Home page logo

basics logo Security Basics mailing list archives

RE: Checking when the OS was first installed
From: "AndrewC" <andrew () whirlow plus com>
Date: Wed, 1 Jun 2005 20:50:50 +0100

Or you could just type "systeminfo" at the command prompt to get system
install date and all the patch/hotfix info you will ever likely need!!?.....

Andrew P Craig MA
The information transmitted in this e-mail is intended only for the person
or entity to which it is addressed and contains confidential information.
Any review, retransmission or other use by persons or entities other than
the intended recipient is prohibited. If you received this in error, please
contact the sender and delete the material from any computer. Thank you. 

-----Original Message-----
From: Times Enemy [mailto:times () krr org] 
Sent: 01 June 2005 09:00
To: security-basics () securityfocus com
Subject: Re: Checking when the OS was first installed


Not sure why, but i am assuming the OS is a Microsoft OS.

I would have to agree, that the creation date for the %systemroot% 
directory should indicate when the OS was installed.  This may not work 
if the OS was upgraded significantly.

Some generic folders to check the creation date:
c:\program files
c:\program files\common files
c:\documents and settings\default user

Some files to check the creation date:
c:\windows\security\logs\backup.log     # may have date inside as well 
as creation date
# the 'c:\windows\security\logs' subdirectory may have several files of 
worth regarding install date
# the same goes for file creation dates within 'c:\windows\system32\config'

et cetera.

This is not 100%, but it should work most of the time.

 From a command prompt, XP Pro:

dir /tc <filename>

EXAMPLE: dir /tc c:\autoexec.bat

This controls which time field displayed or used for sorting, per 'dir /?'.

For hidden files:

dir /ah /tc <filename>

EXAMPLE: dir /ah /tc c:\io.sys

OR right-click file/folder, left-click properties.

If you do enough of these, you should be able to determine the 
installation date.  There may be some simple command, registry entry, or 
the likes that keeps this information, specifically, and solely, but i 
do not know of it at this time.

FWIW, why do you care when the OS was installed?

.times enemy

Ansgar -59cobalt- Wiechers wrote:

On 2005-05-29 Lubrano di Ciccone, Christophe (DEF) wrote:

The date of the boot.ini file or the winnt folder (%systemroot%) may
help you.

Maybe, but since it's the configuration file for the bootloader, it is
prone to changes, so this seems very unreliable to me.

Ansgar Wiechers

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]