Groups | Blog | Home
all groups > iis security > may 2007 >

iis security : Malicious user



maverick
5/18/2007 3:39:01 PM
Not sure if its the right place..but need help cracking this...Just
inherited a bad place........

Users access a certain share point site and browse a directory for a host of
folders.This afternoon one of the folders was deleted which has loads of
subfolders(as it is a sharepoint server)......now I need to find out who this
kool dude is!...

What I have now: System state backup of the Machine,SQL full backup and the
backup(SQL and System) just after the files have been deleted.

All I have is just Auditing for success and failure but nothing with object
access,didnt think if it would matter even if object acess was enabled...

now...with the given situation...how do I get to this dude???Can someone
enrich my novice knowledge please?


thanks
Ken Schaefer
5/20/2007 12:00:00 AM
Hi,

I don't think that Object Access Auditing will help here, as Sharepoint
stores all it's content inside SQL Server..

I don't know what logging/auditing options Sharepoint has, but you may be
able to determine what Windows users were logged into at the time the delete
occured (via Windows Security Event Log). Otherwise, if Sharepoint uses a
single super-account to connect to SQL Server, you will need to see what
logs Sharepoint maintains to see who/what was doing what. If Sharepoint
conects to SQL Server as the end user, then RedGate has a transaction log
reading tool that you can use to read the transaction logs to see what user
context ran what against SQL Server...

Cheers
Ken

--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken

[quoted text, click to view]
maverick
5/23/2007 11:21:01 AM
Thanks for the info Ken...I may sure get onto the user context..

cheers
Maverick

[quoted text, click to view]
AddThis Social Bookmark Button