UPDATE: Someone pointed out, this being forensic software, it could be very walled off, sandboxed, etc, with no access to the file system, read only or not. The point being, my argument about not DIFF'ing, falls flat if there is no access by the file system. That said, I'm resourceful, I would find a way to dump the file structure somewhere, somehow. That's what they want right? Resourcefulness.
I don't know how many of you are IT guys, but for those that are... what the actual fuck is going on, on that stage?
I thought CodeMonkeyZ was supposed to be some computer savant or some shit... but he doesn't even know Windows? Really? Well, you sound like a lame Linux poseur then.
If you were not watching the same thing I was... they are looking like a group of monkeys trying to fuck a football. That's racist isn't it? Speciest? Monkeyist?
They have (at least) two images of the voting server. (Don't know why they call something that isn't supposed to connect to a network, a server, if anything it's a dumb client)
And CodeMonkeyZ the genius computer savant is strolling randomly through the files.
Bro, you're on international stream... DO SOMETHING!
They have a physicist, an IT guy, and CMZ... and not one of them know what the fuck they are doing up there.
Find the registry files... DIFF THEM!
DIFF the program files, (x86) and program data directories.
DIFF the user directories!
DIFF the FUCKING windows directory!
DIFF FUCKING SOMETHING!
DO AN ACTUAL BIT LEVEL SEARCH FOR STUFF, FFS!
The only hypothesis I can form is:
-
CMZ is a bullshitter, caught out on live stream.
-
They are flexing and flashing the files to scare (stupid collaborators) people into flipping, and aren't actually TRYING to do ANYTHING.
Oh, I'm also bothered by them being flummoxed over what I think I heard them talking about an IIS file from 1997? Uh, yeah. Win NT 4.0 SP1 came out in 1997.
That is the most confusing... I don't see a terminal window, or PowerShell win open anywhere.
If he is *nix, he knows how to look at files efficiently. Files are life if you sysadmin outside of Windows.
Maybe he can only access the server via the client app that they're using. I'm not an admin and I have no idea what that app does or can do. The monkey man has to know his stuff on the network side because he was the admin for both 4chan and 8chan and you know those sites are under constant attack.
That's a good point, since it's forensic software, it may keep it walled off.
I assumed that it may be available to the system, just shared in a different userspace with 'read only' set to EVERYONE. But walled-off, probably makes legal eagles happier.