RE: Creation / modification / access dates

From: Andrew Sheldon (forensicsat_private)
Date: Mon Jul 14 2003 - 06:18:19 PDT

  • Next message: Valdis.Kletnieksat_private: "Re: Creation / modification / access dates"

    One of the easiest ways of identifying CD-Rom creation dates is to look at the DIRECTORY creation dates, especially those in the root of the CD - they are created and dated on the date the CD is written. Obviously, this is keyed to the BIOS of the computer used to write the CD.
    
    If you look at the CD in a hex editor (winhex) or forensic tool in Hex view - most CD authoring utils write a date sig in plain text. ie. Nero Burning Rom produces the following header (I've shown the hex offset followed by the "text entry")
    
    @ x8800 - "CD001"
    .
    .
    .
    .
    @ x8B2D - "2003022815440000"
    
    The line at 8B2D is the creation date in the format "yyyymmddhhmm"
    
    Hope this helps
    shelly
    
    
    
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Jul 14 2003 - 07:15:53 PDT