Disks filling up - how to track it

Disks filling up - how to track it

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Disks filling up - how to track it dsb 07-20-2005
Posted by =?Utf-8?B?ZHNi?= on July 20, 2005, 10:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a spanned disk on a 2003 Server. Beginning the middle of last month
the disk had 90 GB of free space and now has 20 GB. How can I track where
all this data is coming from? Specifically the user or their PC, where the
data originates. Virus scans run nightly and no viruses have been found.

Thanks in advance

Posted by =?Utf-8?B?V29uZyBUdWNrIFdhaA== on July 21, 2005, 1:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
These might be due to different scenarios. Lets tackle it case by case.

Scenario 1
------------
These are genuine file required and saved by users that are job related. If
you are not using any 3rd-party tools for the monitoring, you can use the
standard file and folder searching capabilities. This feature allows you to
search for hidden files, modified date, file size (look out for huge file
like mp3 or video) etc.

From the search results, you can then deduce the owner by looking at the
ownership of the file/folder (provided you are using NTFS)

Scenario 2
----------
This is a more paranoid thinking - your system is being hacked.

NTFS support something knwon as Alternate Data Stream (ADS). ADS allows a
file to be attach as hidden to another file. The normal file (the carrier) is
used as a hide out for the hidden file. The size of the carrier seems normal
but the capacity of the disk reduce tremendously. You are not able to search
or access these hidden files as they are - just hidden.

Tool such as LNS (http://ntsecurity.nu/cgi-bin/download/lns.exe.pl) can be
used to detect any ADS exist on your system. Once detected, just copy/move it
to a FAT partition and then copy/move it back to NTFS. ADS attribute will be
lost in FAT.

HTH.


Similar ThreadsPosted
Eliminating data from hard disks;options February 12, 2007, 10:29 am
Desktop.ini auditing filling event logs July 29, 2005, 10:33 am
How to disable automatic form filling on website March 11, 2006, 8:36 pm
track netbios to ip addres May 14, 2007, 9:29 pm
Best Way to Track Service Being Turned On? April 26, 2008, 8:06 pm
Failure Audits 529 & 680: How to track the IP address? July 13, 2005, 3:48 pm
missing key/value in registry of w2k server - hot to track it? June 12, 2005, 10:19 pm
Possible to track user's file system usage? March 20, 2006, 11:44 am
Track transfer of files from desktop system September 7, 2007, 2:42 pm
Track user/computer/ip by Caller Logon ID April 28, 2008, 1:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy