<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6844399733943221829</id><updated>2012-02-17T20:18:00.415+08:00</updated><category term='linux'/><category term='登錄檔'/><category term='教學資料'/><category term='系統常識'/><category term='相關書籍'/><category term='鑑識程序'/><category term='證照相關'/><category term='惡意程式'/><category term='密碼破解'/><category term='鑑識概述'/><category term='資訊安全'/><category term='資料還原'/><category term='資安工具'/><category term='鑑識工具'/><category term='新聞'/><category term='Log'/><category term='記憶體'/><category term='手機鑑識'/><title type='text'>Invisible Man</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default?start-index=101&amp;max-results=100'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>488</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-6825256486889975351</id><published>2012-02-17T20:18:00.000+08:00</published><updated>2012-02-17T20:18:00.465+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><category scheme='http://www.blogger.com/atom/ns#' term='資料還原'/><title type='text'>Blade™ v1.9 Released - AFF® Support, Hiberfile.sys Conversion and New Evaluation Version</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.digital-detective.co.uk/images/blog/Digital_20Detective_20Software_20-_20Blade_20Professional_20-_20Forensic_20Data_20Recovery.png"&gt;&lt;img alt="Digital Detective Software - Blade Professional - Forensic Data Recovery" border="0" src="http://www.digital-detective.co.uk/images/blog/Digital_20Detective_20Software_20-_20Blade_20Professional_20-_20Forensic_20Data_20Recovery_thumb.jpg" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This release of Blade&lt;span&gt;™&lt;/span&gt;&amp;nbsp;brings a number of fixes and some great new features.&amp;nbsp; This is the first release of Blade&lt;span&gt;™&lt;/span&gt; to have evaluation capabilities which allow the user to test and evaluate our software for 30&amp;nbsp; days. When Blade&lt;span&gt;™&lt;/span&gt;  is installed on a workstation for the first time (and a valid USB  dongle licence is not inserted) the software will function in evaluation  mode.&lt;br /&gt;&lt;br /&gt;The following list contains a summary of the new features:&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Support for Advanced Forensic Format (AFF®)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Hiberfil.sys converter - supports XP, Vista, Windows 7 32 and 64bit&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Accurate hiberfil.sys memory mapping, not just Xpress block decompression&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Hiberfil.sys slack recovery&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Codepage setting for enhanced multi-language support&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;SQLite database recovery&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;30&amp;nbsp; Day evaluation version of Blade&lt;span&gt;™&lt;/span&gt; Professional&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;New recovery profile parameters for more advanced and accurate data recovery&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Support for Logicube Forensic Dossier®&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Support for OMA DRM Content Format for Discrete Media Profile (DCF)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;We have also been working on the data recovery engines to make them  more efficient and much faster than before. The searching speed has been  significantly increased.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://blog.digital-detective.co.uk/2012/02/blade-v19-released-aff-support.html &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;strong&gt; &lt;h2&gt;&lt;strong&gt; &lt;h5&gt;&lt;strong&gt; &lt;h4&gt;&lt;strong&gt;Downloads and&amp;nbsp;Full Release&amp;nbsp;Information&lt;/strong&gt;&lt;/h4&gt;&lt;/strong&gt;&lt;/h5&gt;&lt;/strong&gt;&lt;/h2&gt;&lt;/strong&gt;&lt;/span&gt; &lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://kb.digital-detective.co.uk/display/BLADE1/Blade+v1.9" target="_blank"&gt;Blade v1.9 Release Notes&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://kb.digital-detective.co.uk/display/BLADE1/Change+Log+v1.9" target="_blank"&gt;Blade v1.9 Change Log&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.bladeforensics.com/4e06cf00/Blade-v1.9-win32-1.9.12045.5.zip" target="_blank"&gt;Blade v1.9 Software Download&lt;/a&gt; &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-6825256486889975351?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/6825256486889975351/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=6825256486889975351&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6825256486889975351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6825256486889975351'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/blade-v19-released-aff-support.html' title='Blade™ v1.9 Released - AFF® Support, Hiberfile.sys Conversion and New Evaluation Version'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-6388060646857871254</id><published>2012-02-14T20:33:00.000+08:00</published><updated>2012-02-14T20:33:00.648+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識概述'/><title type='text'>電腦鑑識與鑑識會計</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自&lt;a href="http://blog.chinatimes.com/law/archive/2012/01/09/1159626.html"&gt; law&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;筆者算是國內比較早接觸&lt;strong&gt;電腦鑑識&lt;span style="color: blue;"&gt;(數位鑑識)&lt;/span&gt;&lt;/strong&gt;這個領域，大約在91年間就開始閱讀相關文獻，但是那時候很少資料，連英美國家的電腦鑑識書籍，也非常少，而且概念非常混亂。(那時候差不多是網路剛興起及網路泡沫時代)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;為了讓資訊科技發達的我國，也不會與電腦鑑識這個時代潮流脫節，經過努力整理當時各國的書籍與文獻，曾經於93年間出版過一本「&lt;strong&gt;電腦鑑識與企業安全&lt;/strong&gt;」，但是當時這個領域太冷門，出版社後來好像也不知去向，這本書也絕版了。(希望不會是因為本書)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;但無論如何，也成就了亞洲應該是第一本有關電腦鑑識的書籍。雖然從現在的角度來看，這本書的內容頗為粗淺，但畢竟是一個小小里程碑......&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;過了幾年，實務上有了長足的發展，政府部門也在95年間成立了第一座實驗室，又建立了第二座里程碑。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;筆者沒有再深入學習進階的電腦鑑識，開始再開發更冷門的數位證據領域，也在98年間寫了一本「&lt;strong&gt;圖解數位證據&lt;/strong&gt;」的著作，將法院判決中的錯誤見解，在清楚又簡單的編排架構下呈現出來。當然這個領域還是很冷門，所以銷售情況依舊慘澹。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;不過這類型的書籍本來就不是以銷售為目的。經過幾年，感覺這個領域一直在冰箱中，冷到不行。在此冷到不行的同時，筆者也在100年6月完成了法律博士的學位，主題也就是「數位證據」。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;99年間個人資料保護法的通過，電腦鑑識的領域突然熱門了起來。也許是電腦鑑識可以幫助瞭解資料外洩的原因，可以作為企業免責的證明，再加上個人資料保護法的賠償金額過高，迄今每一場相關的研討會都是滿場，其中也幾乎都有一場是有關電腦鑑識的議題。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;本來筆者並未有意踏入個人資料這一個領域。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;為什麼呢？&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;理由很簡單，電腦鑑識並非僅與個人資料有關係，電腦鑑識應該是與每個領域都有關聯性，因為每個領域都有可能涉及到數位證據，電腦鑑識就是一種嚴謹的採證與分析數位證據的程序。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a class="nav" href="http://album.udn.com/kf0630/photo/5372118?o=new#photoanc"&gt;&lt;img border="0" id="photo_img" src="http://blog.udn.com/community/img/PSN_PHOTO/kf0630/f_6957107_1.jpg" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;但是筆者聽過許多講座之後，發現許多主講者也許是為了資訊產品的行銷，講偏了電腦鑑識的真正意涵，搞得好像個人資料保護法的立法目的，是為了相關資訊產業能賣出產品。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;所以，近來筆者開始公告將整合個人資料保護法與電腦鑑識領域，從非商業產品推銷的角度，將正確的知識推廣給想聽的朋友。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;目前也在短短的兩個月不到的期間講了六場，全省超過千人聽過，更利用自己的休閒時間，三個月內已經完成「&lt;strong&gt;圖解個人資料保護法&lt;/strong&gt;」的著作，就等101年年中施行細則的通過，即可出版，相信屆時可以作為有需要朋友的參考。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;最近有某研究所的教授徵詢筆者意見，希望能在其「&lt;strong&gt;鑑識會計&lt;/strong&gt;」的課程中，向研究生解說一下電腦鑑識的概念。如上圖，電腦鑑識確實為鑑識會計領域中的一小部份，透過電腦鑑識的方式，找到企業營運的問題與弊病，如同前面所述，每個領域都有可能涉及到數位證據。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;鑑識會計在100年高考三級中，也首次成為考題，看來繞著電腦鑑識領域打轉的議題，也將會愈來愈多。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-6388060646857871254?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/6388060646857871254/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=6388060646857871254&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6388060646857871254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6388060646857871254'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/blog-post.html' title='電腦鑑識與鑑識會計'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-2760347791898689773</id><published>2012-02-12T20:32:00.000+08:00</published><updated>2012-02-12T20:32:00.284+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><title type='text'>WhatsApp Xtract</title><content type='html'>&lt;div class="post-body entry-content" id="post-body-3076990734900284602" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;div style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; I don't want to bore you explaining what is &lt;i&gt;WhatsApp&lt;/i&gt; .&lt;/span&gt; &lt;span&gt; If you have this serious gap, you can fill it &lt;a href="http://translate.googleusercontent.com/translate_c?anno=2&amp;amp;hl=zh-TW&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=zh-TW&amp;amp;twu=1&amp;amp;u=http://www.whatsapp.com/&amp;amp;usg=ALkJrhhRXNuQYJNB3B92s4YR3daB7Sf8jA" target="_blank"&gt;here&lt;/a&gt; .&lt;/span&gt; &lt;span&gt; Forensically speaking, WhatsApp was a very cool app until the last June.&lt;/span&gt; &lt;span&gt; After that, someone had decided to add the extension “crypt” to such excellent source of information which was &lt;a href="http://translate.googleusercontent.com/translate_c?anno=2&amp;amp;hl=zh-TW&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=zh-TW&amp;amp;twu=1&amp;amp;u=http://www.securitybydefault.com/2011/06/what-whatsapp-doesnt-tell-you.html&amp;amp;usg=ALkJrhgGVNdGloEnskSsUy2z7c0W5fgcEA" target="_blank"&gt;&lt;i&gt;msgstore.db&lt;/i&gt;&lt;/a&gt; .&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span&gt; This database stores information about contacts and also entire conversations.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span&gt; But simply opening it with &lt;a href="http://translate.googleusercontent.com/translate_c?anno=2&amp;amp;hl=zh-TW&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=zh-TW&amp;amp;twu=1&amp;amp;u=http://sqlitebrowser.sourceforge.net/&amp;amp;usg=ALkJrhgA-TZF60j9ULH3gQemC1-YoyedEA" target="_blank"&gt;SQLite Browser&lt;/a&gt; , you can have some troubles in extracting a single chat session with a desired contact, or in reordering the messages.&lt;/span&gt; &lt;span&gt; My last python script wants to overcome these problems, avoiding to deal with complex SQL queries.&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-O3on3-JSCOA/TukgrFWOTfI/AAAAAAAAB2c/Arl2aAG2yG8/s1600/whatsappb.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-O3on3-JSCOA/TukgrFWOTfI/AAAAAAAAB2c/Arl2aAG2yG8/s1600/whatsappb.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://blog.digital-forensics.it/2011/12/whatsapp-xtract.html&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-O3on3-JSCOA/TukgrFWOTfI/AAAAAAAAB2c/Arl2aAG2yG8/s1600/whatsappb.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-2760347791898689773?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/2760347791898689773/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=2760347791898689773&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2760347791898689773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2760347791898689773'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/whatsapp-xtract.html' title='WhatsApp Xtract'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-O3on3-JSCOA/TukgrFWOTfI/AAAAAAAAB2c/Arl2aAG2yG8/s72-c/whatsappb.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-3867508079716310615</id><published>2012-02-11T20:29:00.000+08:00</published><updated>2012-02-11T20:29:00.607+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><title type='text'>What WhatsApp doesn't tell you...</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span&gt;It is the 'top' app in the mobile world, almost immediately followed the ' &lt;i&gt;give me your mobile number&lt;/i&gt; ' request comes the following question ' &lt;i&gt;Do you have WhatsApp?&lt;/i&gt; '.&lt;/span&gt; &lt;span&gt; Clearly this application is changing the concept of free SMS messaging.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span&gt; Alberto warned about &lt;a href="http://translate.googleusercontent.com/translate_c?anno=2&amp;amp;hl=zh-TW&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=zh-TW&amp;amp;twu=1&amp;amp;u=http://www.securitybydefault.com/2011/03/whatsapp-y-su-seguridad-pwn3d.html&amp;amp;usg=ALkJrhhELq4H10Udy86-CSWBzwF_HOEvHg"&gt;insecurity issues in how WhatsApp transmits data in plain text&lt;/a&gt; and what this means in shared environments.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;span&gt; Today we have to talk about the inside, the way in which WhatsApp stores and manages its data.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span&gt; Looking from within the file structure of the application we have two files called &lt;b&gt;msgstore.db&lt;/b&gt; and &lt;b&gt;wa.db&lt;/b&gt; (locations vary, of course, between Android and iPhone).&lt;/span&gt; &lt;span&gt; These files are in SQLite format.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span&gt; Once we import these files with a tool to browse inside their content (eg SQLite Manager), here comes the first surprise: &lt;b&gt;none of the information contained is encrypted&lt;/b&gt; .&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span&gt; Contacts are stored in &lt;b&gt;wa.db&lt;/b&gt; and EVERY sent messages are in &lt;b&gt;msgstore.db&lt;/b&gt; .&lt;/span&gt; &lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-y2fZ9nEHJn4/TfAKe4JyQ_I/AAAAAAAABHU/Y0EQOxVzf3w/s1600/whats.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="302" src="http://2.bp.blogspot.com/-y2fZ9nEHJn4/TfAKe4JyQ_I/AAAAAAAABHU/Y0EQOxVzf3w/s400/whats.png" width="400" /&gt;&lt;/a&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span&gt; Wait a sec, did I say EVERY?&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span&gt; Absolutely, &lt;b&gt;every&lt;/b&gt; sent and received messages are there.&lt;/span&gt; &lt;span&gt;  And why "EVERY" is in uppercase?, simply because although theoretically  WhatsApp give us the opportunity through its graphical interface to  delete conversations, the reality is that they still remain in the  database ad infinitum.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span&gt;  And the issue is even more fun if we sent or received messages at a  time which GPS was enabled, because WhatsApp also stores coordinates in &lt;b&gt;msgstore.db&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-dLpDenGC35g/TfAUfqb-yJI/AAAAAAAABHY/KCyfipkf5PY/s1600/whatscoordenadas.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-dLpDenGC35g/TfAUfqb-yJI/AAAAAAAABHY/KCyfipkf5PY/s1600/whatscoordenadas.png" /&gt;&lt;/a&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt;  In the case of Android there are even more important things stored that  might be of interest to a forensic investigator - or maybe a jealous  boyfriend/girlfriend.&lt;/span&gt; &lt;span&gt; Apparently WhatsApp is configured &lt;i&gt;by default&lt;/i&gt; with a very 'verbose' level of logging and store, within the directory / files / Logs, files with this appearance:&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; # pwd&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; /data/data/com.whatsapp/files/Logs&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; # ls&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; whatsapp-2011-06-06.1.log.gz  whatsapp-2011-06-09.1.log.gz&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; whatsapp-2011-06-07.1.log.gz  whatsapp.log&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; whatsapp-2011-06-08.1.log.gz&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; #&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt;  In these files are recorded every XMPP transactions made by the  application with a very high verbose (debug) level, with the timestamp  of when it receives or sends a message (among other things).&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: left;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; 011-06-09 00:47:21.799 xmpp/reader/read/message 346XXXXXXX@s.whatsapp.net 1307XXXXXX-30 0 false false&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt;  These files are easily "parseable" to extract the ratio of mobile  numbers which has maintained some kind of conversation with us.&lt;/span&gt; &lt;span&gt; I created a small script that parses the file and pulls out this list of numbers:&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;pre class="brush: python" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; &lt;span&gt; import re&lt;/span&gt;&lt;br /&gt;&lt;span&gt; import sys&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt; logfile = sys.argv[1]&lt;/span&gt;&lt;br /&gt;&lt;span&gt; logdata = open(logfile,"r")&lt;/span&gt;&lt;br /&gt;&lt;span&gt; dump = logdata.readlines()&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt; numerosin = []&lt;/span&gt;&lt;br /&gt;&lt;span&gt; numerosout = []&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt; for line in dump:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;        m = re.search('(?&amp;lt;=xmpp/reader/read/message )\d+', line)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;       if m:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;                if not numerosin.count(m.group(0)):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;                        numerosin.append(m.group(0))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;        m = re.search('(?&amp;lt;=xmpp/writer/write/message/receipt )\d+', line)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;        if m:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;                if not numerosout.count(m.group(0)):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;                        numerosout.append(m.group(0))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt; print "Messages received from\n"&lt;/span&gt;&lt;br /&gt;&lt;span&gt; print "\n".join(numerosin)&lt;/span&gt;&lt;br /&gt;&lt;span&gt; print "\nMessages sent to\n"&lt;/span&gt;&lt;br /&gt;&lt;span&gt; print "\n".join(numerosout)&lt;/span&gt; &lt;/span&gt;&lt;/pre&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;span&gt; Executing the script, it will ouput the information as follows:&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; $ python whatsnumbers.py whatsapp-2011-06-08.1.log&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; Messages received form&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; 34611111111&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; 34622222222&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; Messages sent to&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; 34611111111&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span&gt; 34622222222&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;span&gt;轉自&amp;nbsp; http://www.securitybydefault.com/2011/06/what-whatsapp-doesnt-tell-you.html&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-3867508079716310615?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/3867508079716310615/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=3867508079716310615&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/3867508079716310615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/3867508079716310615'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/what-whatsapp-doesnt-tell-you.html' title='What WhatsApp doesn&apos;t tell you...'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-y2fZ9nEHJn4/TfAKe4JyQ_I/AAAAAAAABHU/Y0EQOxVzf3w/s72-c/whats.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-8992124429932789821</id><published>2012-02-09T20:57:00.000+08:00</published><updated>2012-02-09T20:57:00.783+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><title type='text'>Interesting Malware in Email Attempt - URL Scanner Links</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Last weekend I spent some time with extended family helping confirm  for them that their on-line email account got hacked and had been used  to send some malware-linking spam emails to users in their contact list.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Yesterday  our family email account was on the receiving end of someone --  possibly -- who fell victim to an email account hack as our email  address was amongst several others included together receiving the  email. I say possibly as none of us recognized the sender’s email  address and it wasn’t in any of our address books. Possibly our along  with the other’s email addresses had been harvested somehow and this was  a fake spamming account. The “show-as” name was definitely non-standard  and used some letters that related to that in the subject line.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;It  was pretty evident to me this was probably a dangerous site to go to,  but being curiously-minded, I couldn’t pass up the chance to do some  detective work.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The email originated from a yahoo mail account.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The Subject line was baited “ACH Transfer Canceled…” and the display name in the email address contained the letters “NACHA.”&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;ACH is meant to refer to the “Automated Clearing House” which handled financial transactions in the US overseen by the &lt;a href="http://www.nacha.org/c/Intro2ACH.cfm"&gt;NACHA&lt;/a&gt;.&amp;nbsp;  To most Americans, I’m betting these acronyms mean very little and they  would be more taken with a sudden urge to grab some NACHOES instead.  Maybe Europeans would be a little more anxious emails purporting to come  from ACH and NACHA. I digress.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;First thing I looked at was the  message header. Lots of goodies there. We can follow the bounce between  the yahoo mail sender to our ISP’s email servers. Times/dates of  transmission.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Since this was a Yahoo mail account, it appears the  header may actually contain the IP address of the the location the mail  account was logged into from. This is the first time I have seen this  so I need to do more research. The IP associated with this particular  email is located in France.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The website &lt;a href="http://www.ip-address.org/"&gt;IP Address Locator&lt;/a&gt; has lots of good tools for locating IP addresses as well as a feature that allows a copy/paste/analyze of email headers.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The  content of the email was very thin, a single line with all the text ran  together. There is a URL link markup there, however it misses getting  all the characters. Hmm.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Toggling between the different modes of  viewing email content in Thunderbird reveals odd results. If I look at  it in original html mode I see a single line of text with an hyperlink  in the middle.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If I view it in simple html most of the text is the same but a few characters are different.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If I view it in plain text, there is nothing showing.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Hovering over the hyperlink displayed shows a URL shortner link. Hmm. Set that aside for a moment.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So I back and look at the full header view again and find this in the message body:&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;span style="font-size: small;"&gt;Content-Type: text/html; charset=ISO-8859-5 &lt;br /&gt;Content-Transfer-Encoding: base64&lt;/span&gt;&lt;/blockquote&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Ah! So I copy/paste that large text block that follow that into this &lt;a href="http://webnet77.com/cgi-bin/helpers/base-64.pl"&gt;base64 online encoder / decoder&lt;/a&gt; and get a binary file to download!&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;(More regarding content encoding methods here &lt;a href="http://msdn.microsoft.com/en-us/library/ms527009%28v=exchg.10%29.aspx"&gt;Content-Transfer-Encoding&lt;/a&gt; - MSDN, here &lt;a href="http://www.freesoft.org/CIE/RFC/1521/5.htm"&gt;The Content-Transfer-Encoding Header Field&lt;/a&gt; via freesoft.org and here &lt;a href="http://techhelp.santovec.us/decode.htm"&gt;Decoding Internet Attachments - A Tutorial&lt;/a&gt; by Michael Santovec.)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Opening that binary file in Notepad++ reveals the html code with the same actual URL embedded.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Guessing here they are using base64 coding for the content to try to get around email scanners.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;OK, so let’s check out that URL.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Turns out it is using Google’s own URL shortning service: &lt;a href="http://goo.gl/"&gt;Google URL Shortener&lt;/a&gt;.&amp;nbsp; More info here. &lt;a href="http://support.google.com/websearch/bin/answer.py?hl=en&amp;amp;answer=190768"&gt;Google URL shortener - Web Search Help&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Turns  out this is a pretty cool choice from both sides of the security fence.  By appending the URL with “.info” at the end of a Goog.le shortened URL  we can &lt;a href="https://groups.google.com/a/googleproductforums.com/forum/#%21category-topic/websearch/unexpected-search-results/3WuGJd_DLNI"&gt;find out the stats from Goo.gl URL shortener&lt;/a&gt; (Google Groups)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This  is good from an attacker standpoint as they can easily monitor their  success rate on the nibbles of this hook and any “hits” to the actual  URL. Researchers can get info as well by monitoring the same info and  how fast/long the “click-through” may happen.&lt;/span&gt;&lt;/div&gt;&lt;div align="center" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://lh4.ggpht.com/-wRVUeTuFQa4/Txt1MHVwLyI/AAAAAAAAA8Q/oVED6dphkdA/s1600-h/h0j5wpnx.2up%25255B4%25255D.png"&gt;&lt;img alt="h0j5wpnx.2up" border="0" height="484" src="http://lh5.ggpht.com/-jWSVoMZdJ_Y/Txt1MSg4NbI/AAAAAAAAA8Y/bj2aNmeq4Aw/h0j5wpnx.2up_thumb%25255B1%25255D.png?imgmax=800" style="background-image: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="h0j5wpnx.2up" width="587" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Neat isn’t it?&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Now  that I’ve got the actual long URL that this points to, we can start  tossing the URL at some on-line link analysis/scanner tools.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt; shows both TrendMicro and SCUMWARE.org report the long URL as a Malware/Malicious site.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.quttera.com/"&gt;Quttera&lt;/a&gt; reports it as serving up a suspicious javascript content via HTML page code.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://anubis.iseclab.org/?action=home"&gt;Anubis: Analyzing Unknown Binaries&lt;/a&gt;  provided a deeper review of the URL by capturing Windows system events  in a virutal sandbox system. It accesses the Windows registry, mucks  with some keys, created a cookie, reads the autoexec.bat file, mods some  files and maps dll’s to memory and appears to try to download more  stuff. The report is available in HTML, XML, PDF, and TXT formats.