Re: hacked afterthought, tools

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 08/07/04

  • Next message: anonymous_at_discussions.microsoft.com: "Re: IPSEC\L2TP issue"
    Date: Sat, 07 Aug 2004 02:19:18 GMT
    
    

    Not really. If you had auditing of object access enabled and then audited
    folders/files you might have an idea who accessed data and when but it is not
    practical to audit everything as it will decrease computer performance and generate
    thousands and thousands of events in the security log. Security logs can also be
    erased or modified by a hacker. Encryption of data and removal and securing of all
    private keys that can decrypt a file would be one way to insure confidentiality of
    data. In your situation you pretty much have to assume the worst. --- Steve

    http://securityadmin.info/faq.asp#hackerstoc -- link from Karl's FAQ may be helpful.
    http://www.microsoft.com/technet/community/columns/secmgmt/default.mspx -- from
    Microsoft
    http://www.microsoft.com/technet/security/guidance/secmod144.mspx -- auditing
    procedures.

    "hackedupon" <anonymous@discussions.microsoft.com> wrote in message
    news:026c01c47be8$5a1214a0$3501280a@phx.gbl...
    > Hello,
    >
    > If a system gets hacked and you go over the various data.
    >
    > is any tools out there that will tell you what
    > information they got???
    >
    > it was the only system that had a lot of viruses.
    >
    > Recently discovered it was compromised....
    >
    > Is there anyway to find what network data was transmitted?
    >
    > thank you,
    >
    > "hackedupon"


  • Next message: anonymous_at_discussions.microsoft.com: "Re: IPSEC\L2TP issue"

    Relevant Pages

    • Re: Authentication Auditing
      ... > only show in the security log of the domain computer itself - not the ... > it indeed does show that auditing of logon events is enabled for success ... It is enabled but the effective setting dispalys as "No Auditing". ...
      (microsoft.public.win2000.security)
    • Re: Filtering the auditing of file access
      ... access events recorded in the security log when you audit folders/files. ... You also will need to increase the size of your security log substantially ... I have enabled the auditing of object access on our file-server ...
      (microsoft.public.security)
    • Re: Audit Failures/READ_CONTROL SYNCHRONIZE
      ... You're auditing File and Object Access; you've enabled Auditing on the files ... and you're complaining about audit events ... You can't mask events out of the security log in Event Viewer. ... > Client Domain: HEX21 ...
      (comp.os.ms-windows.nt.admin.security)
    • Re: Monitor User Remotely.
      ... activity, auditing of process tracking on ... remotely via administrator share, and folder files have creation timestamps ... he can clear the security log. ... > Is there any way we can remotely monitor him, ...
      (microsoft.public.win2000.security)
    • Re: Auditing file changes
      ... You might want to have them check who is the owner of the file. ... object access in Local Security Policy on the computer and enable auditing ... on the folder or file they need to track. ... security log size will need to be increased substantially to probably at ...
      (microsoft.public.win2000.security)