• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Is it possible for a server admin to know what a user is browing on the network?

Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
I know there is a way to monitor which PC is doing the downloading and how much bandwidth it is using from the server, but is there a way to find out what the culprit machine is browsing/downloading without physically going to the culprit machine on the network?
 
Joined
Jun 28, 2008
Messages
1,109 (0.19/day)
Location
Greenville, NC
System Name Champ's 1440P Rig
Processor Intel i7-4770K @ 4.6 GHz
Motherboard AsRock Z97 Extreme6
Cooling Corsair H60
Memory Corsair Vengeance 16GB 1600 Mhz 4x4 Blue Ram
Video Card(s) Nvidia 1080 FE
Storage Samsung 840 Evo 256 GB/RAID 0 Western Digital Blue 1 TB HDDs
Display(s) Acer XG270HU
Case Antec P100
Power Supply Corsair CX850M
Mouse Logitech G502
Keyboard TT eSports Poseidon
Software Windows 10
Yep, I seen it when I sure my intership at the hospital. It was like remote desktop, but he was able to monitor any computer in the network and even take full control of it and I think block you out. Then there are server files that always keep track of where you are
 
Joined
May 21, 2009
Messages
4,966 (0.91/day)
System Name i7-PC / HTPC / iMac
Processor i7 3820 / Phenom II 940
Motherboard GIGABYTE G1.ASSASSIN2 / M3A79-T Deluxe
Cooling Corsair Hydro H100i / Scythe II (HS only)
Memory G.SKILL Trident X Series 8GB (2 x 4GB) DDR3 1600mhz / 4GB DDR2 1066 (@800) Corsair Dominator
Video Card(s) GB Radeon HD 7950s 3GB / GB Radeon HD 7950s 3GB
Storage 2x 80GB Intel X-25, 2x600gb SATA, 1x1tb 5400RPM storage /1x600GB, 3x500GB,1x160,1x120 SATA
Display(s) 1x 27" Yamakasi / Vizio 42" HDTV
Case Lian Li Lancool PC-K58 / Antec 900
Audio Device(s) HT Omega Striker 7.1 / Onboard and HDMI from ATi Card
Power Supply PC Power & Cooling 750W / 610W
Software Ubuntu / Windows 8.1 Pro / OS X / PHPStorm / Gaming
aside from vnc as champ has mentioned, there are also monitoring tools that can show an administrator all of the requests going in and out of a router/network.

it is something easily done by an administrator worth their salt.
 

brandonwh64

Addicted to Bacon and StarCrunches!!!
Joined
Sep 6, 2009
Messages
19,542 (3.66/day)
Windows shared services should be able to track files on the domain that are transferred from server to machine. Also you can track UDP and TCP connections from each host name as well.
 
Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
I'll have to look into this do I can see how detailed the information is.
For example if someone is torrenting, I would like to know if I can tell the name of the exact file(s) they are downloading.

Piracy in New Zealand is pretty heavy now and can have serious implications for the person downloading after a while.

The catch with the network I am working on is, people can come in with their laptops and use the connection which means I can not gain remote access to these computers.
 
Joined
Oct 2, 2005
Messages
3,059 (0.45/day)
Location
Baltimore MD
Processor Ryzen 5900X
Motherboard ASUS Prime X470 Pro
Cooling Arctic liquid freezer II 240
Memory 2 x 16 Gb Gskill Trident Z 3600 Mhz
Video Card(s) MSI Ventus 3060 Ti OC
Storage Samsung 960 EVO 500 Gb / 860 EVO 1 Tb
Display(s) Dell S2719DGF
Case Lian Li Lancool II Mesh
Audio Device(s) Soundblaster Z
Power Supply Corsair RM850x
Mouse Logitech G703
Keyboard Logitech G513
Software Win 11
wireshark is your friend
 

DeAtHWiSh

New Member
Joined
Dec 24, 2007
Messages
197 (0.03/day)
Location
Miami, FL
System Name Desktop / Laptop
Processor AMD Thuban 1090T@3.6GHz HT@2.6GHz / Intel i7 2630QM @ 2.0GHz
Motherboard Asus CH V 990FX / Intel HM67
Cooling Corsair H100 CPU Load @ 48C (Fans on Low 24/7) / Stock
Memory G.SKILL Sniper Series (2 x 4GB) DDR3 1600 9-9-9-24-2T / Corsiar Vengence DD3 1600 (4GB x 2)
Video Card(s) ASUS 580 GTX DCII / NVidia 555M 1.5GB
Storage OCZ Vertex III 120GB (OS) - Seagate Barracuda 320GB-7200RPM (X2 in RAID 0) / PNY 128GB SSD
Display(s) HP 2711x 1080P 27'' LED ON DVI / 14'' LED 900p
Case Cooler Master HAF X 942 / Alienware
Audio Device(s) Realtek ALC892 8-Channel HD Audio / Realtek HD Audio
Power Supply Cooler Master Silent Pro 850W / Stock
Software Windows 7 Ultimate 64 Bit / Windows 7 Home Premium
Benchmark Scores Real Men Crunch 4 TPU!
Tor browser :( or not
 
Last edited:
Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
Correct me if I'm wrong.

So it seems windows server alone can not see exactly what a person is downloading if the connected computer is not set up specifically unless third party software is installed on the server?

EDIT:-
Isn't Tor designed to block the network from knowing where you've been?
 
T

twilyth

Guest
You need something that encrypts from end to end - like https vs http.

The only way to do this without installing software is to use something like a VPN. This will encrypt everything between your machine and the VPN server. However it's hard to find fast, reliable free vpns. Generally you will have to use a commercial service. The good news is that they aren't that expensive if you shop around.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
is it possible for a server admin to know what a user is browsing on the network? yes of course. the question though should be legal in nature and not technical. if you work for a private company and you are worried that perhaps you have been browsing illegal or inappropriate material while on their network you should look into their privacy policy. most private companies consider the network "theirs" and do not give the impression to their employees that they are provided a level of privacy. public institutions though like state schools and possibly public hospitals will almost never look into what an employee has been doing since it is public and considered protected.

so if you looked at some pron and think you will be fired check out your companies privacy policy and find yourself a good lawyer. even if you did something bad you may actually be able to win out in a lawsuit if your employer illegally spied on you.
 
T

twilyth

Guest
As a general rule, unless you are in a union or get paid by the hour, you're what is referred to as an "at-will" employee. That means that they can fire you for any reason or no reason at all.

There are some limitations on this right though and this may be one of them. I don't know.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
As a general rule, unless you are in a union or get paid by the hour, you're what is referred to as an "at-will" employee.

that varies from state to state.
 
Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
You need something that encrypts from end to end - like https vs http.

The only way to do this without installing software is to use something like a VPN. This will encrypt everything between your machine and the VPN server. However it's hard to find fast, reliable free vpns. Generally you will have to use a commercial service. The good news is that they aren't that expensive if you shop around.

I guess this is why I was running around in circles when trying to figure out what computer was downloading what via windows server trying to find out what computer was downloading what without being blatantly obvious.

Windows server alone is not capable of what I am trying to do.

It appears the perpetrator is as safe from me knowing what they have been downloading through the server if their security settings are at default.

Only knowing the bandwidth downloaded during that time.

Hopefully I can get the senior network admin to install some third party software.
Unfortunately the senior admin thinks anything anyone installs on the network which is not his idea will mess it up beyond repair.
 
Joined
Jun 4, 2011
Messages
3,051 (0.65/day)
System Name The SwagMachine / The Sister
Processor Core i5 3570K @5.2ghz 1.3V/ 1100T
Motherboard ASUS P8Z77-V / ASUS M5A99X EVO
Cooling Phanteks PH TC14PE / Corsair H40
Memory M379B5273DH0-YK0 2X4GB + PVI316G213C1QK 2X4GB / 2x4GB Patriot 2133
Video Card(s) PNY 780Ti /Windforce 7950
Storage 2xSamsung 840 EVO 250gb+WD10EZEX + WD30EZRX/ 1x WD1500 Black
Display(s) AOC Q2963PM+Acer S200HL / Acer S200L+ LG 22LD350
Case Fractal Define R4 / NZXT Trinity
Audio Device(s) Asus Xonar DG / Asus Xonar DG
Power Supply Seasonic 750X / ROSEWILL RG630-S12 630W R
Mouse Razer Deathadder Chroma / Roccat Kone+
Keyboard Razer Blackwidow 2013 Stealth / Roccat Isku
Software Windows 8.1 Pro / Windows 7 Ultimate
Benchmark Scores one time I scored a 3 on 3dmark 11
is it possible for a server admin to know what a user is browsing on the network? yes of course. the question though should be legal in nature and not technical. if you work for a private company and you are worried that perhaps you have been browsing illegal or inappropriate material while on their network you should look into their privacy policy. most private companies consider the network "theirs" and do not give the impression to their employees that they are provided a level of privacy. public institutions though like state schools and possibly public hospitals will almost never look into what an employee has been doing since it is public and considered protected.

so if you looked at some pron and think you will be fired check out your companies privacy policy and find yourself a good lawyer. even if you did something bad you may actually be able to win out in a lawsuit if your employer illegally spied on you.

I know they log searches, and can watch your screen/lock your pc at my school, a few kids have been busted for going on facebook and such, you are never safe, they are watching.
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,444 (2.43/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
I know they log searches, and can watch your screen/lock your pc at my school, a few kids have been busted for going on facebook and such, you are never safe, they are watching.

with windows active directory, everything can be logged very easily. linux admins have to do more work which is why most places just setup a domain controller and have all of the PCs on the network log in to the domain with a users log/pass. from there the admins can completely control the PC. this is why the question should be legal in nature. every corporation, institution has their own policy regarding employee or student privacy.
 
Joined
Aug 10, 2007
Messages
4,267 (0.70/day)
Location
Sanford, FL, USA
Processor Intel i5-6600
Motherboard ASRock H170M-ITX
Cooling Cooler Master Geminii S524
Memory G.Skill DDR4-2133 16GB (8GB x 2)
Video Card(s) Gigabyte R9-380X 4GB
Storage Samsung 950 EVO 250GB (mSATA)
Display(s) LG 29UM69G-B 2560x1080 IPS
Case Lian Li PC-Q25
Audio Device(s) Realtek ALC892
Power Supply Seasonic SS-460FL2
Mouse Logitech G700s
Keyboard Logitech G110
Software Windows 10 Pro
We know and see all! Pay tribute or be turned over to HR!

- Lunch
- Liquor
 
Joined
Jul 3, 2008
Messages
174 (0.03/day)
Processor Intel Core i7 5820k
Motherboard MSI X99S-GAMING7
Cooling Corsair H105
Memory 16GB G.SKILL DDR4
Video Card(s) Gigabyte GTX1070 Gaming G1
Storage Samsung 840 Evo 256GB
Display(s) Acer Predator XB271HU
Case Corsair 800D
Audio Device(s) ASUS XONAR
Power Supply Corsair HX850i
Mouse Logitech G502
Keyboard Filco Majestouch
Software Windows 10
Solarwinds make a whole plethora of applications that you can use to track this information, although it doesn't come cheap. A much easier option would be to simply block all the ports on the firewall and force everyone to browse through a proxy server. That way everything they do is logged and everything that attempts to go directly to the web gets blocked.

If a proxy server isn't practical then block all unneccessary ports. You should do this anyway, not blocking unused ports is akin to locking the front door but leaving the backdoor and windows wide open.

Alternately having a look at the UPnP port list on the router should quickly show the source IP of the torrenting demon. The port should be a rather high number, normally it will also use the same port on both TCP and UDP traffic, which makes it easier to spot.

Windows server will only have a record of what is accessed from THAT server (provided auditing is setup to do so). Your network admin should be able to identify and resolve this extremely quickly if he is half competent.
 
Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
I guess the assumption with the senior network admin, is these kids only know facebook and youtube so adding a third party app which is going to cost would be a waste of money as where I live, we don't get many computer savvy people around.

Especially where I'm designated to give a hand but in a way which costs $0.
 
Top