Jump to content

Recommended Posts

Posted

Hi,

Without going into too much detail I need to check on the internet history of a staff member. We don't have an internal proxy in school / monitoring solution.

 

I could log in as the member of staff and go to history in internet explorer but not sure of their password.

 

Is it possible to log on as administrator and go to the history and temporary internet files of a staff member (more so the history).

 

Thanks

Posted
The program is called encase forensic (or something like that). It is used by police and government agencies to extract timestamps and URLs of the machines Internet history. Only way around this is using something like CCleaner on a daily basis after internet usage which will leave no trace of the index.dat file until it is recreated by the machine when an internet browser is opened.
Posted (edited)

Watch your forensic trail.

 

Are you using a Tableau write-blocker or working off a binary copy of the disk? If you're analysing live data, especially on your own, a good defence will have this thrown out. Files can be planted, dates adjusted, etc.

 

To quote Denzil Washington in Training Day - it's not what you know, it's what you can prove.

Edited by jinnantonnixx
Posted
If using forensic it keeps a back up of the original to prevent tampering. Only way to tamper with the file is to use a hex editor and know all of the hex code there is (hex translators do not help one bit as it is still jumbled up). Add or remove 1 digit and the whole file goes corrupt unless you know exactly what to replace. Not an easy task to forge an index.dat file - even if you copy one across from another machine as it binds by MAC address, guid and HDD internal number to the machine
Posted

I'd second Pasco, booting from read-only media and using a read-only (not the original) copy of the hard disk. Using dd to take the image gets a bit-for-bit copy.

 

But make it very clear to SLT that if you (or you and member of SLT) investigate it yourselves, it probably won't be much use in a tribunal / court room.

 

Not an easy task to forge an index.dat file - even if you copy one across from another machine as it binds by MAC address, guid and HDD internal number to the machine

 

You don't need to forge it. You merely need to cast doubt on the evidence and raise the spectre of tampering / corruption. If you fail to maintain a clear chain of custody, a decent solicitor will get your evidence a) ignored b) ruled as inadmissable. Remember - trial by peers and peers are the people who download comet cursors and click on malware links.

 

i.e (nicked from internal wiki)

Document:

  • The date and time you were asked to remove machine
  • The date and time you did remove the machine
  • Explain any significant difference between the times eg person did not have laptop in school
  • was the machine in use when it was removed?
  • how was it in use?

How you isolate the machine is also important. somebody will have to sign a police statement documenting its isolation and who could have had access to it. The police will need to be sure the trail of evidence is maintained. so if it is in a safe in an office. The key to the safe and the office should not be in the possession of one individual.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...