borderfox Posted November 9, 2011 Posted November 9, 2011 The query is as per the thread title...but let me give some background first. Situation involves a sub contractor working with a multi-national corporation. He was working very closely with them - in so far as he had a user account on the company's internal email system. Without going into detail, a dispute arose. Outlook access was subsequently withdrawn. However, the individual can still view legacy mails up to that time - on the copy of outlook that's on their laptop. Upon reviewing mails, this individual has now noticed a handful of critical mails that they are 110% sure they had not received during the time in which they were working in close cooperation - onsite - with this company. However, the mails show up with dates suggesting that they were sent during the individuals time - working closely with the company. Is it possible - where a company have their own outlook server - that mails could be backdated and then sent out from a couple of the other company employees who are key to the issue at hand? The individual concerned would have logged in on a number of occasions in the weeks following this conflict coming to a head. Any input from anyone with experience of running an outlook server would be very welcome on the subject.
plexer Posted November 9, 2011 Posted November 9, 2011 If all the header datestamps match then the email was sent when it says it was. Ben
plexer Posted November 9, 2011 Posted November 9, 2011 Especially with no current access to the mail server or are you suggesting it was forged and then access was withdrawn? Ben
borderfox Posted November 9, 2011 Author Posted November 9, 2011 (edited) Hi Ben. Thanks for your mail. I'm talking in terms of a concerted effort on behalf of senior management in this organisation - directing IT staff - to insert these mails after the fact. I can't go into the specifics other than to say that I am exploring this as it's a legal issue with high stakes for those involved. If they control the mail server - could they do this...that's my question. I note your point about datestamping on the email header -and so I will try and check that out. Actually, on that point, how exactly can I access the header information of a mail in outlook (apologies if this is basic but I'm not an IT professional). Especially with no current access to the mail server or are you suggesting it was forged and then access was withdrawn?I'm suggesting it was done - then the individual logged in remotely from home - and these mails would then have propagated in their inbox. Subsequently, access was withdrawn. Edited November 9, 2011 by borderfox
glennda Posted November 9, 2011 Posted November 9, 2011 Yes i think you can - but it involves changing the time on the server - something which is very risky as Kerberous could lock it out. I had it a few weeks ago when i setup a new ntp server on our internal network (that queries our lea - dc queries our local server) and this updated and all the servers did aswell - bar the exchange server (which the time jumped 2 hours out). I was able to send emails say at 3:30pm real time but the server thought it was 1:30 so they appeared in outlook as though they arrived at 1:30pm. not sure if this works with date though. EDIT: you may find there is event logs showing that this has been done.
featured_spectre Posted November 9, 2011 Posted November 9, 2011 Right, yes it is possible, and very easily if the exchange server is the ONLY thing running on that server. The server time can be changed on the server and the mail sent (and subsequently exchange will receive it) and it will go into wherever the date on the mailbox fits. To tie in with this, the laptop or PC where the mail originated had to be changed to the same date. It is a fair bit of work to do but it can be done. However there would need to be more than 1 person involved as it would involved the server, domain level admin access and local admin access on the originating machines. I hope that helps in your quest to resolve your problem.
SYNACK Posted November 9, 2011 Posted November 9, 2011 Yes, if the mail is internal then this can be forged or if they have access to the remote sending server aswell. It is just time stamped by each server so if you hve control of those servers you can do whatever. It rapidly becomes a pain though the more systems you involve and the more heavily trafficed the system is.
sukh Posted November 9, 2011 Posted November 9, 2011 1. I;m not sure what exactly what you're trying to acheive here. Yes it can be done but was this the case in your scenario, needs investigation. 2. If it's a legal battle, then more than likely, that would be thrown out of the window as message can be altered. 3. If the company is using journaling then that would stand. 4. If you have a sample of the message, you check the creation date of the message, send date, and a lot more infomration.
