HTFC Forums

H.T.F.C.

How To Fix Computers





Go Back   HTFC Forums > Software Newsgroups > Windows XP > XP Networking

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1  
Old 12-23-2007, 08:27 AM
MPD352
 
Posts: n/a
Default Tracking SSIDs of networks connect to

I'm doing a forensic exam of a computer. I'm trying to figure out where in
the registery or in what file the SSID's and other settings for wireless
connections are stored so I can try to determine what networks the suspect
computer may have connected to.

Where are those settings stored? Are they in the registry or a seperate
file, and if so where?

For various reasons I can't just start up the machine and look as that
changes evidence on the drive.

thanks
Reply With Quote
Sponsored Links
  #2  
Old 12-23-2007, 03:29 PM
V Green
 
Posts: n/a
Default Re: Tracking SSIDs of networks connect to


"MPD352" <MPD352@discussions.microsoft.com> wrote in message
news:3F003CC0-1A26-49D2-B4EC-E14319714ECA@microsoft.com...
> I'm doing a forensic exam of a computer. I'm trying to figure out where in
> the registery or in what file the SSID's and other settings for wireless
> connections are stored so I can try to determine what networks the suspect
> computer may have connected to.
>
> Where are those settings stored? Are they in the registry or a seperate
> file, and if so where?
>
> For various reasons I can't just start up the machine and look as that
> changes evidence on the drive.



Ummm, OK, if you can't turn on the machine, how
you gonna do anything?

>
> thanks



Reply With Quote
  #3  
Old 12-23-2007, 05:23 PM
MPD352
 
Posts: n/a
Default Re: Tracking SSIDs of networks connect to

I've taken a bit for bit image of the hard drive and examine that. We never
run the machine on the original drive as it gives the defense lawyer an
opening to claim we destroyed evidence.

"V Green" wrote:

>
> "MPD352" <MPD352@discussions.microsoft.com> wrote in message
> news:3F003CC0-1A26-49D2-B4EC-E14319714ECA@microsoft.com...
> > I'm doing a forensic exam of a computer. I'm trying to figure out where in
> > the registery or in what file the SSID's and other settings for wireless
> > connections are stored so I can try to determine what networks the suspect
> > computer may have connected to.
> >
> > Where are those settings stored? Are they in the registry or a seperate
> > file, and if so where?
> >
> > For various reasons I can't just start up the machine and look as that
> > changes evidence on the drive.

>
>
> Ummm, OK, if you can't turn on the machine, how
> you gonna do anything?
>
> >
> > thanks

>
>
>

Reply With Quote
  #4  
Old 12-23-2007, 07:30 PM
V Green
 
Posts: n/a
Default Re: Tracking SSIDs of networks connect to

OK, figured it must be something like that, took
your post a bit too literally.

SSID's I've been to recently are at:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\{4D36E972-E325-11CE-B
FC1-08002bE10318}\0011]

The value in the { } brackets and the \0011 are machine - specific
and won't be the same in the Registry you're looking at.

You will just need to nav to the HKLM and look around.

"MPD352" <MPD352@discussions.microsoft.com> wrote in message
news:9A20C5FD-FDFB-4457-9E2A-5476CD221D10@microsoft.com...
> I've taken a bit for bit image of the hard drive and examine that. We never
> run the machine on the original drive as it gives the defense lawyer an
> opening to claim we destroyed evidence.
>
> "V Green" wrote:
>
> >
> > "MPD352" <MPD352@discussions.microsoft.com> wrote in message
> > news:3F003CC0-1A26-49D2-B4EC-E14319714ECA@microsoft.com...
> > > I'm doing a forensic exam of a computer. I'm trying to figure out where

in
> > > the registery or in what file the SSID's and other settings for wireless
> > > connections are stored so I can try to determine what networks the suspect
> > > computer may have connected to.
> > >
> > > Where are those settings stored? Are they in the registry or a seperate
> > > file, and if so where?
> > >
> > > For various reasons I can't just start up the machine and look as that
> > > changes evidence on the drive.

> >
> >
> > Ummm, OK, if you can't turn on the machine, how
> > you gonna do anything?
> >
> > >
> > > thanks

> >
> >
> >



Reply With Quote
  #5  
Old 12-23-2007, 07:54 PM
MPD352
 
Posts: n/a
Default Re: Tracking SSIDs of networks connect to

V.Green:

Thanks, if found a lot of keys that control the hardware, but no SSIDs. I'm
searching my by laptop because I know what my SSID's are. If I could find
thm on my machine I would know where to look witht eh registry analyzer on
the image.

