Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Re: They got me!!! |
|---|---|
| Date: | 6 Apr 2006 14:19:50 -0000 |
Or downloading shareware/freeware files, or free screen savers, or any number of files. I am fairly certain that you use internet exploiter, as do most people, in which case the machine could have been 0wned simply by visiting a malicious web site. To start you can do a search on any files created or modified during the time that you were on vacation. You don't need any special tools to do this, just do a search from you start menu, or your windows explorer. Do an advanced search and set the dates for you vacation time. If your antivirus isn't working you can try an online av scanner at symantec, or housecall.trendmicro.com. If you need to check specific files on your system, there is a great online scanner that uses multiple av vendor scanning engines at www.virustotal.com For system analysis there are many great tools from systeminternals.com. I would use http://www.sysinternals.com/Utilities/Autoruns.html to check which programs are configured to startup during boot time. I would definitly use http://www.sysinternals.com/Utilities/ProcessExplorer.html to see what processes are currently loaded and find out what registry keys they are using, files and dlls they are using, and a feature I like the best, you can see what sephamores and mutexes they are mapped to. I would agree that you have to question the integrity of your system now that it has been comprimised. Depending on the level of comprimise, you may have to start-anew. I would most certainly suggest some type of system integrity checker in the future. There is a nice little program for windows that offers tripwire like functionality at a fairly reasonable price. You can find it here: http://www.winalysis.com/ The road to forensics can be a bumpy one, where many people learn from mistakes, but that is how we get better! Hope that helps! Regards, John Fellers
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: They got me!!!, Levenglick, Jeff |
|---|---|
| Next by Date: | Re: Re: They got me!!!, pentesticle |
| Previous by Thread: | RE: They got me!!!, Levenglick, Jeff |
| Next by Thread: | Re: Re: They got me!!!, pentesticle |
| Indexes: | [Date] [Thread] [Top] [All Lists] |