Technology Get the latest on technology, electronics and software…

IT: File Sharing & Auditing

Thread Tools
 
Old 02-25-2011 | 09:51 AM
  #1  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
IT: File Sharing & Auditing

So, a co-worker of mine found a pornographic picture in the root of one of the IT shares here at work. We have NO IDEA who put it there and are trying to figure out where it came from. It seems to have been there since August 2010...a while without anyone noticing.

Unfortunately, any sort of auditing was not enabled on this server...something I'm going to change very soon.

Is there any way what-so-ever we can figure out which user wrote the file to the share? Or are we SOL without object auditing? The server in question is running Windows Server 2003 R2.
Old 02-25-2011 | 10:01 AM
  #2  
CocheseUGA's Avatar
Banned
 
Joined: Mar 2009
Posts: 18,761
Likes: 960
From: Kennesaw, GA
Is this something that was obviously done intentionally, or something that could have been scrobbled in via a seemingly innocuous search?
Old 02-25-2011 | 10:01 AM
  #3  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
if you right click the pic > properties and hit details, does not show anything under Author?

Or pic > properties > security > advanced > Owner
Old 02-25-2011 | 10:03 AM
  #4  
justnspace's Avatar
Moderator
iTrader: (1)
 
Joined: Feb 2010
Posts: 86,295
Likes: 16,269
:inforresultsbecauseiwanttoseesomeonegetfired:
Old 02-25-2011 | 10:04 AM
  #5  
doopstr's Avatar
Team Owner
 
Joined: Jan 2001
Posts: 25,467
Likes: 2,226
From: Jersey
Originally Posted by rza49311
if you right click the pic > properties and hit details, does not show anything under author?

Or pic > properties > security > advanced > owner
+1
Old 02-25-2011 | 10:08 AM
  #6  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Originally Posted by rza49311
if you right click the pic > properties and hit details, does not show anything under Author?

Or pic > properties > security > advanced > Owner
The owner is "Administrators", unfortunately...the group all of us IT folks are in. Soo, that doesn't help.

Under > Summary > Advanced > the Author is blank.
Old 02-25-2011 | 10:11 AM
  #7  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
Originally Posted by thunder04
The owner is "Administrators", unfortunately...the group all of us IT folks are in. Soo, that doesn't help.

Under > Summary > Advanced > the Author is blank.
http://www.youtube.com/watch?v=1ytCEuuW2_A
Old 02-25-2011 | 10:12 AM
  #8  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Originally Posted by CocheseUGA
Is this something that was obviously done intentionally, or something that could have been scrobbled in via a seemingly innocuous search?
What sort of innocuous search would result in one saving a picture of a vagina on a server share? lol

FWIW, I work for a school district.
Old 02-25-2011 | 10:12 AM
  #9  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Originally Posted by rza49311
That's what I thought.
Old 02-25-2011 | 10:13 AM
  #10  
justnspace's Avatar
Moderator
iTrader: (1)
 
Joined: Feb 2010
Posts: 86,295
Likes: 16,269
Originally Posted by thunder04
What sort of innocuous search would result in one saving a picture of a vagina on a server share? lol

FWIW, I work for a school district.
someone is going to get teh ban hammer.
Old 02-25-2011 | 10:29 AM
  #11  
CocheseUGA's Avatar
Banned
 
Joined: Mar 2009
Posts: 18,761
Likes: 960
From: Kennesaw, GA
Originally Posted by thunder04
What sort of innocuous search would result in one saving a picture of a vagina on a server share? lol

FWIW, I work for a school district.
Not familiar with servers, I didn't know if it was something that could have been accidentally done.


But as far as innocuous searches resulting in vaginas, you'd be surprised. Hell, one person here had an erupting one for an avatar one day.
Old 02-25-2011 | 10:32 AM
  #12  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
It's possible it was an "accident"...but the file was written to the share on a Sunday at 8:25 PM. Even more confusing. I don't have the VPN log from our old VPN server...or else I'd check that to see if anyone was in during that time.
Old 02-25-2011 | 10:37 AM
  #13  
The Dougler's Avatar
Unofficial Goat
iTrader: (1)
 
Joined: Jul 2006
Posts: 15,744
Likes: 112
From: Toronto
seems like you got nothing. delete it, and take necessary actions to make tracking available next time. really all you can do.
Old 02-25-2011 | 11:02 AM
  #14  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Well...a co-worker and I scowered the content filter logs. We didn't find anything in regards to that image.

