邪恶八进制信息安全团队技术讨论组's Archiver

冰血封情 2005-5-13 12:33

[转载]Web Browser Forensics(第二部分)

文章作者:Keith J. Jones and Rohyt Belani

Reviewing part one
Welcome to part two of the Web Browser Forensics series. In part one, we began investigating the intrusion of the Docustodian document management server hosting a law firm's data. The server appeared to have been compromised by a group of hackers who were using it as a repository for their MP3s, MPEGs, and pirated software.
In part one, we also performed a review of the Internet Explorer history and cached files on the system used by Joe Schmo, the primary suspect of the intrusion. Analysis of the web browsing history revealed Internet searches for license cracks and hacking books; however, all this malicious activity appeared to have been performed while Joe was on vacation with his family in Florida.

In part two we now set out to determine who used Joe's machine while he was on vacation. We will proceed by examining further investigative leads that involve performing an in-depth review of the web activity of all other browsers installed on Joe's hard drive.

[url]http://www.securityfocus.com/infocus/1832[/url]

页: [1]
© 1999-2008 EvilOctal Security Team