Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Trojans / Remote Desktop Access |
|---|---|
| Date: | Tue, 10 Aug 2004 09:06:08 -0700 |
Re: QUOTE Are any files changed / updated / connections logged
when remote desktop ( Windows ) is used to access a machine remotely?
For Terminal Services logins, in the security event log (assuming it is logging!), WIN2K will log event 528, login type 2, followed by an event 592 for the program RDPCLIP, and then the standard userinit event 592, and so on. RDPCLIP is the program that allows users to copy files between the term serv connection and the user's desktop. For WIN2003 & XP, event 528, login type 10 indicates a term serv session login. Event 529 with login type 10 indicates failed attempts. Re: QUOTE
Has anyone seen any tools that will identify, in an image, files associated with Trojans? ( EnScripts or other tools? )
Look for the existence of file binaries compressed with UPX, Petite, de-tar, superfast, LZO(p), UCL, etc... Binary files can be uploaded without triggering A/V, because most A/V will not recognize the file format. You have to look inside the WIN32/PE headers to find them. Do a search on internet for PEUtils. Gotta run... r/Jim Butterworth, Sr. Forensic Consultant Guidance Software, Inc. Note: The information contained in this message may be privileged and confidential and thus protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer. Thank you. ----------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Trojans / Remote Desktop Access, Altheide, Cory B. (IARC) |
|---|---|
| Next by Date: | Steganalysis Best Practices, Chad W. Davis |
| Previous by Thread: | RE: Trojans / Remote Desktop Access, Altheide, Cory B. (IARC) |
| Next by Thread: | Steganalysis Best Practices, Chad W. Davis |
| Indexes: | [Date] [Thread] [Top] [All Lists] |