----- Original Message ----- From: "Curt Purdy" <[EMAIL PROTECTED]> To: "'Jennifer Bradley'" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Sunday, August 03, 2003 1:29 PM Subject: RE: [inbox] Re: [Full-Disclosure] Reacting to a server compromise
> Jennifer, I made a reply to someone disagreeing with your statement on > copying the drive, supporting your contention. However, most courts will > not accept log files on magnetic media as evidence due to the ease of > alteration. This is why we collect all logs on a central syslog server that > writes directly to write-once media. That is irrefutable evidence. > and what if all the connections were via proxy on the charged persons computer??? lets convict innocent people, i think not. condider the simple tcpredirect or a proxy, running on ( Jennifers ) system, omg look, Jennifer is being arrested for embezilling ABC company because ABC companys logs show Jennifers ip address as the originating IP address. im still failing to see computer generated access logs based upon IP addresses as evidence. Donnie Werner _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
