Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 68 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow PST hacked
EH-Net
May 26, 2012, 02:28:20 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: PST hacked  (Read 6713 times)
0 Members and 3 Guests are viewing this topic.
Hack_80
Jr. Member
**
Offline Offline

Posts: 59


Black buck


View Profile
« on: December 29, 2010, 12:44:17 AM »

hi,
 i am facing issue of hack in my network. one of the user's PST got hacked and Hacker is sending mails of same pst attached through GMail to his official ID . We blocked specific email ID but still the hacker is sending such mails.
we are unable to trace the hacker. Gone thru Event ID's but no any track been traced.
what is the way out to trace the hacker?

thanks in advance
Logged
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #1 on: December 29, 2010, 04:08:32 AM »

Set up a network IDS like Snort and wait for the malicious / illegal traffic to occur.

When it occurs, save it and follow the "stream" to see what happens but also where it comes from.

That's probably the easiest way.
Logged

I'm an InterN0T'er
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #2 on: January 03, 2011, 02:47:15 PM »

What do you mean by "user's PST got hacked?"   PST files really don't have much in terms of security, all you have to do is open it.   The password protection feature is very rudimentary and can easily be defeated.   Are you sure these emails aren't coming from outside and aren't something like NDR bombs?
Logged

~~~~~~~~~~~~~~
Ketchup
SephStorm
Sr. Member
****
Offline Offline

Posts: 416


View Profile WWW
« Reply #3 on: January 03, 2011, 04:42:53 PM »

While I have no idea what a NDR bomb is, I was going to ask the same question. I would assume the users computer was infected, possibly with a trojan horse... Now that I think about it, even that isnt required. A hacker could create a malicious file with the PST extension. That doesnt require any penetration of your network, just knowledge of valid usernames. Although I assume someone has opened the file win which case we are back to trojan.
Logged

Empires89
Newbie
*
Offline Offline

Posts: 6


Everybody wants to be a cat


View Profile
« Reply #4 on: January 05, 2011, 12:24:39 AM »

There's a million and one ways to spoof an email address to look like it's coming from one server or one user. I don't understand how a PST file can be "hacked" so that it's sending email. To my understanding the PST file is just a file that holds the user's email data, calendar, inbox, etc. When you speak of the "hacker" sending this PST file out I picture in my mind a large attachment, not spoofing.

It might not be coming from the user's computer but instead the email server. Or maybe it's just being spoofed.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.114 seconds with 21 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.