karldenton Posted October 18, 2011 Posted October 18, 2011 Hi, Without going into too much detail I need to check on the internet history of a staff member. We don't have an internal proxy in school / monitoring solution. I could log in as the member of staff and go to history in internet explorer but not sure of their password. Is it possible to log on as administrator and go to the history and temporary internet files of a staff member (more so the history). Thanks
featured_spectre Posted October 18, 2011 Posted October 18, 2011 Grab the index.dat file from their laptop, inside there is the entire history (even if it has been "erased" or "deleted") and can be opened using a certain utility (which the name escapes me at the min)
karldenton Posted October 18, 2011 Author Posted October 18, 2011 Thanks. The index.dat been located in c:/documents and settings / user. Let me know if the name comes to you of the program.
featured_spectre Posted October 18, 2011 Posted October 18, 2011 The program is called encase forensic (or something like that). It is used by police and government agencies to extract timestamps and URLs of the machines Internet history. Only way around this is using something like CCleaner on a daily basis after internet usage which will leave no trace of the index.dat file until it is recreated by the machine when an internet browser is opened.
jinnantonnixx Posted October 18, 2011 Posted October 18, 2011 (edited) Watch your forensic trail. Are you using a Tableau write-blocker or working off a binary copy of the disk? If you're analysing live data, especially on your own, a good defence will have this thrown out. Files can be planted, dates adjusted, etc. To quote Denzil Washington in Training Day - it's not what you know, it's what you can prove. Edited October 18, 2011 by jinnantonnixx
karldenton Posted October 18, 2011 Author Posted October 18, 2011 Hi Thanks. I need to do it tomorrow so haven't really got chance to purchase that software. I won't be doing it on my own
featured_spectre Posted October 18, 2011 Posted October 18, 2011 If using forensic it keeps a back up of the original to prevent tampering. Only way to tamper with the file is to use a hex editor and know all of the hex code there is (hex translators do not help one bit as it is still jumbled up). Add or remove 1 digit and the whole file goes corrupt unless you know exactly what to replace. Not an easy task to forge an index.dat file - even if you copy one across from another machine as it binds by MAC address, guid and HDD internal number to the machine
jinnantonnixx Posted October 18, 2011 Posted October 18, 2011 All the same, don't do anything on your own.
Arthur Posted October 18, 2011 Posted October 18, 2011 No need to buy any software, when Pasco will do what you need for free. Almost all of the Linux forensics discs use it, including PlainSight and CAINE. There is a Windows version too.
tommej Posted October 19, 2011 Posted October 19, 2011 IE HistoryView: Freeware Internet Explorer History Viewer Produces a nice html report of all their history.
pete Posted October 19, 2011 Posted October 19, 2011 I'd second Pasco, booting from read-only media and using a read-only (not the original) copy of the hard disk. Using dd to take the image gets a bit-for-bit copy. But make it very clear to SLT that if you (or you and member of SLT) investigate it yourselves, it probably won't be much use in a tribunal / court room. Not an easy task to forge an index.dat file - even if you copy one across from another machine as it binds by MAC address, guid and HDD internal number to the machine You don't need to forge it. You merely need to cast doubt on the evidence and raise the spectre of tampering / corruption. If you fail to maintain a clear chain of custody, a decent solicitor will get your evidence a) ignored b) ruled as inadmissable. Remember - trial by peers and peers are the people who download comet cursors and click on malware links. i.e (nicked from internal wiki) Document: The date and time you were asked to remove machine The date and time you did remove the machine Explain any significant difference between the times eg person did not have laptop in school was the machine in use when it was removed? how was it in use? How you isolate the machine is also important. somebody will have to sign a police statement documenting its isolation and who could have had access to it. The police will need to be sure the trail of evidence is maintained. so if it is in a safe in an office. The key to the safe and the office should not be in the possession of one individual.
karldenton Posted October 19, 2011 Author Posted October 19, 2011 Thanks everyone. Managed to download an index.dat reader and looked at it with SLT. Nothing untoward at all so all positive there.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now