| | |
Mystery: finding out who uploaded the files
![]() |
•
•
Join Date: Jun 2006
Posts: 7
Reputation:
Solved Threads: 0
I need some help guys. Here is the story
I maintain my company's Intranet and this one time I noticed something really strange. About 11ish in the morning I found out that my web pages have gone bad, the contents of the pages were of the last year (2007), about a month or 2 BEFORE I became the web guy.
I thought maybe the IIS was pointing to some old directories, because I was just working on the pages and they were fine. Turned out that IIS was just fine, the files on the web server however were replaced by files with contents from the past. I thought I may have accidentally replaced the file myself (love the Ctrl+C and V).
I looked at the date of the files 01/15/2008 10:52am, hmm interesting it was only a moment ago, feeling compelled to correct the issue I copied the *weird* files to a folder and replace them with the correct files from my machine. No big deal... BUT I am still puzzled as to how it happened in the first place. I don't keep files that old with me, not to mention I was not working as the web guy at the time when those contents were generated.
My biggest question is: how do I find out who replaced the files. This is a company Intranet setting and only a handful of people have access to the web server. For people who have access they simply use Windows Explorer to navigate to the folder without logging in. Is there a log to find out who change what? The files property didn't tell me anything. To keep it simple if I replaced a file on the server, is it logged at all?
I don't even bother with the Network Administrator, they are practically clueless.
I maintain my company's Intranet and this one time I noticed something really strange. About 11ish in the morning I found out that my web pages have gone bad, the contents of the pages were of the last year (2007), about a month or 2 BEFORE I became the web guy.
I thought maybe the IIS was pointing to some old directories, because I was just working on the pages and they were fine. Turned out that IIS was just fine, the files on the web server however were replaced by files with contents from the past. I thought I may have accidentally replaced the file myself (love the Ctrl+C and V).
I looked at the date of the files 01/15/2008 10:52am, hmm interesting it was only a moment ago, feeling compelled to correct the issue I copied the *weird* files to a folder and replace them with the correct files from my machine. No big deal... BUT I am still puzzled as to how it happened in the first place. I don't keep files that old with me, not to mention I was not working as the web guy at the time when those contents were generated.
My biggest question is: how do I find out who replaced the files. This is a company Intranet setting and only a handful of people have access to the web server. For people who have access they simply use Windows Explorer to navigate to the folder without logging in. Is there a log to find out who change what? The files property didn't tell me anything. To keep it simple if I replaced a file on the server, is it logged at all?
I don't even bother with the Network Administrator, they are practically clueless.
•
•
Join Date: Oct 2007
Posts: 1,079
Reputation:
Solved Threads: 86
If the log files have been properly configured, you should be able to find the info:
http://thesource.ofallevil.com/techn....mspx?mfr=true
See also:
http://searchexchange.techtarget.com...126458,00.html
I've made a zillion mistakes, and this is one of them, so I'd assume this was my own error.
If not, it seems to me you need to make some security changes.
http://thesource.ofallevil.com/techn....mspx?mfr=true
See also:
http://searchexchange.techtarget.com...126458,00.html
I've made a zillion mistakes, and this is one of them, so I'd assume this was my own error.
If not, it seems to me you need to make some security changes.
BS, PH, CIB
•
•
Join Date: Jun 2006
Posts: 7
Reputation:
Solved Threads: 0
I just checked the IIS logs but it does not tell me anything related to the files modification.
This question is equivalent to if I replace a file on my co-worker's PC, can he find out who did it?
I have also looked at the server security log but that log tells me *anyone* who was trying to access the web site. I did do a test where I uploaded a file to the server, the security log shows my PC name and it logs me in 6 consecutive entries. I tried to find the if there are similar 6 entries near the time of the event and I cannot find similar entries
This question is equivalent to if I replace a file on my co-worker's PC, can he find out who did it?
I have also looked at the server security log but that log tells me *anyone* who was trying to access the web site. I did do a test where I uploaded a file to the server, the security log shows my PC name and it logs me in 6 consecutive entries. I tried to find the if there are similar 6 entries near the time of the event and I cannot find similar entries
•
•
Join Date: Jun 2006
Posts: 7
Reputation:
Solved Threads: 0
Just found out what really happened, if anyone interested:
Our former Web person, currently an Application Analyst, went in the Microsoft SourceSafe and restore the old files, when the SourceSafe asked her if she wanted to Replace current files, an option which is not selected by default, she hit that option. She is also one of the very few people who has access to the SourceSafe folder, being an Web guy, I don't even have the rights.
Intentional? I am about 99% sure she did it on purpose. I wonder if I should report her, I can't go to my manager because in on of my analyzed possible scenarios I put my boss behind all this.
Our former Web person, currently an Application Analyst, went in the Microsoft SourceSafe and restore the old files, when the SourceSafe asked her if she wanted to Replace current files, an option which is not selected by default, she hit that option. She is also one of the very few people who has access to the SourceSafe folder, being an Web guy, I don't even have the rights.
Intentional? I am about 99% sure she did it on purpose. I wonder if I should report her, I can't go to my manager because in on of my analyzed possible scenarios I put my boss behind all this.
•
•
Join Date: Oct 2007
Posts: 1,079
Reputation:
Solved Threads: 86
Hard to say. I do problem solving. not politics.
If you're officially in charge, you should at least document the events.
I'd report it and make sure her credentials were revoked, which should be done as a routine precaution anyway.
I read an article recently that said disgruntled employees are responsible for some very high percentage of such events.
Good luck.
If you're officially in charge, you should at least document the events.
I'd report it and make sure her credentials were revoked, which should be done as a routine precaution anyway.
I read an article recently that said disgruntled employees are responsible for some very high percentage of such events.
Good luck.
BS, PH, CIB
![]() |
Other Threads in the IT Professionals' Lounge Forum
- Previous Thread: I like Linux!
- Next Thread: OMG -Signatures DO work for promoting my website.Proof inside
| Thread Tools | Search this Thread |
1gbit advertising advice amazon archive british broadband business businessprocesses career censorship cern china cio collectiveintelligence connectivity consumer consumers corporateearnings datatransfer debtcollectors dictionary digg digital ebay ecommerce email employment environment facebook food government grid high-definition hottub infodelivery infotech intel internet interview ipod isp japan kindle lhc library malware marketing mit moonfruit news onlineshopping piracy piratebay pope porn program r&d religion remoteworking research retail sex shopping simple skype smallbusiness smb socialmedia socialnetworking software softwareengineer spam speed spending startrek statistics stocks study stumbleupon survey tabletpc technology touch-screen touchscreen twitter uk videoinprint voips web webdeveloper words






