25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CO42019 – Project 4<br />

As previously discovered <strong>the</strong> event time is contained within <strong>the</strong> above noted 32bits<br />

immediately followed by a repetition <strong>of</strong> <strong>the</strong> value.<br />

By resetting <strong>the</strong> hex value to 0000 0000 it was noted that <strong>the</strong> time <strong>and</strong> date counted up<br />

from 00:00:00 01/01/1970.<br />

Note: Research has shown that storing a date in format will prove to be problematic in <strong>the</strong><br />

year 2038. People are referring to this as <strong>the</strong> Y2K38 Bug.<br />

Project – Week 5.doc Page 2 <strong>of</strong> 9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!