When a server gets rooted, should I disconnect network or power?
- by Aleksandr Levchuk
When a server gets rooted (e.g. a situation like this), one of the first things that should be done is containment. Quoting from Robert Moir's Answer:
"disconnect the victim from its muggers"
A server can be contained by pulling the network cable or the power cable.
Taking into consideration the need for:
Protecting victims from further damage
Executing successful forensics
(Possibly) Protecting valuable data on the server
Which method is better?