Re: Computer forensics to uncover illegal internet use

From: Mike Sweeney (mikesweeney_at_packetattack.com)
Date: 08/30/05

  • Next message: Keenan Smith: "RE: Computer forensics to uncover illegal internet use"
    Date: Mon, 29 Aug 2005 21:40:30 -0700
    To: "Edmond Chow" <echow@gettechnologies.com>
    
    

    Before anything.. make a copy of the disk and lock the original away
    with a chain of evidence. Use Ghost or DD. Work only on a copy.

    Examine the disk using something like Knoppix STD or Audit or other
    bootable CD.

    swap file..
    history files for IE
    Alternative Browser history files
    use a undelete tool to see what might be recovered for cookies etc
    check for firewall logs or proxy server logs

    If he is really that clever, look for alternative data streams and
    hidden files..
    Look for a hidden partition

    Some history and last URLs can be found in the registry

    I'm sure other will toss in their 3 cents too :)

    MikeS
    ____________________________________

    mikesweeney@packetattack.com
    www.packetattack.com
    Home of "Network Security using Linux"

    Office 714.637.4235

    On Aug 29, 2005, at 8:45 PM, Edmond Chow wrote:

    >
    > Dear List,
    >
    > I'm working on the following project and would appreciate your views:
    >
    > I have been tasked with finding out if a certain desktop computer
    > was used
    > to view pornographic sites on the internet. This user has gone to
    > great
    > lengths to try to mask his illegal activities by erasing cookies,
    > temp.
    > files and by installing anti-spyware software on his computer. Are
    > there
    > any tools that would allow me to still uncover proof that he had
    > accessed
    > these sites? So far, the tech department is telling me that he did
    > access
    > illegal sites on only two dates but I suspect that this illegal
    > activity
    > started many months or years ago and it will be up to me to find
    > more proof.
    >
    > Also, at a network level, we know his IP address but yet my technical
    > support department is telling me that they cannot (either because
    > they don't
    > want to or because they are not technically capable of) tell me what
    > internet sites this IP address has accessed in the past.
    > Logically, there
    > must be a point in the network (on some piece of hardware) where I can
    > consult log files to track his activities? Or, is there a log file
    > that I
    > can consult that will tell me what sites all my users have accessed
    > and from
    > what IP address?
    >
    > In terms of access to the desktop in question, I will have full
    > access as
    > the computer will be in my possession in the coming days.
    >
    > Thank-you and any help that you can provide would be most appreciated.
    >
    > Regards,
    >
    >
    > Edmond
    >
    >
    >
    >
    >
    >
    >


  • Next message: Keenan Smith: "RE: Computer forensics to uncover illegal internet use"

    Relevant Pages

    • Re: IO Bottleneck
      ... A lot of it is going to utilize the disk. ... noticable to users is the sequential write of the log files. ... files on their own separate set of write-optimized physical disks is a low ... of your users are OWA users, then the impact on the server should be much ...
      (microsoft.public.exchange.design)
    • Re: securing system after giving away root password
      ... >>I signed an agreement with a provider in Germany for server housing. ... > complete and total control over your machine. ... They could have changed any log files. ... They can thus remove your hard disk, ...
      (comp.os.linux.security)
    • RE: disk caching
      ... Also, write caching is ... disabled on a disk ... >Active Directory log files. ... >Move the Active Directory database and the Active ...
      (microsoft.public.windows.server.general)
    • Re: SBS Client Application Launcher ERROR Message - Manual Test Results
      ... I ran the command line as you suggested via cut and paste to ... No new log files created on WKS. ... Do diags on WKS NIC and Server NIC ... Are you having any issues with the network ...
      (microsoft.public.windows.server.sbs)
    • Re: [Full-Disclosure] Re: Teenager cleared of hacking - Off Topic?
      ... > The experts gave very clear evidence that the attack was initiated ... > locally and log files cannot be planted remotely the way they werew ... overflow an allocated cluster - disk is allocated in "chunks" that are ... > that it was inserted later because of the physical position of the ...
      (Full-Disclosure)