PDA

Click to See Complete Forum and Search --> : Fingerprinting exploits in system and application log files


t2k2
October 15th, 2002, 09:34 PM
Here is an exerpt from an article on Security Focus I found today. I thought that it looked quite informative and ideal for someone new to forensics since it gives good insight into what forensics analysts do and how.

Forensic analysts and incident response engineers are armed with a slew of open source and commercial forensic toolsets to attempt to understand and analyze break-ins they did not witness. The most critical component of forensic analysis is system log files. In particular, the analyst must be able to understand and recognize footprints that exploits leave on system logfiles. Identifying these signatures, and their impact on the application within the log files, is the key to understanding what took place during a security incident.


The article is pretty lengthy, but you can find it here (http://online.securityfocus.com/infocus/1633) .

Tiger Shark
November 7th, 2002, 09:27 PM
Nice article......

Anyone know of anything similar for Windows systems......

Which one of you *nix chaps is that giggling in the background????? ;)

thehorse13
January 26th, 2003, 10:11 PM
BWA HAHAHAHAHAHAHAHAHA

Actually, I use different OSes for different purposes. Each have their strong points and each have their crappy ones.

I did see a decent post on Security Focus on Windows log file forensics. You may want to pan the site and see what you come up with.