Undies: ;)
Well, to be honest that's a question of your corporate policy and the laws in Oz.... :DQuote:
So I takle it from the story, that my approach of getting me mates together and rolling around to the intruders house in pickups , and taking to the black hat with crobars and pick axes isn't the best solution?
Really, there are only three "results" in a forensic investigation:-
1. No-one can find the attacker, ever.... he's too good.
2. You can't find the attacker but the government can... But that's going public.
3. You can find him, then you decide what to do.
Unless the attacker makes a really _stupid_ mistake like Joshua did you will be relying on lawyers or the authorities to track the attacker back through ISP's, ('cos you won't get the time of day from them). If the trail leaves the country even the government may "dead end" right there too, but by then it's probably public information.
As far as I am concerned, no matter how much of a bitch fit I might throw about being "beaten", my attitude is that I need to know where, what, and how.... Then I have a chance of cleaning it up and preventing a repeat episode. I see, all too often, people saying that their web page was defaced and they have restored from a backup, then it got defaced, then they restored from a backup...... etc... endlessly. It's like sleeping on a bed of rocks... You wake up every morning sore all over, so you replace the rocks..... All the while there's a bed 5 yards away..... Fix the problem not the symptom. The logs and the procedure are the bed, if it isn't there you will continue to sleep on the rocks.
I do like your solution though..... ;)
