Question about link...
 
Notifications
Clear all

Question about linkfile header

9 Posts
4 Users
0 Reactions
538 Views
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

I was working with linkfiles (Desktop, SendTo, Start menu etc.) and saw the same fileheader in all .lnk files

4c0000000114020000000000c000000000000046h

Is this the one and only fileheader for all .lnk files (if so, I can use it to carve and search). There's not much information about the fileheader on the internet (I did read

http//www.forensicfocus.com/link-file-evidentiary-value

http//www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf

)

Stamitz


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

If you re-read the second link that you provided…page 2 and an understanding of file signatures answers your question.

HTH,

Harlan


   
ReplyQuote
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

Thanks keydet89

Jesse Hager mentions 0000004Ch as the file header and the rest (0114020000000000c000000000000046h) as the unique identifier GUID of the shell links.

this is also what i see with all of the linkfiles on my Win XP

So, I can carve or search for this hex string !

Stamitz


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Stamitz…

Please be sure to read the second half of what I said…

"…an understanding of file signatures…"

H


   
ReplyQuote
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

Thanks, i'll keep on learning every day …


   
ReplyQuote
 ddow
(@ddow)
Reputable Member
Joined: 21 years ago
Posts: 278
 

Thanks, i'll keep on learning every day …

We all do. That is the addiction of forensics. ) ?? ( ??


   
ReplyQuote
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

I'm still study the topic of link files. On keydet89's site I found a great article about the MAC times in link files

http//windowsir.blogspot.com/2007/12/windows-shortcut-lnk-files.html

With Encase I also found out that the "creation" time didn't change. I wonder if I can rely on this now or is this very risky ?


   
ReplyQuote
(@kfoggon)
New Member
Joined: 18 years ago
Posts: 4
 

Look here

http//www.i2s-lab.com/Papers/The_Windows_Shortcut_File_Format.pdf

This might help.


   
ReplyQuote
(@stamitz)
Eminent Member
Joined: 18 years ago
Posts: 34
Topic starter  

Yep, I know the document of Jesse Hager. But it doesn't tell if the MAC times (those related to the file it represents, offsets 28 - 51) will stay the same, whatever happens with the shortcut or file it represents.


   
ReplyQuote
Share: