Re: investigating misuse of the internet

From: M. Burnett (mb_at_xato.net)
Date: 07/09/03

  • Next message: Sanjiv Menezes: "RE: FW: Keyboard Locking/Invisible Screensaver"
    To: <focus-ms@securityfocus.com>
    Date: Wed, 9 Jul 2003 10:26:46 -0600
    
    

    If the system has not been powered off, you may be able to type:
    ipconfig /displaydns. This will show all recent host name lookups
    that are still cached. The advantage of this is that even if the
    person used a proxy or tunnel to bypass your monitoring software, the
    DNS lookups were still probably done locally.

    Of course, if you wish to pursue legal action, you must carefully
    consider the ramifications of how you gather evidence.

    M.

    On Wed, 9 Jul 2003 09:21:57 +0100 (BST), ICT User wrote:
    >Hello all,
    >
    >Occasionally our monitoring software alerts us that someone has
    >tried to access a dodgy web site. If it is deemed serious enough
    >then as well as the reports the we can generate from the software,
    >we are asked to actually go and check out the user's machine for any
    >evidence of misuse.
    >
    >Does anyone know of a formal check list of stuff to go through when
    >doing this on a Windows PC (98 or 2000). I have found lots of info
    >about what to look for when investigating a hacked PC, but what
    >about when looking for signs of a user's internet activity?
    >Temporary internet files, history, cookies, search for jpegs, mpegs,
    >etc. These are the sort of things we normally look at, but I want
    >to make sure that I don't miss anything important just in case it
    >goes legal.
    >
    >Also, if the user had set Internet Explorer options to keep 0 days
    >history then does this mean all evidence has gone, or is there
    >anything else I can look at, e.g. any registry keys?
    >
    >Thanks,
    >
    >Andy
    >
    >
    >
    >__________________________________________________ Yahoo! Plus - For
    >a better Internet experience
    >http://uk.promotions.yahoo.com/yplus/yoffer.html
    >
    >
    >---------------------------------------------------------------------
    >--------
    >---------------------------------------------------------------------
    >---------

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Sanjiv Menezes: "RE: FW: Keyboard Locking/Invisible Screensaver"

    Relevant Pages

    • Re: what a crock!!!!!!!!!!!!!!!!!!!!!!!
      ... him that to file a lawsuit based upon an internet post he would first ... as some of the evidence presented in recent Microsoft and ... believe that any court would accept an e-mail as PROOF of anything? ... can tell you as fact that they won't in Thailand. ...
      (rec.knives)
    • Cupping Addresses Many Diseases
      ... These posts evidence the tendencies of you shteaters to kill and rape ... from the Wyoming Internet Crimes Against ... All of you shteaters were TOLD to stay off my posts .. ...
      (alt.support.chronic-pain)
    • Re: cytoreductive surgery (Steph)
      ... He posts his picture and complete resume right on the internet for ... medicine, if you can't provide good evidence, the treatment is experimental. ... the Americans) in internal medicine, clinical oncology, and radiation ...
      (sci.med.diseases.cancer)
    • Re: troll update
      ... His lies are easy to fight in a court of law, internet is full of evidence of his racism, verbal abuse against entire nations, people, their families and so on. ... The " comedy " videos of him that got me not once but twice arrested he don't find worth mentioning or the videos insulting my ex or the black guy or my person. ...
      (soc.culture.greek)
    • Thankyou - Re: Permissions needed for a Windows Forms Control to call a WebService
      ... > SystemColor enumeration members in your main control otherwise Internet ... Internet Explorer only passes Host evidence, so ... Rather than opening your computer to attacks because the .NET security ... > needlessly open things such as setting the Internet zone to FullTrust. ...
      (microsoft.public.dotnet.framework.aspnet.security)

  • Quantcast