Last visit was: It is currently Sat Sep 23, 2023 4:04 pm


All times are UTC-05:00




Post new topic Reply to topic  [3 posts ] 
    Author Message
     Post subject:Why the bloody hell?
    PostPosted:Mon Jul 07, 2008 6:57 pm 
     

    Joined:Sun Jul 06, 2008 9:19 am
    Posts:8
    Decided to do a little experiment. Saved my character and went off hacking databases and deleting files.

    All filed are deleted and in addition...

    a) All log files with my IP are removed with highest version of log deleter: not caught

    b) All log files are removed with my IP except connection established are removed with highest version of log deleter: caught

    c) All log files are deleted from console and the system is crashed: not caught

    This doesn't make much sense. Any sysadmin with even traces of brains would look for mismatching connection logs. If there's a connection established and connection terminated log - it looks fishy but isn't direct evidence. After all any bloke with a modem could connect to an IP and later, failing to log on, disconnect. Now a missing connection established log is CLEAR EVIDENCE of someone having messed with the logs.

    Yet surprisingly the legitimate-looking connection gets me caught, while the obviously tampered-with one doesn't. Why?


    Top
    Offline  
     Post subject:Re: Why the bloody hell?
    PostPosted:Mon Jul 07, 2008 10:35 pm 
    Organ Donor
    User avatar
     

    Joined:Mon Aug 13, 2007 1:47 pm
    Posts:529
    Location:Jawjuh
    Well I guess this answers the age-old debate of whether leaving the logs is good for you.

    Ironically, many people were saying that people were getting caught for deleting the logs and should leave them. Whoops.

    _________________
    Creative people must be stopped! (Latest Entry 7/31/11: "Fishsticks (18+))

    Pleasantville by Night, a humorous horror web RPG


    Top
    Offline  
     Post subject:Re: Why the bloody hell?
    PostPosted:Thu Aug 21, 2008 5:06 pm 
     

    Joined:Wed Jan 03, 2007 5:17 am
    Posts:68
    Yahoo Messenger:xmodctech
    AOL:rebeliousness434
    Location:127.0.0.1
    Actually if you hunt up the post from a while back, you will see that i plainly stated that if you delete all your ip files, that you plainly have to leave one log which should be the very last connection. Otherwise you have an ip logged as disconnecting but the logs don't show that the ip connected. since you deleted all your ip connected logs all they have to do is search back the one ip disconnected log left.

    _________________
    Image


    Top
    Offline  
    Display posts from previous: Sort by 
    Post new topic Reply to topic

      All times are UTC-05:00


      Who is online

      Users browsing this forum: No registered users and 16 guests


      You cannot post new topics in this forum
      You cannot reply to topics in this forum
      You cannot edit your posts in this forum
      You cannot delete your posts in this forum
      You cannot post attachments in this forum

      Search for:
      Jump to:  
      cron
      Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
      Theme created by Miah with assistance from hyprnova