&amp;nbsp;  Also, they offer a traffic.pcap file to download so you can examine the  network traffic generated and perform any NFA you want to do.&amp;nbsp; This  site/tool rocks from a depth of information standpoint.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://urlquery.net/index.php"&gt;urlQuery&lt;/a&gt; gives some more report feedback when it is sandboxed. Lots of Java script stuff. Another strong URL analysis reporting site.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Trying  it a few more times changing the browser type/java version/flash  version gets different results and the URL serving code reflects all  kinds of different IP’s each time so that long URL seems to be hosted at  a dynamic IP host allowing it to bounce around (serving up HTTP  redirects) and serve up the malware code depending on platform from all  over the place making it harder to track down the source.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;urlQuery  actually identified the network traffic code as being detected as  Blackhole exploit kit v1.2 HTTP GET request.&amp;nbsp; Another clue.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I tossed the pcap file I got from Anubis into &lt;a href="http://www.netresec.com/?page=NetworkMiner"&gt;NETRESEC NetworkMiner&lt;/a&gt;.  Nothing very interesting but my Microsoft Security Essentials alerted  when the HTML page was reassembled by NetworkMiner and quarantined the  file. It identified the page code as being &lt;a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Exploit%3AJS%2FBlacole.AR&amp;amp;ThreatID=-2147314153"&gt;Exploit:JS/Blacole.AR&lt;/a&gt;. (MS’s way of saying “blackhole” I suppose…)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Here  are a series of links regarding these kinds of email spam threats in  general as well as Blackhole info in particular as it relates with email  spam campaigns, if you are curious.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://labs.m86security.com/2011/12/prevalent-exploit-kits-updated-with-a-new-java-exploit/"&gt;Prevalent Exploit Kits Updated with a New Java Exploit&lt;/a&gt; - M86 Security Labs Blog  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://labs.m86security.com/2011/09/an-analysis-of-the-ach-spam-campaign/"&gt;An analysis of the ACH spam campaign&lt;/a&gt; - M86 Security Labs Blog  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://labs.m86security.com/2011/12/cutwail-spam-campaigns-lure-users-to-blackhole-exploit-kit/"&gt;Cutwail Spam Campaigns Lure Users to Blackhole Exploit Kit&lt;/a&gt; - M86 Security Labs Blog  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://labs.m86security.com/2011/10/steve-jobs-alive-spam-campaign-leads-to-exploit-page/"&gt;“Steve Jobs Alive!” Spam Campaign Leads To Exploit Page&lt;/a&gt; - M86 Security Labs Blog  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://labs.m86security.com/tag/malicious-spam/"&gt;All Posts tagged Malicious Spam&lt;/a&gt; - M86 Security Labs Blog  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.itsecuresite.com/seclabs/websense/malicious-email-scam-re-scan-from-a-xerox-w-pro-xxxxxxx-returns-with-a-new-face.html"&gt;Malicious email scam "Re: Scan from a Xerox W. Pro #XXXXXXX" returns with a new face&lt;/a&gt; - IT Secure Site more on a related Blackhole email spam attempt.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://research.zscaler.com/2011/02/blackhole-exploits-kit-attack-growing.html"&gt;Blackhole exploits kit attack growing&lt;/a&gt; - Zscaler Research  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.reversecurity.com/2011/12/exploit-kit-email-investigating.html"&gt;Exploit Kit in my Morning Email (BlackHole Exploit Kit . . . Maybe)&lt;/a&gt; - ReverSecurity&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I doubt this is the last our email inbox will see of these things, but the whole process has been quite fun to follow.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I’ve  decided to leave out links/images of the actual email and the  header-code/URL (short/long) but have passed it along to a number of  security-spam websites in case it is of use.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;A long time ago I  had a list of URL-testing sites to feed a URL into to see if they were  safe or not.&amp;nbsp; Most seem to have gone away, however the following forums  had a number of new ones worth bookmarking. Hat tip to “PROROOTECT” for  the legwork!&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://malwaretips.com/Thread-Free-Online-On-demand-URL-Security-Scanners"&gt;Free Online On-demand URL Security Scanners&lt;/a&gt; - MalwareTips forum  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://forum.sysinternals.com/free-Online-security-scans-for-suspicious-url-link_topic22045.html"&gt;FREE ONLINE SECURITY SCANS For Suspicious URL Link&lt;/a&gt; - Sysinternals Forums&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Here  is a combined and cleaned up list based on the collective work there  from PROROOTECT in both places and at least one or two I’m tossing in  and a few from those lists I removed that seem dead/redirected  incorrectly.&amp;nbsp; PROROOTECT does make a great point that the effectiveness  of these vary, so a “bad” URL in one may come back as “clean” in  another. So it’s best to run your URL through multiple sources.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Note,  these are URL/web-page scanners. They are a bit different than on-line  file-scanners/sandboxes used to analyze malware samples. Though a few  seem to come pretty darn close with the depth of their reports/analysis.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Not “necessarily” ordered in order of usefulness.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ip-address.org/"&gt;IP Address Locator&lt;/a&gt; - Track IP, Search IP, Find IP, Trace IP Lookup, What Is My IP Address Location  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.trueurl.net/service/"&gt;TrueURL&lt;/a&gt; - decode short URLs  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cekpr.com/decode-short-url/"&gt;Decode Short URL Decoder - cekPR.com&lt;/a&gt; - decode short URLs  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://tinyurl.com/preview.php"&gt;TinyURL.com&lt;/a&gt; - preview a TinyURL  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://longurl.org/"&gt;LongURL&lt;/a&gt; - decode short URLs  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://untiny.com/"&gt;Untiny&lt;/a&gt; - decode short URLs  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://webnet77.com/cgi-bin/helpers/base-64.pl"&gt;base64 online encoder / decoder&lt;/a&gt; - decode base 64 code in emails  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.quttera.com/"&gt;Quttera&lt;/a&gt; - FREE Online Heuristic URL Scanner  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=1afb6ac9f757382648d33ba6ab317fcb9"&gt;Anubis&lt;/a&gt; - Analyzing Unknown Binaries  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://vurldissect.co.uk/"&gt;vURL Online&lt;/a&gt; - Quickly and safely dissect malicious or suspect websites  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://web-sniffer.net/"&gt;HTTP Web-Sniffer 1.0.37&lt;/a&gt; - view HTTP request/response headers  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://wepawet.iseclab.org/"&gt;Wepawet &lt;/a&gt;- analyzes URLs for javascript/PDF or Flash exploits.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.finjan.com/ngus/default.aspx"&gt;Finjan URL Analysis&lt;/a&gt; - URL analysis  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt; - Free Online Virus, Malware and URL Scanner  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://urlvir.com/search/"&gt;UrlVir.com&lt;/a&gt; - URL scanner using domain, IP or MD5 hash value. Hosted by NoVirusThanks  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.surbl.org/surbl-analysis"&gt;SURBL Blacklist lookup&lt;/a&gt; - check database for known websites that have appeared in unsolicited (spam) emails. More on the program here: &lt;a href="http://www.surbl.org/"&gt;SURBL&lt;/a&gt;&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.urlvoid.com/"&gt;URLVoid.com BETA&lt;/a&gt; - scan website for malware, threats and other bad things.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://vscan.urlvoid.com/"&gt;URL &amp;amp; Link Scanner - Scan URLs for malicious code&lt;/a&gt; - URLVoid.com BETA to scan URL with multiple AV engines.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://wave.webaim.org/"&gt;WAVE&lt;/a&gt;  - Web Accessibility Evaluation Tool - may not tell you if a site is  “malicious” but provides a visual report on the site as well as any  funky coding going on.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://siteinspector.comodo.com/"&gt;Comodo Site Inspector&lt;/a&gt; - scan page to see if it generates malicious activity or hosts malware.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.unmaskparasites.com/"&gt;Website Security Check&lt;/a&gt; - Unmask Parasites. Scans site for evidence of exploit code.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://safeweb.norton.com/"&gt;Norton Safe Web, from Symantec&lt;/a&gt; - is a site safe?  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://vms.drweb.com/online/?lng=en"&gt;Dr.Web&lt;/a&gt; - is a site safe?  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://global.sitesafety.trendmicro.com/"&gt;Trend Micro Site Safety Center&lt;/a&gt; - is a site safe?  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://linkscanner.explabs.com/linkscanner/AVG/default.aspx"&gt;AVG LinkScanner Online&lt;/a&gt;- is a site safe?  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://browsingprotection.f-secure.com/swp/?x=pA5UCNjtCqgJSX12LHExug"&gt;F-Secure Browsing Protection Portal&lt;/a&gt; - Can you trust a site?  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.avg.com.au/resources/web-page-scanner/"&gt;AVG Online Virus Scanner | Scan Web Pages | AVG LinkScanner Drop Zone&lt;/a&gt; - Can you trust a site? (Aussie edition)  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://onlinelinkscan.com/"&gt;Online Link Scan&lt;/a&gt; - Virus, Trojan, Adware and Malware Scanner using a variety of scanning engines.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.phishtank.com/"&gt;PhishTank&lt;/a&gt; - site to report suspicious/phishing URL sites.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.checkpageforshit.com/"&gt;Check page for sh*t&lt;/a&gt; - resources including a URL check in Google spyware checker.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;PROROOTECT’s  suggestion to use an online URL screenshotting service to capture the  displayed URL safely is some good outside the box thinking. Kinda a  “look-before-you-leap” thing if all the above items pass OK.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.shotbot.fr/index.en.php"&gt;Shotbot - Screenshot Bot | Ascreen Generator&lt;/a&gt; - generates jpeg thumbnails of public websites.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://netrenderer.com/"&gt;IE NetRenderer - Browser Compatibility Check -&lt;/a&gt;  I like this one in that you can pick your browser version from a  selection. If the URL/page responds differently based on your browser,  then this might show it.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.thumbalizr.com/index.php"&gt;thumbalizr&lt;/a&gt; - thumb your webpages  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://url2png.com/"&gt;url2png&lt;/a&gt; - website screenshot service  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://loads.in/"&gt;loads.in&lt;/a&gt; - webpage load screenshots in multiple browser with option to pick from from over 50 locations worldwide  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.shrinktheweb.com/"&gt;ShrinkTheWeb&lt;/a&gt; - website screenshot service  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://browsershots.org/"&gt;Browsershots&lt;/a&gt;  - supports/mimics so many different browser types and OS’s and allows  defining Javascript/java/flash versions that it’s just plain coolly  obscene!&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Fun trip if it wasn’t so serious…&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;--Claus V.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;&lt;span style="color: #c0504d;"&gt;Update:&lt;/span&gt;&lt;/strong&gt; I meant to add this in to the original post but got sidetracked. A recent &lt;a href="http://computer-forensics.sans.org/blog/2012/01/19/digital-forensics-case-leads-refs-ex01-and-dfironline"&gt;Digital Forensics Case Leads&lt;/a&gt;  post has mention of a super-fantastic investigation/forensic report  involving anonymous emails. This is must-read material, not just in  terms of the investigative methodology but also the way the report was  composed and presented. Very clearly done!&amp;nbsp; I’m keeping a saved copy of  the report for future reference; both technically and as a report  template. From the post via the link above:&lt;/span&gt;&lt;/div&gt;&lt;blockquote style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;span style="font-size: small;"&gt;University of Illinois recently released a detailed &lt;a href="http://www.uillinois.edu/our/news/2012/emails/FinalReport.only.Jan13.pdf"&gt;investigation report&lt;/a&gt;  (PDF) regarding anonymous emails allegedly sent by its Chief of Staff  to the University's Senates Conference. The report is an interesting  read, and also serves as a potentially useful model for those looking  for report samples and templates.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;轉自 http://grandstreamdreams.blogspot.com/2012/01/interesting-malware-in-email-attempt.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-8992124429932789821?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/8992124429932789821/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=8992124429932789821&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8992124429932789821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8992124429932789821'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/interesting-malware-in-email-attempt.html' title='Interesting Malware in Email Attempt - URL Scanner Links'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/-jWSVoMZdJ_Y/Txt1MSg4NbI/AAAAAAAAA8Y/bj2aNmeq4Aw/s72-c/h0j5wpnx.2up_thumb%25255B1%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-729003842686333086</id><published>2012-02-07T20:55:00.000+08:00</published><updated>2012-02-07T20:55:00.410+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Ripping Volume Shadow Copies – Introduction</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Windows XP is the  operating system I mostly encounter during my digital forensic work.  Over the past year I’ve been seeing more and more systems running  Windows 7. 2011 brought with it my first few cases where the corporate  systems I examined (at my day job) were all running Windows 7. There was  even a more drastic change for the home users I assisted with cleaning  malware infections because towards the end of the year all my cases  involved Windows 7 systems. I foresee Windows XP slowly becoming a relic  as the corporate environments I face start upgrading the clients on  their networks to Windows 7. One artifact that will be encountered more  frequently in Windows 7 is Volume Shadow Copies (VSCs). VSCs can be a  potential gold mine but for them to be useful one must know how to  access and parse the data inside them. The Ripping Volume Shadow Copies  series is discussing another approach on how to examine VSCs and the  data they contain.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What Are Volume Shadow Copies&lt;/strong&gt;&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;VSCs are not new to Windows 7 and have actually&lt;a href="http://technet.microsoft.com/en-us/library/ee923636%28WS.10%29.aspx"&gt; been around since Windows Server 2003&lt;/a&gt;.  Others in the DFIR community have published a wealth of information on  what VSCs are, their forensic significance, and approaches to examine  them. I’m only providing a quick explanation since Troy Larson’s &lt;a href="http://computer-forensics.sans.org/summit-archives/2010/files/12-larson-windows7-foreniscs.pdf"&gt;presentation slides&lt;/a&gt; provide an excellent overview about what VSCs are as well as&amp;nbsp;Lee Whitfield’s&lt;a href="http://www.forensic4cast.com/2010/04/into-the-shadows/"&gt; Into the Shadows&lt;/a&gt;  blog post. Basically, the Volume Shadow Copy Service (VSS) can backup  data on a Windows system. VSS monitors a volume for any changes to the  data stored on it and will create backups only containing those changes.  These backups are referred to as a shadow copies. According to  Microsoft, the following activities will create shadow copies on Windows  7 and Vista systems:&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Manually (Vista &amp;amp; 7)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Every 24 Hours (Vista)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Every 7 Days (7)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Before a Windows Update (Vista &amp;amp; 7)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &amp;nbsp;Unsigned Driver Installation (Vista &amp;amp; 7)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &amp;nbsp;A program that calls the Snapshot API (Vista &amp;amp; 7)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Importance of VSCs&lt;/strong&gt;&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;The data inside VSCs may  have a significant impact on an examination for a couple of reasons.  The obvious benefit is the ability to recover files that may have been  deleted or encrypted on the system. This ringed true for me on the few  cases involving corporate systems; if it wasn’t for VSCs then I wouldn’t  have been able to recover the data of interest. The second and possibly  even more significant is the ability to see how systems and/or files  evolved over time. I briefly touched on this in the post &lt;a href="http://journeyintoir.blogspot.com/2011/12/ripping-volume-shadow-copies-sneak-peek.html"&gt;Ripping Volume Shadow Copies Sneak Peek&lt;/a&gt;.  I mentioned how parsing the configuration information helped me know  what file types to search for based on the installed software. Another  example was how the user account information helped me verify a user  account existed on the system and narrow down the timeframe when it was  deleted. A system’s configuration information is just the beginning;  documents, user activity, and programs launched are all great candidates  to see how they changed over time.&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;To illustrate I’ll use a  document as an example. When a document is located on a system without  VSCs - for the most part - the only data that can be viewed in the  document is what is currently there. Previous data inside the document  might be able to be recovered from copies of the document or temporary  files but won’t completely show how the document changed over time. To  see how the document evolved would require trying to recover it at  different points in time from system backups (if they were available).  Now take that same document located on a system with VSCs. The document  can be recovered from every VSC and each one can be examined to see its  data. The data will only be what was inside the document when each VSC  was created but it could cover a time period of weeks to months.  Examining each document from the VSCs will&amp;nbsp;shed light on how the  document evolved. Another possibility is the potential to recover data  that was in the document at some point in the past but isn't in the  document that was located on the system. If system backups were  available then they could provide additional information since more  copies of the document could be obtained at other points in time.&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Accessing VSCs&lt;/strong&gt;&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;The Ripping Volume  Shadow Copies approach works against mounted volumes. This means a  forensic image or hard drive has to be mounted to a Windows system  (Vista or 7) in order for the VSCs in the target volume to be ripped.  There are different ways to see a hard drive or image’s VSCs and I  highlighted some options:&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Mount the hard drive by installing it inside a workstation (option will alter data on the hard drive)&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Mount the hard drive by using an external hard drive enclosure (option will alter data on the hard drive)&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Mount the hard drive by using a hardware writeblocker&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &amp;nbsp;Mount the forensic image using Harlan Carvey’s method documented &lt;a href="http://windowsir.blogspot.com/2011/01/accessing-volume-shadow-copies.html"&gt;here&lt;/a&gt;, &lt;a href="http://windowsir.blogspot.com/2011/09/howto-mount-and-access-vscs.html"&gt;here&lt;/a&gt;, and the slide deck referenced &lt;a href="http://windowsir.blogspot.com/2011/12/meetup.html"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp; Mount the forensic image  using Guidance Software’s Encase with the PDE module (option is well  documented in the QCCIS white paper &lt;a href="http://www.qccis.com/downloads/whitepapers/QCC%20VSS%20Whitepaper.pdf"&gt;Reliably recovering evidential data from Volume Shadow Copies&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Regardless of the option used to mount the hard drive or image, the Windows &lt;a href="http://technet.microsoft.com/en-us/library/cc754968%28WS.10%29.aspx"&gt;vssadmin command&lt;/a&gt; or &lt;a href="http://www.shadowexplorer.com/"&gt;Shadow Explorer&lt;/a&gt;  program can show what if VSCs are available for a given mounted volume.  The pictures below show the Shadow Explorer program and vssadmin  command displaying the some VSCs for the mounted volume with drive  letter C.&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-wxn4E8XDVp4/TyYMWDITnEI/AAAAAAAAAdM/c6hK299WvP0/s1600/shadowexplorer.jpg" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="362" src="http://3.bp.blogspot.com/-wxn4E8XDVp4/TyYMWDITnEI/AAAAAAAAAdM/c6hK299WvP0/s640/shadowexplorer.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Shadow Explorer Displaying C Volume VSCs&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-Zs1UF8xgDPE/TyYMiOpjrCI/AAAAAAAAAdU/F52--ybAD88/s1600/vssadmin+vscs.jpg" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="248" src="http://4.bp.blogspot.com/-Zs1UF8xgDPE/TyYMiOpjrCI/AAAAAAAAAdU/F52--ybAD88/s640/vssadmin+vscs.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;VSSAdmin Displaying C Volume VSCs&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Picking VSCs to examine  is dependent on the examination goals and what data is needed to  accomplish those goals. However, time will be a major consideration.  Does the examination need to review an event, document, or user activity  for specific times or for all available times on a computer? Answering  that question will help determine if certain VSCs covering specific  times are picked or if every available VSCs should be examined. Once the  VSCs are selected then they can be examined to extract the information  of interest.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Another Approach to Examine VSCs&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;Before discussing  another approach to examining VSCs it’s appropriate to reflect on the  approaches practitioners are currently using. The first approach is to  forensically image each VSC and then examine the data inside each image.  Troy’s slide deck referenced earlier has a slide showing how to image a  VSC and Richard Drinkwater's&lt;a href="http://forensicsfromthesausagefactory.blogspot.com/2010/02/volume-shadow-copy-forensics-cannot-see.html"&gt; Volume Shadow Copy Forensics post&lt;/a&gt;  from a few years ago shows imaging VSCs as well. The second popular  approach doesn’t use imaging since it copies data from each VSC followed  by examining that data. The QCCIS white paper referenced earlier  outlines this approach using the robocopy program as well as Richard  Drinkwater in his posts &lt;a href="http://forensicsfromthesausagefactory.blogspot.com/2010/04/volume-shadow-copy-forensics-robocopy.html"&gt;here&lt;/a&gt; and &lt;a href="http://forensicsfromthesausagefactory.blogspot.com/2010/04/volume-shadow-copy-forensics-robocopy_13.html"&gt;here&lt;/a&gt;.  Both approaches are feasible for examining VSCs but another approach is  to examine the data directly inside VSCs bypassing the need for imaging  and copying. The Ripping VSCs approach examines data directly inside  VSCs and the two different methods to implement the approach are:  Practitioner Method and Developer Method.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ripping VSCs: Practitioner Method&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;The Practitioner Method  uses ones existing tools to parse data inside VSCs. This means someone  doesn’t have to learn a new tool or learn a programming language to  write their own tools. All that’s required is for the tool to be command  line and the practitioner willingness to execute the tool multiple  times against the same data. The picture below shows how the  Practitioner Method works.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-G--fAfA-sBI/TyYNPpIunTI/AAAAAAAAAdc/xpr0kOx2AH4/s1600/pract+method+imagewith+arrows.jpg" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="448" src="http://4.bp.blogspot.com/-G--fAfA-sBI/TyYNPpIunTI/AAAAAAAAAdc/xpr0kOx2AH4/s640/pract+method+imagewith+arrows.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Practitioner Method Process&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Troy Larson demonstrated how a symbolic link can be used to provide access to VSCs. The &lt;a href="http://technet.microsoft.com/en-us/library/cc753194%28WS.10%29.aspx"&gt;mklink command&lt;/a&gt;  can create a symbolic link to a VSC which then provides access to the  data stored in the VSC. The Practitioner Method uses the access provided  by the symbolic link to execute one’s tools directly against the data.  The picture above illustrates a tool executing against the data inside  Volume Shadow Copy 19 by traversing through a symbolic link. One could  quickly determine the differences between VSCs, parse registry keys in  VSCs, examine the same document at different points in time, or track a  user’s activity to see what files were accessed. Examining VSCs can  become tedious when one has to run the same command against multiple  symbolic links to VSCs; this is especially true when dealing with 10,  20, or 30 VSCs. A more efficient and faster way is to use&lt;a href="http://journeyintoir.blogspot.com/2011/08/batch-scripting-references.html"&gt; batch scripting&lt;/a&gt;  to automate the process. Only a basic understanding about batch  scripting (need to know how a For loop works) can create powerful tools  to examine VSCs. In future posts I’ll cover how simple batch scripts can  be leverage to rip data from any VSCs within seconds.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ripping VSCs: Developer Method&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;I’ve been using the  Practitioner Method for some time now against VSCs on live systems and  forensic images. The method has enabled me to see data in different ways  which was vital for some of my work involving Windows 7 systems.  Recently I figured out a more efficient way to examine data inside VSCs.  The Developer Method can examine data inside VSCs directly which  bypasses the need to go through a symbolic link. The picture below shows  how the Developer Method works.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-s_XYhIgcveY/TyYNr_McSCI/AAAAAAAAAdk/MkdrmlzddwA/s1600/developer+method+image+with+arrows.jpg" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="452" src="http://3.bp.blogspot.com/-s_XYhIgcveY/TyYNr_McSCI/AAAAAAAAAdk/MkdrmlzddwA/s640/developer+method+image+with+arrows.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;Developer Method Process&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;The Developer Method  programmatically accesses the data directly inside of VSCs. The majority  of existing tools cannot do this natively so one must modify existing  tools or develop their own. I used the Perl programming language to  demonstrate that the Developer Method for ripping VSCs is possible. I  created simple Perl scripts to read files inside a VSC and I modified  Harlan’s lslnk.pl to parse Windows shortcut files inside a VSC. Unlike  the Practitioner Method, at the time of this post I have not extensively  tested the Developer Method. I’m not only discussing the Developer  Method for completeness when explaining the Ripping VSCs approach but my  hope is by releasing my research early it can help spur the development  of DFIR tools for examining VSCs.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What’s Up Next?&lt;/strong&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;Volume Shadow Copies  have been a gold mine for me on the couple corporate cases where they  were available. The VSCs enabled me to successfully process the cases  and that experience is what pushed me towards a different approach to  examining VSCs. This approach was to parse the data while it is still  stored inside the VSCs. I’m not the only DFIR practitioner looking at  examining VSCs in this manner. Stacey Edwards shared in her post &lt;a href="http://computer-forensics.sans.org/blog/2011/06/09/vscs-logparser"&gt;Volume Shadow Copies and LogParser&lt;/a&gt; how she runs the program logparser against VSCs by traversing through a symbolic link. Rob Lee shared his work on&lt;a href="http://computer-forensics.sans.org/blog/2011/09/16/shadow-timelines-and-other-shadowvolumecopy-digital-forensics-techniques-with-the-sleuthkit-on-windows"&gt; Shadow Timelines&lt;/a&gt;  where he creates timelines and lists deleted files in VSCs by executing  the Sleuthkit directly against VSCs. Accessing VSCs’ data directly can  reduce examination time while enabling a DFIR practitioner to see data  temporally. Ripping Volume Shadow Copies is a six part series and the  remaining five posts will explain the Practitioner and Developer methods  in-depth.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 1: Ripping Volume Shadow Copies - Introduction&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 2: Ripping VSCs - Practitioner Method&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 3: Ripping VSCs - Practitioner Examples&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 4: Ripping VSCs - Developer Method&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 5: Ripping VSCs - Developer Example&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Part 6: Examing VSCs with GUI Tools&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;轉自 http://journeyintoir.blogspot.com/2012/01/ripping-volume-shadow-copies.html &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-729003842686333086?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/729003842686333086/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=729003842686333086&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/729003842686333086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/729003842686333086'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/ripping-volume-shadow-copies.html' title='Ripping Volume Shadow Copies – Introduction'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-wxn4E8XDVp4/TyYMWDITnEI/AAAAAAAAAdM/c6hK299WvP0/s72-c/shadowexplorer.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-1243012337585355614</id><published>2012-02-04T20:31:00.001+08:00</published><updated>2012-02-04T20:31:00.302+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>base64 Encode / Decode</title><content type='html'>&lt;a href="http://webnet77.com/cgi-bin/helpers/base-64.pl"&gt;http://webnet77.com/cgi-bin/helpers/base-64.pl&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-1243012337585355614?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/1243012337585355614/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=1243012337585355614&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1243012337585355614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1243012337585355614'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/base64-encode-decode.html' title='base64 Encode / Decode'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-135650654119208053</id><published>2012-02-03T20:26:00.000+08:00</published><updated>2012-02-03T20:26:00.665+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Internet Explorer RecoveryStore(Travelog) 解析工具</title><content type='html'>&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;RecoverRS&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;    &lt;span style="font-size: small;"&gt;    Based on the research in to Internet Explorer’s Automatic Crash     Recovery files, two command line applications were created; RipRS     and ParseRS; collectively known as RecoverRS.&lt;span&gt;&amp;nbsp;    &lt;/span&gt;Detailed information regarding the operation of these two     applications is available in Appendix C, the RecoverRS manual.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;    &lt;span style="font-size: small;"&gt;    RipRS is designed to extract ACR files from a raw disk image using     known decimal offsets.&lt;span&gt;&amp;nbsp; &lt;/span&gt;A     list of known offsets can be obtained by using the search string     discussed in the above section titled ‘Finding Compound Files in     Unallocated Space’ using programs such as EnCase or FTK.&lt;span&gt;&amp;nbsp;    &lt;/span&gt;Using these known offsets, RipRS uses the methodology     discussed in the above section titled ‘Carving Compound Files in     Unallocated Space’ to determine the compound file’s size.&lt;span&gt;&amp;nbsp;    &lt;/span&gt;RipRS then searches the compound file for the string     ‘0B00252A-8D48-4D0B-7B79887F2B96’, a GUID that is unique to ACR     files.&lt;span&gt;&amp;nbsp; &lt;/span&gt;If RipRS     determines that the compound file is in fact an ACR file, it     searches the ACR file for strings unique to either recovery store     files or tab data files to determine which type the file it.&lt;span&gt;&amp;nbsp;    &lt;/span&gt;Once RipRS has determined the ACR file type, the file is     written to the output directory specified by the user using the     naming convention RecoveryStore.{offset&lt;offset&gt;}.dat or     {offset&lt;offset&gt;}.dat for recovery store files and tab data files     respectively.&lt;span&gt;&amp;nbsp; &lt;/span&gt;    &lt;/offset&gt;&lt;/offset&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;    &lt;span style="font-size: small;"&gt;    ParseRS is designed to extract browsing information from ACR files;     either those found on the system or those carved from unallocated     space by RipRS.&lt;span&gt;&amp;nbsp; &lt;/span&gt;As     mentioned previously, if ACR files are carved from unallocated     space, information linking the tab data files with their respective     recovery store files and some date/time information will be lost.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &amp;nbsp;&lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.jtmoran.com/files/Setup.msi"&gt;Download RecoverRS&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.jtmoran.com/files/RecoverRS.pdf"&gt;Download RecoverRS Manual&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.jtmoran.com/tools/default.html &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-135650654119208053?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/135650654119208053/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=135650654119208053&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/135650654119208053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/135650654119208053'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/internet-explorer-recoverystoretravelog_03.html' title='Internet Explorer RecoveryStore(Travelog) 解析工具'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-6447803836123426793</id><published>2012-02-01T20:19:00.000+08:00</published><updated>2012-02-01T20:19:00.892+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>解析Internet Explorer RecoveryStore(Travelog)</title><content type='html'>&lt;h3 class="post-title entry-title" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; Internet Explorer RecoveryStore (aka Travelog) as evidence of Internet Browsing activity &lt;/span&gt;&lt;/h3&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="post-header" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;  &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt; &lt;div dir="ltr" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: left;"&gt; &lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;This artifact has attracted my attention of late as I have seen some very useful information here in a few recent cases. Here you find not only browsed urls but webpage details like title (sometimes content) and timestamps. Even data from encrypted pages (https) are stored here in plaintext, which by default IE does not save in internet cache. I have even seen email and facebook passwords here on occasion!&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;What is RecoveryStore and why is it present?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;IE 8 and 9 have a tab recovery feature by virtue of which you can restore all your tabbed browsing sessions if IE crashes, or when you close IE and chose to save tabs on exit (so that they may be reopened automatically when IE is started next time). &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-6vWCV4qlDtQ/ToSvgUoaaOI/AAAAAAAAAAQ/are7oZYARiA/s1600/IE+restore+last+session.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-6vWCV4qlDtQ/ToSvgUoaaOI/AAAAAAAAAAQ/are7oZYARiA/s1600/IE+restore+last+session.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;With IE8, Microsoft also introduced the concept of a ‘Travelog’. This is a mechanism to track urls (and associated parameters) that are fetched from a page when AJAX is used. AJAX is a technology which enables dynamic refreshes of small portions of a page without reloading the whole page. It was popularized by gmail and subsequently most webpages use it today. With AJAX, your main page url does not change, however the page contents change when your click around in the page (accessing data from other urls), this creates problems as you cannot use the browser back button to go back one click. To solve this problem (with back and forward buttons), the travelog is used to track AJAX urls. Read up more about it on MDSN &lt;a href="http://msdn.microsoft.com/en-us/library/cc891506%28v=vs.85%29.aspx"&gt;here&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;So where is this cached information?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;The RecoveryStore can be found under &lt;profile&gt;/Application Data on an XP machine and under &lt;profile&gt;/AppData/Local on a Vista or Windows 7 machine under subfolder Microsoft/Internet Explorer/Recovery&lt;/profile&gt;&lt;/profile&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;  &lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-94vFJBFR_I0/ToSxWxVULGI/AAAAAAAAAAU/BVP2bNVdxjE/s1600/rs+location.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="249" src="http://4.bp.blogspot.com/-94vFJBFR_I0/ToSxWxVULGI/AAAAAAAAAAU/BVP2bNVdxjE/s400/rs+location.png" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;Location of RecoveryStore files on a Windows 7 Machine&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Two folders are present by default, Active and LastActive. Sometimes a couple of other folders are seen, High and Low. All folders contain similar data, a few files with &lt;guid&gt;.dat as their name and a single RecoveryStore.&lt;guid&gt;.dat file per folder. GUIDs are in the standard format {xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}.&lt;/guid&gt;&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;Analysis of RecoveryStore files Part I&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;All files are in the Microsoft OLE structured storage container format. When opened with a suitable viewer (many freeware available for this, if you use encase, use ‘view file structure’ to mount), you find many streams (files) within it.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;There is a single RecoveryStore.&lt;guid&gt;.dat file which represents the recovery store preserving tab order and some other information. It references the other &lt;guid&gt;.dat files.&lt;/guid&gt;&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;RecoveryStore.&lt;guid&gt;.dat &lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;This file contains 3 or more streams in it. If more than one session (instances of IE) are running, then more streams will be present. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border-style: none; text-align: justify;"&gt;&lt;tbody&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 153.9pt;" valign="top" width="205"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Stream Name&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 324.9pt;" valign="top" width="433"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Description &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 153.9pt;" valign="top" width="205"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;|KjjaqfajN2c0uzgv1l4qy5nfWe&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 324.9pt;" valign="top" width="433"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Contains some guids&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 153.9pt;" valign="top" width="205"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;FrameList&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 324.9pt;" valign="top" width="433"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;List of DWORDs, function unknown &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 153.9pt;" valign="top" width="205"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;TSxx&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 324.9pt;" valign="top" width="433"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Contains guids of Tabs in Session x (ie,if TS1 then tabs in   session 1)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-3WRMCul-fUI/ToS12xgE9jI/AAAAAAAAAAY/9dmpyM0bFzc/s1600/rs+hex.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="230" src="http://2.bp.blogspot.com/-3WRMCul-fUI/ToS12xgE9jI/AAAAAAAAAAY/9dmpyM0bFzc/s400/rs+hex.png" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;RecoveryStore.&lt;guid&gt;.dat file viewed in an OLE object viewer&lt;br /&gt;The FrameList stream is shown above&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;&lt;guid&gt; in the filename&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;The GUID is actually a UUID (version 1), which is comprised of a FILETIME like timestamp and the machine MAC address. The details of this scheme can be referenced from RFC 4122 (&lt;a href="http://www.ietf.org/rfc/rfc4122.txt"&gt;http://www.ietf.org/rfc/rfc4122.txt&lt;/a&gt;).&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;The timestamp is the first 60 bits of the UUID, and this represents the number of 100 second nanosecond intervals since 15 October 1582. Note the only major difference from Microsoft FILETIME values used everywhere else in windows is the starting date which is 01 January 1601 for FILETIME.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;This time is going to be the tab/recoverystore created time and can be used to cross check the timestamp on disk for forensic validation. These UUIDs are also found in the ‘|KjjaqfajN2c0uzgv1l4qy5nfWe’ stream in RecoveryStore.&lt;guid&gt;.dat&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;&lt;u&gt;Example&lt;/u&gt;: {FD1F46CF-E6AB-11E0-9FAC-001CC0CD46AA}.dat&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;From this UUID, we can extract the timestamp as 01E0E6ABFD1F46CF which decodes to 09/24/2011 12:51:58 UTC. &lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;The last 6 bytes is the MAC address on the machine (00 1C C0 CD 46 AA), it can be from any of the network interfaces on the machine.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: left;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;Timestamp Easy Conversion Process&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: left;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;(http://computerforensics.parsonage.co.uk/downloads/TheMeaningofLIFE.pdf)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;An easy way of converting the timestamp without messing too much with the math behind it is to subtract the time period between 15 October 1582 and 1 January 1601 and then using a FILETIME decoder program (like &lt;a href="http://www.digital-detective.co.uk/freetools/decode.asp"&gt;DCODE&lt;/a&gt;) to do the rest. For the above example, we subtract 146BF33E42C000 (the excess time period) from the original value to get 1CC7AB8BEDC86CF which is decoded as 09/24/2011 12:51:58 UTC. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;&lt;guid&gt;.dat files&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Each file represents a tab in the browser. Inside each file are 3 or more streams.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border-style: none; text-align: justify;"&gt;&lt;tbody&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 131.4pt;" valign="top" width="175"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Stream Name&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 347.4pt;" valign="top" width="463"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Description&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 131.4pt;" valign="top" width="175"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;|KjjaqfajN2c0uzgv1l4qy5nfWe&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 347.4pt;" valign="top" width="463"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Contains some guids and last URL of tab&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 131.4pt;" valign="top" width="175"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Travelog&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 347.4pt;" valign="top" width="463"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;List of DWORDs representing each Travelog entry&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 131.4pt;" valign="top" width="175"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;TLxx&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 347.4pt;" valign="top" width="463"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0in;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Travelog stream (TL0, TL1, …)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-AIOrz_ScsLs/ToS2qEEDIyI/AAAAAAAAAAg/1WG2OnbGmOk/s1600/guid.png" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="227" src="http://4.bp.blogspot.com/-AIOrz_ScsLs/ToS2qEEDIyI/AAAAAAAAAAg/1WG2OnbGmOk/s400/guid.png" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;'|KjjaqfajN2c0uzgv1l4qy5nfWe' stream inside a &lt;guid&gt;.dat file shown above&lt;/guid&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;Travelog Stream&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;This stream has a complex binary format which stores many items. The base URL, referrer url and page title are always present. Page content, some timestamps and ajax parameters are optionally present. &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;I have been studying the format of the Travelog and will shortly publish it as Part II of this blog entry.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;Update: An encase script is now available for download &lt;a href="http://www.swiftforensics.com/2011/12/travelog-parser-script.html"&gt;here&lt;/a&gt;&amp;nbsp;to parse out travelog info.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;轉自&lt;i&gt; http://www.swiftforensics.com/2011/09/internet-explorer-recoverystore-aka.html&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;  &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-6447803836123426793?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/6447803836123426793/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=6447803836123426793&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6447803836123426793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6447803836123426793'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/02/internet-explorer-recoverystoretravelog.html' title='解析Internet Explorer RecoveryStore(Travelog)'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-6vWCV4qlDtQ/ToSvgUoaaOI/AAAAAAAAAAQ/are7oZYARiA/s72-c/IE+restore+last+session.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-1585896080928467545</id><published>2012-01-29T20:50:00.001+08:00</published><updated>2012-01-29T20:50:00.076+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Free Wipies</title><content type='html'>New Year’s Eve is almost upon us.&amp;nbsp; Figured I close out 2011 with one final post.&lt;br /&gt;Out of a recent &lt;a href="http://tinyapps.org/blog/misc/201107170700_once_is_enough.html"&gt;TinyApps.org post on drive wiping&lt;/a&gt; I followed a white-rabbit and ended up on this &lt;a href="http://www.anti-forensics.com/disk-wiping-with-dcfldd"&gt;Disk Wiping with dcfldd&lt;/a&gt; at the Anti-Forensics blog.&lt;br /&gt;I’m  always on the lookout for tips and techniques when it comes to  secure-wiping drives and the post was full of great info regarding use  of the &lt;a href="http://dcfldd.sourceforge.net/"&gt;dcfldd&lt;/a&gt; tool.&lt;br /&gt;When  it comes to secure drive (whole-disk) wiping, I’ve still tended to rely  on two tools in particular for their ease-of-use and convenience.&lt;br /&gt;The first is Microsoft Windows DISKPART command &lt;a href="http://technet.microsoft.com/en-us/library/cc766465%28WS.10%29.aspx"&gt;“Clean all”&lt;/a&gt; which “specifies that each and every sector on the disk is zeroed, which completely deletes all data contained on the disk.”&lt;br /&gt;The  pro is that the command is very simple to remember and use, and when  coupled with a WinPE disk, is dead-simple to effectively wipe out most  all drives I encounter.&lt;br /&gt;The second one I love is the CLI tool “wipe.exe” as found in the &lt;a href="http://gmgsystemsinc.com/fau/"&gt;Forensic Acquisition Utilities&lt;/a&gt; set by George M. Garner.&lt;br /&gt;The  pro about this one is that it actually includes a progress indicator so  you have some degree of feedback on how far you’ve wiped.&lt;br /&gt;I always verify my zero-out wipes when done. For that I prefer to use the sector-viewer tool &lt;a href="http://mh-nexus.de/en/hxd/"&gt;HxD&lt;/a&gt; to scan through the post-wiped drive to ensure it all come up clean; &lt;a href="http://frhed.sourceforge.net/"&gt;Frhed - Free hex editor&lt;/a&gt; is another nice alternative.&lt;br /&gt;I  also keep a collection of secure file-wipe tools handy as well.&amp;nbsp; These  are useful for when I have a personal document with sensitive info that  is no longer needed, or at work where I have successfully recovered a  customer’s data from a seriously crashed drive and the files were  successfully restored; don’t need to keep those around on the workbench  PC.&lt;br /&gt;&lt;a href="http://portableapps.com/apps/utilities/eraserdrop_portable"&gt;EraserDrop Portable&lt;/a&gt;  - PortableApps.com is an easy to use and easy-to-configure tool I find  useful to manage large volumes of files/folders needing secure deletion.  It is based on &lt;a href="http://www.heidi.ie/eraser/"&gt;Eraser&lt;/a&gt;.&lt;br /&gt;&lt;a href="http://portableapps.com/apps/utilities/eraser_portable"&gt;Eraser Portable&lt;/a&gt;  - PortableApps.com - Portable software for USB, portable and cloud  drives is the portable version of that tool. It is very flexible and  powerful, though the interface and job/task “scheduling” might be  off-putting to less advanced users. Besides handing wiping of  files/folders, it also can wipe free-space on a drive.&lt;br /&gt;&lt;a href="http://www.gaijin.at/en/dlwipefile.php"&gt;WipeFile&lt;/a&gt;  over at Gaijin is a simple and basic file-wipe tool with lots of  options. Just launch, set your wipe-preferences, and drag-n-drop your  files for wiping.&amp;nbsp; See the related Gaijin tool &lt;a href="http://www.gaijin.at/en/dlwipedisk.php"&gt;WipeDisk&lt;/a&gt; as well.&lt;br /&gt;&lt;a href="http://www.fileshredder.org/"&gt;File Shredder&lt;/a&gt;  is a “new-to-me” secure-wipe tool. It is quite small and consists of  two files; the main exe and a dll helper.&amp;nbsp; The interface is nice and it  also includes wiping of free-space.&lt;br /&gt;&lt;a href="http://xtort.net/freeware/xtort-software/ultrashredder/"&gt;ultrashredder&lt;/a&gt; is even smaller. Basically just drag-n-drop. While you can set the number of over-writes, you can’t set the pattern.&lt;br /&gt;&lt;a href="http://www.paehl.de/cms/dpwipe"&gt;DPWipe 1.1&lt;/a&gt; by Dirk Paehl is similar to Ultrashredder in the GUI layout, however it does allow selection of the wipe method.&lt;br /&gt;&lt;a href="http://www.lassekolb.info/bfacs.htm"&gt;Blowfish Advanced CS&lt;/a&gt;.  This is an oldie-but-a-goodie which was the very first secure wipe  (file and freespace) tool I started using back in my Win98 days. It  probably has been passed on by other tools here but I still keep it  around for fond-memories.&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb897443"&gt;SDelete&lt;/a&gt;  is Microsoft Sysinternal’s CLI tool to wipe files as well as zero-out  free-space.&amp;nbsp; I like it particularly well for that second task.&lt;br /&gt;&lt;a href="http://www.cezeo.com/products/disk-redactor/"&gt;Disk Redactor&lt;/a&gt; also handles wiping of all free space on a drive very nicely with a helpful GUI interface.&lt;br /&gt;These  are all specialized secure-wipe tools and are pretty easy and  convenient to use; a few even have options to integrate into the Windows  context-menu shell.&amp;nbsp; However if you frequently use an alternative  Windows file manager (like I prefer to do), there are more than one  which include a hand-dandy “secure-file-wipe” option baked right in!&lt;br /&gt;&lt;a href="http://www.freecommander.com/"&gt;FreeCommander&lt;/a&gt;  remains my #1 all-time favorite “multi-pass” tool for Windows file  management. it includes a secure wipe action that performs a multi-step  wipe of the selected item(s). You can set how many passes you want that  routine to run.&lt;br /&gt;&lt;a href="http://www.explorerplusplus.com/"&gt;Explorer++&lt;/a&gt; also includes a “destroy” option (1 or 3-pass choice) to secure delete selected files/folders.&lt;br /&gt;&lt;a href="http://www.alterion.us/a43/"&gt;A43&lt;/a&gt; likewise includes a basic secure-destroy option.&lt;br /&gt;&lt;a href="http://xiles.net/nexusfile/"&gt;NexusFile&lt;/a&gt; has a “shred and delete” feature.&lt;br /&gt;&lt;a href="http://myco.yonan.ro/"&gt;My Commander&lt;/a&gt; reminds me in many ways of FreeCommander, and it does have a secure delete action.&lt;br /&gt;Happy New Year!&lt;br /&gt;&lt;br /&gt;轉自 http://grandstreamdreams.blogspot.com/2011/12/free-wipies.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-1585896080928467545?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/1585896080928467545/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=1585896080928467545&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1585896080928467545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1585896080928467545'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/free-wipies.html' title='Free Wipies'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-2208642933931350651</id><published>2012-01-28T20:49:00.000+08:00</published><updated>2012-01-28T20:49:00.083+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Make a dual-boot WinPE CD</title><content type='html'>I’ve been in the workshop for the past several days hammering out a new WinPE product for our technical field-support team.&lt;br /&gt;You may recall from the GSD post &lt;a href="http://grandstreamdreams.blogspot.com/2011/11/winpe-building-and-pgp-support-links.html"&gt;WinPE Building and PGP Support Links Updated &lt;/a&gt;that  I have previously built a highly-customized PGP WDE injected WinPE boot  CD to allow our team to manually off-line boot, then authenticate into a  PGP v9.x encrypted hard-drive.&lt;br /&gt;Now we are rolling out systems  encrypting with PGP Desktop 10.x.&amp;nbsp; Unfortunately the v10 isn’t  backwards-compatible in supporting the v9 encrypted systems.&lt;br /&gt;So I  cleared off the workbench and using the techniques I have previously  outlined here, built a new customized WinPE boot disk that supports  PGP-WDE 10.x.&lt;br /&gt;Only there was one problem; we currently now have a  mixed PGP-WDE environment where some systems are running PGP Desktop  v9.x and others are running v10.x.&lt;br /&gt;I started to plan just having  the techs carry both WinPE boot disks with them.&amp;nbsp; But that seemed  silly.&amp;nbsp; The WIM files were both very small.&amp;nbsp; Too bad I couldn’t include  both BOOT.WIM files on the same CD as the rest of the CD structure was  identical.&lt;br /&gt;Or could I…..?&lt;br /&gt;I knew a suggestion Brett had  made earlier that with some BCD file editing on a customized WinPE  booting USB stick, that I could multi-boot different WinPE BOOT.WIM.&amp;nbsp; We  outlined that process in this GSD &lt;a href="http://grandstreamdreams.blogspot.com/2010/03/winpe-multi-boot-bootable-usb-storage.html"&gt;WinPE Multi-boot a Bootable USB Storage device &lt;/a&gt;post. I can tell you it works like a charm.&lt;br /&gt;But surely that doesn’t work for WinPE CDs. That’s crazy talk. Right?&lt;br /&gt;Nope. Works fine.&lt;br /&gt;David over at the “ITC Guy’s Doodles” blog has it all laid out, simple as can be (with screen-shots):&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://ict-doodles.biz.hr/2011/03/02/creating-winpe-multi-boot/"&gt;Creating WinPE multi-boot&lt;/a&gt; - ICT guy's doodles&lt;/li&gt;&lt;/ul&gt;David  and I are assuming here you already have the WAIK installed and are  long-past the steps regarding building a customized WinPE build or two.  If not, check out these GSD posts first for some background if needed:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2009/02/custom-win-pe-boot-disk-building-step.html"&gt;Custom Win PE Boot Disk Building: Step Four – Pulling it all together&lt;/a&gt; – GSD blog.  &lt;/li&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2009/03/custom-winpe-building-post-script-and.html"&gt;Custom WinPE Building: Post-Script and PE 3.0&lt;/a&gt; - GSD blog. &lt;/li&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2009/08/quickpost-bootable-usb-stick.html"&gt;QuickPost: Bootable USB Stick&lt;/a&gt; – GSD blog. &lt;/li&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2009/07/usb-tricks-for-vista-and-windows-7.html"&gt;USB Tricks for Vista and Windows 7&lt;/a&gt; – GSD blog.  &lt;/li&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2009/11/sexy-usb-boots-win-pe-style.html"&gt;Sexy USB Boots (Win PE style)&lt;/a&gt; – GSD blog.  &lt;/li&gt;&lt;li&gt;&lt;a href="http://grandstreamdreams.blogspot.com/2010/03/winpe-and-dismpeimg-to-boost-scratch.html"&gt;WinPE and DISM/PEimg to boost Scratch Space (Ram Disk)&lt;/a&gt; – GSD blog. &lt;/li&gt;&lt;/ul&gt;Once  you’ve done that and have your primary WinPE folder structure set as  well as your custom BOOT.WIM files ready you basically do this:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Launch your WAIK Deployment Tools Command Prompt (in Windows 7 I chose to run it elevated as Administrator).&lt;/li&gt;&lt;li&gt;Change  directories to your WinPE building folder (in my case it was  C:\winpe_x86 yours may differ adjust recipe accordingly for your WinPE  baking altitude).&lt;/li&gt;&lt;li&gt;Copy into the c:\winpe_x86\ISO\sources folder  the BOOT.WIM files you want to include. Note they will need to be named  different things. Your first/default booting wim can remain “boot.wim”  to keep things easy, but the 2nd (and each additional one if so desired)  should be named something more descriptive.&lt;/li&gt;&lt;li&gt;Next you will need to edit the BCD file for the booting build which is located in C:\winpe_x86\ISO\boot location.&lt;/li&gt;&lt;li&gt;&lt;a href="http://ict-doodles.biz.hr/2011/03/02/creating-winpe-multi-boot/"&gt;Follow David’s steps&lt;/a&gt;  to make a copy of the default boot entry item to a new second one with a  different boot guid. Then you need to “fix” some of the copied  sub-items to associate with the new guid value.&lt;/li&gt;&lt;li&gt;Finally, you can rename the default boot item description to something more meaningful.&lt;/li&gt;&lt;/ol&gt;Use  oscdimg to build the ISO file and when you boot it, you should now see  your different boot image options appear on the boot selection menu!&lt;br /&gt;Sweet!&lt;br /&gt;I’m&amp;nbsp;  not aware of any limitations to the number of different bootable wim  files you can have.&amp;nbsp; I suppose that’s mostly limited to the size of your  CD/DVD media (if not USB-booting) as well as the size of the custom WIM  files themselves.&lt;br /&gt;So for me, I now have one physical bootable CD  with two distinct WinPE boot choices…one for PGP v9 and one for PGP v10  support.&amp;nbsp; Locked and loaded now baby!&lt;br /&gt;In theory, if you weren’t  really comfortable with all this CLI work, you could use one of two GUI  based tools to edit the \winpe_x86\ISO\boot\BCD file.&lt;br /&gt;&lt;a href="http://neosmart.net/EasyBCD/"&gt;EasyBCD 2.1.2 - NeoSmart Technologies&lt;/a&gt; supports WinPE BCD files. There is also a &lt;a href="http://neosmart.net/forums/showthread.php?t=642"&gt;EasyBCD 2.2 Beta Build&lt;/a&gt; that may have additional support. Check out the forum as well as this &lt;a href="http://neosmart.net/forums/showthread.php?t=7234&amp;amp;highlight=WinPE"&gt;Multiboot WinPE CD - How to specify .WIM&lt;/a&gt; forum post for some tips.&lt;br /&gt;In  fact, somewhere between eating lunch, listening to a football game, and  trying to pay attention to a holiday story Lavie was telling me while I  was following David’s steps, my own “descriptions” work for the BCD  file got mixed up a bit and I wasn’t getting the custom boot  descriptions to appear as desired.&lt;br /&gt;I was able to quickly and easily use the &lt;a href="http://www.boyans.net/"&gt;Visual BCD Editor - Windows 7/Vista&lt;/a&gt;  to clean up the mess I made and get it all put right.&amp;nbsp; So if you knew  what you were doing, you could do it all from the GUI with this tool  rather than the CLI.&lt;br /&gt;Anyway, thanks to Bret for his original tip and for David for the game-walkthrough for making a multi-boot WinPE CD.&lt;br /&gt;&lt;br /&gt;轉自 http://grandstreamdreams.blogspot.com/2012/01/make-dual-boot-winpe-cd.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-2208642933931350651?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/2208642933931350651/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=2208642933931350651&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2208642933931350651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2208642933931350651'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/make-dual-boot-winpe-cd.html' title='Make a dual-boot WinPE CD'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-9118137764574395158</id><published>2012-01-27T20:38:00.000+08:00</published><updated>2012-01-27T20:38:00.042+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Wipies -- Addendum</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You may recall that both GSD posts on secure wiping -- &lt;a href="http://grandstreamdreams.blogspot.com/2011/12/free-wipies.html"&gt;Free Wipies &lt;/a&gt;and &lt;a href="http://grandstreamdreams.blogspot.com/2012/01/wipies-part-ii-full-coverage-cleaning.html"&gt;Wipies - Part II (Full Coverage Cleaning) &lt;/a&gt;-- were both inspired by a blog post by the &lt;a href="http://tinyapps.org/blog/"&gt;TinyApps.Org&lt;/a&gt; blogger.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Last  night I received a kind message from this dear friend pulling my  attention back to the deeper issue raised in that post, and while this  isn’t a completely unknown issue, it is one that can be easily  overlooked by the best of sysadmins in our zeal to “secure wipe the darn  thing” and get on with our other daily grinds.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The TinyApps how-to post &lt;a href="http://tinyapps.org/docs/wipe_drives_hdparm.html"&gt;ATA Secure Erase (SE) and hdparm&lt;/a&gt;  shares an added benefit for those who dare to tread that hard-drive  wiping technique through the “enhanced secure erase” option.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;(Very)  Basically the issue comes down to this: hard drives may have bad  sectors that have been found and so marked as well as additional “host  protected area (HPA)s” both of which can be skipped by many  “block-erase” wiping tools and utilities. The end result is the  possibility of recoverable data left behind in these areas if a standard  block-erase method is used.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Host_protected_area"&gt;Host protected area&lt;/a&gt; - Wikipedia, the free encyclopedia  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Device_configuration_overlay"&gt;Device configuration overlay&lt;/a&gt; - Wikipedia, the free encyclopedia&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So  even though you are diligently laying down your randomized data and/or  zeros to all the (accessible) sectors of the drive, the drive itself may  be actually hiding physical sectors from your software that will not  get overwritten no matter how hard you try.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;As TinyApps linked for me in the communication, even the almighty &lt;a href="http://www.dban.org/"&gt;Darik's Boot And Nuke&lt;/a&gt; clearly says in its FAQ that it must be used with knowledge to address some of these issues:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.dban.org/node/34"&gt;Does DBAN wipe remapped sectors?&lt;/a&gt; - Darik's Boot And Nuke&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;blockquote style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;span style="font-size: small;"&gt;&lt;strong&gt;Does DBAN wipe remapped sectors?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Use the ATA-6 wipe method if you want to wipe remapped sectors. Most methods do not wipe remapped sectors.&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.dban.org/node/35"&gt;Does DBAN wipe the Host Protected Area ("HPA")?&lt;/a&gt; - Darik's Boot And Nuke&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;blockquote style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;span style="font-size: small;"&gt;&lt;strong&gt;Does DBAN wipe the Host Protected Area ("HPA")?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;No. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Most  vendors that are using the HPA have a toggle for it in the BIOS setup  program. Future releases of DBAN may override or dishonor the HPA. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;Why not now and why not by default?&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Some vendors are using the HPA instead of providing rescue media. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;Wiping  the HPA would surprise and strand people that expect the HPA to have  rescue materials, and it often results in OEM technical support marking  and abandoning people that do it. The HPA is a low risk because it is  not accessible during normal operations. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;DBAN defaults are  chosen to best protect people with a minimal understanding of this kind  of problem. This point is still open for discussion in the help forum  and in the appropriate bug ticket.&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;That’s not to  say this information makes DBAN (or any of the others like it) a bad or  faulty tool, just one with some limitations (like most all other  block-erase wipe tools) that must be fully understood before deciding if  its methods are sufficient for the use at hand.  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;For example,  there are forensic drive access/capture tools that can detect these  areas and ensure the investigator is able to respond to them.&amp;nbsp; That’s  great news for the good guys and a warning that bad-guys can also take  advantage of this as well: &lt;a href="http://www.wiebetech.com/hpa_dco.php"&gt;HPA/DCO Detection - WiebeTech Forensic Docks&lt;/a&gt;&lt;/span&gt;  &lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Here (again) are links to two posts about the HPA/remapped sector issue with drive wiping well worth the read:  &lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://ultraparanoid.wordpress.com/2007/09/12/securely-erase-hard-drives/"&gt;Securely erase hard drives&lt;/a&gt; - ultraparanoid  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://ultraparanoid.wordpress.com/2007/06/20/can-god-create-a-rock-so-heavy-even-he-cant-lift-it/"&gt;Can God Create a Rock So Heavy Even He Can’t Lift It?&lt;/a&gt; - ultraparanoid&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I  suppose one good place to start is pre-inspecting your drive before you  get wiping to better understand what you are dealing with.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;There  are a few Windows-based tools that I am aware of that can let you look  at either/both HPA area(s) as well as DCO info (if they exist).&amp;nbsp; In most  cases, these do require specialized booting of the system either  directly with a true DOS disk or a Linux tool to access the drive  correctly.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://hddguru.com/software/2005.10.02-MHDD/"&gt;MHDD&lt;/a&gt; - HDDGuru&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.hdat2.com/"&gt;HDAT2/CBL Hard Disk Repair Utility&lt;/a&gt; - Lubomir Cabla&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cgsecurity.org/wiki/TestDisk_6.12_Release"&gt;TestDisk 6.12 Release&lt;/a&gt; - CGSecurity&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So,  that brings us back to using a combo of tools and methods to wipe both  check for the presence of&amp;nbsp; HPA/DCO and address/remove them first before  using a block-erase wipe tool or to learn some new techniques for an  “all-in-one” wipe method to get it all.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;em&gt;For “modern” hard disk drives that support this feature&lt;/em&gt;  the “enhanced secure erase” method may be the only option short of  extreme physical destruction (with prejudice and malice aforethought) of  the drive to ensure all data is irrevocably cleared from the drive.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;TinyApps “how-to” post is a great starting point at using a Linux Live CD to accomplish the process and what is happening :&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://tinyapps.org/docs/wipe_drives_hdparm.html"&gt;ATA Secure Erase (SE) and hdparm&lt;/a&gt; - TinyApps blog&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;More background here at &lt;a href="https://ata.wiki.kernel.org/articles/a/t/a/ATA_Secure_Erase_936d.html"&gt;ATA Secure Erase&lt;/a&gt; - ata Wiki&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://mackonsti.wordpress.com/2011/11/22/ssd-secure-erase-ata-command/"&gt;SSD Secure Erase with proper ATA command&lt;/a&gt; - mackonsti blog&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml"&gt;CMRR - Secure Erase&lt;/a&gt;  tool - over at the Center for Magnetic Recording Research (CMRR) is  another option, though a read through of many comments and other posts  suggests this tool may have some performance issues…or not.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ocztechnologyforum.com/forum/showthread.php?74093-How-to-use-HDDErase"&gt;Guide How to use HDDErase&lt;/a&gt; - OCZ Forum&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;The &lt;a href="http://partedmagic.com/doku.php"&gt;Parted Magic&lt;/a&gt;  LiveCD- I have learned - includes an ERASE tool which does support the  “enhanced secure erase” protocol if the drive at hand does as well.&amp;nbsp; It  takes care of a lot of the CLI work that might off-put casual wipers. &lt;a href="http://blog.corsair.com/?p=4484"&gt;How To Secure Erase Corsair SSDs With Parted Magic&lt;/a&gt;  -- Corsair Blog.&amp;nbsp; I’ve used Parted Magic quite a lot in the past but  never for secure wiping and never realized it had this option.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://gparted.sourceforge.net/index.php"&gt;GParted&lt;/a&gt; can do this as well, though it doesn’t seem to have the “wizard” for hdparm that Parted Magic does: &lt;a href="http://www.gskill.us/forum/showthread.php?t=5901"&gt;Use GParted to secure erase SSD - GSKILL TECH FORUM&lt;/a&gt;.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Note:  As TinyApps points out in his post, in-fact any Linux distro that  includes hdparm at a version of 9.31 or greater would work; the lower  versions have a 2-hour timeout which can leave the remaining portion of  the disk unwiped.&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ocztechnologyforum.com/forum/showthread.php?74304-Secure-Erase-for-Windows"&gt;Guide Secure Erase for Windows&lt;/a&gt; - OCZ Forum&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ocztechnologyforum.com/forum/showthread.php?76612-Secure-Erase-From-Within-Linux-For-Windows-Users"&gt;Guide Secure Erase From Within Linux For Windows Users&lt;/a&gt; - OCZ Forum&lt;/span&gt; &lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ocztechnologyforum.com/forum/showthread.php?62457-How-to-Restore-SSD-performance-WITHOUT-using-HDDErase"&gt;Guide How to Restore SSD performance WITHOUT using HDDErase&lt;/a&gt; - OCZ Forum&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;It is my understanding that Windows port of hdparm may work as well that is found in &lt;a href="http://www.cygwin.com/"&gt;Cygwin&lt;/a&gt;. I’ve seen some forum posts discuss that some versions (the later ones) are better than earlier ones.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://blog.tiensivu.com/aaron/archives/963-The-Win32Cygwin-version-of-hdparm-will-tell-you-if-you-have-HIPM-or-DIPM-capabilities..html"&gt;The Win32/Cygwin version of 'hdparm' will tell you if you have HIPM or DIPM capabilities.&lt;/a&gt; - Aaron Tiensivu's Blog&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Christian Franke has also provided a native Win32 tool version if you just need it without Cygwin.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://hdparm-win32.dyndns.org/hdparm/"&gt;Index of /hdparm&lt;/a&gt; - via Christian Franke&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So to sum up from my perspective,&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ol style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;If  you want to keep the OEM HPA area intact (maybe you have a Dell system  with diagnostics loaded there) and plan to recycle the drive/system in  your organization, then a simple whole-disk block-erase of the drive may  be sufficient.&amp;nbsp; Updating the DCO information probably isn’t necessary  and may help -- in fact -- preserve the previously found “bad sectors”  info if it is present.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;If you plan on giving the  drive/system away then you should strongly consider attempting the  “enhanced secure erase” method first to see if your drive supports it.  If not, then you may have to settle for either a whole-disk block-erase  wipe and hope for the best (that there is no sensitive data in any  HPA/DCO areas (if present) or use one of many &lt;a href="http://www.youtube.com/watch?v=LEWQGlVZXrw"&gt;reliable&lt;/a&gt;, &lt;a href="http://www.youtube.com/watch?v=S_BgtldCwqw"&gt;complete&lt;/a&gt;,&amp;nbsp; &lt;a href="http://www.youtube.com/watch?v=ZcGCL3c45sI"&gt;irrevocable&lt;/a&gt;, &lt;a href="http://www.youtube.com/watch?v=z-QfRhl7gKA"&gt;physically destructive&lt;/a&gt; methods.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Hopefully I have covered this sufficiently for you to Google on from here.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If not, as always your comments are welcome and appreciated.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;And  if anyone knows of any additional Windows/DOS/*Nix tools that can  handle “enhanced secure erase” wiping of a modern drive, please leave a  tip in the comments.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-9118137764574395158?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/9118137764574395158/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=9118137764574395158&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9118137764574395158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9118137764574395158'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/wipies-addendum.html' title='Wipies -- Addendum'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-7091120349324791390</id><published>2012-01-27T20:30:00.000+08:00</published><updated>2012-01-27T20:30:01.467+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><title type='text'>REMnux: A Linux Distribution for Reverse-Engineering Malware</title><content type='html'>&lt;h1 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;REMnux: A Linux Distribution for Reverse-Engineering Malware&lt;/span&gt;&lt;/h1&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;REMnux is a lightweight Linux distribution for assisting malware  analysts in reverse-engineering malicious software. The distribution is  based on &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnVidW50dS5jb20v&amp;amp;b=29"&gt;Ubuntu&lt;/a&gt; and is maintained by Lenny Zeltser.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;About REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;REMnux incorporates a number of tools  for analyzing malicious  software that runs on Microsoft Windows, as well as browser-based  malware, such as Flash programs and obfuscated JavaScript. The toolkit  includes programs  for &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmV2ZXJzZS1tYWx3YXJlL2FuYWx5emluZy1tYWxpY2lvdXMtZG9jdW1lbnRzLmh0bWw%3D&amp;amp;b=29"&gt;analyzing malicious documents&lt;/a&gt;, such PDF files, and utilities for reverse-engineering malware through memory forensics. &lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;REMnux can also be used for emulating network services within an  isolated lab environment when performing behavioral malware analysis. As  part of this process, the analyst typically infects another laboratory  system with the malware sample and redirects the connections to the  REMnux system listening on the appropriate ports.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can learn the malware analysis techniques that make use of the  tools installed and pre-configured on REMnux by taking my  course on &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmV2ZXJzZS1tYWx3YXJlLw%3D%3D&amp;amp;b=29"&gt;Reverse-Engineering Malware&lt;/a&gt; (REM) at SANS Institute.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Originally released in 2010, REMnux has been updated to version 3 in December 2011.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;What REMnux Is Not&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;REMnux does not aim to include all malware analysis tools in  existence, and omits the utilities designed to work on Windows. If you  are looking for a more full-featured Linux distribution that supports a  wider range of digital forensic analysis, take a look at &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29tcHV0ZXItZm9yZW5zaWNzLnNhbnMub3JnL2NvbW11bml0eS9kb3dubG9hZHMv&amp;amp;b=29"&gt;SANS Investigative Forensic Toolkit (SIFT) Workstation&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;a href="" name="download-remnux"&gt;&lt;/a&gt;&lt;/span&gt;   &lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Downloading REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL3NvdXJjZWZvcmdlLm5ldC9kb3dubG9hZHMvcmVtbnV4L3ZlcnNpb24zLw%3D%3D&amp;amp;b=29"&gt;download the REMnux distribution&lt;/a&gt; as a VMware virtual appliance archive and also as an ISO image of a Live CD. MD5 has values of the latest files are:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;VMware virtual appliance archive: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc291cmNlZm9yZ2UubmV0L3Byb2plY3RzL3JlbW51eC9maWxlcy92ZXJzaW9uMy9yZW1udXgtMy4wLXZtLXB1YmxpYy5yYXIvZG93bmxvYWQ%3D&amp;amp;b=29"&gt;remnux-3.0-public-vm.rar&lt;/a&gt; (MD5 hash 4264b43aae783578ce00fdd7a5aaee64).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;ISO image of a Live CD: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc291cmNlZm9yZ2UubmV0L3Byb2plY3RzL3JlbW51eC9maWxlcy92ZXJzaW9uMy9yZW1udXgtcHVibGljLTMuMC1saXZlLWNkLmlzby9kb3dubG9hZA%3D%3D&amp;amp;b=29"&gt;remnux-3.0-public-live-cd.iso&lt;/a&gt;  (MD5 hash 30cc52beed10de5c3e31a2a1d9ffdba8).&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Getting Started With REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Since REMnux is an Ubuntu-based Linux distribution, you need to be  familiar with the basic aspects of using Linux to make use of REMnux.  The good news is that you don't need to know how to perform system  administration tasks to find REMnux useful, since many malware analysis  tools are already preinstalled on REMnux. Below    are some notes to help you get started with becoming comfortable in  REMnux.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;To get a sense for the tools installed, configured and tested on  REMnux and how to use them for malware analysis, take a look at the &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmVtbnV4L3JlbW51eC1tYWx3YXJlLWFuYWx5c2lzLXRpcHMuaHRtbA%3D%3D&amp;amp;b=29"&gt;REMnux Usage Tips cheat sheet&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Using the REMnux  Virtual Appliance&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Prior to using REMnux as a VMware virtual appliance, you need to download a VMware product, such as &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnZtd2FyZS5jb20vcHJvZHVjdHMvcGxheWVyLw%3D%3D&amp;amp;b=29"&gt;VMware Player&lt;/a&gt;,  &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnZtd2FyZS5jb20vcHJvZHVjdHMvd29ya3N0YXRpb24v&amp;amp;b=29"&gt;VMware Workstation&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnZtd2FyZS5jb20vcHJvZHVjdHMvZnVzaW9uL292ZXJ2aWV3Lmh0bWw%3D&amp;amp;b=29"&gt;VMware Fusion&lt;/a&gt;. If using VMware ESX server, you can use the &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnZtd2FyZS5jb20vcHJvZHVjdHMvY29udmVydGVyLw%3D%3D&amp;amp;b=29"&gt;VMware vCenter Converter&lt;/a&gt; tool to convert the virtual appliance to the ESX format.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Then, download the &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc291cmNlZm9yZ2UubmV0L3Byb2plY3RzL3JlbW51eC9maWxlcy92ZXJzaW9uMy9yZW1udXgtMy4wLXZtLXB1YmxpYy5yYXIvZG93bmxvYWQ%3D&amp;amp;b=29"&gt;REMnux VMware virtual appliance rar file&lt;/a&gt;. Extract the file's contents into a dedicated directory using a tool such as "&lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vZW4ud2lraXBlZGlhLm9yZy93aWtpL1VucmFy&amp;amp;b=29"&gt;unrar&lt;/a&gt;".  Open the .vmx file using the virtualization tool, such as VMware  Player. The REMnux virtual appliance should start up within your VMware  product.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The REMnux virtual appliance is configured to use the "host only"  network, isolating the REMnux instance from the physical network. To  connect REMnux to the network, for instance, to provide it with Internet  access, change the settings of the virtual appliance to the appropriate  network, such as "NAT". Then reboot REMnux or issue the "renew-dhcp"  command.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If using VMware, you can optionally &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmVtbnV4L2luc3RhbGwtdm13YXJlLXRvb2xzLmh0bWw%3D&amp;amp;b=29"&gt;install VMware Tools in REMnux&lt;/a&gt; to automatically adjust the screen size.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can other virtualization software, such as &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnZpcnR1YWxib3gub3JnLw%3D%3D&amp;amp;b=29"&gt;VirtualBox&lt;/a&gt;, which is able to import VMware virtual machine images. If using VirtualBox you may need to &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL3dpa2kudWJ1bnR1LmNvbS9VYnVudHVNYWdhemluZS9Ib3dUby9Td2l0Y2hpbmdfRnJvbV9WTVdhcmVfVG9fVmlydHVhbEJveDpfLnZtZGtfVG9fLnZkaV9Vc2luZ19RZW11XytfVmRpVG9vbA%3D%3D&amp;amp;b=29"&gt;convert the VMware virtual appliance to the VirtualBox format&lt;/a&gt;.  Alternatively, you can create a new virtual machine using VirtualBox  and point it to the hard drive file (.vmdk) that's part of the REMnux  virtual appliance.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Malware Analysis Tools Set Up On REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Analyze Flash malware: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnN3ZnRvb2xzLm9yZy8%3D&amp;amp;b=29"&gt;SWFTtools&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm5vd3JhcC5kZS9mbGFzbS5odG1s&amp;amp;b=29"&gt;flasm&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm5vd3JhcC5kZS9mbGFyZS5odG1s&amp;amp;b=29"&gt;flare&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2dpdGh1Yi5jb20vQ3liZXJTaGFkb3cvUkFCQ0RBc20%3D&amp;amp;b=29"&gt;RABCDAsm&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vaG9va2VkLW9uLW1uZW1vbmljcy5ibG9nc3BvdC5jb20vMjAxMS8xMi94eHhzd2ZweS5odG1s&amp;amp;b=29"&gt;xxxswf.py&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Interacting with IRC bots: IRC server (&lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lmluc3BpcmNkLm9yZy8%3D&amp;amp;b=29"&gt;Inspire IRCd&lt;/a&gt;) and client (&lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmVwaWNzb2wub3JnLw%3D%3D&amp;amp;b=29"&gt;epic5&lt;/a&gt;)&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Observe and interact with network activities: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LndpcmVzaGFyay5vcmcv&amp;amp;b=29"&gt;Wireshark&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmhvbmV5ZC5vcmcv&amp;amp;b=29"&gt;Honeyd&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmluZXRzaW0ub3JnLw%3D%3D&amp;amp;b=29"&gt;INetSim&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5hY3RpdmVzdGF0ZS5jb20vcmVjaXBlcy80OTEyNjQtbWluaS1mYWtlLWRucy1zZXJ2ZXIv&amp;amp;b=29"&gt;fakedns&lt;/a&gt;, fakesmtp , NetCat, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm5ldHJlc2VjLmNvbS8%2FcGFnZT1OZXR3b3JrTWluZXI%3D&amp;amp;b=29"&gt;NetworkMiner&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbmdyZXAuc291cmNlZm9yZ2UubmV0Lw%3D%3D&amp;amp;b=29"&gt;ngrep&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvcGFzc2l2ZS1kbnMtcXVlcnktdG9vbC8%3D&amp;amp;b=29"&gt;pdnstool&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnRjcGR1bXAub3JnLw%3D%3D&amp;amp;b=29"&gt;tcpdump&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Decode JavaScript: Firefox &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vZ2V0ZmlyZWJ1Zy5jb20v&amp;amp;b=29"&gt;Firebug&lt;/a&gt;, QuickJava and &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2FkZG9ucy5tb3ppbGxhLm9yZy9lbi1VUy9maXJlZm94L2FkZG9uLzEwMzQ1Lw%3D%3D&amp;amp;b=29"&gt;JavaScript Deobfuscator&lt;/a&gt; extensions, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm1vemlsbGEub3JnL3JoaW5vL2RlYnVnZ2VyLmh0bWw%3D&amp;amp;b=29"&gt;Rhino debugger&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2dpdGh1Yi5jb20vZWluYXJzL2pzLWJlYXV0aWZ5&amp;amp;b=29"&gt;JS-Beautify&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm1vemlsbGEub3JnL2pzL3NwaWRlcm1vbmtleS8%3D&amp;amp;b=29"&gt;SpiderMonkey&lt;/a&gt;, V8, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmFzcGhldXRlLmNvbS9lbmdsaXNoLzIwMDExMTIzLmFzcA%3D%3D&amp;amp;b=29"&gt;Windows Script Decoder&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vanN1bnBhY2suYmxvZ3Nwb3QuY29tLw%3D%3D&amp;amp;b=29"&gt;Jsunpackn&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Explore and interact with web malware: Firefox  Tamper Data and User Agent Switcher extensions, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vdGlueWh0dHBkLnNvdXJjZWZvcmdlLm5ldC8%3D&amp;amp;b=29"&gt;TinyHTTPd&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnBvcnRzd2lnZ2VyLm5ldC9idXJwLw%3D%3D&amp;amp;b=29"&gt;Burp Suite Free Edition&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnN0dW5uZWwub3JnLw%3D%3D&amp;amp;b=29"&gt;Stunnel&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL3d3dy50b3Jwcm9qZWN0Lm9yZy8%3D&amp;amp;b=29"&gt;Tor&lt;/a&gt; , &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vanN1bnBhY2suYmxvZ3Nwb3QuY29tLzIwMDkvMDYvdmVyeS1jb29sLWphdmFzY3JpcHQtZGVjb2Rpbmctb24uaHRtbA%3D%3D&amp;amp;b=29"&gt;Jsunpackn&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvdG9yc29ja3Mv&amp;amp;b=29"&gt;torsocks&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Analyze shellcode: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmdudS5vcmcvc29mdHdhcmUvZ2RiLw%3D%3D&amp;amp;b=29"&gt;gdb&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vZW4ud2lraXBlZGlhLm9yZy93aWtpL09iamR1bXA%3D&amp;amp;b=29"&gt;objdump&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vcmFkYXJlLm5vcGNvZGUub3JnLw%3D%3D&amp;amp;b=29"&gt;Radare&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmV2ZXJzZS1tYWx3YXJlL2NvbnZlcnQtc2hlbGxjb2RlLmh0bWw%3D&amp;amp;b=29"&gt;shellcode2exe&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbGliZW11LmNhcm5pdm9yZS5pdC8%3D&amp;amp;b=29"&gt;libemu&lt;/a&gt;'s sctest&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Examine suspicious executables: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnVweC5vcmcv&amp;amp;b=29"&gt;upx&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vaGFuZGxlcnMuZHNoaWVsZC5vcmcvamNsYXVzaW5nL3BhY2tlcmlkLnB5&amp;amp;b=29"&gt;packerid&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmNlcnQuYXQvZG93bmxvYWRzL3NvZnR3YXJlL2J5dGVoaXN0X2VuLmh0bWw%3D&amp;amp;b=29"&gt;bytehist&lt;/a&gt;, DensityScout, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vYmxvZy5kaWRpZXJzdGV2ZW5zLmNvbS9wcm9ncmFtcy94b3JzZWFyY2gv&amp;amp;b=29"&gt;xorsearch&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2dpdGh1Yi5jb20vaGVsbG1hbi94b3J0b29s&amp;amp;b=29"&gt;xortool&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbWFyazAubmV0L3NvZnQtdHJpZC1lLmh0bWw%3D&amp;amp;b=29"&gt;TRiD&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvbWFsd2FyZWNvb2tib29rL3NvdXJjZS9icm93c2UvdHJ1bmsvMTIvMS94b3J0b29scy5weQ%3D%3D&amp;amp;b=29"&gt;xortools.py&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmNsYW1hdi5uZXQv&amp;amp;b=29"&gt;ClamAV&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc3NkZWVwLnNvdXJjZWZvcmdlLm5ldC8%3D&amp;amp;b=29"&gt;ssdeep&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbWQ1ZGVlcC5zb3VyY2Vmb3JnZS5uZXQv&amp;amp;b=29"&gt;md5deep&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvbWFsd2FyZWNvb2tib29rL3NvdXJjZS9icm93c2UvdHJ1bmsvMy84L3Blc2Nhbm5lci5weQ%3D%3D&amp;amp;b=29"&gt;pescanner&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvcHlldy93aWtpL01hbHdhcmVBbmFseXNpcw%3D%3D&amp;amp;b=29"&gt;Pyew&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmV2ZXJzZS1tYWx3YXJlL2FuYWx5emluZy1tYWxpY2lvdXMtZG9jdW1lbnRzLmh0bWw%3D&amp;amp;b=29"&gt;Analyze malicious documents&lt;/a&gt;: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vYmxvZy5kaWRpZXJzdGV2ZW5zLmNvbS9wcm9ncmFtcy9wZGYtdG9vbHMv&amp;amp;b=29"&gt;Didier Steven's PDF tools&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc2VjbGFicy5vcmcvb3JpZ2FtaS8%3D&amp;amp;b=29"&gt;Origami framework&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2dpdGh1Yi5jb20vOWIvcGRmeHJheV9saXRl&amp;amp;b=29"&gt;PDF X-RAY Lite&lt;/a&gt;, Peepdf, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vanN1bnBhY2suYmxvZ3Nwb3QuY29tLzIwMDkvMDYvdmVyeS1jb29sLWphdmFzY3JpcHQtZGVjb2Rpbmctb24uaHRtbA%3D%3D&amp;amp;b=29"&gt;Jsunpackn&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmFjY2Vzc3BkZi5jb20vcGRmdGsv&amp;amp;b=29"&gt;pdftk&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vZXZpbGNvZGVjYXZlLmJsb2dzcG90LmNvbS8yMDEwLzA4L21hbGljaW91cy0gb2ZmaWNlLWZpbGVzLWFuYWx5c2lzLmh0bWw%3D&amp;amp;b=29"&gt;pyOLEScanner.py&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=czovL2JpdGJ1Y2tldC5vcmcvaGF5cG8vaGFjaG9pci93aWtpLw%3D%3D&amp;amp;b=29"&gt;Hachoir&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Decompile Java programs: Jad, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vamF2YS5kZWNvbXBpbGVyLmZyZWUuZnIvP3E9amRndWk%3D&amp;amp;b=29"&gt;JD-gui&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Perform memory forensics: &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3Avdm9sYXRpbGl0eS93aWtpL0ZlYXR1cmVzQnlQbHVnaW4%3D&amp;amp;b=29"&gt;Volatility Framework&lt;/a&gt; with &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vY29kZS5nb29nbGUuY29tL3AvbWFsd2FyZWNvb2tib29rL3NvdXJjZS9icm93c2UvdHJ1bmsvbWFsd2FyZS5weQ%3D%3D&amp;amp;b=29"&gt;malware&lt;/a&gt;, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vamxzLXNjcmlwdHMuZ29vZ2xlY29kZS5jb20v&amp;amp;b=29"&gt;timeliner&lt;/a&gt; and other modules, AESKeyFinder and RSAKeyFinder.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;    &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Handle miscellaneous tasks: unzip, unrar, strings, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbGludXhicml0LmNvLnVrL3NvZnR3YXJlL2ZlaC8%3D&amp;amp;b=29"&gt;feh&lt;/a&gt; image viewer, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnNjaW50aWxsYS5vcmcvU2NpVEUuaHRtbA%3D%3D&amp;amp;b=29"&gt;SciTE &lt;/a&gt;text editor, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm9wZW5zc2guY29tLw%3D%3D&amp;amp;b=29"&gt;OpenSSH &lt;/a&gt;server, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vamVzc2Vrb3JuYmx1bS5saXZlam91cm5hbC5jb20vMjY5NzQ5Lmh0bWw%3D&amp;amp;b=29"&gt;findaes&lt;/a&gt;, Xpdf PDF viewer, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LmNqbXdlYi5uZXQvdmJpbmRpZmYv&amp;amp;b=29"&gt;VBinDiff&lt;/a&gt; file comparison/viewer, &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vZnJlZW1pbmQub3JnLw%3D%3D&amp;amp;b=29"&gt;FreeMind&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Questions on and Improvements to REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;        &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Do you have recommendations for making REMnux more useful? If so, please let me know.          You can contact me by &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vYWJvdXQvY29udGFjdC5odG1s&amp;amp;b=29"&gt;email&lt;/a&gt; or &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vdHdpdHRlci5jb20vbGVubnl6ZWx0c2Vy&amp;amp;b=29"&gt;via Twitter&lt;/a&gt;. You're welcome to get in touch with me if you have questions regarding using REMnux.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;   &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Articles About REMnux&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;      &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;ISSA Journal published an article by Russ McRee on &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vaG9saXN0aWNpbmZvc2VjLm9yZy90b29sc21pdGgvZG9jcy9zZXB0ZW1iZXIyMDEwLmh0bWw%3D&amp;amp;b=29"&gt;using REMnux with malware analysis&lt;/a&gt; (PDF). Its examples include the activation of INetSim, and the use of PDF analysis tools.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;LWC.net published an article by Koen Vervloesem that &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vbHduLm5ldC9BcnRpY2xlcy8zOTY3MTIv&amp;amp;b=29"&gt;showcases some REMnux capabilities&lt;/a&gt;. Its examples include the use of SWF and PDF analysis tools.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Christiaan Beek described how to use JSunpack-n, installed on REMnux, to &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vc2VjdXJpdHliYW5hbmFzLmNvbS8%2FcD00NTU%3D&amp;amp;b=29"&gt;analyze a malicious PDF file&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Dennis Fisher outlined the capabilities of &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vdGhyZWF0cG9zdC5jb20vZW5fdXMvYmxvZ3MvbmV3LWxpbnV4LW9zLXJlbW51eC1kZXNpZ25lZC1yZXZlcnNlLWVuZ2luZWVyaW5nLW1hbHdhcmUtMDcwOTEw&amp;amp;b=29"&gt;the original REMnux release&lt;/a&gt; and &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vdGhyZWF0cG9zdC5jb20vZW5fdXMvYmxvZ3MvbmV3LXZlcnNpb24tcmVtbnV4LW1hbHdhcmUtYW5hbHlzaXMtbGludXgtZGlzdHJpYnV0aW9uLXJlbGVhc2VkLTEyMTYxMQ%3D%3D&amp;amp;b=29"&gt;the v3 update&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Erik Hjelmvik illustrated the use of &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3Lm5ldHJlc2VjLmNvbS8%2FcGFnZT1CbG9nJmFtcDttb250aD0yMDExLTEyJmFtcDtwb3N0PVJFTW51eC1ub3ctaW5jbHVkZXMtTmV0d29ya01pbmVy&amp;amp;b=29"&gt;NetworkMiner on REMnux&lt;/a&gt;.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Michael Kassner discussed &lt;a href="http://www.browserunblocker.com/browse.php?u=Oi8vd3d3LnRlY2hyZXB1YmxpYy5jb20vYmxvZy9zZWN1cml0eS9yZW1udXgtcmV2ZXJzZS1lbmdpbmVlcmluZy1tYWx3YXJlLzcwOTQ%3D&amp;amp;b=29"&gt;the purpose of REMnux&lt;/a&gt; and outlined some of the tools installed on it.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;轉自 http://www.browserunblocker.com/browse.php?u=Oi8vemVsdHNlci5jb20vcmVtbnV4Lw%3D%3D&amp;amp;b=29&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-7091120349324791390?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/7091120349324791390/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=7091120349324791390&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7091120349324791390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7091120349324791390'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/remnux-linux-distribution-for-reverse.html' title='REMnux: A Linux Distribution for Reverse-Engineering Malware'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-1715577849389617149</id><published>2012-01-25T20:27:00.000+08:00</published><updated>2012-01-25T20:27:00.091+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='密碼破解'/><title type='text'>The Password is…</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Last week we got a call from one of Lavie’s cousins. She and her  husband had suddenly began getting phone calls from concerned friends as  well as strange “undeliverable” email notices.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Mysteriously, at  least one email had been sent from their on-line email account to all  the recipients in their contacts in batches of ten or so.&amp;nbsp; Some folks  had told them their own security apps had alerted when they tried to  follow the link in the email.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;It was pretty apparent to the  couple that “something” was amiss with their PC but exactly what, they  weren’t sure. They had already downloaded a second anti-virus tool and  scanned their system with nothing found. They decided to call me to see  if I could help them. I recommended they change the password and any  security challenge questions immediately which they did, then arranged  for a house-call the following day.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I already had a clue on what  probably occurred, but went though my full checklist of items as I  assessed the system. No rouge processes, no unexpected auto-start items.  Additional security scans came through with flying colors.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Then I  turned my attention to their email account.&amp;nbsp; This particular email  provider (unfortunately) doesn’t provide any IP-based user sign-in event  logging like some other main-stream web-mail providers do. That would  have provided golden information.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://support.google.com/mail/bin/answer.py?hl=en&amp;amp;answer=45938"&gt;Last account activity&lt;/a&gt; - Gmail Help&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.makeuseof.com/tag/check-if-your-gmail-is-hacked-with-activity-monitor/"&gt;Check if Your Gmail Account is Hacked with Activity Monitor&lt;/a&gt; - MakeUseOf&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://developer.yahoo.com/blogs/ydn/posts/2011/04/yahoo-enables-monitoring-of-login-activity-for-better-account-protection/"&gt;Yahoo! Enables Monitoring of Login Activity for Better Account Protection&lt;/a&gt; - YDN Blog&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;What  we did have is one overlooked original email in the “Sent” folder  showing a mail time of 8:15 PM Wed night.&amp;nbsp; Neither of the couple  reported being logged in on the system (or the email) at that time so it  seemed fairly certain that is when the event occurred.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I mailed that to myself to look into the URL more later.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;They use IE 9 and the system was fully patched. Flash and Java were outdated, but not too bad.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Based  on my survey and additional questioning, it appears to me that someone  had “hacked” their account using some kind of brute-force attack on  their account, quickly they had composed at least one email containing a  single URL to everyone in their address book.&amp;nbsp; I couldn’t find any  evidence of a persistent threat on their system, and based on their  feedback, I doubted a cross-site-scripting vulnerability had occurred.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;For the really curious, here is a link to the &lt;a href="http://urlquery.net/index.php"&gt;urlQuery&lt;/a&gt; (free online URL scanner) findings from that particular URL I found: &lt;a href="http://urlquery.net/report.php?id=16168"&gt;urlQuery scan result&lt;/a&gt;.  Turns out that particular link leads to a compromised (?) website  serving up fake AV scanner malware via some JavaScript code.&amp;nbsp; That is  why some recipients of the email were likely getting alerts when they  visited the site. Sneaky.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Turns out hacking email accounts and  appropriating them (even “non-maliciously”) for spamming is big business  and a common event for many web-citizens.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.theatlantic.com/magazine/archive/2011/11/hacked/8673/1/"&gt;Hacked!&lt;/a&gt; - The Atlantic - James Fallows has a fantastic cautionary tale about the loss of an email account to a hack-attack.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://lifehacker.com/5875848/how-can-i-find-out-why-my-email-account-just-spammed-my-friends-and-family"&gt;How Can I Find Out Why My Email Account Just Spammed My Friends and Family?&lt;/a&gt; - Lifehacker post has some tips on trying to get a handle on the aftermath cleanup.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This couple -- it turns out -- had been using a very weak password so it fell probably pretty fast.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Turns out weak passwords remain a common plague.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://isc.sans.edu/diary.html?storyid=12310"&gt;ISC Diary | Analysis of the Stratfor Password List&lt;/a&gt; is another clear warning of this danger.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Steve Ragan posted a simply amazing &lt;a href="http://www.thetechherald.com/articles/Report-Analysis-of-the-Stratfor-Password-List"&gt;Report: Analysis of the Stratfor Password List&lt;/a&gt;  which has crazy fascinating data on passwords and just how weak most of  them were, along with his own password cracking work to show just how  easy these fall.&amp;nbsp; See also: &lt;a href="http://nakedsecurity.sophos.com/2012/01/04/researchers-find-many-weak-stratfor-passwords/"&gt;Researchers find many weak Stratfor passwords&lt;/a&gt; -Naked Security.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/06/brief-sony-password-analysis.html"&gt;A brief Sony password analysis &lt;/a&gt;- Troy Hunt’s Blog&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.tomshardware.com/news/imperva-rockyou-most-common-passwords,9486.html"&gt;Your Top 20 Most Common Passwords&lt;/a&gt; - Tom’s Hardware&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;And just over the weekend there was this: &lt;a href="http://blog.chron.com/techblog/2012/01/zappos-customer-info-is-breached-change-your-password-now/"&gt;Zappos customer info is breached. Change your password now! [Updated] &lt;/a&gt;- TechBlog via Chron.com&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;What is one to do? This maybe?&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;img alt="z0sfabbn.qeg" border="0" height="484" src="http://lh5.ggpht.com/-m_5dK8BSvJ8/TxTnCMT8O8I/AAAAAAAAA7w/UuwXstOIkxM/z0sfabbn.qeg%25255B5%25255D.png?imgmax=800" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: block; float: none; margin-left: auto; margin-right: auto; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="z0sfabbn.qeg" width="599" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://xkcd.com/936/"&gt;xkcd: Password Strength&lt;/a&gt; (see also &lt;a href="http://xkcd.com/792/"&gt;xkcd: Password Reuse&lt;/a&gt;)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If  you want a quick way to assess the complexity/strength of the passwords  you may have stored in your web-browser or some Windows applications,  check out the &lt;a href="http://www.nirsoft.net/utils/password_security_scanner.html"&gt;Password Security Scanner&lt;/a&gt; freeware tool by NirSoft.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Some highly recommended online locations to check your current password strength against are:&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.microsoft.com/security/pc-security/password-checker.aspx"&gt;Password Checker: Using Strong Passwords&lt;/a&gt; - Microsoft Security&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://howsecureismypassword.net/"&gt;How Secure Is My Password?&lt;/a&gt; - website&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.passwordmeter.com/"&gt;Password Strength Checker&lt;/a&gt; - The Password Meter&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.testyourpassword.com/"&gt;Test Your Password&lt;/a&gt; - website&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://rumkin.com/tools/password/passchk.php"&gt;Strength Test&lt;/a&gt; - Rumkin.com&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Coming  up with a truly secure and complex password can be a major task for  some folks. And the web has no dearth of fantastic advice on the subject  of what defines a strong password and how to create one.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.hanselman.com/blog/TenThingsToDoToSecureAnImportantPersonsComputerOrEvenAshtonsOrAKardashians.aspx?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+ScottHanselman+%28Scott+Hanselman+-+ComputerZen.com%29"&gt;Ten Things To Do to Secure an Important Person's Computer (or even Ashton's or a Kardashian's)&lt;/a&gt; - Scott Hanselman&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.grc.com/passwords.htm"&gt;Ultra High Security Password Generator&lt;/a&gt; - GRC &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.grc.com/haystack.htm"&gt;Password Haystacks: How Well Hidden is Your Needle?&lt;/a&gt; - GRC&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://www.grc.com/ppp.htm"&gt;Flexible One-Time Password MetaSystem&lt;/a&gt; - GRC&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.schneier.com/blog/archives/2009/08/password_advice.html"&gt;Password Advice&lt;/a&gt; - Bruce Schneier’s Schneier on Security blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.wired.com/politics/security/commentary/securitymatters/2007/01/72458"&gt;Secure Passwords Keep You Safer&lt;/a&gt; - Wired Security Matters post&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div align="center" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/div&gt;&lt;div class="wlWriterEditableSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:c1d21702-95a7-4f71-8e33-4aeddce4aa5f" style="display: inline; float: none; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin: 0px; padding: 0px;"&gt;&lt;div style="clear: both; width: 448px;"&gt;&lt;span style="font-size: small;"&gt;From SophosLabs via YouTube&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;And just today, Lifehacker released a super-cool mega-graphic on password selection&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://lifehacker.com/5876541/use-this-infographic-to-pick-a-good-strong-password"&gt;Use This Infographic to Pick a Good, Strong Password&lt;/a&gt; - Lifehacker &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/"&gt;Troy Hunt&lt;/a&gt;  did a series of great, in-depth posts on password selection and science  that are must-reads. I’m liking Troy’s writing and analysis and his  blog has been added to my RSS must-read feed list.&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/07/science-of-password-selection.html"&gt;The science of password selection&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/08/im-sorry-but-were-you-actually-trying.html#more"&gt;I’m sorry, but were you actually trying to remember your comical passwords?&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/04/bad-passwords-are-not-fun-and-good.html#more"&gt;Bad passwords are not fun and good entropy is always important: demystifying security fallacies&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/03/3-reasons-youre-forced-into-creating.html#more"&gt;The 3 reasons you’re forced into creating weak passwords&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/01/whos-who-of-bad-password-practices.html#more"&gt;Who’s who of bad password practices – banks, airlines and more&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.troyhunt.com/2011/03/only-secure-password-is-one-you-cant.html#more"&gt;The only secure password is the one you can’t remember&lt;/a&gt; - Troy Hunt’s Blog&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Those  last two points are my takeways, that nothing is more frustrating that  internal application or external website password policies that are weak  by design and force me to use a short password. And that the best  password is one so damn complex there is no way I can remember it, even  under duress.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I prefer to use the longest password the  site/application will accept based on character count. (By the  way…seriously guys, place your password policy and field limits up front  to make this easy to figure out!)&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;How do I come up with one? I  use two tools, a portable password manager application that stores the  passwords in an encrypted container and a utility to generate randomized  gobbly-gook passwords. In fact, many of the first item include the  second item as a built in feature.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I linked to some of the GRC  random password generators earlier but these other free portable  password generation tools are great:&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cezeo.com/products/passwordsguru/"&gt;Password Guru&lt;/a&gt; - CEZEO Software generates complex and secure passwords with rule filters for length and special characters.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.gaijin.at/en/dlpg.php"&gt;Password Generator&lt;/a&gt;  - Gaijin Software - can generate up to 1000 passwords at once with  advanced rule filters. Also includes a password checker to test password  strength.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.securesafepro.com/pasgen.php?source=wincatalog.com"&gt;Password GeneratorXP&lt;/a&gt;  - I’ve been using an ealier version of this app for a very long time.  Latest version is 1.5 updated in December 2011.&amp;nbsp; Can generate random  passwords up to 99 characters long! Rules allow character  inclusion/exclusion and supports special symbols. Super app.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://pwgen-win.sourceforge.net/"&gt;PWGen&lt;/a&gt;  - Open-Source Password Generator for Windows using AES and SHA-2  crytography methods. Can support passwords with up to a crazy 20,000  length, can be fed a wordlist includes file if you prefer, can exclude  “ambiguous” characters (like o and 0, l and 1, etc.). It can create up  to 1,000,000 passwords at a time based on your rule patterns, or a  single password instantly. The included manual file is great reading  regarding password security in general and not just the program  operation itself.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://passworg.badhim.com/"&gt;PassworG - Free password generator software&lt;/a&gt; - pretty simple to use but strong password generator that might be easier for some folks to use.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So how do you manage these complex passwords?&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://keepass.info/"&gt;KeePass Password Safe&lt;/a&gt; (or) &lt;a href="http://portableapps.com/apps/utilities/keepass_portable"&gt;KeePass Password Safe Portable&lt;/a&gt;  is my personal preference. It has a ton of features, is free and  portable, and has a lot of options for organizing the stored records. It  is the cat’s meow.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://passwordsafe.sourceforge.net/"&gt;Password Safe&lt;/a&gt;  is a similar password keeper that comes highly recommended. The  interface might be just a bit more easy for some folks to take to as  opposed to KeePass.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.dheone.com/"&gt;Era Password manager&lt;/a&gt; is a nice password keeper tool again a bit simpler in interface but powerful under the hood if you go looking deeper.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cygnusproductions.com/freeware/pc.asp"&gt;Password Corral&lt;/a&gt; by Cygnus Productions is pretty nice.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://github.com/zdia/gorilla/wiki/"&gt;Password Gorilla&lt;/a&gt; - See this &lt;a href="http://www.fpx.de/fp/Software/Gorilla/help.html"&gt;Using Password Gorilla&lt;/a&gt; page for an overview.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Pick at least one tool from each category and learn to use them, then use them always.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;And  for those of you who say “Claus, put all my wicked crazy passwords  (from PWGen) in an encrypted database password manager (KeePass) and  stick them on my USB drive for fast access? What if I loose it?”&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I suppose you could create a &lt;a href="http://www.truecrypt.org/"&gt;TrueCrypt&lt;/a&gt; encrypted file, then put the encrypted KeePass data base inside it…&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Just be sure you select a different crazy complex random password for each of them.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;And put them in another password manager for safekeeping in case you forget.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;轉自 http://grandstreamdreams.blogspot.com/2012/01/password-is.html&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-1715577849389617149?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/1715577849389617149/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=1715577849389617149&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1715577849389617149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1715577849389617149'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/password-is.html' title='The Password is…'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/-m_5dK8BSvJ8/TxTnCMT8O8I/AAAAAAAAA7w/UuwXstOIkxM/s72-c/z0sfabbn.qeg%25255B5%25255D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-4768154673857834257</id><published>2012-01-24T20:24:00.001+08:00</published><updated>2012-01-24T20:24:00.522+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>It’s a USB Thing</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I was working on a USB project recently and needed to capture an image of a USB device for restoration.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;That got me reviewing my pile of USB tools and looking for updates. Found some and a bunch of new-to-me freeware USB tools.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Here you go.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.alexpage.de/usb-image-tool/"&gt;USB Image Tool&lt;/a&gt; - alex’s coding playground - updated to v 1.58 with some nice fixes.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.osforensics.com/tools/write-usb-images.html"&gt;ImageUSB - Write an image to multiple USB Flash Drives&lt;/a&gt; - PassMark Software - great standalone tool to make/push images of USB flash drive devices. Hard to go wrong with this one!&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://quick.mixnmojo.com/software/usb-disk-ejector"&gt;USB Disk Ejector&lt;/a&gt;  - Quick And Easy Software - This is a “cutsie” app but seems much easer  to me to use than hunting in the system tray for the Windows USB device  ejection method. Definitely makes it easier to identify the correct  device when there are more than one connected and I’m rushing.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://deveject.com/"&gt;Dev Eject&lt;/a&gt;  - Stop right now and add this one to your utility pile. Seriously. A  co-worker has been having problems ejecting USB HDD devices from his XP  system and turned to me to figure things out. He didn’t think he had any  open calls to the device running and &lt;a href="http://www.nirsoft.net/utils/opened_files_view.html"&gt;OpenedFilesView&lt;/a&gt;  didn’t report any clues either. I turned to Dev Eject and immediately  found the culprit: Symantec AV seemed to be doing a file-scan (slowly)  when he was ejecting the device. More info in this AddictiveTips post: &lt;a href="http://www.addictivetips.com/windows-tips/identify-processes-hindering-removable-media-ejection-with-dev-eject/"&gt;Identify Processes Hindering Removable Media Ejection With Dev Eject&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://betanews.com/2011/11/24/use-command-line-to-safely-remove-usb-drives/"&gt;Use command line to safely remove USB drives&lt;/a&gt; by Mike Williams at BetaNews has a lot of clever tips.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Want lots of freeware USB tools? Serious, low level USB tools? CLI USB tools (and then some)?&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Uwe Sieber’s got you covered! &lt;a href="http://www.uwe-sieber.de/drivetools_e.html"&gt;Drive Tools for Windows&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;RemoveDrive V2.2 - Safe removal of drives&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;RestartSrDev - restarts "Safely Removed" devices which have the "Code 21" problem code&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;EjectMedia V2.2 - ejects a media from a drive&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;ReMount - reassigning mounpoints (change drive letters)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;ListDosDevices&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;USB-WriteCache V0.1&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.uwe-sieber.de/usbdlm_e.html"&gt;USB Drive Letter Manager - USBDLM&lt;/a&gt; (Note: USBDLM is Freeware for private and educational (schools, colleges, universities) use only.)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://mt-naka.com/hotswap/index_enu.htm"&gt;HotSwap!&lt;/a&gt; - Kazuyuki Nakayama - gives more friendly interface than the “Safely Remove Hardware” icon in the system tray does.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.nirsoft.net/utils/usb_log_view.html"&gt;USBLogView&lt;/a&gt; - NirSoft tool to record all USB devices plugged into a system and logs to a file.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.nirsoft.net/utils/usb_devices_view.html"&gt;USBDeview v2.00&lt;/a&gt; - NirSoft tool to list all USB devices plugged into a system as well as all USB devices previously used (with details).&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.rmprepusb.com/"&gt;RMPrepUSB&lt;/a&gt;  - Tool to partition and format USB drive and make it bootable. Free for  private use only. If you know what you are doing, this tool isn’t  needed but it goes a long way to helping noobies and the author has a  large number of tutorials as well. More here: &lt;a href="http://agnipulse.com/2010/04/rmprepusb-amazing-usb-formatting-tool/"&gt;RMPrepUSB – Amazing USB Formatting Tool!&lt;/a&gt; - post from AgniPulse,&lt;a href="http://www.thewindowsclub.com/rmprepusb-install-windows-usb-speed-up"&gt;RMPrepUSB : Install Windows on USB, Speed up USB and do more with it&lt;/a&gt; via The Windows Club and &lt;a href="http://www.addictivetips.com/windows-tips/rmprepusb-create-bootable-windows-linux-usb-test-rw-speed-more/"&gt;RMPrepUSB: Create Bootable Windows/Linux USB, Test R/W Speed &amp;amp; More&lt;/a&gt; post via AddictiveTips.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.addictivetips.com/windows-tips/how-to-create-customizable-multiboot-system-rescue-disk/"&gt;How To Create Customizable Multiboot System Rescue Disk&lt;/a&gt; - AddictiveTips post on using &lt;a href="http://www.sarducd.it/"&gt;SARDU&lt;/a&gt; builder to make a multiboot USB tool.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;轉自 http://grandstreamdreams.blogspot.com/2012/01/its-usb-thing.html&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-4768154673857834257?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/4768154673857834257/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=4768154673857834257&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4768154673857834257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4768154673857834257'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/its-usb-thing.html' title='It’s a USB Thing'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-7225311540452687946</id><published>2012-01-23T20:22:00.000+08:00</published><updated>2012-01-23T20:22:00.158+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Digital Image\Video Resources</title><content type='html'>Little bro recently made a Christmas contribution to the “Claus-needs-a-new-hobby” campaign.&lt;br /&gt;While  a portion of it does involve me staying up much later each night now  (like I needed that bad-habit) reading George R. R. Martin's “Game of  Thrones” series on my Kindle, the most recent focus is the coming  addition of a &lt;a href="http://usa.canon.com/cusa/consumer/products/cameras/digital_cameras/powershot_s95"&gt;Canon PowerShot S95&lt;/a&gt; to my photography tools.&lt;br /&gt;For the longest time I have been seriously looking at the newer digital rangefinder class of cameras and the &lt;a href="http://www.amazon.com/Olympus-Interchangeable-Lens-14-42mm-Silver/dp/B002CGSYKS/ref=sr_1_3?s=electronics&amp;amp;ie=UTF8&amp;amp;qid=1326742708&amp;amp;sr=1-3"&gt;Olympus PEN E-P1&lt;/a&gt;  (Amazon link) fell into my price-point. I’ve yearned for this one for  some time, however this particular model has been updated several times  (more $$) and the &lt;a href="http://www.amazon.com/Canon-PowerShot-S95-Stabilized-3-0-Inch/dp/B003ZSHNGS/ref=sr_1_2?s=photo&amp;amp;ie=UTF8&amp;amp;qid=1326340631&amp;amp;sr=1-2"&gt;Canon PowerShot S95&lt;/a&gt;  (Amazon link) was in the same range (price-wise). Though it also has a  newer version, this one just seemed to have many more features (do I  really need 1080p video when the S95’s 720p only video may never get  used either?).&lt;br /&gt;In the end it was the collection of &lt;a href="http://www.flickr.com/groups/canonpowershot_s95/"&gt;Flickr: Canon PowerShot S95&lt;/a&gt;  group photos that sold me on it along with the smaller  (pocket/backpack) format over the E-P1. It came down to me being honest  with myself. I can’t take good pictures and improve my technique if I  don’t carry the camera with me almost all times to take pictures to  begin with…and the S95 is much more pocketable (and less imposing when  in use) than the E-P1 or my Canon Rebel XT DSLR. So, photography links  on the sidebar have been amended to remove the PEN and add the S95.&lt;br /&gt;Hope to share some pics from it soon.&lt;br /&gt;So, that leads us into these great digital imaging tools I’ve found recently (or have been updated).&lt;br /&gt;&lt;a href="http://research.microsoft.com/en-us/um/redmond/groups/ivm/ice/"&gt;Microsoft Research Image Composite Editor (ICE)&lt;/a&gt; - This remains my favorite image-stitching tool. Can also handle video stitching techniques: &lt;a href="http://hdview.wordpress.com/2011/04/05/microsoft-ice-updatevideo-to-panorama-lens-vignette-improved-blending/"&gt;Microsoft ICE update–video to panorama, lens vignette, improved blending&lt;/a&gt; - HD View&lt;br /&gt;&lt;a href="http://hugin.sourceforge.net/"&gt;Hugin - Panorama photo stitcher&lt;/a&gt;  - This is a new-to-me project. It looks a lot more sophisticated that  ICE so I’m looking forward to trying it out as well. It has a lot of  control.&lt;br /&gt;&lt;a href="http://www.scarablabs.com/scarab-darkroom"&gt;Scarab Darkroom&lt;/a&gt;  - Beta version is free. From the page “Scarab Darkroom is a digital  camera raw file converter/photo editor that supports most raw format  capable cameras from Canon, Nikon, Olympus, Panasonic, Pentax, Samsung,  and Sony. It is fast, easy to use, and produces excellent results.  Development is still at the beta version stage.”&amp;nbsp; My S95 has Raw+JPEG  shooting format…. More here at AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/edit-and-convert-raw-image-to-jpg-with-scarab-darkroom/"&gt;Edit And Convert RAW Images To JPG With Scarab Darkroom&lt;/a&gt;&lt;br /&gt;It’s been a while since I last posted a roundup of freeware video editing tools: &lt;a href="http://grandstreamdreams.blogspot.com/2009/07/video-editing-resource-roundup.html"&gt;grand stream dreams: Video-Editing Resource Roundup&lt;/a&gt;&lt;br /&gt;Here are some new links: &lt;a href="http://www.thewindowsclub.com/free-video-editing-software-download-windows?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=free-video-editing-software-download-windows"&gt;Top 3 free video editing software for Windows 7&lt;/a&gt; via The Windows Club links to &lt;a href="http://fixounet.free.fr/avidemux/download.html"&gt;Avidemux&lt;/a&gt;, &lt;a href="http://virtualdub.org/download.html"&gt;VirtualDub&lt;/a&gt;, and &lt;a href="http://videospin.com/Redesign/"&gt;VideoSpin&lt;/a&gt;.&lt;br /&gt;What amazes me is that the pro-class &lt;a href="http://www.lightworksbeta.com/"&gt;Lightworks&lt;/a&gt;  Open Source Project (free!) for video editing never seems to come up.  It is incredible. Is it too complicated? I’m looking forward to shooting  some 720p video to experiment with the application.&lt;br /&gt;&lt;br /&gt;轉自 http://grandstreamdreams.blogspot.com/2012/01/digital-imagevideo-resources.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-7225311540452687946?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/7225311540452687946/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=7225311540452687946&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7225311540452687946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7225311540452687946'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/digital-imagevideo-resources.html' title='Digital Image\Video Resources'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-5990885636973584453</id><published>2012-01-22T20:19:00.001+08:00</published><updated>2012-01-22T20:19:00.017+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Utility Updates</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Quick linkfest running down some old tools updated and new tools discovered.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963902"&gt;Autoruns v11.21&lt;/a&gt;:  This update to Autoruns fixes a number of minor bugs, including one  that could result in a crash when certain scheduled tasks are  configured. Microsoft Sysinternals.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653"&gt;Process Explorer v15.12&lt;/a&gt;:  This update to Process Explorer makes the search dialog asynchronous  and reports the types of found items. It also fixes several bugs,  including showing a small font when run after an older version, a bug in  the restart-process functionality, working set columns not showing  data, and again shows information about service processes when run from  an unprivileged user account. Microsoft Sysinternals.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb897439"&gt;Strings v2.42&lt;/a&gt;:  This Strings release fixes a bug that would result in a crash when the  –n or -b options are specified without a file name. Microsoft  Sysinternals.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://blogs.technet.com/b/markrussinovich/archive/2011/11/29/3467449.aspx"&gt;Mark’s Blog: Case of the Installer Service Error&lt;/a&gt;:  Follow along with Mark in another of his popular ‘Case of the  Unexplained’ troubleshooting examples where he retraces the steps of a  network administrator that used Process Monitor to figure out why the  Windows Intune installer failed on one of his systems and goes on to fix  the problem.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://blogs.technet.com/b/markrussinovich/archive/2012/01/05/3473797.aspx"&gt;Mark’s Blog: The Case of My Mom’s Broken Microsoft Security Essentials Installation&lt;/a&gt;: Mark goes deep with the Sysinternals tools to fix a corrupt installation of MSE on his mom’s PC over the holidays.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://csved.sjfrancke.nl/"&gt;CSVed 2.2.1&lt;/a&gt; - Now at 2.2.1 version.&amp;nbsp; See also NirSoft’s &lt;a href="http://www.nirsoft.net/utils/csv_file_view.html"&gt;CSVFileView&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.piriform.com/blog/2011/12/21/ccleaner-v314"&gt;CCleaner v3.14&lt;/a&gt; - Piriform - System cleaner&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.piriform.com/blog/2011/12/1/recuva-v142"&gt;Recuva v1.42&lt;/a&gt; - Piriform - File recovery tool&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.piriform.com/blog/2011/11/24/speccy-v114"&gt;Speccy v1.14&lt;/a&gt; - Piriform - System information collector&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://singularlabs.com/software/ccenhancer/"&gt;CCEnhancer&lt;/a&gt; - v 2.5 - SingularLabs - plugin for CCleaner adding support for over 500 additional aps.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://singularlabs.com/software/javara/"&gt;JavaRa&lt;/a&gt; - v 1.16 - SingularLabs - not updated but great tool to remove old/redundant versions of JRE.&amp;nbsp; Now under development is &lt;a href="http://singularlabs.com/2011/12/16/javara-2-0-alpha-build-available/"&gt;JavaRa 2.0 alpha build&lt;/a&gt; which includes updating, removal and some additional bells-n-whistles.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.wecode.biz/p/alternative-flash-player-auto-updater.html"&gt;Wecode.biz: Alternative Flash Player Auto-Updater&lt;/a&gt;  - interesting tool to help update Adobe Flash Player. The latest builds  of Flash Player do have an auto-updating feature baked in but it  doesn’t (to me) seem to fire off and find newer builds as quickly as I  would like to see. This is an alternative that might work good on  friends and family PC’s.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://isc.sans.edu/diary.html?storyid=12166&amp;amp;rss"&gt;ISC Diary | Newest Adobe Flash 11.1.102.55 and Previous 0 Day Exploit&lt;/a&gt; -Why keeping Flash updated is important…as if we didn’t need a reminder.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://crystalmark.info/?lang=en"&gt;Crystal Dew World&lt;/a&gt; - lots of updates here including CrystalDiskInfo and CrystalDiskMark&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.nirsoft.net/utils/application_crash_report.html"&gt;WinCrashReport - Displays a report about crashed Windows application&lt;/a&gt; - New NirSoft tool. See also this post by Nir Softer himself : &lt;a href="http://blog.nirsoft.net/2011/08/26/new-crash-reporting-utility-for-windows/"&gt;New crash reporting utility for Windows&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.nucleustechnologies.com/pst-viewer.html"&gt;PST Viewer - Free tool to open and view content of PST files without Ms Outlook&lt;/a&gt; - Kernel Data Recovery. See also this review: &lt;a href="http://betanews.com/2011/09/12/gave-up-microsoft-outlook-but-need-your-pst-file-theres-an-app-for-that/"&gt;Gave up Microsoft Outlook but need your PST file? There's an app for that&lt;/a&gt; - BetaNews. I like this tool in that when I recently had to &lt;a href="http://www.cgsecurity.org/wiki/PhotoRec"&gt;carve the PST files off a nuked HDD&lt;/a&gt;  to recover an end-users PST files, I got a ton of them. Rather than  mounting each one to a working Outlook client profile, I just fired up  this tool to inspect them with the user to find out which ones we wanted  to attach and which ones were duplicates. Saved a boat-load of time.  Could be good for incident responders as well.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://blog.mandiant.com/archives/1936"&gt;Highlighter v1.1.3 Released&lt;/a&gt; - Mandiant M-unition blog notice. &lt;a href="http://www.mandiant.com/products/free_software/highlighter/"&gt;Download link&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://sourceforge.net/projects/batchcompiler/"&gt;Download Batch Compiler&lt;/a&gt;  - SourceForge - You need to install on a system (not portable) but  still could be a great resource for building more complex batch files.  See more info here at AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/batch-compiler-create-batch-scripts-convert-them-to-exe-format/"&gt;Batch Compiler: Create Batch Scripts &amp;amp; Convert Them To EXE Format&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.splashtop.com/remote"&gt;Splashtop Remote Desktop&lt;/a&gt; - interesting new tool for remote connection management. See this &lt;a href="http://www.windows7hacker.com/index.php/2012/01/splashtop-is-a-better-alternative-to-windows-rdp/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+windows7hacker+%28windows7hacker%29"&gt;Splashtop Is A Better Alternative To Windows RDP&lt;/a&gt; at Windows7hacker blog.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://wlwbackup.codeplex.com/"&gt;Windows Live Writer Backup&lt;/a&gt; - Codeplex project page - See this &lt;a href="http://www.windows7hacker.com/index.php/2011/12/windows-live-writer-backup/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+windows7hacker+%28windows7hacker%29"&gt;Windows Live Writer Backup&lt;/a&gt; post at Windows7hacker blog.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-5990885636973584453?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/5990885636973584453/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=5990885636973584453&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5990885636973584453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5990885636973584453'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/utility-updates.html' title='Utility Updates'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-1359962060674195537</id><published>2012-01-21T20:20:00.000+08:00</published><updated>2012-01-21T20:20:01.200+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>File and Folder Linkfest</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;As we continue the dig-out over here at the Valca link farm we now must turn attention to file and folder management tools.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://trackfolderchanges.codeplex.com/"&gt;Track Folder Changes&lt;/a&gt;  - CodePlex project page - really clever tool still in development that  shows (real-time) as files/folders are being changes for a specific  folder/directory to be monitored. Nice GUI. More information at &lt;a href="http://www.windows7hacker.com/index.php/2011/11/track-folder-changes-in-real-time"&gt;Track Folder Changes in Real Time&lt;/a&gt; Windows7hacker post and &lt;a href="http://www.freewaregenius.com/2011/11/12/track-changes-to-folders-with-track-folder-changes/"&gt;Track changes to folders with Track Folder Changes&lt;/a&gt; post at freewaregenius.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.nirsoft.net/utils/search_my_files.html"&gt;SearchMyFiles&lt;/a&gt; - NirSoft - Soo love this tool! It’s one of my must-haves for file-finding.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.voidtools.com/"&gt;Everything Search Engine&lt;/a&gt;  - Love this one too. Wicked fast but does it by building its own index  database. Doesn’t search within files; just file/folder names.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.jam-software.com/ultrasearch/?language=EN"&gt;UltraSearch - Freeware for Ultra-Fast File Search&lt;/a&gt;  - JamSoftware - A bit like Everything but doesn’t build an index  database rather relies on the MFT. Comes with a portable version.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://locate32.net/component/option,com_frontpage/Itemid,1/"&gt;Locate32 Web Site&lt;/a&gt; - Another nice free Windows file indexing application.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.irnis.net/soft/xfff/"&gt;eXpress FreshFiles Finder&lt;/a&gt; - Super-great tool to quickly find the “freshest” files on a system.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.topsoftwaresite.nl/"&gt;FileProcessor&lt;/a&gt; - really powerful tool to find files as well as perform a number of actions on those found files. More info via AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/fileprocessor-set-filters-search-perform-batch-actions-on-files/"&gt;FileProcessor: Set Filters, Search &amp;amp; Perform Batch Actions On Files&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.uderzo.it/main_products/space_sniffer/index.html"&gt;SpaceSniffer&lt;/a&gt; - Love it to visualize space usage on drives.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.allsync.biz/en_getfoldersize.htm"&gt;GetFolderSize&lt;/a&gt; - Interesting tool for scanning file/folder size usage on drives. Different GUI but pretty cool! Spotted via &lt;a href="http://www.windows7hacker.com/index.php/2011/11/getfoldersize-to-determine-the-size-of-folders-on-your-hard-drive"&gt;GetFoldersize to Determine the Size of Folders on Your Hard Drive&lt;/a&gt; - Windows7hacker.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.sulaco.co.za/downloads.htm"&gt;FolderSize&lt;/a&gt; - Jan Horns tiny but quick app for folder size reporting.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.novirusthanks.org/download/"&gt;NoVirusThanks Freeware tools&lt;/a&gt; - interesting tools (free and commercial) for Windows system monitoring. Good overview on them here: &lt;a href="http://www.softwarecrew.com/2011/12/novirusthanks-releases-four-handy-system-monitoring-tools-as-freeware/"&gt;NoVirusThanks releases four handy system monitoring tools as freeware&lt;/a&gt; -Softwarecrew.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cgsecurity.org/wiki/TestDisk"&gt;TestDisk - CGSecurity&lt;/a&gt; - Now at Version 6.13 for file/disk recovery.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://odin-win.sourceforge.net/"&gt;ODIN - Open Disk Imager for Windows&lt;/a&gt; - interesting GUI/CLI based tool for drive backup and imaging. More info via AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/backup-restore-and-verify-disk-images-with-odin/"&gt;Backup, Restore And Verify Disk Images With ODIN&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.hardwipe.com/"&gt;Hardwipe | File &amp;amp; Drive Wiper&lt;/a&gt;  - GSD has had a number of posts already regarding file/drive wiping but  this new-to-me tool is worth mentioning here. More info via  AddictiveiIps: &lt;a href="http://www.addictivetips.com/windows-tips/easily-wipe-clean-files-folders-and-hard-drives-with-hardwipe/"&gt;Easily Wipe &amp;amp; Clean Files, Folders And Hard Drives With Hardwipe&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.hexacorn.com/blog/2011/12/19/forensic-riddle-5-answer-2/"&gt;Forensic Riddle #5 – Answer&lt;/a&gt; - Hexacorn Blog has been posting a series of great puzzlers this one leads us to this clever Microsoft resource: &lt;a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa365247%28v=vs.85%29.aspx"&gt;Naming Files, Paths, and Namespaces&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://winaero.com/download.php?view.16"&gt;TakeOwnershipEx&lt;/a&gt; - WinAero - GUI tool that allows you to get full access to files and folders. More info via AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/take-ownership-of-files-and-folders-in-windows-8/"&gt;Take Ownership Of Files And Folders In Windows 8&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://dbc-studio.blog.163.com/blog/static/75751050201141683429667/"&gt;NTFS Permissions Tools 最新进展 (ver 1.0.0.45078 RC1 (2011-06-14))&lt;/a&gt; - Site is Chinese but AddictiveTips has the lowdown on usage here: &lt;a href="http://www.addictivetips.com/windows-tips/allocate-ntfs-permissions-easily-with-ntfs-permissions-tool/"&gt;Allocate NTFS Permissions Easily With NTFS Permissions Tool&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://sourceforge.net/projects/kickassundelete/files/Kickass%20Undelete%201.2%20beta/"&gt;Kickass Undelete - Browse /Kickass Undelete 1.2 beta&lt;/a&gt;  - SourceForge.net - I really like this tool for file recovery. It’s not  a all-in-one recovery tool, but is another great utility to keep on  your response toolbelt.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://winaero.com/comment.php?comment.news.8"&gt;WinAero: Librarian&lt;/a&gt; - powerful libraries manager for Windows 7. Slick interface and easy tool to use.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://bexplorer.codeplex.com/"&gt;BExplorer (Better Explorer)&lt;/a&gt;  - CodePlex - I want to like this project very much. I’m not feeling the  love of the existing Windows 7 explorer menu-bar and this would go a  long way to making it more powerful to use. However I’ve also had  stability/installation issues on both Win7 x32/x64 systems so while it  is on my “watch-list” it isn’t yet installed on my system.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.freecommander.com/"&gt;FreeCommander&lt;/a&gt;  - This alternative dual-pane Windows file manager remains  top-of-the-heap on my systems. It is required usage here at GSD. I’ve  still not found a better alternative though many come close. The  developer is hard at work on a new version and the betas look very slick  and powerful. Whenever the final public release of that one comes out.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://myco.yonan.ro/?page_id=202"&gt;My Commander&lt;/a&gt;  - The interface on this one looks remarkably similar to FreeCommander.  It comes in both 32bit and 64 bit flavors. It is quite nice and would  probably be a close runner-up.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://xiles.net/nexusfile/"&gt;NexusFile: File Manager for Windows&lt;/a&gt; - This is one with GUI attitude. Want a nice “dark” look? This is it.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.explorerplusplus.com/"&gt;Explorer++&lt;/a&gt;  - I like this one as a USB stick alternative. Constantly updated and in  both x32/x64 flavors it is a single EXE file which makes it nicely  portable.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.alterion.us/a43/"&gt;A43&lt;/a&gt; - this  was my original love in alternative WIndows file managers. It remains  alive in development and has a lot of handy plugins in a format that  others don’t seem to offer. Check it out.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-1359962060674195537?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/1359962060674195537/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=1359962060674195537&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1359962060674195537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1359962060674195537'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/file-and-folder-linkfest.html' title='File and Folder Linkfest'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-1216503942713821854</id><published>2012-01-20T20:18:00.000+08:00</published><updated>2012-01-20T20:18:00.488+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>EXIF/meta-data Linkage</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Been sitting on these for a while (sigh).&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.metabilitysoftware.com/"&gt;Metability Software&lt;/a&gt; is building a really cool and powerful tool to work with and explore EXIF data in images. &lt;a href="http://www.metabilitysoftware.com/products/filemind-professional.html"&gt;FileMind Professional&lt;/a&gt;.  It has a really nice tabbed main workspace and supports  importing/exporting and reporting of EXIF data. I’m using the current  (free) &lt;a href="http://www.metabilitysoftware.com/products/beta-lounge.html"&gt;Beta Software&lt;/a&gt; version and it rocks.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;They also offer a cool little freeware app &lt;a href="http://www.metabilitysoftware.com/products/filemind-quickfix.html"&gt;FileMind QuickFix&lt;/a&gt; which can strip out sensitive EXIF data before posting photo files to the web. Check it out.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.photome.de/home_en.html"&gt;PhotoME - Exif, IPTC &amp;amp; ICC Metadata Editor&lt;/a&gt;  is another free tool which can be used to show/display meta-data of  image files. It is exceptionally well-rounded and has been around for a  long time. Hat-tip to AddictiveTips for their post which led me to it: &lt;a href="http://www.addictivetips.com/windows-tips/photome-lets-you-view-analyze-and-edit-image-exif-iptc-metadata/"&gt;PhotoMe Lets You View, Analyze and Edit Image EXIF &amp;amp; IPTC Metadata&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.digitalconfidence.com/downloads.html"&gt;BatchPurifier LITE - Free Metadata Removal Tool&lt;/a&gt; - Another free tool to remove meta-data from files in batch.&amp;nbsp; See a review at AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/batch-remove-image-jpeg-metadata-with-batchpurifier-lite/"&gt;Batch Remove Image/JPEG Metadata With BatchPurifier Lite&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://translate.google.com/translate?rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=en&amp;amp;twu=1&amp;amp;u=http://www.kula-shaker.ru/autojpegtrunk-english"&gt;AutoJpegTrunk (Google Translated)&lt;/a&gt; - very simple freeware tool/wrapper for ExifTool by Phil Harvey to clean meta-data. Again spotted at AddictiveTips: &lt;a href="http://www.addictivetips.com/windows-tips/autojpegtrunk-exiftool-based-utility-to-batch-remove-image-meta-data/"&gt;AutoJpegTrunk: ExifTool-Based Utility To Batch Remove Image Meta Data&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.sno.phy.queensu.ca/%7Ephil/exiftool/"&gt;ExifTool by Phil Harvey&lt;/a&gt; - freeware awesomeness for the core tool of all things meta-data handling.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Need more? see these &lt;a href="http://www.sno.phy.queensu.ca/%7Ephil/exiftool/#links"&gt;Additional Resources&lt;/a&gt; on Phil Harvey’s page.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://vinetto.sourceforge.net/"&gt;Vinetto : a forensics tool to examine Thumbs.db files&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://cfed-ttf.blogspot.com/2007/12/vinetto-thumbs-db-parserviewer.html"&gt;Vinetto - A Thumbs DB Parser/Viewer&lt;/a&gt;  - Computer Forensics/E-Discovery Tips/Tricks and Information blog -  includes info to get it running on Win32 as well as a built Win32 copy  of Mark McKinnon’s work.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Why do we care about meta-data (examining and/or purging)?&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Well for starters “dere’s gold in dem dere hills!”&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.securityaegis.com/stealing-gps-data-from-images-in-pentests/"&gt;Stealing GPS Data from Images in Pentests&lt;/a&gt; - Security Aegis&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.knowyourfiles.com/2011/06/strip-your-images-not-yourself/"&gt;Strip your Images, not Yourself&lt;/a&gt;- Metability Software blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.knowyourfiles.com/2011/05/what-the-situation-room-really-shows/"&gt;What the Situation Room REALLY Shows…&lt;/a&gt;- Metability Software blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.knowyourfiles.com/"&gt;Know Your Files&lt;/a&gt; - Metability Software blog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.craigball.com/metadata.pdf"&gt;Beyond Data about Data: The Litigator's Guide to Metadata&lt;/a&gt; [PDF] 2005 - found via e-evidence.info&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="https://encrypted.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=walker%2C%20jessica%20m.%20what%27s%20a%20little%20metadata%20mining%20between%20colleagues%3F&amp;amp;source=web&amp;amp;cd=3&amp;amp;ved=0CC8QFjAC&amp;amp;url=http%3A%2F%2Fdocdet.mantech.com%2Fdocdet%2Farchive%2FWhat%2527s%2520a%2520Little%2520Metadata%2520Mining%2520Between%2520Colleagues.pdf&amp;amp;ei=I2wUT-37FIb22gXcp4DGCQ&amp;amp;usg=AFQjCNFrKxIov_C8gQWv4mMJrEhKSCaRqw"&gt;What's a Little Metadata Mining Between Colleagues&lt;/a&gt; [PDF] 2006 - Jessica M. Walker found via e-evidence.info&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.cerias.purdue.edu/news_and_events/events/symposium/2007/materials/pdfs/E26-CF9.pdf"&gt;Mobile Phones: Digital Photo Metadata&lt;/a&gt; [PDF Poster] 2007 - found via e-evidence.info. Note link to the “&lt;a href="http://carvey_gmu2005.zip/" title="http://www.windows-ir.com/Carvey_gmu2005.zip"&gt;Carvey_gmu2005.zip&lt;/a&gt;” file is broken so either it got moved or dropped. Maybe Harlan can repost or share the updated link? I’d love to see it.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://windowsir.blogspot.com/2005/08/gmu2005-presentations-updated.html"&gt;GMU2005 presentations&lt;/a&gt;  [Zipped PP Presentations] August 2005 -Harlan Carvey - Topics: The  Windows Event Log file format; Tracking USB storage devices across  Windows systems; File/document metadata. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://windowsir.blogspot.com/2011/07/updates.html"&gt;Windows Incident Response: Updates&lt;/a&gt; - Quoting Keydet89 from the linked post:&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;blockquote style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;span style="font-size: small;"&gt;“Did  you map all of the USB removable storage devices that had been  connected to the system?&amp;nbsp; You don't need to have the management software  installed to copy images and videos (hint, hint) off of a phone...just  connect it via a USB cable and copy the images (which will likely have  some very useful &lt;a href="http://www.sno.phy.queensu.ca/%7Ephil/exiftool/"&gt;EXIF&lt;/a&gt; data available).”&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;In  addition, there are a number of freeware (and $-$$$$) image  viewers/tools that also include meta-data handling embedded in them.  This post is focused on meta-data specific tools. I’ll post linkage on  some of the other applications that are more in this later class soon.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://grandstreamdreams.blogspot.com/2012/01/exifmeta-data-linkage.html &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-1216503942713821854?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/1216503942713821854/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=1216503942713821854&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1216503942713821854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/1216503942713821854'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/exifmeta-data-linkage.html' title='EXIF/meta-data Linkage'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-9205660618220990677</id><published>2012-01-19T20:12:00.000+08:00</published><updated>2012-01-19T20:12:00.902+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Active Directory Linkfest</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I’m working hard at getting up to speed on the whole Microsoft Active Directory thing.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Until  lately, I’ve not had either the need nor the opportunity to get heavily  involved in supporting customers in a full-blow AD environment. Sure,  there are some basic “foundational" things I’ve been able to pick up and  use, but now we are moving forward into a brave new world and I gotta  kick up my expertise a bit. I’ve already purchased and am working  through this excellent &lt;a href="http://www.amazon.com/Active-Directory-Designing-Deploying-Running/dp/059652059X/ref=pd_sim_b_1"&gt;Active Directory: Designing, Deploying, and Running Active Directory, Fourth Edition&lt;/a&gt; (Amazon.com link) book to get the ball rolling.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;So  expect a few more AD-related posts around here…at least on the front  end they will be more resource linking related as I fill out my virtual  bookshelf.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=20092"&gt;Group Policy for Beginners&lt;/a&gt; - Microsoft Download Center - Great MS Word file to introduce basic Group Policy concepts.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://learnthat.com/2008/07/introduction-to-active-directory/"&gt;Introduction to Active Directory&lt;/a&gt; - Learnthat.com - Nice heavily illustrated tutorial on Active Directory basics.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.microsoft.com/download/en/search.aspx?q=active%20directory"&gt;Active Directory Search Results&lt;/a&gt; - Microsoft Download Center. Lots and lots of documents, tools and tips.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.microsoft.com/events/series/adaug.aspx?tab=virtuallabs"&gt;Microsoft Events (Beta)&lt;/a&gt;  - Amazing Microsoft site chock-full of awesome webcasts, podcasts, and  virtual training sessions. All categorized, searchable, and level-rated&amp;nbsp;  Note the only “gotcha” is that the site seems to be driven by  Silverlight and is very Internet Explorer dependent. Don’t hop to these  pages in another browser unless it contains an IE-engine rendering  engine.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://events.microsoft.com/Pages/Home.aspx?k=active%20directory&amp;amp;cs=This%20Site&amp;amp;u=https%3A%2F%2Fevents.microsoft.com#m=;r=0;s=;yourrole=2;eventtype=2;level=2;timelength=2;v=list;pi=;mi=;si=;ai="&gt;Active Directory Related Pages&lt;/a&gt; - Microsoft Events - honed down to just AD items.&amp;nbsp; I’ve got a lot of work here.&amp;nbsp; For example, there is this &lt;a href="https://www.microsoft.com/resources/virtuallabs/step2-technet.aspx?LabId=08b57649-2fd1-4d28-ae29-1425049d4346&amp;amp;BToken=ex"&gt;Migrating from Novell NetWare to Windows Server 2003&lt;/a&gt; you can eventually find which includes the full lab as well as a PDF guide.&amp;nbsp; Cool!&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://msmvps.com/blogs/ad/archive/2009/12/17/free-active-directory-virtual-labs.aspx"&gt;Free Active Directory Virtual Labs&lt;/a&gt; - The Life of Brian&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=7887"&gt;Download: Remote Server Administration Tools for Windows 7 with SP1&lt;/a&gt; - Microsoft Download Center - Download Details&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=4950"&gt;Download: Group Policy Documentation Survival Guide&lt;/a&gt; - Microsoft Download Center - Download Details&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The &lt;a href="http://4sysops.com/"&gt;4sysops - For Windows Administrators&lt;/a&gt;  website hosted by Michael Pietroforte is my go-to source for the best  of tools and tips related to Windows system administration. It is full  of great information and resources related to Active Directory items!&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/tag/active-directory/"&gt;Active Directory&lt;/a&gt; - 4sysops - Link roundup of ALL AD-tagged posts at 4sysops&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/free-windows-active-directory-tools/"&gt;Free Active Directory Tools&lt;/a&gt; - 4sysops - Link roundup of ALL (free) AD-related tools featured on 4sysops&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-active-directory-telephone-book/"&gt;FREE: Active Directory Telephone Book&lt;/a&gt; - 4sysops - free tool to create an organizational phone-book based on AD information.&amp;nbsp; Knowledge is power!&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-active-directory-topology-diagrammer/"&gt;FREE: Active Directory Topology Diagrammer&lt;/a&gt; - 4sysops - New feature/tool supported by Visio 2003 or higher.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-sysadmin-anywhere-active-directory-management/"&gt;FREE: SysAdmin Anywhere – Active Directory Management&lt;/a&gt; - 4sysops - really slick interface on this tool to manage users in AD.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-ad-info-user-friendly-active-directory-reporting-tool/"&gt;FREE: AD Info – User friendly Active Directory reporting tool&lt;/a&gt; - 4sysops - full featured tool that has lots of pre-built queries for reporting.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-account-lockout-tools-view-lockout-status-and-unlock-account/"&gt;FREE: Account Lockout Tools – View lockout status and unlock account&lt;/a&gt; - 4sysops - Feature post on a component from &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=7af2e69c-91f3-4e63-8629-b999adde0b9e&amp;amp;DisplayLang=en"&gt;Microsoft’s Account Lockout and Management Tools&lt;/a&gt;. Sweet.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-ad-tidy-identify-last-logged-on-user-and-computer-accounts/"&gt;FREE: AD Tidy – Identify last logged on user and computer accounts&lt;/a&gt;  - 4sysops - “It can be used to identify when user/computer accounts  last logged on to the network and can tidy up these accounts in various  different ways.”&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/free-active-directory-explorer-active-directory-viewer/"&gt;FREE: Active Directory Explorer – Active Directory Viewer&lt;/a&gt; - 4sysops - Review and reminder of the must-have Microsoft Sysinternals &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb963907"&gt;AD Explorer&lt;/a&gt; utility. Power to the people!&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/how-to-disable-usb-drive-use-in-an-active-directory-domain/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+4sysops+%284sysops%29"&gt;How to disable USB drive use in an Active Directory domain&lt;/a&gt; - 4sysops - Just in case you need to…&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/troubleshoot-slow-logon-part-1-profile-size/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+4sysops+%284sysops%29"&gt;Troubleshoot slow logon – Part 1: Profile size&lt;/a&gt; - 4sysops - Great troubleshooting guide on login issues.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/troubleshoot-slow-logon-part-2-the-3-headed-monster/"&gt;Troubleshoot slow logon – Part 2: The 3-headed monster&lt;/a&gt;- 4sysops - Great troubleshooting guide on login issues continued.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4sysops.com/archives/change-the-local-administrator-password-on-multiple-computers-with-powershell/?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+4sysops+%284sysops%29"&gt;Change the local administrator password on multiple computers with PowerShell&lt;/a&gt; - 4sysops - Who doesn’t have to deal with this monster from time to time.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Expect more AD-related resource posts moving forward.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If you have any great and free AD-related tools, tips and resources please share in the comments!&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://grandstreamdreams.blogspot.com/2012/01/active-directory-linkfest.html &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-9205660618220990677?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/9205660618220990677/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=9205660618220990677&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9205660618220990677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9205660618220990677'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/active-directory-linkfest.html' title='Active Directory Linkfest'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-230362710260951925</id><published>2012-01-13T21:50:00.000+08:00</published><updated>2012-01-13T21:50:00.211+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><category scheme='http://www.blogger.com/atom/ns#' term='記憶體'/><title type='text'>Dual Purpose Volatile Data Collection Script</title><content type='html'>&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;When responding to a  potential security incident a capability is needed to quickly triage the  system to see what's going on. Is a rogue process running on the  system, whose currently logged onto the system, what other systems are  trying to connect over the network, or how do I document the actions I  took on the system. These are valid questions during incident response  whether the response is for an actual event or a simulation. One area to  examine to get answers is the systems' volatile data. Automating the  collection of volatile data can save valuable time which in turn helps  analysts examine the data faster in order to get answers. This post  briefly describes (and releases) the Tr3Secure volatile data collection  script I wrote.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Tr3Secure needed a  toolset for responding to systems during attack simulations and one of  the tools had to quickly collect volatile data on a system (I previously  discussed what Tr3Secure is &lt;a href="http://journeyintoir.blogspot.com/2011/12/jiir-updates.html"&gt;here&lt;/a&gt;).  However, the volatile data collection tool had to provide dual  functions. First and foremost it had to properly preserve and acquire  data from live systems. The toolset is initially being used in a  training environment but the tools and processes we are learning need to  be able to translate over to actual security incidents. What good is  mastering a collection tool that can’t be used during live incident  response activities? The second required function was the tool had to  help with training people on examining volatile data. Tr3Secure members  come from different information security backgrounds so not every member  will be knowledgeable about volatile data. Collecting data is one thing  but people will eventually need to know how to understand what the data  means. The DFIR community has a few volatile data collection scripts  but none of the scripts I found provided the dual functionality for  practical and training usage. So I went ahead and wrote a script to meet  our needs.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Practical Usage&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;These were some  considerations taken into account to ensure the script is scalable to  meet the needs for volatile data collection during actual incident  response activities.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;u&gt; Flexibility&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Different responses will  have different requirements on where to store the volatile data that’s  collected. At times the data may be stored on the same drive where the  DFIR toolset is located while at other times the data may be stored to a  different drive. I took this into consideration and the volatile data  collection script allows for the output data to be stored on a drive of  choice. If someone prefers to run their tools from a CD-ROM while  someone else works with a large USB removable drive then the script can  be used by the both of them.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Organize Output&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Troy Larson posted a few  lines of code from his collection script to the Win4n6 sometime ago.  One thing I noticed about his script was that he organized the output  data based on a case number. I incorporated his idea into my script; a  case number needs to be entered when the script is run on a system. A  case folder enables data collected from numerous systems to be stored in  the same folder (folder is named Data-Case#). In addition to organizing  data into a case folder, the actual volatile data is stored in a  sub-folder named after the system the data came from (system's computer  name is used to name the folder). To prevent overwriting data by running  the script multiple times on the same system I incorporated a timestamp  into the folder name (two digit month, day, year, hour, and minute).  