teejay Posted November 10, 2011 Posted November 10, 2011 It should be possible to figure this out from the message tracking log on the exchange server, if not then forensic examination of the exchange database will show it up. You do need someone with forensic analysis skills with exchange, best speaking to Microsoft support in the first instance. It will cost money and is not something to mess around having a go yourself as the evidence could then be inadmissable if it was serious enough to go to court. 1
sukh Posted November 10, 2011 Posted November 10, 2011 What I dont see is, if there is access to the env or not. It seems like this is from an Outlook end and the user doesnt work the company anymore. Therefore wouldn't have access to the Exch server. No you cant get the info. 1
borderfox Posted November 10, 2011 Author Posted November 10, 2011 What I dont see is, if there is access to the env or not. It seems like this is from an Outlook end and the user doesnt work the company anymore. Therefore wouldn't have access to the Exch server. No you cant get the info. Your quite right. This was always from the outlook end -as the individual concerned did not contract to this organisation for anything remotely I.T. related. This individual is in dispute (as in pending legal action) with the organisation. Based on all of your comments above, it seems that it is plausable that the system could have been tampered with to facilitate the company 'planting' a number of emails in his inbox.....emails that will have a deleterious effect on him proving wrong-doing. Having come to this conclusion, the question now is how does he deal with this scenario? That is to say, how does he prove that these mails have been mischievously planted there - to weaken the grievance he claims against them?
sukh Posted November 14, 2011 Posted November 14, 2011 Depends on how far the indivdual want to take this. In fact, it depends on how and if the email are going to be used against him or not. If the evidence is with emails then dispute the authenticity. If one can't prove, then they cant be used.
borderfox Posted November 15, 2011 Author Posted November 15, 2011 Depends on how far the indivdual want to take this.Well, lets just say that it's already in train - and will be running the full course. In fact, it depends on how and if the email are going to be used against him or not.It's safe to assume that they were planted there with a view to discrediting the course of events that the complainant would be presenting. If one can't prove, then they cant be used.I hadn't considered it like this - so thanks for mentioning that. Looking at this from another angle, if we were to assume that it's possible for the complainant to have this checked (via a court order or other legal mechanism), given access to company systems, would an I.T. professional be likely to get evidence to prove this? Can anyone suggest how this could be approached? Are there people who specialise in this type of thing...i guess it's computer forensics, is it not?? It would be good to get a general opinion from I.T. savvy folk here - as to how this aspect of it could best be handled.
featured_spectre Posted November 15, 2011 Posted November 15, 2011 (edited) IF you have a court order/subpoena, you would need someone impartial (and you could recommend someone to the courts who has nothing to do with the case and knows neither party) to have the evidence checked on the servers/machines. At which point all machines pertinent to the case in question would need to be surrendered to said IT professional. On top of this, any additional machines that would need checking would also have to be submitted, as would all passwords and other details required to gain the appropriate access. From there the IT Professional would then need to have an allowed period of time (1 day per machine should be sufficient, however 2 days per machine would be what I would spec for). My own personal approach would be to check the following Back up all machines in a full system state - this way if I make any errors the machines can be restored to how they were (covering myself on this one) Then I would check for Timestamps in the headers of the email account in question IP/DNS stamps in the headers of the email account in question Content of said emails (and print off hard copies including headers) I would then do the following Go to the exchange server and check the above, and check the database entries for when emails entered into the exchange database. Reason being is that these are exceedingly difficult to forge and requires a fair bit of configuring to do without screwing everything up. Check SPF (Sender Policy Framework) records which are stored on the exchange server as well as authenticated machines from which the email address can be sent. If for example I sent something from say [email protected] it would store at your exchange box, however it would tell you in the SPF that a non-authenticated machine sent that email and will flag up as a spoofed email address / mail. I would also document every step I did so that another person can verify my findings as appropriate. It is not a case of computer forensics, but just simply knowing what to look for and giving accurate reports for the people as required. Edited November 15, 2011 by featured_spectre
FN-GM Posted November 15, 2011 Posted November 15, 2011 IF you have a court order/subpoena, you would need someone impartial (and you could recommend someone to the courts who has nothing to do with the case and knows neither party) to have the evidence checked on the servers/machines Remember this guy is in the Republic of Ireland so different laws applies so it may not be the same there as it is in the UK.
