Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Built-in Windows commands to determine if a system has been hacked

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 12-Mar-2008, 07:37 AM
Mitzs's Avatar
Mitzs Mitzs is offline CertForums News Posting Member
Lifetime Member
Posts: 2,960
Points: 1995 Mitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 points
Power: 54
None
Join Date: 11 Apr 2005
Location: Tenneesse USA
Certifications: Microcomputers and network specialist.
Built-in Windows commands to determine if a system has been hacked

Quote:
“
Let's face it, Windows machines get hacked, and in some environments it happens a lot. Fortunately, Microsoft has built numerous tools into Windows so administrators and power users can analyze a machine to determine whether it's been compromised. In this tip, which is the first of a two-part series, I'll cover five useful command-line tools built into Windows for such analysis.
”
http://searchsecurity.techtarget.com...303709,00.html


Don't walk in front of me, I may not follow. Don't walk behind me, I may not lead. Walk beside me and just be my friend. (Old Irish Proverb)
 
Reply With Quote
  #2  
Old 12-Mar-2008, 07:58 AM
Tinus1959's Avatar
Tinus1959 Tinus1959 is offline
Lifetime Member
Posts: 1,328
Points: 1083 Tinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 points
Power: 26
None
Join Date: 11 Apr 2007
Location: The Netherlands
Age: 48
Certifications: See my signature
WIP: MCSD, MCAD, CCNA, CCNP
Nice article. To bad they did not screen it better for errors.

For example:

The [N] here is an integer, indicating that WMIC should run the given command every [N] seconds. That way, users can look for changes in the settings of the system over time, allowing careful scrutiny of the output. Using this function to pull a process summary every 5 seconds, users could run:
C:\> wmic process list brief /every:1


MCP (NT 3.51) MCSE (NT 4.0, 2000, 2003) MCSA (2000, 2003), MCT (since 1999), Vista, Exchange 2007, A+, Network+, Security+, CEH.
 
Reply With Quote
  #3  
Old 12-Mar-2008, 04:47 PM
Mitzs's Avatar
Mitzs Mitzs is offline CertForums News Posting Member
Lifetime Member
Posts: 2,960
Points: 1995 Mitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 points
Power: 54
None
Join Date: 11 Apr 2005
Location: Tenneesse USA
Certifications: Microcomputers and network specialist.
Quote:
“
Originally Posted by Tinus1959 View Post
Nice article. To bad they did not screen it better for errors.

For example:

The [N] here is an integer, indicating that WMIC should run the given command every [N] seconds. That way, users can look for changes in the settings of the system over time, allowing careful scrutiny of the output. Using this function to pull a process summary every 5 seconds, users could run:
C:\> wmic process list brief /every:1
”
Tinus, you should send them an email shairing that with them. You never know.


Don't walk in front of me, I may not follow. Don't walk behind me, I may not lead. Walk beside me and just be my friend. (Old Irish Proverb)
 
Reply With Quote
  #4  
Old 12-Mar-2008, 05:21 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
The only problem with those tools is that if your computer has been rootkitted those tools can't be trusted as they rely on the system itself to report to them. If the system has been rootkitted it will lie to the tools, and the output from the tools will therefore be useless.



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #5  
Old 12-Mar-2008, 06:50 PM
S0l5 S0l5 is offline
New Member
Posts: 39
Points: 0 S0l5 has no points
Power: 1
None
Join Date: 04 Mar 2008
Quote:
“
Originally Posted by ffreeloader View Post
The only problem with those tools is that if your computer has been rootkitted those tools can't be trusted as they rely on the system itself to report to them. If the system has been rootkitted it will lie to the tools, and the output from the tools will therefore be useless.
”
Isnt that the same for Linux?

 
Reply With Quote
  #6  
Old 12-Mar-2008, 06:59 PM
csx's Avatar
csx csx is offline
Valued Member
Posts: 271
Points: 50 csx has between 1 & 100 points
Power: 7
None
Join Date: 21 Dec 2005
Location: Thanet, Birchington
Age: 22
Certifications: A+, Network+, 271, 272, HNC!
WIP: 270 and Open Uni
Interesting article! thanks

 
Reply With Quote
  #7  
Old 12-Mar-2008, 07:27 PM
ffreeloader's Avatar
ffreeloader ffreeloader is offline
Lifetime Member
Posts: 3,649
Points: 3030 ffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 pointsffreeloader has over 3000 points
Power: 72
None
Join Date: 26 Jul 2005
Location: USA
Age: 54
Certifications: MCSE, MCDBA, CCNA, A+
WIP: LPIC 1
Quote:
“
Originally Posted by S0l5 View Post
Isnt that the same for Linux?
”
Yup. Once any system is rootkitted it's completely unreliable, so putting forth tools that rely on the system to be truthful when a system has been hacked is at best a very iffy proposition.

That's why Linux tools include tools that run from a cd to check binaries, and system settings. That way they don't depend on the compromised system to check itself.



Behold, the turtle. He makes progress only when he sticks his neck out.

James Bryant Conant
 
Reply With Quote
  #8  
Old 13-Mar-2008, 08:13 AM
Tinus1959's Avatar
Tinus1959 Tinus1959 is offline
Lifetime Member
Posts: 1,328
Points: 1083 Tinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 points
Power: 26
None
Join Date: 11 Apr 2007
Location: The Netherlands
Age: 48
Certifications: See my signature
WIP: MCSD, MCAD, CCNA, CCNP
Quote:
“
Originally Posted by Mitzs View Post
Tinus, you should send them an email shairing that with them. You never know.
”
Will do.


MCP (NT 3.51) MCSE (NT 4.0, 2000, 2003) MCSA (2000, 2003), MCT (since 1999), Vista, Exchange 2007, A+, Network+, Security+, CEH.
 
Reply With Quote
  #9  
Old 13-Mar-2008, 08:19 AM
Tinus1959's Avatar
Tinus1959 Tinus1959 is offline
Lifetime Member
Posts: 1,328
Points: 1083 Tinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 pointsTinus1959 has over 1000 points
Power: 26
None
Join Date: 11 Apr 2007
Location: The Netherlands
Age: 48
Certifications: See my signature
WIP: MCSD, MCAD, CCNA, CCNP
Quote:
“
Originally Posted by Tinus1959 View Post
Will do.
”
Mitzs, are you a member there? I can't find a link to respond to that article. Could you do me the favor?


MCP (NT 3.51) MCSE (NT 4.0, 2000, 2003) MCSA (2000, 2003), MCT (since 1999), Vista, Exchange 2007, A+, Network+, Security+, CEH.
 
Reply With Quote
  #10  
Old 13-Mar-2008, 08:41 AM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
Toto
Posts: 3,467
Points: 1977 UCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 points
Power: 57
None
Join Date: 04 May 2006
Well done Mitzs - that's an interesting article

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Domain functional levels.. spacer_07 Server Exams 5 20-Feb-2008 01:28 PM
Windows Vista: One Year Later tripwire45 News 4 10-Feb-2008 09:06 PM
HELP! New System Overheating! Neil Hardware & Upgrading 56 30-Nov-2007 11:10 PM
Preview for MCP's: Windows Server "Longhorn" Certification wagnerk General 7 14-May-2007 07:31 PM
Windows PE 2.0: a tiny version of Windows for system maintenance Mr.Cheeks News 0 05-Sep-2006 07:39 AM


All times are GMT. The time now is 09:00 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages