Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE: Tracking down anonymous user

Subject: RE: Tracking down anonymous user
Date: Fri, 29 Dec 2006 09:44:13 -0500
Another way to go about this is to find some unique part of the email
that may help identify the tool used to craft it.  For instance,
Ghostmail.  If you can identify the program used, in my case (GM.exe by
default), you might be able to search some filesystems for the
particular program.  Also, what about searching for all files accessed
on the date the email was sent?  The email was probably sent from some
admin machine. 

Just some thoughts.

JMB


mikef@everfast.com wrote:
I thought it was odd that outlook didn't display any header
information either. I checked for the headers at the recipient's
computer but it's blank. I've been through all the log files that I
have and made some adjustments for future requirements. The part that
really has me concerned is that the account used is a high level
account which should only be used for SQL processes.     


<Prev in Thread] Current Thread [Next in Thread>