| 
 (IEHistoryView){ Viewing Past URL Web 
History } 
 
			
				| Section 0. Background 
				Information |  
	IEHistoryView extracts information from the 
	history file (index.dat) of Internet Explorer. 
 
		This history information includes the URLs 
		that user visited, the Web site title, The number of times that this URL 
		was visited (Hits column), and the last date/time that the Web site 
		visit occurred.The history file also contains a list of 
		local files that the user opened with Internet Explorer (Usually .html 
		and image files). 
	Lab Notes
	
		In this lab we will do the following: 
		
			Download  IEHistoryViewCreate Web HistoryRetrieve Web History with IEHistoryView 
Legal Disclaimer
	
		As a condition of your use of this Web 
		site, you warrant to computersecuritystudent.com that you will not use 
		this Web site for any purpose that is unlawful or 
		that is prohibited by these terms, conditions, and notices. 
		In accordance with UCC § 2-316, this 
		product is provided with "no warranties, either express or implied." The 
		information contained is provided "as-is", with "no guarantee of 
		merchantability." In addition, this is a teaching website 
		that does not condone malicious behavior of 
		any kind. You are on notice, that continuing 
		and/or using this lab outside your "own" test environment
		is considered malicious and is against the law. 
		© 2012 No content replication of any 
		kind is allowed without express written permission.    
			
				| Section 1: Play 
				Virtual Machine |  
	Start Up Damn Vulnerable WXP-SP2.
	
		Instructions:
		
			Click on Damn Vulnerable WXP-SP2 
			Click on Edit virtual machine Settings 
			Note(FYI):
		
			For those of you not part of my class, 
			this is a Windows XP machine running SP2.   Edit Virtual Machine Settings
	
		Instructions:
		
			Click on Network Adapter 
			Click on the Bridged Radio button 
			Click on the OK Button    Play Virtual Machine
	
		Instructions:
		
			Click on Damn Vulnerable WXP-SP2 
			Click on Play virtual machine 
			   Logging into Damn Vulnerable WXP-SP2.
	
		Instructions:
		
			Username: administrator 
			Password: Use the Class Password or 
			whatever you set it.   Open a Command Prompt
	
		Instructions:
		
			Start --> All Programs --> Accessories 
			--> Command Prompt   Obtain Damn Vulnerable WXP-SP2's IP Address
	
		Instructions:
		
			ipconfig Note(FYI):
		
			In my case, Damn Vulnerable WXP-SP2's 
			IP Address 192.168.1.116. 
			This is the IP Address of the Victim 
			Machine that will be attacked by Metasploit. 
			Record your Damn Vulnerable WXP-SP2's 
			IP Address.     
			
				| Section 2: Download 
				and Install |  
	Start your Internet Explorer Web Browser
		Instructions: 
		
			Start --> All Programs --> Internet 
			Explorer  Download IEHistoryView
		Instructions: 
		
			Place http://www.nirsoft.net/utils/iehv.zip 
			in the Address Box and hit enter.Click Save  Save As
		Instructions: 
		
			Navigate to C:\tools
				If the tools folder does not exist, 
				then create it.Click the Save Button  Click Open Folder
		Instructions: 
		
			Click Open Folder  Extract iehv.zip
		Instructions: 
		
			Right Click on iehv.zipSelect Extract All...  Select Next
		Instructions: 
		
			Click Next  Select Next
		Instructions: 
		
			Click Next  Click Finished
		Instructions: 
		
			Click Finished   
			
				| Section 3: Create 
				Some Web History. |  
	Open Up Internet Explorer.
		Instructions: 
		
			Start --> All Programs --> Internet 
			Explorer  Create Metasploit Web History
		Instructions: 
		
			Go to http://www.metasploit.com  Create Nmap Web History
	  
	Open My Computer
		Instructions:
			Start --> All Programs --> My Computer  Start iehv.exe
		Instructions:
			Navigate to C:\tools\iehvRight Click on iehv.exeClick OpenClick Run   IEHistoryView
		Note(FYI):
			IEHistoryView shows a simplistic view of 
		URL, Title, Hits, Modified Date, Expiration Date, Username.You can see WHO viewed WHAT WHEN.   Let's do a simply search
		Instructions:
			Select Edit --> Find History Item   Enter Search String
		Instructions:
			Find What:  
		metasploit Note(FYI):
		This search string is limited to the name of the website and not a 
		content search.  Results
		Note(FYI):
			Noticed 
			that http://www.metasploit.com is highlighted. 
		   
	Select All URLs
		Instructions:
			Click on the very first URLPress and Hold the Shift ButtonClick on the very last URL link  Select Highlighted Items
		Instructions:
			Edit --> Select Highlighted Items  Copy Selected Items
		Instructions:
			Edit --> Copy Select Items (Tab 
			Delimited)  Open Notepad
		Instructions:
			Start --> All Programs --> Accessories 
			--> Notepad  Paste URL's
		Instructions:
			Edit --> Paste  Save URL's
		Instructions:
			File --> Save As...Navigate to
			C:\Evidence
				If you do not have an Evidence 
				Folder, then please create it.File name: IE-YYYYMMDD.csv
				YYYY - Represents the YearMM - Represents the MonthDD - Represents the DayIn my case, I named the file 
				IE-20121215.csvClick Save  Open a Command Prompt
	
		Instructions:
		
			Start --> All Programs --> Accessories 
			--> Command Prompt   
	Proof of Lab
	
		Instructions: 
		
			cd C:\Evidence dir | findstr IE-20121215.csv
				Remember, the file name 
				IE-20121215.csv might be differently named according to the 
				today's date.type IE-20121215.csv | findstr 
			metasploitdate /techo "Your Name" 
			
				This should be your actual name. 
				e.g., echo "John Gray" 
		
		Proof of Lab Instructions
			Press both the <Ctrl> and <Alt> keys at 
			the same time.Do a <PrtScn> Paste into a word document Upload to Moodle   | 
    
 
 |