12.07.2015 Views

© SANS Institute 2000 - 200 5, Author retains full rights. - matus

© SANS Institute 2000 - 200 5, Author retains full rights. - matus

© SANS Institute 2000 - 200 5, Author retains full rights. - matus

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Forensic Analysis of a Compromised Intranet ServerThe Sleuth Kit commands run in this task were:fls –r –m -> list both the allocated and the deleted files, recurse on directories(-r), display the output in timeline import format (-m)ils –m -> list inodes information in mactime mode (-m)The second part of the timeline creation sorts the information indate ascending order: it is also possible to select a starting andending date and other parameters to better refine the analysistask. Into the timeline analysis phase, it is a good idea tocorrelate such data with the “uptime historical” output suppliedby the WFT tool.An extract of the timeline file is depicted in the followingpicture:Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46Figure 7 - Timeline format file© <strong>SANS</strong> <strong>Institute</strong> <strong><strong>200</strong>0</strong> - <strong>200</strong> 5, <strong>Author</strong> <strong>retains</strong> <strong>full</strong> <strong>rights</strong>.The timeline lists information in the following format, from theleftmost column to the right direction: File size (Bytes); lastmac actionKey fingerprint(m=saved,= AF19 FA27a=read,executed,2F94 998D FDB5 DE3Dc=created,inodeF8B5 06E4 A169 4E46allocated);file permissions, GID, UID, inode number, file or inodespecification.While examining the timeline, the forensic analyst had theconfirmation the system had been infected by the W32/Lovgate.g@MRoberto Obialero© <strong>SANS</strong> <strong>Institute</strong> <strong><strong>200</strong>0</strong> - <strong>200</strong>5 <strong>Author</strong> <strong>retains</strong> 22 <strong>full</strong> <strong>rights</strong>.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!