Penetration Testing mailing list archives
Re: Light forensics
From: "Adrian Puente Z." <puenteadrian () gmail com>
Date: Thu, 07 Jan 2010 01:37:27 -0600
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Eduardo Sierra wrote:
Hi, We had a security incident, and i'm doing a "light" forensics. Is there a log you can check to see IP Address Changes in a Windows XP Box?
Well logging in Windows XP is really lame, in my little experience with Windows Incidents the Event Viewer shows you all the logs the system uses. Maybe I am wrong but I believe that maybe the Windows Registry keeps something.
Any good free tool to undelete files?
Free Apps in windows systems y really rare. But I recommend GetdataBack http://www.runtime.org/data-recovery-software.htm It always have worked for me, I haven't found any good NTFS free recovery tool.
Many thanks, Eduardo Sierra ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iEYEARECAAYFAktFjzIACgkQW2tF/eN2yfYPAgCcC81XoSwgemuRzdElVNWWL3on 0MMAnAnqlVZgSVSpjVVUNLr8AQsQ6d4H =0/o2 -----END PGP SIGNATURE----- ------------------------------------------------------------------------ This list is sponsored by: Information Assurance Certification Review Board Prove to peers and potential employers without a doubt that you can actually do a proper penetration test. IACRB CPT and CEPT certs require a full practical examination in order to become certified. http://www.iacertification.org ------------------------------------------------------------------------
Current thread:
- Light forensics Eduardo Sierra (Jan 06)
- Re: Light forensics Alonso Caballero Quezada / ReYDeS (Jan 11)
- Re: Light forensics Wim Remes (Jan 11)
- Re: Light forensics Tom Ritter (Jan 11)
- Re: Light forensics Adrian Puente Z. (Jan 11)
- Re: Light forensics H. Kurth Bemis (Jan 11)
- RE: Light forensics Levenglick, Jeff (Jan 11)
- RE: Light forensics Dave Kleiman (Jan 11)
- Re: Light forensics Felipe Martins (Jan 18)
- RE: Light forensics Boyd, Chad (Jan 18)
- Re: Light forensics Adel Abushaev (Jan 11)