Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: Timestomp - Change NTFS Timestamp values

  1. #11
    AO übergeek phishphreek's Avatar
    Join Date
    Jan 2002
    Posts
    4,325
    Originally posted here by mmkhan
    Mainly for user awareness, i think u haven't gone through one of the presentations present there. The presentation is quite interesting describing various techniques and then anti techniques
    Presentation:http://metasploit.com/projects/antif...If_You_Can.ppt
    You're right... I was blocked by websense when I was reading this at work.
    I hate that ****ing thing!
    Quitmzilla is a firefox extension that gives you stats on how long you have quit smoking, how much money you\'ve saved, how much you haven\'t smoked and recent milestones. Very helpful for people who quit smoking and used to smoke at their computers... Helps out with the urges.

  2. #12
    Computer Forensics
    Join Date
    Jul 2001
    Posts
    672
    Interesting bit on timestomp. The thing is, timestamps have always been a hard thing to base an investigation off of or even use in one. touch, perl-fu..pick any ol' way you want to modify a time stamp and you can do it. The nice thing is that this tool hits the MFT entry time(or E as they call it) as well.
    The presentation was very well done and incredibly true. I can only hope that vendors are paying attention to the work these guys are doing. One thing they didn't mention, was TSK or any linux based tools.

    Fooling signature detection was an interesting piece. It may fool the casual observer, but the MZ in an exe isn't the only piece in a header of an executable that's used to detect it. it's typically the default used in the magic file but that's not the only indicator. In addition, I would imagine that tools that sort by mismatched extensions and the output of `file` with a specific magic file would take care of this issue.
    I'll have to play around with FTK and other tools and transmogrify when it's released.
    Antionline in a nutshell
    \"You\'re putting the fate of the world in the hands of a bunch of idiots I wouldn\'t trust with a potato gun\"

    Trust your Technolust

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •