Modified before Created?

Discussion in 'other security issues & news' started by AKAJohnDoe, May 2, 2009.

Thread Status:
Not open for further replies.
  1. AKAJohnDoe

    AKAJohnDoe Registered Member

    Joined:
    Sep 26, 2007
    Posts:
    989
    Location:
    127.0.0.1
    How is this possible? And the size!
     

    Attached Files:

  2. crofttk

    crofttk Registered Member

    Joined:
    May 15, 2004
    Posts:
    1,979
    Location:
    Eastern PA, USA
    Perhaps it was copied out of dllcache on April 28th and perhaps it's compressed?

    Like this one - except size difference is a different reason:
    test.JPG
     
    Last edited: May 3, 2009
  3. lotuseclat79

    lotuseclat79 Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    5,390
    Another reason may be the system clock was not set properly when the document was created which may account for the illusion. Either that or it was magic!

    -- Tom :)
     
  4. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    http://www.xxcopy.com/xxcopy15.htm
    To illustrate: here is a file (compressed) in ../dllcache.

    adm1.gif

    I copy the file to another location and the created date changes but the modified date stays the same.

    adm2.gif

    I don't think that the information provided in that article is completely correct. In my dllcache directory, most of the files have 1999 as both created and modified, meaning, I think, that 1999 was the date that the installer was set up with all of the directories/files. So, the file was created in the installer directory on that date. Here is an example:

    atm-creationdate.GIF

    The 2003.12.06 created date in the first screenshot was when I installed Win2K. I think SP4 updated some of these dlls, hence, the later created date.

    The created date of my dllcache directory is 2003.12.06.

    So, I have two created dates for files in that directory, both technically correct, yet a bit misleading.

    ----
    rich
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.