featured_spectre Posted November 15, 2011 Posted November 15, 2011 Didn't realise Pembrokeshire was ROI
teejay Posted November 15, 2011 Posted November 15, 2011 Well, lets just say that it's already in train - and will be running the full course. It's safe to assume that they were planted there with a view to discrediting the course of events that the complainant would be presenting. I hadn't considered it like this - so thanks for mentioning that. Looking at this from another angle, if we were to assume that it's possible for the complainant to have this checked (via a court order or other legal mechanism), given access to company systems, would an I.T. professional be likely to get evidence to prove this? Can anyone suggest how this could be approached? Are there people who specialise in this type of thing...i guess it's computer forensics, is it not?? It would be good to get a general opinion from I.T. savvy folk here - as to how this aspect of it could best be handled. The simple answer is: a) Stop discussing it on here, this is a public forum and and discussion could discredit the case b) SEEK PROFESSIONAL LEGAL ADVICE who will advise and take appropriate action if it's felt this is required
borderfox Posted November 15, 2011 Author Posted November 15, 2011 (edited) Remember this guy is in the Republic of Ireland so different laws applies so it may not be the same there as it is in the UK. Didn't realise Pembrokeshire was ROI Sorry folks - my bad. Originally from IRL but in UK now - so discussed in the context of the UK. The simple answer is: a) Stop discussing it on here, this is a public forum and and discussion could discredit the case b) SEEK PROFESSIONAL LEGAL ADVICE who will advise and take appropriate action if it's felt this is required It was never the intention to discuss any legal aspects whatsoever. I felt it was necessary to give some background. Otherwise, the query is purely technical - regarding the mechanics of how servers could be examined to prove that data was tampered with. IF you have a court order/subpoena, you would need someone impartial (and you could recommend someone to the courts who has nothing to do with the case and knows neither party) to have the evidence checked on the servers/machines. At which point all machines pertinent to the case in question would need to be surrendered to said IT professional. On top of this, any additional machines that would need checking would also have to be submitted, as would all passwords and other details required to gain the appropriate access. From there the IT Professional would then need to have an allowed period of time (1 day per machine should be sufficient, however 2 days per machine would be what I would spec for). My own personal approach would be to check the following Back up all machines in a full system state - this way if I make any errors the machines can be restored to how they were (covering myself on this one) Then I would check for Timestamps in the headers of the email account in question IP/DNS stamps in the headers of the email account in question Content of said emails (and print off hard copies including headers) I would then do the following Go to the exchange server and check the above, and check the database entries for when emails entered into the exchange database. Reason being is that these are exceedingly difficult to forge and requires a fair bit of configuring to do without screwing everything up. Check SPF (Sender Policy Framework) records which are stored on the exchange server as well as authenticated machines from which the email address can be sent. If for example I sent something from say [email protected] it would store at your exchange box, however it would tell you in the SPF that a non-authenticated machine sent that email and will flag up as a spoofed email address / mail. I would also document every step I did so that another person can verify my findings as appropriate. It is not a case of computer forensics, but just simply knowing what to look for and giving accurate reports for the people as required. This is exactly the type of info I was looking for - thanks very much for taking the time to respond. As I don't have the technical expertise that you guys possess, can I ask do others agree that the above approach will work? Edited November 15, 2011 by borderfox
sukh Posted November 15, 2011 Posted November 15, 2011 SPF wont be relevant if the message are sent internally, need to clarify if the message was internal>internal? What you need to do is. 1. Get message tracking logs from the Exchange server and analyse them 2. IF auditing is enabled, see if any send as permission were granted to this users mailbox. Again IF auditing in enabled to check if any admin modified this mailbox. Again IF auditing is enabled check to see when this object was last modified. 3. Check message headers of the messages in question.
featured_spectre Posted November 15, 2011 Posted November 15, 2011 Ahhh good point. I was assuming they would be spoofed from internal to show external which spf should show.
borderfox Posted November 16, 2011 Author Posted November 16, 2011 SPF wont be relevant if the message are sent internally, need to clarify if the message was internal>internal? Yes, that's correct - internal only.
featured_spectre Posted November 16, 2011 Posted November 16, 2011 In that case all but the SPF record from my statement before would still be relevant.
borderfox Posted November 16, 2011 Author Posted November 16, 2011 In that case all but the SPF record from my statement before would still be relevant. Ok, thanks. That's much appreciated.
featured_spectre Posted November 16, 2011 Posted November 16, 2011 You sir are most welcome. If it helps if I could arrange accommodation and travel I could probably do all that work for you (for a reasonable fee)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now