Following the IP trail

From: Simon Wellborne (simon.wellborne@initiative-technology.co.nz)
Date: Wed Aug 22 2001 - 22:54:47 PDT

  • Next message: Mellen, Christopher: "sector CRC"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    I apologise in advance if the message is sent with inappropriate
    content.
    
    I am in the process of attempting to pinpoint a user activities on a
    Windows NT Domain through logon and logoff records.  I need to be
    able to confirm what IP address was assigned to a particular machine
    on a particular date.
    
    I have a copy of the DHCP database from close to the date in
    question, but I now need a tool (other than a HEX editor) to examine
    the database and retrieve that information.
    
    I would appreciate any feedback from any person who has found a
    method of extracting IP addresses-Machine name associations from the
    MS DHCP database file.
    
    regards
    
    
    
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP Personal Security 7.0.3
    
    iQA/AwUBO4SaalowRiBBhQzuEQJW4ACg+ULPSXg4VDs8LY+PJ5lWFyxYCqIAoNkE
    BEjhnIggZhRKR/rEHuJYy9Uv
    =SUrL
    -----END PGP SIGNATURE-----
    
    
    
    
    

    ----------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



    This archive was generated by hypermail 2b30 : Thu Aug 23 2001 - 11:04:01 PDT