Last edited by teranfon; 02-25-2011 at 08:35 PM.
Old 02-25-2011 | 11:09 AM
  #15  
justnspace's Avatar
Moderator
iTrader: (1)
 
Joined: Feb 2010
Posts: 86,295
Likes: 16,269
idunno what it is, but you made me click the link.....

:ibITcomesintomyoffice:
Old 02-25-2011 | 08:24 PM
  #16  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
The link in post 14 is NSFW. After some investigation I now know what it is. Mods: feel free to remove it (I'm sorry I posted it).

It looks like this guy may get canned.
Old 02-25-2011 | 09:52 PM
  #17  
alex2364's Avatar
Three Wheelin'
 
Joined: Oct 2000
Posts: 1,669
Likes: 72
From: Northern VA
What type of site was it? I thought it was a torrent site.
Old 02-26-2011 | 12:03 AM
  #18  
goose25's Avatar
Keeping emos out of
 
Joined: May 2004
Posts: 6,811
Likes: 1
From: Colorado Springs
Closed networks once again FTMFW
Old 02-26-2011 | 06:18 AM
  #19  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
Originally Posted by thunder04
The link in post 14 is NSFW. After some investigation I now know what it is. Mods: feel free to remove it (I'm sorry I posted it).

It looks like this guy may get canned.
Old 02-26-2011 | 06:24 AM
  #20  
justnspace's Avatar
Moderator
iTrader: (1)
 
Joined: Feb 2010
Posts: 86,295
Likes: 16,269
interesting.....
Old 02-26-2011 | 10:50 AM
  #21  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Originally Posted by justnspace
idunno what it is, but you made me click the link.....

:ibITcomesintomyoffice:
Originally Posted by alex2364
What type of site was it? I thought it was a torrent site.
The site was a "torrent" site along with a forum...with emphasis on pornography (Japanese Adult Video) and content around children. Although through the limited poking around I did, I didn't find any content with naked children and/or children with naked adults...but some were in very skimpy bathing suits. VERY VERY CREEPY. Disturbs me to no end.

Depending on what the lawyer says on Monday...we're most likely seizing his computers (he has a laptop and two desktops) and he'll be put on administrative leave until investigation is complete.

Last edited by thunder04; 02-26-2011 at 10:52 AM.
Old 03-01-2011 | 09:24 PM
  #22  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
The person in question is resigning as of tomorrow. He was doing some bad things and fessed up to them. He even said that the vag jpeg on the server may have been from him.

We've confiscated his desktop and laptop, keys, and changed passwords and alarm codes. Although he's resigning and cooperating with our requests, we still have to poke around in case there is in fact child porn on any of his computers (which we're legally obligated to report).

Old 03-01-2011 | 09:31 PM
  #23  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by thunder04
The person in question is resigning as of tomorrow. He was doing some bad things and fessed up to them. He even said that the vag jpeg on the server may have been from him.

We've confiscated his desktop and laptop, keys, and changed passwords and alarm codes. Although he's resigning and cooperating with our requests, we still have to poke around in case there is in fact child porn on any of his computers (which we're legally obligated to report).

Thunder, I do this for a living and highly recommend you do NOT poke around. Find someone who does this for a living and have them create a forensic image with Encase, FTK, etc.. NOT Ghost, etc.

If you find Child Porn on the computer, not only can the evidence be inadmissible in criminal court, but since you may gain from his termination (position open, you look like the hero) you have no defense to the argument that you put the picture there. He can say he confessed because he was scared and didn't mean it.

Feel free to PM me if you want. This is serious business.

If you prefer, I can find a local police for you who knows what they are doing to come and do a quick preview of the computer for images. That way, at least the person who finds the pics knows how to testify in court, which will be required.
Old 03-01-2011 | 09:35 PM
  #24  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
I definitely do not gain in any way of his departure!! It only creates more work for me.

Don't worry, I'm not touching it with a 10ft pole. I meant we as in the district and not we as in the IT department...my bad.

