Ferrous Moon
http://www.ferrousmoon.com:80/forums/

Caught??
http://www.ferrousmoon.com:80/forums/viewtopic.php?f=52&t=1082
Page 1 of 1

Author:  Lenzar [Tue Nov 27, 2007 1:50 pm ]
Post subject:  Caught??

How the hell was I caught when I made sure I deleted the logs off InterNIC?

Is it because I accidently routed through UIS first?

Author:  nightdagger [Tue Nov 27, 2007 2:26 pm ]
Post subject: 

Unless you're using Log Deleter v4, there's a chance you can be caught, even if you wipe the logs. A smart hacker can use a log undeleter to recover a log wiped with version 1 through 3. Version 4 is undetectable and unrecoverable, so upgrading to version 4 is always a first priority for me in my games.

Author:  Lenzar [Tue Nov 27, 2007 4:03 pm ]
Post subject: 

I /was/ using v4...

It makes no sense that I was caught

Author:  Miah [Tue Nov 27, 2007 6:31 pm ]
Post subject: 

It does if you didn't also kill the details that you logged into admin mode on the same server you clipped the logs on.

Author:  blueskirt [Tue Nov 27, 2007 6:53 pm ]
Post subject: 

Speaking of which, if you can be caught by using Log Deleter v1, v2 and v3, what is the point of these softwares?

I played this game a very long time but I would like to know how the log mechanics work.
What does the game check when it checks the logs?
Can you be caught if the only log present is "Connection from <IP> closed"?
Can you be caught if there is a 5 hours delay between "Connection from <IP> established" and "Connection from <IP> closed"?
Can you be caught if the IP of the "Connection closed" log differ from the "Connection established" log?
Can you be caught if you delete every logs present except your last "connection established" and "connection closed" logs?

Author:  Miah [Tue Nov 27, 2007 8:28 pm ]
Post subject: 

Quote:
Speaking of which, if you can be caught by using Log Deleter v1, v2 and v3, what is the point of these softwares?
Because it doesn't matter so much on lesser mission. It mostly depends on what lever the hacker is that traces you down. Some of them are incompetent and and tell that something was duplicated, as is the case of a V3 deleter.
Quote:
Can you be caught if the only log present is "Connection from <IP> closed"?
Yes. A connection closed log without a log that it opened is quite suspect.
Quote:
Can you be caught if there is a 5 hours delay between "Connection from <IP> established" and "Connection from <IP> closed"?
What would you be caught doing?
Quote:
Can you be caught if the IP of the "Connection closed" log differ from the "Connection established" log?
If the IP is different, yes. If the time is, no.
Quote:
Can you be caught if you delete every logs present except your last "connection established" and "connection closed" logs?
Generally speaking, no. The reason behind this is this there's a lacking burden of proof. While you could be reasonably traced, there's not enough evidence to formally charge you with a crime.

Author:  blueskirt [Thu Nov 29, 2007 11:49 am ]
Post subject: 

Thank for the answers! :)
Quote:
Quote:
Can you be caught if there is a 5 hours delay between "Connection from <IP> established" and "Connection from <IP> closed"?
What would you be caught doing?
By that I meant, let's suppose these logs are present on Internic:

21:01:30 - IP logged on as Admin
21:01:00 - IP Connection Established
21:00:00 - Bounce from IP to IP
16:01:00 - IP Disconnected

16:00:00 - IP Connection Established

Now if you delete the logs in red and disconnect from Internic, the logs will show this:

21:02:00 - IP Disconnected
16:00:00 - IP Connection Established

Making it looks like you've been connected on Internic for 5 hours and 2 minutes non-stop. Do you risk being caught if you do that?

Author:  FinalWarrior [Thu Nov 29, 2007 4:10 pm ]
Post subject: 

I've had a set of logs that made it look like I was connected to InterNIC for the better part of a week.

AFAIK, the game doesn't care about the time difference.

-- Griffinhart

Page 1 of 1 All times are UTC-05:00
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
http://www.phpbb.com/