Hi: I work in search and rescue and am getting peripherally involved in advising on attempts to reopen a missing person case from two years ago. The individual disappeared in a wilderness setting. There's a very slight hope he might have visited the local library shortly before he set off on a day hike & technical climb. The assumption is that he might have searched for information on routes. As far as I know, the only IT investigation done was the local police investigator being told that the library's computer histories were wiped each evening and no further attempt was made to track down web sites visited.
After two years, it's clearly a long shot and, in fact, I'm recommending against this as a priority line of inquiry simply because of limited people available to follow up (and none with technical expertise). Still, I'd like to understand the potential here better and the slight hope some useful information/clues might be recovered.
So, for information now and in the future, what can be recovered from:
1) the individual computer used. I was thinking that if the person's web mail, say, were known we could search for that IP address and then bracket a time and computer the person was using. Does that make sense? While web history might be wiped, would caches likely be wiped as well? For future reference, how is cache information organized such that it might be traced to a user at the computer at a certain time?
2) the router of the library. Are logs kept indefinitely or only until a text cache reaches a certain size?
3) the ISP for the library. Do ISPs tend to hang on to use logs or are they dumped after x time?
What information might be recoverable from the individual web sites visited?
Many thanks!
George
After two years, it's clearly a long shot and, in fact, I'm recommending against this as a priority line of inquiry simply because of limited people available to follow up (and none with technical expertise). Still, I'd like to understand the potential here better and the slight hope some useful information/clues might be recovered.
So, for information now and in the future, what can be recovered from:
1) the individual computer used. I was thinking that if the person's web mail, say, were known we could search for that IP address and then bracket a time and computer the person was using. Does that make sense? While web history might be wiped, would caches likely be wiped as well? For future reference, how is cache information organized such that it might be traced to a user at the computer at a certain time?
2) the router of the library. Are logs kept indefinitely or only until a text cache reaches a certain size?
3) the ISP for the library. Do ISPs tend to hang on to use logs or are they dumped after x time?
What information might be recoverable from the individual web sites visited?
Many thanks!
George