Depending on what my supervisor decides, I may toss you a PM.
Old 03-01-2011 | 09:39 PM
  #25  
TylerT's Avatar
Turd Polisher
iTrader: (1)
 
Joined: Jul 2007
Posts: 6,806
Likes: 3,027
From: San Diego
Do you guys have a Barracuda / any other Spam & Firewall?

You can always look through your Exchange server / E-mail server message logs and search for the image name as an attachment, that's if you're suspecting an adult got a hold of the image through e-mail.
Old 03-01-2011 | 09:40 PM
  #26  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Yeah, I have seen it happen many times and it sometimes works out and sometimes does not.

I am not soliciting for the work here. I wouldn't pretend to admin your systems, so your IT people shouldn't pretend to be computer forensics specialists. No shame in knowing your limitations. Truthfully, the PD should handle all this for you based on what the dude admitted to. I used to do it a lot for school districts when they had concerns about a teacher or IT guy back when I was LE. Let me know if you need any info.
Old 03-01-2011 | 09:41 PM
  #27  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Originally Posted by TylerT
Do you guys have a Barracuda / any other Spam & Firewall?

You can always look through your Exchange server / E-mail server message logs and search for the image name as an attachment, that's if you're suspecting an adult got a hold of the image through e-mail.
Long shot. Could have been a thumbdrive, cd, right click and save as, FTP, Dropbox, included in a Powerpoint, IRC F-Serve, etc...
Old 03-01-2011 | 09:45 PM
  #28  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
Originally Posted by TylerT
Do you guys have a Barracuda / any other Spam & Firewall?

You can always look through your Exchange server / E-mail server message logs and search for the image name as an attachment, that's if you're suspecting an adult got a hold of the image through e-mail.
We've found all we need to find at this point. The next step is most likely what stogie suggests. I'm going to talk to my supervisor about it tomorrow. He was very shaken up about this event. Wasn't an easy thing to comprehend and handle for all of us. It's still disturbing. I worked with this guy for 4 years...trusted him. I saw signs of fishy stuff (he VPNed in a lot more than he needed to which was flag #1)...but I wanted to believe that he was a good guy.
Old 03-01-2011 | 09:50 PM
  #29  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
We think the file on the server was a case of Firefox remembering the last place he downloaded. August-October is usually our busiest time of the year, and he could've been saving files to the tech share for us to access. He decided to do his naughty thing...went to download a pic..."where'd it go?!"...and forgot about it.

In any case, it doesn't really matter. Enough proof of anything will be on his laptop and/or desktop computer.
Old 03-01-2011 | 10:00 PM
  #30  
stogie1020's Avatar
Needs more Lemon Pledge
 
Joined: Mar 2005
Posts: 52,768
Likes: 2,000
From: Phoenix, AZ
Sounds like you guys have it handles. Like I said, PM me if you need any advice or a resource local to you.
Old 03-01-2011 | 10:23 PM
  #31  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
^Definitely. Thanks.
Old 03-02-2011 | 05:55 AM
  #32  
CocheseUGA's Avatar
Banned
 
Joined: Mar 2009
Posts: 18,761
Likes: 960
From: Kennesaw, GA
Old 03-02-2011 | 06:58 AM
  #33  
Whiskers's Avatar
Go Giants
 
Joined: Aug 2004
Posts: 69,918
Likes: 1,236
From: PA
Ok, it was me...
Old 03-02-2011 | 09:04 AM
  #34  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,104
Likes: 80
From: Northern VA
^ Oh...well then. I guess we may be overreacting. It's all good!
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
MrHeeltoe
1G TSX Tires, Wheels, & Suspension
20
02-23-2023 01:54 PM
MrHeeltoe
2G TSX Tires, Wheels & Suspension
3
09-29-2015 10:43 PM
MrHeeltoe
3G TL Tires, Wheels & Suspension
0
09-28-2015 05:43 PM
thegipper
3G TL (2004-2008)
5
09-28-2015 01:01 PM
UA7_Ando
3G TL (2004-2008)
10
09-28-2015 07:53 AM



Quick Reply: IT: File Sharing & Auditing



All times are GMT -5. The time now is 07:59 AM.