"V Green" wrote:

> OK, figured it must be something like that, took
> your post a bit too literally.
>
> SSID's I've been to recently are at:
>
> [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\{4D36E972-E325-11CE-B
> FC1-08002bE10318}\0011]
>
> The value in the { } brackets and the \0011 are machine - specific
> and won't be the same in the Registry you're looking at.
>
> You will just need to nav to the HKLM and look around.
>
> "MPD352" <MPD352@discussions.microsoft.com> wrote in message
> news:9A20C5FD-FDFB-4457-9E2A-5476CD221D10@microsoft.com...
> > I've taken a bit for bit image of the hard drive and examine that. We never
> > run the machine on the original drive as it gives the defense lawyer an
> > opening to claim we destroyed evidence.
> >
> > "V Green" wrote:
> >
> > >
> > > "MPD352" <MPD352@discussions.microsoft.com> wrote in message
> > > news:3F003CC0-1A26-49D2-B4EC-E14319714ECA@microsoft.com...
> > > > I'm doing a forensic exam of a computer. I'm trying to figure out where

> in
> > > > the registery or in what file the SSID's and other settings for wireless
> > > > connections are stored so I can try to determine what networks the suspect
> > > > computer may have connected to.
> > > >
> > > > Where are those settings stored? Are they in the registry or a seperate
> > > > file, and if so where?
> > > >
> > > > For various reasons I can't just start up the machine and look as that
> > > > changes evidence on the drive.
> > >
> > >
> > > Ummm, OK, if you can't turn on the machine, how
> > > you gonna do anything?
> > >
> > > >
> > > > thanks
> > >
> > >
> > >

>
>
>

Reply With Quote
  #6  
Old 12-23-2007, 08:26 PM
MPD352
 
Posts: n/a
Default RE: Tracking SSIDs of networks connect to

V.Green:

You got me looking in the right place, and I found it. It is within
HKLM\SOFTWARE\Microsoft\WZCSVC\Parameters\Interfac es\ You then look within
the keys for entries named Static#0000, Static#000, so on. These are the
SSID's in binary - with the right tool you can view the SSID. This
particular machine belonged to a transient, and was full of statics, which
indicates he was just walking around looking for open access points. Thanks,

"MPD352" wrote:

> I'm doing a forensic exam of a computer. I'm trying to figure out where in
> the registery or in what file the SSID's and other settings for wireless
> connections are stored so I can try to determine what networks the suspect
> computer may have connected to.
>
> Where are those settings stored? Are they in the registry or a seperate
> file, and if so where?
>
> For various reasons I can't just start up the machine and look as that
> changes evidence on the drive.
>
> thanks

Reply With Quote
  #7  
Old 12-23-2007, 08:54 PM
V Green
 
Posts: n/a
Default Re: Tracking SSIDs of networks connect to

Yep, that makes sense.

I don't use WZC (ugh!), preferring the Intel wireless config
utility, hence the different location.

Glad it worked out.

"MPD352" <MPD352@discussions.microsoft.com> wrote in message
news:01E1E3AB-C1D0-4FA6-8C8D-010AFCE61802@microsoft.com...
> V.Green:
>
> You got me looking in the right place, and I found it. It is within
> HKLM\SOFTWARE\Microsoft\WZCSVC\Parameters\Interfac es\ You then look within
> the keys for entries named Static#0000, Static#000, so on. These are the
> SSID's in binary - with the right tool you can view the SSID. This
> particular machine belonged to a transient, and was full of statics, which
> indicates he was just walking around looking for open access points. Thanks,
>
> "MPD352" wrote:
>
> > I'm doing a forensic exam of a computer. I'm trying to figure out where in
> > the registery or in what file the SSID's and other settings for wireless
> > connections are stored so I can try to determine what networks the suspect
> > computer may have connected to.
> >
> > Where are those settings stored? Are they in the registry or a seperate
> > file, and if so where?
> >
> > For various reasons I can't just start up the machine and look as that
> > changes evidence on the drive.
> >
> > thanks



Reply With Quote
Sponsored Links
Fix your Windows Problems - FAST.
FREE Safe Scan Registry Check. Locate & Fix Errors in Minutes!
Reply


Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
connect to othe networks william davidson Windows Vista 2 11-15-2007 03:22 PM
tracking help Norvin Windows XP 3 11-01-2007 04:28 PM
I cannot connect to wireless networks Red Brand Windows XP 2 05-06-2007 12:04 AM
WLAN showing up in Preferred Networks but not Active Networks--WHY src36 XP Networking 0 07-17-2004 04:22 PM
1 xp connect to two different networks sladinki007 XP Networking 4 06-10-2004 08:20 PM


All times are GMT. The time now is 06:40 PM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
© 2004 - 2007 Web-S-Sense Pty. Ltd. Usenet and forums posts © their respective authors.
Ad Management by RedTyger