Malicious user
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > Malicious user




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Malicious user  
maverick


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
05-19-07 12:17 AM

Not sure if  its the right place..but need help cracking this...Just
inherited a bad place........

Users access a certain share point site and browse a directory for a host of
folders.This afternoon one of the folders was deleted which has loads of
subfolders(as it is a sharepoint server)......now I need to find out who thi
s
kool dude is!...

What I have now: System state backup of the Machine,SQL full backup and the
backup(SQL and System) just after the files have been deleted.

All I have is just Auditing for success and failure but nothing with object
access,didnt think if it would matter even if object acess was enabled...

now...with the given situation...how do I get to this dude???Can someone
enrich my novice knowledge please?


thanks
maverick.





[ Post a follow-up to this message ]



    Re: Malicious user  
Ken Schaefer


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
05-20-07 06:21 AM

Hi,

I don't think that Object Access Auditing will help here, as Sharepoint
stores all it's content inside SQL Server..

I don't know what logging/auditing options Sharepoint has, but you may be
able to determine what Windows users were logged into at the time the delete
occured (via Windows Security Event Log). Otherwise, if Sharepoint uses a
single super-account to connect to SQL Server, you will need to see what
logs Sharepoint maintains to see who/what was doing what. If Sharepoint
conects to SQL Server as the end user, then RedGate has a transaction log
reading tool that you can use to read the transaction logs to see what user
context ran what against SQL Server...

Cheers
Ken

--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken

"maverick" <maverick@discussions.microsoft.com> wrote in message
news:5E0B094E-BCCE-4D93-9366-DC630651D7B5@microsoft.com...
> Not sure if  its the right place..but need help cracking this...Just
> inherited a bad place........
>
> Users access a certain share point site and browse a directory for a host
> of
> folders.This afternoon one of the folders was deleted which has loads of
> subfolders(as it is a sharepoint server)......now I need to find out who
> this
> kool dude is!...
>
> What I have now: System state backup of the Machine,SQL full backup and
> the
> backup(SQL and System) just after the files have been deleted.
>
> All I have is just Auditing for success and failure but nothing with
> object
> access,didnt think if it would matter even if object acess was enabled...
>
> now...with the given situation...how do I get to this dude???Can someone
> enrich my novice knowledge please?
>
>
> thanks
> maverick.






[ Post a follow-up to this message ]



    RE: Malicious user  
maverick


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
05-24-07 12:20 AM

Thanks for the info Ken...I may sure get onto the user context..

cheers
Maverick

"maverick" wrote:

> Not sure if  its the right place..but need help cracking this...Just
> inherited a bad place........
>
> Users access a certain share point site and browse a directory for a host 
of
> folders.This afternoon one of the folders was deleted which has loads of
> subfolders(as it is a sharepoint server)......now I need to find out who t
his
> kool dude is!...
>
> What I have now: System state backup of the Machine,SQL full backup and th
e
> backup(SQL and System) just after the files have been deleted.
>
> All I have is just Auditing for success and failure but nothing with objec
t
> access,didnt think if it would matter even if object acess was enabled...
>
> now...with the given situation...how do I get to this dude???Can someone
> enrich my novice knowledge please?
>
>
> thanks
> maverick.





[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 08:28 PM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register