Security Incidents mailing list archives
Changing file times, was -> Re: Trojan of somesort - Update
From: Harlan Carvey <keydet89 () yahoo com>
Date: Fri, 28 May 2004 09:55:58 -0700 (PDT)
Although looking at the dates of files is one of the simpler and more important tool when investigating a possible issue, we need to keep in mind how easy it is to change it.
This is definitely something to keep in mind, but it's not the whole story. When performing incident response and forensics, one should never rely on one piece of information/evidence exclusively. There's another distinction to keep in mind. It's relatively easy to throw out things like this that are trivial...but the question remains, *is* it being done? Can anyone out there demonstrate, with proof, that a compromised box that they responded to had file times that were tampered with? I suppose one example might be a CP case in which the perp altered the last access times of the files to when he was on vacation, or to 1979, or to 2153. Has anyone actually seen a case in which the MAC times of the file were altered, and if so, can you show proof of this? Just b/c something *can* happen, doesn't mean that it *does* happen.
It's easier on some systems than others, and practically ridiculous on FAT file systems.
To be honest, I'm not aware that there's any real distinction with regards to file system. On both NTFS and FAT, as long as you have write access to the file in question, the file times can be changed. I've demonstrated this time and again, in presentations as well as in my book. If I'm missing something with regards to the distinction with regards to how easy it is to change MAC times on FAT vs NTFS, please let me know.
Current thread:
- Re: Trojan of somesort - Update, (continued)
- Re: Trojan of somesort - Update Harlan Carvey (May 27)
- Re: Trojan of somesort - Update Harlan Carvey (May 27)
- RE: Trojan of somesort - Update James C Slora Jr (May 28)
- RE: Trojan of somesort - Update Harlan Carvey (May 28)
- RE: Trojan of somesort - Update James C Slora Jr (May 29)
- RE: Trojan of somesort - Update Harlan Carvey (May 28)
- Re: Trojan of somesort - Update Gadi Evron (May 28)
- Re: Trojan of somesort - Update Paul Schmehl (May 28)
- Re: Trojan of somesort - Update Harlan Carvey (May 28)
- Re: Trojan of somesort - Update Gadi Evron (May 28)
- Changing file times, was -> Re: Trojan of somesort - Update Harlan Carvey (May 28)
- Re: Changing file times, was -> Re: Trojan of somesort - Update Gadi Evron (May 28)
- RE: Trojan of somesort - Update David Gillett (May 28)
- Re: Trojan of somesort - Update Harlan Carvey (May 28)
- Administrivia: Trojan of somesort - Hack definition branch == dead Daniel Hanson (May 29)