (ELK) or some other log searching mechanism you are free to do so. The raw logs are attached to this assignment below. While you can definitely succeed at this assignment using plain old grep, I would recommend you don’t. While grep will work due to the small size of the log files being provided, grep fails to perform when you are in an actual Enterprise with massive amounts of data. To access Splunk:
1. Log in to the Georgia Tech VPN
2. Navigate to https://splunk.class.security.gatech.edu (Links to an external site.)
3. Log in with your GT username and password 4. Click “Search and Reporting”
5. Start searching!
The data for this assignment is in the “project2” index. You can see all of the data by searching for “index=project2” and changing the time dialog from “Last 24 hours” to “All time.” Splunk already has the fields extracted from the logs for you.
Incident Report:
Write an incident report based on this assignment. Use the provided template from additional resources. The audience for this report will be your executive leadership and the affected business unit leadership.
As discussed in the report writing lecture, make sure to include (these are all sections in the template):
• An executive summary
• A detailed timeline of the incident. Include detail of the attack
• Any containment and eradication steps that you would have taken. (e.g. would you have requested that the web server be restored from back up?). Document these steps as if you had taken them (e.g. At 12:05pm the security team requested the web server be restored from previous clean back up)
• Financial impact o Include effort estimates for your investigation and the time resources from any other involved teams
o Anything else you can think of that might have had financial impact o The numbers can be completely made up • Lessons learned
Additional Resources
Example Real World Incident Report




