Jump to content

PiqueABoo

Members
  • Posts

    2,184
  • Joined

  • Last visited

Everything posted by PiqueABoo

  1. ::disclaimer:: The following discussion has no known relation to the OPs scenario. > The files themselves could easily be trivial, but the access to the > system serious. Unauthorised access to systems is supposed to be serious in the criminal sense. Shouldn't you call the cops so they can take away all your computers and lose bits...? > Or conversly, the claim that they were written in school time > could be the critical part, Whereas it would have been fine in their own time five mins after the bell? IME that typically means A thinks B is playing/something rather than doing real work.. and I think it's better to approach that by properly managing what work B has done (or not done)... and save the tech from being perceived as a net-facist who spys on you.
  2. Again I'd just open a DOS box, run something like and make your masters read the (printed) output of: >dir /tc /s "c:\path_to_suspect_files" > a:\creationtimes.txt IMNSHO I think "serious incident" and "files are nothing serious" are mutually exclusive.
  3. NTFS records timestamps for: Modified, Accessed, Created and MFT Entry Modified. You get the first three (MAC times) via Explorer "Choose Details" or by using the command line "DIR /T" option. Various forensics tools can display the fourth timestamp (and so can at least one freebie anti-forensics utility that can change all four of them). I'm no expert but I don't believe there's an easy way to find out about system time changes... you have to find that indirectly via timestamp discrepencies in places like recycle bins, IE caches and so on.
  4. No immediate help , but in a similar scenario I set up an SSL tunnel to a target server with "stunnel" and then ran RDP through that. I didn't realise MS supported this over HTTP. AIUI you get the RDP activex control from a web page, but that control makes a normal RDP connection to the target server port 3389. Is proper RDP over HTTP a new feature for R2? Regardless I'd run up some network monitor (e.g. windump|ethereal) and verify whether the client is trying to contact to the server port 3389.
  5. More or less. Since you're new to this.. most recent machines have more than enough of CPU power, but you generally need quite a bit of spare RAM to accomodate VMs... I get by with less, but 1GB would be more comfortable. I'd start by downloading and using the VMware Player to run and play with virtual appliances.. and if you find one you want to use then upgrade to VMWare server to run it for real. Again I don't know if the virtual appliance I linked is any good, but if not there are probably some others that do similar jobs.
  6. What about just grabbing an off-the-shelf "virtual appliance" for this e.g. http://www.vmware.com/vmtn/appliances/directory/542 [Dunno how good that one is].
  7. I used the win32 Soho Mail Server a couple of years ago to collect mail via POP3 accounts for a couple of weeks and serve it out again via POP3. Different scenario so I can't guarantee redirecting collected POP3 mail to an Exchange server via SMTP will work, but on paper it will: http://www.sohoserver.co.uk One of those useful for the toolbox utils and I really liked it, but you need to know how email works to configure it.
  8. Starting with my current home PC a couple of years ago (I got someone to replace the caps coz it's a dual CPU I'm fond of) I've seen zillions of these. There's a good overview of the problem, brands and the like at http://www.badcaps.net. Key point: It's not just motherboards.
  9. I'm got one of those..... 2K3 DC.. no SP, but most MS security hotfixes... eventid.net didn't help. Taskman shows three times normal system usage for Kernel Memory(K) -> Paged Pool... seems to be like this fairly soon after a reboot... one of the reskit memory utils suggests the memory has been consumed by some GDI land driver thingy whose Tag is gh05.. and that's as far as I've got... ..my next step is to binary chop all non-essential services.. turn 'em off... restart .. see what happens... it it's ok turn half back on... etc.
  10. Don't remeber them before, but I've got Discuss, Mobile Favourites and Research buttons on the IE toolbar now. Did ActiveSync 4.2 do all of that?
  11. Noticed that's just been released.. does it break anything?
  12. You need Exchange SP2 and the mobile device needs the Messaging & Security Feature Pack for WM5. It's uses a sequence of HTTP connections. 1) The device makes a connection telling Exchange which folders it cares about and how long to monitor them. 2) If anything changes in those folders Exchange gives the device a list of folders that have changed so it can sync the new content, otherwise Exchange hits the timeout and gives the device an empty list. 3) Goto 1.
  13. The place to start is by looking for red stuff in the event logs dated last Thu morning. [Exchange server time out-of sync-with-domain is another contender]
