-
Notifications
You must be signed in to change notification settings - Fork 13.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
dir of directory not displaying file modified timestamps #15919
Comments
Alright yeah I was able to reproduce this. The modified timestamp is different in the output of Meterpreter's |
Another interesting piece of behavior here is that the Notice the difference in the Last Modified timestamp for the two entries of Setup.evtx:
|
@smcintyre-r7 - I experienced this as well. It seems the dir of an individual file is correct, but I suspect the dir of a directory shows each file's creation time instead of modified time. |
You're right, it's swapping the timestamps and I figured out why. When you run Now that I know what the problem is, I just need to figure out what the "correct" order is based on the other Meterpreters and switch the one(s) that are incorrect to it. Thanks for reporting this bug! I have everything I need to get it sorted out now. |
Glad you tracked it down, thank you @smcintyre-r7 ! |
Steps to reproduce
dir "c:\Windows\System32\winevt\Logs"
dir "c:\Windows\System32\LogFiles\Scm"
dir "c:\Windows\System32\LogFiles\Scm\5c571bff-df7d-4678-8297-7a6e5833b2e3"
dir "c:\Windows\System32\winevt\Logs\Security.evtx"
timestomp -v "c:\Windows\System32\LogFiles\Scm\5c571bff-df7d-4678-8297-7a6e5833b2e3"
timestomp -v "c:\Windows\System32\winevt\Logs\Security.evtx"
This section should also tell us any relevant information about the
environment; for example, if an exploit that used to work is failing,
tell us the victim operating system and service versions.
meterpreter > sysinfo
Computer : REDACTED
OS : Windows 2008 R2 (6.1 Build 7601, Service Pack 1).
Architecture : x64
System Language : en_US
Domain : REDACTED
Logged On Users : 2
Meterpreter : x64/windows
Example output and discrepancy
Were you following a specific guide/tutorial or reading documentation?
N/A
Expected behavior
dir of directory should show proper modified timestamps
Current behavior
dir of directory appears to be showing Accessed or Created times
Metasploit version
Framework: 6.1.11-dev
Console : 6.1.11-dev
Additional Information
Module/Datastore
The following global/module datastore, and database setup was configured before the issue occurred:
Collapse
History
The following commands were ran during the session and before this issue occurred:
Collapse
Framework Errors
The following framework errors occurred before the issue occurred:
Collapse
Web Service Errors
The following web service errors occurred before the issue occurred:
Collapse
Framework Logs
The following framework logs were recorded before the issue occurred:
Collapse
Web Service Logs
The following web service logs were recorded before the issue occurred:
Collapse
Version/Install
The versions and install method of your Metasploit setup:
Collapse
The text was updated successfully, but these errors were encountered: