![]() |
|
|
|
Registered
Join Date: Sep 2009
Location: North of You
Posts: 9,160
|
Computer Guys - Hacking into Outlook
Fist off, what I am doing is legal. I own the server, I own the email, all employees have signed waivers allowing me access to the email.
The issue is that an employee appears to be doing something unethical/illegal. Some 'classified' information has become public knowledge, he is the most likely culprit. I need to check his emails and verify that he is not acting contrary to the business interests. There are several reasons to suspect he is doing something wrong, but no proof so far. Issue #2 is that the employee in question runs IT. The 'outside service guy' and the 'passwords' are under his control. I am allowed access, but requesting this information will notify him of my suspicions. I should have had passwords from the beginning but I never bothered. Is there a way to get into Outlook without him? Can I hire an IT guy to hack in after hours? Or another way? I have full access to the employees computer and service after hours. |
||
![]() |
|
Registered
|
It's not terribly difficult to do and it can be done without him knowing.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs. '84 Targa - Arena Red - AX #104 '07 Toyota Camry Hybrid - Yes, I'm that guy... '01 Toyota Corolla - Urban Camouflage - SOLD |
||
![]() |
|
Registered
Join Date: Sep 2009
Location: North of You
Posts: 9,160
|
Can you elaborate?
|
||
![]() |
|
Registered
|
It really depends on how the server is setup, are you running Exchange server or is each employee just have their own pop3 email with your ISP?
Does the server run RAID and if so, is the primary drive RAID as well or just a single disk. If it's a single disk, rebooting the server with a special CD in can allow access to the directories and allow you to copy the info needed. RAID just adds another layer to the process. It really depends on how the system is setup.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs. '84 Targa - Arena Red - AX #104 '07 Toyota Camry Hybrid - Yes, I'm that guy... '01 Toyota Corolla - Urban Camouflage - SOLD |
||
![]() |
|
Registered
Join Date: Dec 2007
Posts: 1,231
|
What OS is he running?
If he is running XP or Vista, you can slip into his office on a weekend with something like ophcrack and it can tell you the password to his computer based on the password hashes: Ophcrack You can download the live CD and burn it (You can do this by downloading the .iso file and using a program such as CDBurnerXP.) It's pretty easy to navigate the menus. After you figure out the password to his computer you should easily be able to access outlook and possible backup his .pst files if you find something dirty. Last edited by RedBaron; 10-11-2010 at 01:04 PM.. |
||
![]() |
|
Registered
Join Date: Nov 2003
Location: Seattle
Posts: 1,785
|
Often if you can get onto the mailserver and have admin access you can run an app called exmerge. This will allow you to export the mailbox to a .pst file and look at it offline.
This doesn't raise any flags on the account itself since you aren't connecting directly to the mailbox. A backup to pst can also be done through Outlook, but if he's remotely decent at IT he won't leave his machine logged in and unlocked overnight.
__________________
Rob 1980 SC - 2011 Tiguan - 2018 Tesla M3P |
||
![]() |
|
![]() |
Family Values
Join Date: Jun 2003
Location: Los Angeles, CA
Posts: 4,075
|
1) Who signs the checks? The outside service guy should be under the control of the check signer.
2) Any IT guy or company worth their salt will not try to remotely "hack" your network. They'll want proof of your authority and on-site access. 3) Assuming you find the smoking gun, what then? You'll need an IT company to assume network support ASAP as you will likely sack the current guy and the out-sourced vendor. 4) Reality is, that unless your current IT admin is a moron, he likely covered his tracks and wasn't so stupid as to use the company mail system for that kind of crap. 5) Bottom line is that you don't trust the guy with the keys to your kingdom. That's problem number one.
__________________
- Joe Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves. - William Pitt |
||
![]() |
|
Registered
Join Date: Mar 2003
Posts: 10,345
|
A quick google reveals that PSTViewer will allow viewing the .pst and .ost files from his local machine w/o logging into outlook,etc.
Boot his desktop with a Linux LiveCD, copy the .pst and .ost files to some external storage, copy again to a windows machine, run pstviewer, wallah. Note that I know near nothing about MS products...
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.” |
||
![]() |
|
Registered
Join Date: Sep 2009
Location: North of You
Posts: 9,160
|
Quote:
Quote:
Quote:
Quote:
That will be resolved shortly. With cause, not with a severance package. |
||||
![]() |
|
Registered
Join Date: Mar 2003
Posts: 10,345
|
I would recommend lining up a replacement you can trust to be impartial about the whole thing who can go in, lock him out completely, do an audit to make sure there are no hidden back doors in, etc. and re-configure all your security passwords/hosts/etc. Then have someone lined up for contract/permament position.
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.” |
||
![]() |
|
Cogito Ergo Sum
|
Find out if there is an independent computer forensic analyst in your area.... This would be an easy case for a forensic guy...
|
||
![]() |
|
RETIRED
|
Pull the Hardrive, copy it......open it up. If he's stupid enuff to use company email, he's still got the emails.....no need to go to the server.
__________________
1983/3.6, backdate to long hood 2012 ML350 3.0 Turbo Diesel |
||
![]() |
|
![]() |
Registered
Join Date: Feb 2010
Posts: 920
|
I thought .pst files were only archives. that wouldnt give him access to the current inbox...
Anyone with SV rights on the network can log into AD and blow his passwords away. although he might suspect something depending on how often you force password changes I'm not as up on it as a few of you are.... as for copying the hard drive The inbox is not stored on the local drive... Last edited by Rednine11; 10-12-2010 at 06:23 AM.. |
||
![]() |
|
Hilbilly Deluxe
|
Unless he is exceptionally stupid, you won't find anything.
Lots of ways to send information other than the corporate mail server. A larger problem in my opinion is you no longer have trust for your IT Admin, which is a pretty scary/crappy position to be in. |
||
![]() |
|
Cogito Ergo Sum
|
I'm sound like a broken record... But you need to find a CFA in your area. A good one could come in at night, get in, get out, and leave no trace... It won't be cheap but it will be done right and let you know if you need to ****can your IT guy....
CFA= Computer Forensics Analyst.... |
||
![]() |
|
Registered
|
Quote:
|
||
![]() |
|
Registered
|
I still don't think it was mentioned, but Exchange server is used and email is imap, then looking at his wkstation won't get you anywhere. It would have to be server side.
|
||
![]() |
|
Senior Member
Join Date: Jun 2000
Location: N. Phoenix AZ USA
Posts: 28,943
|
How about you and SloDave get together OFF of this thread? Pay him a bit to go into the system and find the info you need.
Agree with the above that you need to have another new and good IS/IT person standing in the wings. Personally I would not trust them to do what I am recommending Dave do. Then once the new IS/IT person is in place, get master passwords and such and start things out right this time.
__________________
2013 Jag XF, 2002 Dodge Ram 2500 Cummins (the workhorse), 1992 Jaguar XJ S-3 V-12 VDP (one of only 100 examples made), 1969 Jaguar XJ (been in the family since new), 1985 911 Targa backdated to 1973 RS specs with a 3.6 shoehorned in the back, 1959 Austin Healey Sprite (former SCCA H-Prod), 1995 BMW R1100RSL, 1971 & '72 BMW R75/5 "Toaster," Ural Tourist w/sidecar, 1949 Aeronca Sedan / QB |
||
![]() |
|
Cogito Ergo Sum
|
Ya.... Sounds like you need to get Dave to go on a Canadian Vacation... He really likes skiing.
![]() |
||
![]() |
|