Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Forensic recovery of MSN Instant Messages

Thread Tools
 
Search this Thread
 
Old 15 November 2010, 02:14 PM
  #1  
TelBoy
Scooby Regular
Thread Starter
 
TelBoy's Avatar
 
Join Date: Aug 2000
Location: God's promised land
Posts: 80,907
Likes: 0
Received 0 Likes on 0 Posts
Question Forensic recovery of MSN Instant Messages

Hi all,

Does anybody know with 100% certainty, whether a message sent on a home PC, running Home Vista if that's relevant, via MSN Instant Messenger to another private pc, with both computers set to "don't-save" chat logs, is forensically recoverable, using any means available? It was from about 6 months ago. There is no evidence that either pc was being externally monitored.


Many thanks.
Old 15 November 2010, 02:38 PM
  #2  
boxst
Scooby Regular
 
boxst's Avatar
 
Join Date: Nov 1998
Posts: 11,905
Likes: 0
Received 0 Likes on 0 Posts
Default

You can ask Burr on here as he deals with recovering things from hard drives / phones etc..

My played with computers for a long time and recovers lots of stuff for people opinion is 'no'.

Steve
Old 15 November 2010, 03:02 PM
  #3  
jura11
Scooby Regular
iTrader: (7)
 
jura11's Avatar
 
Join Date: Apr 2010
Location: www.slowboy-racing.co.uk
Posts: 10,523
Received 1 Like on 1 Post
Default

Hi matey try this http://computerforensics.parsonage.c...versations.pdf
Old 15 November 2010, 03:12 PM
  #4  
TelBoy
Scooby Regular
Thread Starter
 
TelBoy's Avatar
 
Join Date: Aug 2000
Location: God's promised land
Posts: 80,907
Likes: 0
Received 0 Likes on 0 Posts
Default

Cheers for that jura. Just wondered what the real world situation is, whether in reality all the methods outlined there do actually produce accurate results.
Old 15 November 2010, 03:18 PM
  #5  
MDS_WRX
Scooby Regular
iTrader: (1)
 
MDS_WRX's Avatar
 
Join Date: Oct 2010
Location: Darlington
Posts: 500
Likes: 0
Received 0 Likes on 0 Posts
Default

There's no "100% certainty" answer without actually trying. If the block that stored the information has been overwritten several times, then probably not no, however you won't know whether it has or not until someone tries for you.

My guess would be "probably not" but that's all it is, a guess and you won't be able to get a "100% certainty" answer from anyone just replying to a forum post.
Old 16 November 2010, 12:37 PM
  #6  
mart360
Scooby Regular
 
mart360's Avatar
 
Join Date: Jul 2005
Posts: 12,329
Likes: 0
Received 0 Likes on 0 Posts
Default

Prehaps a quick refresher in File storage is required.


When you save a file on a computer, its saved on the hard drive in any location that available - due do space & file size.

A record of the file / name / size and start position on the disk is stored in a master data table.

When you load / delete or change the file, the file & the master data table are ammended.

if you dlete the file, rather than delete the whole file, the OS just deletes a a set of values from the master data table, effectivly allowing the OS to overwrite the residual data on the drive. (its quicker than individually deleting each block)

If i recall it used to be a hash value of C5 (it's been some time ) this value releates to the position of the bolck of data on the hard drive.

All the recovery stuff does, is change the hash value back to make the file / location visible, and from that they can recover the residual block of data

Over write the file with new data, and it becomes difficult.

However you cant always guarantee any files written over the top will completly fit the footprint the original file had

brings back the days of sector editors


Mart
Old 16 November 2010, 01:04 PM
  #7  
hodgy0_2
Scooby Regular
 
hodgy0_2's Avatar
 
Join Date: Jul 2008
Location: K
Posts: 15,633
Received 21 Likes on 18 Posts
Default

the OP states that " both computers are set to "don't-save" chat logs" so is the data even persistent on the machine (written to disk), I would have thought not

Last edited by hodgy0_2; 16 November 2010 at 01:21 PM.
Old 16 November 2010, 01:44 PM
  #8  
TelBoy
Scooby Regular
Thread Starter
 
TelBoy's Avatar
 
Join Date: Aug 2000
Location: God's promised land
Posts: 80,907
Likes: 0
Received 0 Likes on 0 Posts
Default

Yes, no chat logs have ever been "deleted" on either computer - they were never saved in the first place. But does that mean they never hit the hard drive?
Old 16 November 2010, 01:52 PM
  #9  
boxst
Scooby Regular
 
boxst's Avatar
 
Join Date: Nov 1998
Posts: 11,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by TelBoy
Yes, no chat logs have ever been "deleted" on either computer - they were never saved in the first place. But does that mean they never hit the hard drive?
They may have hit some temporary file, but as above after 6 months it is unlikely that they have survived.

I assume you know what you are looking for? If so you can do a sector-scan for that (hopefully unique) word.

Steve
Old 16 November 2010, 02:17 PM
  #10  
hodgy0_2
Scooby Regular
 
hodgy0_2's Avatar
 
Join Date: Jul 2008
Location: K
Posts: 15,633
Received 21 Likes on 18 Posts
Default

they might have been included in the system page file that writes temporary information to disk -- but this is cleared and recreated during a reboot and I doubt the information in the page file is "readable" anyway

I think the chances of recovery are very very small

most data recovery companies would tell you whether you have any hope over the phone, and most will even examine the disk for free and tell you what can be recovered.
Old 16 November 2010, 03:56 PM
  #11  
SwissTony
Scooby Regular
iTrader: (19)
 
SwissTony's Avatar
 
Join Date: Mar 2003
Location: In the Doghouse
Posts: 28,226
Received 12 Likes on 3 Posts
Default

why is no one asking Tel what the message read
Old 17 November 2010, 01:36 PM
  #12  
GlesgaKiss
Scooby Regular
 
GlesgaKiss's Avatar
 
Join Date: Dec 2007
Location: Scotland
Posts: 6,284
Likes: 0
Received 4 Likes on 4 Posts
Default

Just what I was thinking.

If in doubt and it's essential the data isn't found there's dban or even physical destruction, but that would be a last resort. Probs not necessary unless you're a secret agent.

Last edited by GlesgaKiss; 17 November 2010 at 01:39 PM.
Old 17 November 2010, 09:46 PM
  #14  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Default

Microsoft? Analyse MSN communications? Who would have thought?

Six degrees of separation in instant messaging

mb
Old 18 November 2010, 11:37 AM
  #15  
TelBoy
Scooby Regular
Thread Starter
 
TelBoy's Avatar
 
Join Date: Aug 2000
Location: God's promised land
Posts: 80,907
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for all the replies online and off. I think the group consensus is "extremely unlikely", but i'll update the thread as and when i have a definitive answer. Cheers.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
SilverM3
ScoobyNet General
8
24 February 2021 01:03 PM
Abx
Subaru
22
09 January 2016 05:42 PM
IanG1983
Subaru Parts
1
30 September 2015 04:52 PM
alcazar
Computer & Technology Related
2
29 September 2015 07:18 PM



Quick Reply: Forensic recovery of MSN Instant Messages



All times are GMT +1. The time now is 02:32 PM.