Hi all -
I am researching this information for a friend of mine performing an investigation.
The question is, is there any way a file may be entered into the temporary internet files without your realization?
We all know that all files entered into that folder are truly done without your realization while surfing, but how else? Particularly if you know you had never visited the site or viewed it's content. Spyware? Virus? Any other reason known?
Thanks for the help
Temporary Internet files
- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
If you're trying to make a case that an image could be placed in your Internet Cache that wasn't put there from browsing a web site, certainly. It's just a folder like any other folder on the hard drive. Malware and virus trojans commonly hide things in the IE cache. Your room mate could copy his entire porn folder into your IE cache folder without your knowing it.
Not to mention that even if you never browsed a single porn site in your life, you could have a pornographic image stored in your cache just from a popup from an adbanner on an otherwise respectable web site. You may never even see it if you moved on to the next page quickly before it was displayed, but your browser would faithfully cache it for you.
Not to mention that even if you never browsed a single porn site in your life, you could have a pornographic image stored in your cache just from a popup from an adbanner on an otherwise respectable web site. You may never even see it if you moved on to the next page quickly before it was displayed, but your browser would faithfully cache it for you.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

- FlyingPenguin
- Flightless Bird
- Posts: 33161
- Joined: Wed Nov 22, 2000 11:13 am
- Location: Central Florida
- Contact:
Temp folder (usually located in \Documents and Settings\{user name}\Local Settings\temp) and the Windows temp folder (\Windows\temp) are even more of a prime location for malware to store porn and pirated videos, apps and music.
I've seen plenty of infected systems that were using the temp folder as a place to store pirated files that were then being uploaded on demand (basically some trojan turns the system into a free P2P host).
If I was asked for my expert opinion I would not be able to discount that some porn in a temp folder on a PC had been put there without the users knowledge.
I've seen plenty of infected systems that were using the temp folder as a place to store pirated files that were then being uploaded on demand (basically some trojan turns the system into a free P2P host).
If I was asked for my expert opinion I would not be able to discount that some porn in a temp folder on a PC had been put there without the users knowledge.
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

it certainly can
check out this article and the related stories - you can google a lot on this one
schoolteacher ended up with porn on homeroom computer - when the word got out, the computer forensics community jumped in and showed how it was absolutely possible that she had no idea it was there
http://tech.blorge.com/Structure:%20/20 ... hind-bars/
schoolteacher ended up with porn on homeroom computer - when the word got out, the computer forensics community jumped in and showed how it was absolutely possible that she had no idea it was there
http://tech.blorge.com/Structure:%20/20 ... hind-bars/
<a href="http://www.heatware.com/eval.php?id=123" target="_blank" >Heatware</a>