How to Investigate ...
 
Notifications
Clear all

How to Investigate a suspected image file??

11 Posts
6 Users
0 Reactions
1,167 Views
sudha
(@sudha)
Trusted Member
Joined: 16 years ago
Posts: 52
Topic starter  

Hi All,

I have an image file i.e. screen shot of a mail that the person has sent to some id.
Now the sender (un-trusted) takes the screen shot of the sent mail and sends it to me. But how will I say that the sender has not modified the image file for the date & time stamp that he sent.

The question is if he has altered the image with sent time and date or not?

How to proceed with such an case?

Thanks in advance
Sudha


   
Quote
(@dksniper)
Eminent Member
Joined: 17 years ago
Posts: 25
 

Are you asking if there is any way of confirming the sent time and date of the original email or the screenshot of the email?


   
ReplyQuote
sudha
(@sudha)
Trusted Member
Joined: 16 years ago
Posts: 52
Topic starter  

Are you asking if there is any way of confirming the sent time and date of the original email or the screenshot of the email?

Yes… Or if there is any way through which i can say that the image is modified using some editing tools like ms paint..


   
ReplyQuote
(@rich2005)
Honorable Member
Joined: 19 years ago
Posts: 541
 

Long and short of it, if you just have a screenshot and thats it, you can say nothing about it with any authority.


   
ReplyQuote
sudha
(@sudha)
Trusted Member
Joined: 16 years ago
Posts: 52
Topic starter  

hummm…
Until unless i get to access the sent items of the sender (suspect) i cannot say anything ?

But that's the fact that i have told my superiors also…

thanks a lot for backing me up D


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
 

Correct me if I'm wrong but even if the email was stored in a .pst file, the time stamp can be edited.


   
ReplyQuote
sudha
(@sudha)
Trusted Member
Joined: 16 years ago
Posts: 52
Topic starter  

Correct me if I'm wrong but even if the email was stored in a .pst file, the time stamp can be edited.

You can edit a mail only when it is being forwarded right??

but here i have been given with a screen shot and the image can be easily be edited without any notifications and it can be sent…


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
 

If you were to image a machine and access the file the email is stored, a hex editor can be used to change the date and time the email was sent.

For example Outlook stores emails in a .pst file held in application data on windows. Editing the time stamp of the actual email would change how it appears in the screenshot and any further inquires.

Of course if the image is of a web based mail service its a different matter. A screenshot alone isn't reliable.


   
ReplyQuote
(@larrydaniel)
Reputable Member
Joined: 17 years ago
Posts: 229
 

I agree with Rich. A screenshot alone is not something I would be able to attest to. No way to verify it.


   
ReplyQuote
sudha
(@sudha)
Trusted Member
Joined: 16 years ago
Posts: 52
Topic starter  

Of course if the image is of a web based mail service its a different matter. A screenshot alone isn't reliable.

No luck there either (
It is G-mail account


   
ReplyQuote
Page 1 / 2
Share: