Difference between revisions of "Internet Explorer History File Format"

From Forensics Wiki
Jump to: navigation, search
(File Locations: Added more information about locations of index.dat files.)
(External Links: added a really informative link)
Line 64: Line 64:
* [http://www.cqure.net/wp/?page_id=18 IEHist program for reading index.dat files]
* [http://www.cqure.net/wp/?page_id=18 IEHist program for reading index.dat files]
* [http://www.milincorporated.com/a3_index.dat.html What is in Index.dat files]
* [http://www.milincorporated.com/a3_index.dat.html What is in Index.dat files]
* [http://www.foundstone.com/us/pdf/wp_index_dat.pdf Detailed analysis of index.dat file format]
[[Category:File Formats]]
[[Category:File Formats]]

Revision as of 14:33, 26 March 2008

Information icon.png

Please help to improve this article by expanding it.
Further information might be found on the discussion page.

Internet Explorer stores the web browsing history in a file called index.dat. The file contains multiple records.


File Locations

Internet Explorer history files keep a record of URLs that the browser has visited, cookies that were created by these sites, and any temporary internet files that were downloaded by the site visit. As a result, Internet Explorer history files are kept in several locations. Regardless of the information stored in the file, the file is named index.dat.

On Windows 95/98 these files were located in the following locations: %systemdir%\Temporary Internet Files\Content.ie5 %systemdir%\Cookies %systemdir%\History\History.ie5

On Windows 2000/XP the file locations have changed: %systemdir%\Documents and Settings\%username%\Local Settings\Temporary Internet Files\Content.ie5 %systemdir%\Documents and Settings\%username%\Cookies %systemdir%\Documents and Settings\%username%\Local Settings\History\history.ie5

Internet Explorer also keeps daily, weekly, and monthly history logs that will be located in subfolders of %systemdir%\Documents and Settings\%username%\Local Settings\History\history.ie5. The folders will be named MSHist<two-digit number><starting four-digit year><starting two-digit month><starting two-digit day><ending four-digit year><ending two-digit month><ending two-digit day>. For example, the folder containing data from March 26, 2008 to March 27, 2008 might be named MSHist012008032620080327.

File Header

Every version of Internet Explorer since Internet Explorer 5 has used the same structure for the file header and the individual records. Internet Explorer history files begin with:

43 6c 69 65 6e 74 20 55 72 6c 43 61 63 68 65 20 4d 4d 46 20 56 65 72 20 35 2e 32

Which represents the ascii string "Client UrlCache MMF Ver 5.2"

The next field in the file header starts at byte offset 28 and is a four byte representation of the file size. The number will be stored in little-endian format so the numbers must actually be reversed to calculate the value.

Also of interest in the file header is the location of the cache directories. In the URL records the hash directories are given as a number, with one representing the first cache directory, two representing the second and so on. The hash directories are kept at byte offset 64 in the file. Each directory entry is 12 bytes long, but only the first eight bytes are relevant.

Record Formats

URL Records

These records indicate web pages that were actually viewed. They contain the requested URL and the web server's response. They begin with the header, in hexadecimal:

55 52 4C 20

This corresponds to the string URL followed by a space.

The definition for the structure in C99 format:

typedef struct _URL_RECORD {
  /* 000 */ char        Signature[4];
  /* 004 */ uint32_t    Length;
  /* 008 */ uint64_t    LastModified;
  /* 010 */ uint64_t    LastAccessed;
  /* 018 */ uint32_t    Expires;
  /* 01c */ 
  // Not finished yet
The Length field is represented by four bytes that give the number of 128 byte blocks that make up the URL record. Therefore, a length of
05 00 00 00
would indicate five blocks (because the number is stored in little-endian format) of 128 bytes for a total record length of 640 bytes.

The actual interpretation of the "LastModified" and "LastAccessed" fields depends on the type of history file in which the record is contained. As a matter of fact, Internet Explorer uses three different types of history files, namely Daily History, Weekly History, and Main History. Other "index.dat" files are used to store cached copies of visited pages and cookies. The information concerning how to intepret the dates of these different files can be found on Capt. Steve Bunting's web page at the University of Delaware Computer Forensics Lab ( Please be aware that most free and/or open source index.dat parsing programs, as well as quite a few commercial forensic tools, are not able to correctly interpret the above dates. More specifically, they interpret all the time and dates as if the records were contained into a Daily History file regardless of the actual type of the file they are stored in.

REDR Records

HASH Records

LEAK Records

External Links