Академический Документы
Профессиональный Документы
Культура Документы
! Everything that a user does today can occur via the Web
Internet Artifacts ! From browsing to creating documents
! Google Chromebook
COMP 2555: Principles of Computer Forensics ! Web browsers are a popular tool to load additional
Autumn 2014
http://www.cs.du.edu/2555 tools into compromised servers
! Default browser shipped with Microsoft’s operating ! Contains records of different types of information
systems ! Temporary internet files
! Few interesting places ! History
! Index.dat ! Cookies
! Favorites
! Cookies ! Cache location:
! Cache ! XP and 2003: Documents and Settings\user\Local Settings
\Temporary Internet Files\Content.IE5\index.dat
! Vista and 7: Users\user\AppData\Local\Microsoft\Windows
\Temporary Internet Files\Content.IE5\index.dat
L10: Internet Artifacts
6 Cache
7 Firefox
! Files that are cached locally on the system ! Uses SQLite3 databases to store history data
! Location: ! Uses user-specific profile directories
! XP: Documents and Settings\%username%\Local Settings ! XP: Documents and Settings\%username%\Local Settings
\Temporary Internet Files\Content.IE5\ \Application Data\Mozilla\Firefox\Profiles
! Vista and 7: Users\%username%\AppData\Local\Microsoft ! Vista/7: Users\%username%\AppData\Roaming\Mozilla\Firefox
\Windows\Temporary Internet Files\Content.IE5 \Profiles
! Cached file are located in four randomly named ! Linux: /home/$username/.mozilla/firefox/Profiles
subdirectories ! OS X: /Users/$username/Library/Application Support/
! MSIE Cache File (index.dat) has all the information needed to Firefox/Profiles
map any file of interest with the URL the file was retrieved ! profiles.ini lists which is the default profile
from
! Time of last access by client
L10: Internet Artifacts
! Cookies ! Bookmarks
! In the cookies.sqlite database ! In the places.sqlite database
! Can produce information such as ! Database table of importance: moz_bookmarks
! last time user visited a site
! whether or not the user was registered or logged in at a particular ! Extensions
site
! Enhance or modify the behavior of the browser
! Database table of importance: moz_cookies
! Installed extensions are listed in “extensions.rdf” XML file in
the profiles directory
! Visited places
! In the places.sqlite database
! Contains URLs visited and time of visit
! Database tables of importance: moz_places and
L10: Internet Artifacts
! Typically stored in subdirectory named “Cache” in the ! Open source Web browser developed by Google
user’s Library/Caches/Firefox/%profile%/ directory ! Utilizes a variety of SQLite databases to store user data
! check location using about:cache URL on Firefox
! Contains a number of unidentifiable files along with ! Profile location
! One _CACHE_MAP_ file ! XP: Documents and Settings\%username%\Application Data
! Three cache block files _CACHE_001_ through \Google\Chrome\default
_CACHE_003_ ! Vista/7: Users\%username%\AppData\Local\Google\Chrome
! Together they contain information regarding the URLs and \default
filenames associated with cached data ! Linux: /home/$username/.config/google-chrome/Default
! As well as a time stamp
! OS X: /Users/$username/Library/Application Support/
! No open source tool to parse this data! Google/Chrome/Default
! Bookmarks are stored in the “Bookmarks” file under ! Default browser included on Mac OS X
the user’s profile directory ! Also available for Windows
! Uses the JavaScript Object Notation (JSON) format
! File locations
! The “Local State” file is used by Chrome to restore ! XP : Documents and Settings\%username%\Application Data
state after an unexpected shutdown \Apple Computer\Safari
! Uses JSON format ! Vista/7 : Users\%username%\AppData\Roaming\Apple
Computer\Safari
! Chrome cache ! OS X: /Users/$username/Library/Safari
! Consists of an index file (file name to URL mapping)
! Four numbered data files (data_0 through data_3)