  14. 802.11X is supposed to be layer-2 authentication. I've yet to have the uhh.. pleasure of playing with it seriously, but I thought the only traffic that goes anywhere until after authentication is: a) PC <-> [AP|Switch|Whatever] <-> RADIUS I guess that doesn't stop you spitting out malicious wireless packets aimed at other wireless devices or just flooding it etc., but in principle it should be quite helpful for ARP poisoning. If anyone knows different, please tell..
  15. ::concentrates:: Nope, can only imagine it being somone else's server. If you're rolling your own certs you should give people the CA cert to install along with the couple of lines it takes to explain cert security warnings i.e. if you get one then do NOT proceed. If there is a genuine case for remote access to sensitive files (rarely true) there are better ways of doing it.
  16. Is Somone1 with a rogue box on your internal network supplanting an HTTPS server so that (presumably) Someone2 on the outside can tunnel in, high up on the likely threat list? Someone1 likely has outbound SSL access already.. and logmein.com is a perfect example of what you can do with that. Top of my list in this kind of scenario is someone hacking some poorly written web app...
  17. I definitely would NOT pay for a cert for Exchange.. roll your own, write a little guide on how to install the CA cert... and if you're really keen on improving their behaviour, tell them how to verify the fingerprint on the CA cert before they install it. The only time this is a bit more painful is when you're getting MS-based PDAs to talk to Exchange over SSL (you must get your CA cert onto those for it to work). Once upon a time I used OpenSSL to make better authentication certs than Windows would (coz of the US crypto-export regs), but nowadays I'd stick with Cert Services for most Windows scenarios.
  18. Beware: I thought the latest was a *major* update and unlike the old one the library stuff comes separately etc.
  19. I've always trained myself so I'm not up on the rates, but that doesn't sound like a lot for professional training on seven exams (a couple of which are a teensy bit hard). I'd look closely at whether it amounts to much more than being given a pile of Sybex books and someone standing at the front reading through bits of them very quickly.
  20. The "public consultation" document for the code of practice for RIPA part III is here: http://www.homeoffice.gov.uk/documents/cons-2006-ripa-part3/ If you [want|dare] to comment you've got until the end of August (whether they pay any attention unless perhaps you represent some big corporate is anyone's guess). Lest you think these things are written by flawlesly clever folk you couldn't possibly surpass, here's a sample: 18. Where, in those specific circumstances, the person found guilty of the section 53 offence could show that the protected information did not contain an indecent photograph or pseudo-photograph of a child they could be liable to no more than a maximum term of two years. IOW we won't send you to prison for *more* than two years for failing to decrypt some cryptogobbledygook, if you can prove a negative..
  21. I'd give "monitoring" it's own section closer to the start to make it stand out more. It's a key point in any case, but since the RIP Act you really need to ensure people know about the confidentiality or otherwise of their comms & data on your network.
  22. If you've got Exchange + Outlook/OWA etc.. users can see address, depts, phones... and search by some of them.
  23. Doesn't really matter if your NTFS permission are right, but I don't really see much point in making share hidden when their names are predictable.
  24. Mmm.. appropriately configured DWL-7100APs usually work ok ... the problems tend to be with the PC/Laptop, wireless card, accompanying software and typos in encryption keys. Definitely get it working without encryption first. When you get around to entering encryption keys, if the field automagically hides the chars (e.g. ******** ) type the key into notepad - check it's correct - then cut and paste it into the field.
  25. Nope, it's in PJ 2006. Look here: http://www.publications.parliament.uk/pa/cm200506/cmbills/119/06119.27-33.html#j381 They're not commercial and I don't publish them, but NT security is one of my things and in the last decade I have "made" lots of tools. Some of these were pure research, proof-of-concept stuff with no other obvious use besides breaking security and stealing things.. oh and having informed arguments with the MS security folk about what needs fixing. Anyway, I'm currently not employed as a security professional (e.g. pen-tester) and I would really, really, really resent it if it essentially becomes illegal to do what I've done unless you are employed by Qinetiq or whoever.
×
×
  • Create New...