Computing.Net > Forums > Windows XP > Activity Tracking

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Activity Tracking

Reply to Message Icon

Name: Kate Ellis
Date: November 8, 2008 at 04:07:04 Pacific
OS: Windows XP Pro SP2
CPU/Ram: AMD Athlon 512MB
Comment:

We have recently had some problems with our office computers and have discovered someone was able to get into our network from the outside (ex-employee). We have been trying to find some way of proving who it was that was able to get in but the event log on the computer has been wiped. Oddly enough there is no sign of anything on the server however it seems my PC was used to play around with our files. Is there anything in the computer (besides the event log) that may have recorded what was done on a set date that this person may have overlooked (We do not have any extra software that could have clocked it). The fiddling has obviously been malicious and we know who it is, so it would be wonderful to prove it. Can anyone help?



Sponsored Link
Ads by Google

Response Number 1
Name: guapo
Date: November 8, 2008 at 07:09:24 Pacific
Reply:

Windows machines don't normally log IP addresses. Is the server running an actual domain or is it just a workstation used to share files? If it's an actual domain, has the former employee's account been disabled? Is the router a wireless router using DHCP?


0

Response Number 2
Name: Kate Ellis
Date: November 8, 2008 at 09:31:02 Pacific
Reply:

The server is running a domain and the former employees account has definitely been deleted. The router is not wireless but there are wireless access points attached to it. Perhaps I should have mentioned that there are two other current employees that have a remote access link to the network as well as our computer maintenance company. I don't know if that may have a bearing on this problem. The former employee also had this connection but that was disabled when he left.


0

Response Number 3
Name: Jennifer SUMN
Date: November 8, 2008 at 10:12:27 Pacific
Reply:

The FIRST thing you should do is change all passwords. Also, setup a VPN so that it's required to access your network from outside your Firewall.

You may think you know who did this, but you'd need proof in order to prosecute (if you want to go that route.)

If you do allow Remote Access, don't you have auditing available so that you can see which users have logged in from outside? Even if the event log was deleted on one particular computer, after it was recreated, the log would show the logoff of the user.

"So won’t you give this man his wings
What a shame
To have to beg you to see
We’re not all the same
What a shame" - Shinedown


0

Response Number 4
Name: guapo
Date: November 8, 2008 at 12:59:52 Pacific
Reply:

The easiest way into the network is the wireless access point. On my LAN, I use static IP addresses instead of DHCP. That way the router isn't providing IP addresses to anyone who is outside with a laptop.

As Jennifer said, change all the passwords and setup auditing. The site below explains how to do it.

http://www.windowsecurity.com/artic...


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: Activity Tracking

utility for tracking activity www.computing.net/answers/windows-xp/utility-for-tracking-activity/8178.html

XP whistler Active Windows www.computing.net/answers/windows-xp/xp-whistler-active-windows/519.html

tracking software www.computing.net/answers/windows-xp/tracking-software/116125.html