Networking Forums

Networking Forums > Computer Networking > Windows Networking > logfiles

Reply
 
 
Joel Eusebio
Guest
Posts: n/a

 
      07-10-2004, 12:01 AM
Hi All,

I am investigating a possible compromise on one of our Windows 2003
servers. Where do I start looking for evidence of a file that was
downloaded to the box?. My suspicion was a trojan was downloaded to the
box and opened up backdoor ports. Thanks.

leenix66

 
Reply With Quote
 
 
 
 
Jeff Cochran
Guest
Posts: n/a

 
      07-10-2004, 04:58 AM
On Fri, 09 Jul 2004 17:01:27 -0700, Joel Eusebio <(E-Mail Removed)>
wrote:

>I am investigating a possible compromise on one of our Windows 2003
>servers. Where do I start looking for evidence of a file that was
>downloaded to the box?. My suspicion was a trojan was downloaded to the
>box and opened up backdoor ports. Thanks.


FTP logs, IIS logs, Firewall logs, security log in Event Viewer if you
enabled auditing on the particular events before they happened, etc.

Jeff
 
Reply With Quote
 
Joel Eusebio
Guest
Posts: n/a

 
      07-10-2004, 05:46 PM
Thanks.....but if auditing was not enabled it's really hard to look for
evidence.

Joel

"Jeff Cochran" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> On Fri, 09 Jul 2004 17:01:27 -0700, Joel Eusebio <(E-Mail Removed)>
> wrote:
>
> >I am investigating a possible compromise on one of our Windows 2003
> >servers. Where do I start looking for evidence of a file that was
> >downloaded to the box?. My suspicion was a trojan was downloaded to the
> >box and opened up backdoor ports. Thanks.

>
> FTP logs, IIS logs, Firewall logs, security log in Event Viewer if you
> enabled auditing on the particular events before they happened, etc.
>
> Jeff



 
Reply With Quote
 
Jeff Cochran
Guest
Posts: n/a

 
      07-10-2004, 08:59 PM
On Sat, 10 Jul 2004 10:46:22 -0700, "Joel Eusebio" <(E-Mail Removed)>
wrote:

>Thanks.....but if auditing was not enabled it's really hard to look for
>evidence.


Yep. In the event logs at least. But your firewall log should trap
everything. Um, assuming you enabled that as well.

Pretty much, if you're not logging anything and aren't configured to
track access, then you aren't going to be able to track access very
well.

Jeff

>"Jeff Cochran" <(E-Mail Removed)> wrote in message
>news:(E-Mail Removed)...
>> On Fri, 09 Jul 2004 17:01:27 -0700, Joel Eusebio <(E-Mail Removed)>
>> wrote:
>>
>> >I am investigating a possible compromise on one of our Windows 2003
>> >servers. Where do I start looking for evidence of a file that was
>> >downloaded to the box?. My suspicion was a trojan was downloaded to the
>> >box and opened up backdoor ports. Thanks.

>>
>> FTP logs, IIS logs, Firewall logs, security log in Event Viewer if you
>> enabled auditing on the particular events before they happened, etc.
>>
>> Jeff

>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off




1 2 3 4 5 6 7 8 9 10 11