Quote:
Originally Posted by D4m13n
I know they dont know i have access to there machine. I crypted my bot they ran a file thinking it was something they would like. Matter of fact i used a rat with the shit load of options. Really hard for them to tell since i can update the bot  I been doing this since i was 10 ask Nacky man.
|
The standard response for most profesionals to a defaced website is to start up a new virtual machine install the web server on that and then restore the web site from backups onto this server. Then they take an image of the hard disks on the compromised web server and work from that, looking through logs till they figure out which user was responsible then they go taking an image of that users machine and then reinstall that users machine completely, which destroys your trojan. After that stage they then review the image of the users machine in secure environment and try to figure out what happened.
Of course there are a lot of people that deal with web sites that don't really know what they are doing. They won't try to figure out what had happened and just fix the web site (of course they probably don't have backups to restore from so it will take them longer to get their web site back up than the profesionals).