RE: Google Forensic...
 
Notifications
Clear all

RE: Google Forensics

4 Posts
4 Users
0 Reactions
457 Views
(@customukr)
New Member
Joined: 15 years ago
Posts: 3
Topic starter  

Hi,

I have a task I was hoping for some assistance.

We're trying to find out the ID of an employee that is installing Google chrome.
When chrome is installed, it starts to play up with privileges on the main server, and requires a lengthy session to reset.

I presume we need to find the SID ID within the software in registry and match that to the persons profile. Not overwhelming evidence as of course someone else could be logged onto that system, but it's a start.

Please could you advise,

Thanks,

Chris


   
Quote
(@cults14)
Reputable Member
Joined: 17 years ago
Posts: 367
 

Can you give us some clues about the environment please?


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

We're trying to find out the ID of an employee that is installing Google chrome.
When chrome is installed, it starts to play up with privileges on the main server, and requires a lengthy session to reset.

I am sorry, can you better explain?
I mean is a browser all that is needed to "change privileges on the main server"? 😯

What makes you think that Chrome is installed at all (and that particular install was used to compromise the server settings)?

I mean, besides finding the culprit, the issue is "allowing to change server settings" from a browser (which I don't think necessarily must be Chrome).
BTW, besides an install, the thingy can be used as "portable" or from a VM or the like.
And even if specific browser is needed, SRWARE Iron
http//www.srware.net/en/software_srware_iron_download.php
behaves exactly like Chrome (actually it is Chrome with some fluff removed).

jaclaz


   
ReplyQuote
Adam10541
(@adam10541)
Honorable Member
Joined: 13 years ago
Posts: 550
 

I'm not a network engineer but if installing a browser messes with your main server then whoever set up the main server may have made some mistakes.

Apart from that far easier to just restrict all users to non Admin privileges and make sure no one can install anything except Domain admins.


   
ReplyQuote
Share: