[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <1098256953.17299.19.camel@je.nets.com>
From: hackerwacker at cybermesa.com (James Edwards)
Subject: Windows Time Synchronization - Best Practices
On Tue, 2004-10-19 at 11:22, Richard Stevens wrote:
> Why FD? What is the direct security implications of this?
>
> I'm sure someone can construct a rather tenuous link, but really....
All forensics requires a time line or time reference so the separate
pieces of forensic data can be assembled in the order they happened.
Otherwise, each data point cannot be related to the others. Data is
often gathered from multiple devices. Security and time are very much
related.
I would suggest NTP and using GMT.
--
James H. Edwards
Routing and Security Administrator
At the Santa Fe Office: Internet at Cyber Mesa
jamesh@...ermesa.com
noc@...ermesa.com
(505) 795-7101
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20041020/59d2e995/attachment.bin
Powered by blists - more mailing lists