Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 77 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow tool to trace users
EH-Net
February 10, 2012, 01:03:30 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: tool to trace users  (Read 5634 times)
0 Members and 1 Guest are viewing this topic.
Hack_80
Jr. Member
**
Offline Offline

Posts: 56


Black buck


View Profile
« on: January 02, 2009, 12:54:30 AM »

Hi
   I am facing a challenge of recovering a deleted files. Is there any tools which can trace the users who had accessed and deleted the files of remote machine.
Kindly suggest if any

Thanks
Logged
shednik
Jr. Member
**
Offline Offline

Posts: 75


View Profile
« Reply #1 on: January 02, 2009, 07:46:05 AM »

Is auditing service turned on, on the remote server?
« Last Edit: January 02, 2009, 08:32:23 AM by shednik » Logged

CCNA, MCP, A+, N+

WIP: Masters of Infosec, CEH, & Mastering C
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« Reply #2 on: January 02, 2009, 08:30:46 AM »


There are a number of free and commercial tools out there that can help you extract and correlate bits and pieces of information from the system being investigated that eventually will point you to the user that deleted the files. I'm not sure if there is one that can automatically tell you the user who didn't.

However, the most important thing is that you extract the hidden INFO2 files from the subject host, using Helix Live CD for example. Every user in the system will have this file created the first time the Recycle Bin used. The purpose of this file is to track deleted files and folders original location, as well as file size and deletion time. This makes it possible to relate the deleted files with specific users.
Logged

Security+, OSCP, CEH
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3845


Editor-In-Chief


View Profile WWW
« Reply #3 on: January 02, 2009, 09:28:31 AM »

Hey blackazarro,

Sounds like a great tutorial for our readers.  Wink

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« Reply #4 on: January 02, 2009, 10:13:38 AM »

Code:
Sounds like a great tutorial for our readers.

Yeah... but I'm not an expert yet. Just little things I know.

Hack_80, I forgot to mention that the INFO2 file is useful if the deleted files are automatically moved to the Recycle Bin. If the user deleted the files from a remote command prompt or the Recycle Bin is configured to remove files immediately when they are deleted then the INFO2 it will be of no use. There other methods as well to prevent from sending it to the Recycle Bin.

Now since this user accessed the host remotely via shares or whatever, I wonder if there's an entry to the INFO2 file if files/folders are deleted. Hmmm...
« Last Edit: January 02, 2009, 10:26:44 AM by blackazarro » Logged

Security+, OSCP, CEH
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« Reply #5 on: January 02, 2009, 10:41:51 AM »


A tool from Foundstone for analyzing INFO2 files:

Rifiuti v1.0
Logged

Security+, OSCP, CEH
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #6 on: January 02, 2009, 11:26:17 AM »

Hack_80, can you provide any additional information about the platforms involved and the access method used?  Did the user have access to that file via: remote desktop, shared drives, remote shell, citrix, etc, etc, etc...?  Were these windows/UNIX/etc boxes?  Your answers to those questions are going to dictate where you'd go to get the relevant data. 
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
Hack_80
Jr. Member
**
Offline Offline

Posts: 56


Black buck


View Profile
« Reply #7 on: January 03, 2009, 03:42:56 AM »

Hi,
  the files deleted from windows 2000 adv server with SP4.
Logged
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 204



View Profile
« Reply #8 on: January 03, 2009, 10:08:08 AM »

first things first, have you made am image of the drive?  If you're primary concern is to recover the file then you need to get the drive imaged ASAP if that system is still in use.  Otherwise you'll just write over parts of it at some point.  Do you have access to some UNIX/Linux/BSD system that will let you do a simple dd?  As long as nobody has played with the drive too much then you should be able to pull the file right back off.
Logged

CISSP, CISM, CISA, GCIH, CEH, HMFIC, KTHXBIROFLCOPTER
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.34 seconds with 24 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.