1 Feb 2009 22:28
Re: Weird IP
<anastasiosm <at> gmail.com>
2009-02-01 21:28:55 GMT
2009-02-01 21:28:55 GMT
As Ansgar Wiechers said, > If the system was compromised, an attacker could also have altered the > logs to clear his trails. I would agree with that. But it is also important to answer the questions made by Robin Wood before point any fingers to anyone. Considering the only logs you have are coming from the webserver, and assuming that it is not compromised (so that logs have been modified, passwords been stolen etc), I think it worths checking how the card numbers can be accessed normally, eg through a web-interface, how do users authenticate etc, possible attack scenario you should also include in your list could be that of a CSRF attack. Tasos
RSS Feed