Appending a timestamp to the folder name means the script can execute  against the same system numerous times and all of the volatile data is  stored in separate folders. Lastly, the data collected from the system  is stored in separate sub-folders for easier access. The screenshot  below shows the data collected for Case Number 100 from the system  OWNING-U on 01/01/2012 at 15:46.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-DtwvJpn9bAk/TwH5qtI7ayI/AAAAAAAAAbY/T_mogLlv8WY/s1600/1+folder+containing+data.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="282" src="http://1.bp.blogspot.com/-DtwvJpn9bAk/TwH5qtI7ayI/AAAAAAAAAbY/T_mogLlv8WY/s640/1+folder+containing+data.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Documentation&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Automating data  collection means that documentation can be automated as well. The script  documents everything in a collection log. Each case has one collection  log so regardless if data is collected from one or ten systems an  analyst will only have to worry about reviewing one log.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-1XheE-7JLQs/TwH56dIXFeI/AAAAAAAAAbk/hiu2nz0r5lY/s1600/2+collection+log+location.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="284" src="http://2.bp.blogspot.com/-1XheE-7JLQs/TwH56dIXFeI/AAAAAAAAAbk/hiu2nz0r5lY/s640/2+collection+log+location.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;The following  information is documented both to the screen for an analyst to see and a  collection log file: case number, examiner name, target system, user  account used to collect data, drives for tools and data storage, time  skew, and program execution. The script prompts the analyst for the case  number, their name, and the drive to store data on. This information is  automatically stored in the collection log so the analyst doesn’t have  to worry about maintaining documentation elsewhere. In addition, the  script prompts the analyst for the current date and time which is used  to record the time difference between the system and the actual time.  Every program executed by the script is recorded in the collection log  along with a timestamp of when the program executed. This will make it  easier to account for artifacts left on a system if the system is  examined after the script is executed. The screenshot below shows the  part of the collection log for the data collected from the system  OWNING-U.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-91R9AilUoUE/TwH66hPb3hI/AAAAAAAAAbw/7aISioIyiV4/s1600/3+collection+log.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="392" src="http://1.bp.blogspot.com/-91R9AilUoUE/TwH66hPb3hI/AAAAAAAAAbw/7aISioIyiV4/s640/3+collection+log.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Preservation&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;a href="http://www.ietf.org/rfc/rfc3227.txt"&gt;RFC 3227&lt;/a&gt;’s  Order of Volatility outlines that evidence should be collected starting  with the most volatile then proceeding to the less volatile. The script  takes into account the order of volatility during data collection. When  all data is selected for collection, the memory is first imaged then  volatile data is collected followed by collecting non-volatile data. The  volatile data collected is: process information, network information,  logged on users, open files, clipboard, and then system information. The  non-volatile data collected is installed software, security settings,  configured users/groups, system's devices, auto-runs locations, and  applied group policies. Another item the script incorporated from Troy  Larson’s comment in the Win4n6 group is preserving the prefetch files  before volatile data is collected. I never thought about this before I  read his comment but it makes sense. Volatile data gets collected by  executing numerous programs on a system and these actions can overwrite  the existing prefetch files with new information or files. Preserving  the prefetch files upfront ensures analysts will have access to most of  the prefetch files that were on the system before the collection  occurred (four prefetch files may be overwritten before the script  preserves them). The script uses robocopy to copy the prefetch files so  the file system metadata (timestamps, NTFS permissions, and file  ownership) is collected along with the files themselves. The screenshot  below shows the preserved files for system OWNING-U.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-ZBKxLiFPLqQ/TwH7OvKB27I/AAAAAAAAAb8/s-Es8Vuwi6I/s1600/4+preserved+prefetch+files.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="418" src="http://3.bp.blogspot.com/-ZBKxLiFPLqQ/TwH7OvKB27I/AAAAAAAAAb8/s-Es8Vuwi6I/s640/4+preserved+prefetch+files.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Tools Executed&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;The readme file  accompanying the script outlines the various programs used to collect  data. The programs include built-in Windows commands and third party  utilities. The screenshot below shows the tools folder where the third  party utilities are stored.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-aHLTuFtRLho/TwH7gyfbiII/AAAAAAAAAcI/mAgdxocSt6s/s1600/5+tools+folder.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="296" src="http://2.bp.blogspot.com/-aHLTuFtRLho/TwH7gyfbiII/AAAAAAAAAcI/mAgdxocSt6s/s640/5+tools+folder.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-otmyjFgsoiM/TwH7mAeklZI/AAAAAAAAAcU/ElYMb8OlLbE/s1600/6+tools+folder.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="536" src="http://4.bp.blogspot.com/-otmyjFgsoiM/TwH7mAeklZI/AAAAAAAAAcU/ElYMb8OlLbE/s640/6+tools+folder.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;I’m not going to discuss every program but I at least wanted to highlight a few. Windows &lt;a href="http://technet.microsoft.com/en-us/library/cc766465%28WS.10%29.aspx"&gt;diskpart command&lt;/a&gt;  allows for disks, partitions, and volumes to be managed through the  command line. The script leverages diskpart to make it easy for an  analyst to see what drives and volumes are attached to a system.  Hopefully, the analyst won’t need to open up Windows explorer to see  what the removable media drive mappings are since the script displays  the information automatically as shown below. Note, to make diskpart  work a text file needs to be created in the tools folder named  diskpart_commands.txt and the file needs to contain these two commands  on separate lines: list disk and list volume.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-VTYB_-Xae8c/TwH72b32CPI/AAAAAAAAAcg/TABlCli-6Po/s1600/7+diskpart+screenshot.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://3.bp.blogspot.com/-VTYB_-Xae8c/TwH72b32CPI/AAAAAAAAAcg/TABlCli-6Po/s640/7+diskpart+screenshot.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;a href="http://www.mandiant.com/products/free_software/memoryze/"&gt;Mandiant’s Memoryze&lt;/a&gt;  is used to obtain a forensic image of the system’s memory. Memoryze  supports a wide range of Windows operating systems which makes the  script more versatile for dumping RAM. The key reason the script uses  Memoryze is because it’s the only free memory imaging program I found  that allows an image to be stored in a folder of your choice. Most  programs will place the memory image in the same folder where the  command line is opened. This wouldn’t work because the image would be  dropped in the folder where the script is located instead of the drive  the analyst wants. Memoryze uses an xml configuration file to image RAM  so I borrowed a few lines of code from the MemoryDD.bat batch file to  create the xml file for the script. Note, the script only needs the  memoryze.exe; to obtain the exe install Memoryze on a computer then just  copy memoryze.exe to the Tools folder.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;a href="http://www.pxserver.com/WinAudit.htm"&gt;PXServer’s Winaudit&lt;/a&gt;  program obtains the configuration information from a system and I first  became acquainted with the program during my time performing  vulnerability assessments. The script uses Winaudit to collect some  non-volatile data including the installed software, configured  users/groups, and computer devices. Winaudit is capable of collecting a  lot more information so it wouldn’t be that hard to incorporate the  additional information by modifying the script.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Training Usage&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;These were the two items put into the script to assist with training members on performing incident response system triage.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Ordered Output Reports&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;The script collects a  wealth of information about a system and this may be overwhelming to  analysts new to examining volatile data. For example, the script  produces six different reports about the processes running on a system. A  common question when faced with so many reports is how should they be  reviewed. The script’s output reports have numbers which is the  suggested order for them to be reviewed. This provides a little  assistance to analysts until they develop their own process for  examining the data. The screenshots below shows the process reports in  the output folder and those reports opened in Notepad ++.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-lk43ZNztscw/TwH8b98RbvI/AAAAAAAAAcs/hG4IJvaaPZM/s1600/8+process+output.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="524" src="http://2.bp.blogspot.com/-lk43ZNztscw/TwH8b98RbvI/AAAAAAAAAcs/hG4IJvaaPZM/s640/8+process+output.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-FlIWoMiQ4j8/TwH8i4XVW5I/AAAAAAAAAc4/4Keqz2qqYuQ/s1600/9+notepad+%252B+processes.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="406" src="http://3.bp.blogspot.com/-FlIWoMiQ4j8/TwH8i4XVW5I/AAAAAAAAAc4/4Keqz2qqYuQ/s640/9+notepad+%252B+processes.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;u&gt;Understanding Tool Functionality and Volatile Data&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;The script needs to help  people better understand what the collected data means about the system  where it came from. Two great references for collecting, examining, and  understanding volatile data are &lt;a href="http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Second/dp/1597494224"&gt;Windows Forensic Analysis, 2nd edition&lt;/a&gt; and &lt;a href="http://www.amazon.com/Malware-Forensics-Investigating-Analyzing-Malicious/dp/159749268X/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1325350624&amp;amp;sr=1-1"&gt;Malware Forensics: Investigating and Analyzing Malicious Code&lt;/a&gt;.  I used both books when researching and selecting the script’s tools to  collect volatile data. What better ways to help someone better  understand the tools or data then by directing them to references that  explain it? I placed comments in the script containing the page number  where a specific tool is discussed and the data explained in both books.  The screenshot below shows the portion of the script that collects  process information and the references are highlighted in red.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-q0LxDJYXSUQ/TwH9AuWKSHI/AAAAAAAAAdE/wZIU-6nYQZw/s1600/10+References+in+comments.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="330" src="http://1.bp.blogspot.com/-q0LxDJYXSUQ/TwH9AuWKSHI/AAAAAAAAAdE/wZIU-6nYQZw/s640/10+References+in+comments.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Releasing the Tr3Secure Volatile Data Collection Script&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;There are very few  things I do forensically that I think are cool; this script happens to  be one of them. There are not many tools or scripts that work as  intended while at the same time provide training. People who have more  knowledge about volatile data can hit the ground running with the script  investigating systems. The script automates imaging memory image,  collecting volatile/non-volatile data, and documenting every action  taken on the system. People with less knowledge can leverage the tool to  learn how to investigate systems. The script collects data then the  ordered output and references in the comments can be used to interpret  the data. Talk about killing two birds with one stone.&lt;/span&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;The following is the location to the zip file containing the script and the readme file &amp;lt;&lt;a href="http://code.google.com/p/jiir-resources/downloads/detail?name=tr3secure_data-collection-script.zip&amp;amp;can=2&amp;amp;q="&gt;zip download link is here&lt;/a&gt;&amp;gt;. Please be advised, a few programs the script uses require administrative rights to run properly.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;轉自 http://journeyintoir.blogspot.com/2012/01/dual-purpose-volatile-data-collection.html&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-230362710260951925?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/230362710260951925/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=230362710260951925&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/230362710260951925'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/230362710260951925'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/dual-purpose-volatile-data-collection.html' title='Dual Purpose Volatile Data Collection Script'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-DtwvJpn9bAk/TwH5qtI7ayI/AAAAAAAAAbY/T_mogLlv8WY/s72-c/1+folder+containing+data.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-4743551917943654987</id><published>2012-01-11T21:29:00.000+08:00</published><updated>2012-01-11T21:29:00.749+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>找出 Linux 是否有隱藏的 Process 與 Port - unhide</title><content type='html'>很多 rootkits 用了一些隱藏技巧，用 netstat 也找不出來，這個時候可以用 &lt;a href="http://www.hkcode.com/linux-bsd-notes/172"&gt;chkrootkit&lt;/a&gt; 這類工具掃瞄，另外還可以用 Unhide 搜索是否有不尋常的 process 及 port。&lt;br /&gt;Unhide 是一個輕巧的安全工具，可以找出 rootkit 所開啟的 process 或 TCP/UDP ports，除了 Unix 版本外，它還有 Windows 版本。&lt;br /&gt;&lt;br /&gt;如果是使用 Redhat，可以到 &lt;a href="http://pkgs.org/download/unhide" target="_blank" title="unhide"&gt;pkgs.org&lt;/a&gt; 下載相應版本的 rpm 檔案裝。&lt;br /&gt;在 Debian / Ubuntu 則較簡單，用 apt-get 安裝就好了。&lt;br /&gt;&lt;br /&gt;&lt;div class="shell"&gt;# apt-get install unhide&lt;/div&gt;&lt;div class="shell"&gt;&amp;nbsp;&lt;/div&gt;至於使用上也是很簡單，一般上以下幾個指令就會搜索系統內隱藏的 process 及 ports:&lt;br /&gt;&lt;br /&gt;&lt;div class="shell"&gt;# unhide-posix proc&lt;br /&gt;# unhide-posix sys&lt;br /&gt;# unhide-tcp&lt;/div&gt;&lt;div class="shell"&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="shell"&gt;轉自 http://www.hkcode.com/linux-bsd-notes/615 &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-4743551917943654987?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/4743551917943654987/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=4743551917943654987&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4743551917943654987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4743551917943654987'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/linux-process-port-unhide.html' title='找出 Linux 是否有隱藏的 Process 與 Port - unhide'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-2113807593071206053</id><published>2012-01-09T21:53:00.000+08:00</published><updated>2012-01-09T21:53:00.403+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><title type='text'>Jump List Analysis</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I've recently spoke with a couple of analysts I know, and during the  course of these conversations, I was somewhat taken aback by how little  seems to be known or available with respect to Jump Lists.&amp;nbsp; Jump Lists  are artifacts that are new to Windows 7 (...not new as of Vista...), and  are also available in Windows 8.&amp;nbsp; This apparent lack of attention to  Jump Lists is most likely due to the fact that many analysts simply  haven't encountered Windows 7 systems, or that Jump Lists haven't played  a significant role in their examinations.&amp;nbsp; I would suggest, however,  that any examination that includes analysis of user activity on a system  will likely see some significant benefit from understanding and  analyzing Jump Lists.&lt;br /&gt;&lt;br /&gt;I thought what I'd try do is consolidate some information on Jump Lists  and analysis techniques in one location, rather than having it spread  out all over.&amp;nbsp; I should also note that I have a section on Jump Lists in  the upcoming book, &lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://www.amazon.com/Windows-Forensic-Analysis-Toolkit-Third/dp/1597497274/ref=sr_1_4?s=books&amp;amp;ie=UTF8&amp;amp;qid=1325076730&amp;amp;sr=1-4"&gt;&lt;i&gt;Windows Forensic Analysis 3/e&lt;/i&gt;&lt;/a&gt;,  but keep in mind that one of the things about writing books is that  once you're done, you have more time to conduct research...which means  that the information in the book may not be nearly as comprehensive as  what has been developed since I wrote that section.&lt;br /&gt;&lt;br /&gt;In order to develop a better understanding of these artifacts, I wrote  some code to parse these files.&amp;nbsp; This code consists of two Perl modules,  one for parsing the basic structure of the *.automaticDestinations-ms  Jump List files, and the other to parse LNK streams.&amp;nbsp; These modules not  only provide a great deal of flexibility with respect to what data is  parsed and how it can be displayed (TLN format, CSV, table, dumped into a  SQLite database, etc.), but also the depth to which the data parsing  can be performed. &lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Jump List Analysis&lt;/b&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-7_oKEQuD6MQ/TvseN4J8qtI/AAAAAAAAAf0/TLWwvIoWy38/s1600/images.jpg" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="187" src="http://4.bp.blogspot.com/-7_oKEQuD6MQ/TvseN4J8qtI/AAAAAAAAAf0/TLWwvIoWy38/s200/images.jpg" width="200" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;Jump  Lists are located within the user profile, and come in two flavors;  automatic and custom Jump Lists.&amp;nbsp; The automatic Jump Lists  (*.automaticDestinations-ms files located in &lt;i&gt;%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations&lt;/i&gt;)  are created automatically by the shell as the user engages with the  system (launching applications, accessing files, etc.).&amp;nbsp; These files  follow the &lt;a href="http://msdn.microsoft.com/en-us/library/dd942138%28v=prot.13%29.aspx"&gt;MS-CFB&lt;/a&gt; compound file binary format, and each of the numbered streams within the file follows the &lt;a href="http://msdn.microsoft.com/en-us/library/dd871305%28v=prot.13%29.aspx"&gt;MS-SHLLINK&lt;/a&gt; (i.e., LNK) binary format.&lt;br /&gt;&lt;br /&gt;The custom Jump Lists (*.customDestinations-ms files located in &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;i&gt;%UserProfile%\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations&lt;/i&gt;) are created when a user "pins" an item (see &lt;a href="http://www.youtube.com/watch?v=u8RdY9sylcw"&gt;this video&lt;/a&gt;  for an example of how to pin an item).&amp;nbsp; The *.customDestinations-ms  files are apparently just a series of LNK format streams appended to  each other.&lt;br /&gt;&lt;br /&gt;Each of the Jump List file names starts with a long string of characters  that is the application ID, or "AppID", that identifies the specific  application (and in some cases, version) used to access specific files  or resources.&amp;nbsp; There is a list of AppIDs on the &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;a href="http://www.forensicswiki.org/wiki/List_of_Jump_List_IDs"&gt;ForensicsWiki&lt;/a&gt;, as well as one on the &lt;a href="http://forensicartifacts.com/2011/09/jump-list-appids/"&gt;ForensicArtifacts&lt;/a&gt; site.&lt;br /&gt;&lt;br /&gt;From an analysis perspective, the existence of automatic Jump Lists is  an indication of user activity on the system, and in particular  interaction via the shell (Windows Explorer being the default shell).&amp;nbsp;  This interaction can be via the keyboard/console, or via RDP.&amp;nbsp; Jump  Lists have been found to persist after an application has been deleted,  and can therefore provide an indication of the use of a particular  application (and version of that application), well after the user has  removed it from the system.&amp;nbsp; Jump Lists can also provide indications of  access to specific files and resources (removable devices, network  shares).&amp;nbsp; &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;Further, the binary structure of the automatic Jump Lists provides  access to additional time stamp information.&amp;nbsp; For example, the  structures for the compound binary file directory entries contain fields  for creation and modification times for the storage object; while  writing and testing code for parsing Jump Lists, I have only seen the  creation dates populated.&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Digging Deeper: LNK Analysis&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Within the automatic Jump List files, all but one of the streams (i.e.,  the DestList stream) are comprised of LNK streams.&amp;nbsp; That's right...the  various numbered streams are comprised of binary streams following the &lt;a href="http://msdn.microsoft.com/en-us/library/dd871305%28v=prot.13%29.aspx"&gt;MS-SHLLINK&lt;/a&gt; binary format.&amp;nbsp; As such, you can either use something like MiTeC's &lt;a href="http://www.mitec.cz/ssv.html"&gt;SSV&lt;/a&gt;  to view and extract the individual streams, and then use an LNK viewer  to view the contents of each stream, or you can use Mark Woan's &lt;a href="http://www.woanware.co.uk/?page_id=266"&gt;JumpLister&lt;/a&gt;  to view and extract the contents of each stream (including the DestList  stream).&amp;nbsp; The numbered streams do not have specific MAC times  associated with them (beyond time stamps embedded in MS-CFB format  structures), but they do contain MAC time stamps associated with the  target file.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Most any analyst who has done LNK file analysis is aware of the wealth  of information contained in these files/streams.&amp;nbsp; My own testing has  shown that various applications populate these streams with different  contents.&amp;nbsp; One thing that's of interest...particularly since it was  pointed out in Harry Parsonage's &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;a href="http://computerforensics.parsonage.co.uk/linkfiles/linkfiles.htm"&gt;&lt;i&gt;The Meaning of LIFE&lt;/i&gt;&lt;/a&gt;  paper...is that some LNK streams (I say "some" because I haven't seen  all possible variations of Jump Lists yet, only a few...) contain &lt;a href="http://msdn.microsoft.com/en-us/library/dd891345%28v=prot.13%29.aspx"&gt;ExtraData&lt;/a&gt; (defined in the binary specfication), including a &lt;a href="http://msdn.microsoft.com/en-us/library/dd891376%28v=prot.13%29.aspx"&gt;TrackerDataBlock&lt;/a&gt;.&amp;nbsp;  This structure contains a machineID (name of the system), as well as  two "Droids", each of which consists a VolumeID GUID and a version 1  UUID (ObjectID).&amp;nbsp; These structures are used by the Link Tracking  Service; the first applies to the new volume (where the target file  resides now), and the second applies to the birth volume (where the  target file was when the LNK stream was created).&amp;nbsp; As demonstrated in  Harry's paper, this information can be used to determine if a file was  moved or copied; however, this analysis is dependent upon the LNK stream  being created prior to the action taking place.&amp;nbsp; The code that I wrote  extracts and parses these values into their components, so that checks  can be written to automatically determine if the target file was moved  or copied.&lt;br /&gt;&lt;br /&gt;There's something specific that I wanted to point out here that has to  do with LNK and Jump List analysis.&amp;nbsp; The format specification for the  ObjectID found in the TrackerDataBlock is based on UUID version 1,  defined in &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;a href="http://www.faqs.org/rfcs/rfc4122.html"&gt;RFC 4122&lt;/a&gt;.&amp;nbsp;  Parsing the second half of the "droid" should provide a node identifier  in the last 6 bytes of stream.&amp;nbsp; Most analysts simply seem to think that  this is the MAC address (or &lt;i&gt;a&lt;/i&gt; MAC address) for the system on  which the target file was found.&amp;nbsp; However, there is nothing that I've  found thus far that states emphatically that it &lt;i&gt;MUST&lt;/i&gt; be the MAC address; rather, all of the resources I've found indicate that this value &lt;i&gt;can be&lt;/i&gt;  a MAC address.&amp;nbsp; Given that a system's MAC address is not stored in the  Registry by default, analysis of an acquired image makes this value  difficult to verify.&amp;nbsp; As such, I think that it's very important to point  out that while this value can be a MAC address, there is nothing to  specifically and emphatically state that it must be a MAC address.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DestList Stream&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;The DestList stream is found only in the automatic Jump Lists, and does not follow the MS-SHLLINK binary format (go &lt;a href="http://windowsir.blogspot.com/2011/06/meetup-tools-and-other-stuff.html"&gt;here&lt;/a&gt; to see the publicly documented structure of this stream).&amp;nbsp; Thanks to testing performed by &lt;a href="http://www.wegcomputerforensics.com/"&gt;Jimmy Weg&lt;/a&gt;,  it appears that not only is the DestList stream a  most-recently-used/most-frequently-used (MRU/MFU) list, but some  applications (such as Windows Media Player) appear to be moving their  MRU lists to Jump Lists, rather than continuing to use the Registry.&amp;nbsp; As  such, the DestList streams can be a very valuable component of timeline  analysis.&lt;br /&gt;&lt;br /&gt;What this means is that the DestList stream can be parsed to see when a  file was most recently accessed.&amp;nbsp; Unlike Prefetch files, Jump Lists do  not appear (at this point) to contain a counter of how many times a  particular file (MSWord document, AVI movie file, etc.) was accessed or  viewed, but you may be able to determine previous times that a file was  accessed by parsing the appropriate Jump List file found in Volume  Shadow Copies.&amp;nbsp; &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Summary&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Organizations are moving away from Windows XP and performing  enterprise-wide rollouts of Windows 7.&amp;nbsp; More and more, analysts will  encounter Windows 7 (and before too long, Windows 8) systems, and need  to be aware of the new artifacts available for analysis.&amp;nbsp; Jump Lists can  hold a wealth of information, and understanding these artifacts can  provide the analyst with a great deal of clarity and context.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Resources&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;ForensicsWiki: &lt;a href="http://www.forensicswiki.org/wiki/Jump_Lists"&gt;Jump Lists&lt;/a&gt;&lt;br /&gt;Jump List Analysis pt. &lt;a href="http://windowsir.blogspot.com/2011/08/jump-list-analysis.html"&gt;I&lt;/a&gt;, &lt;a href="http://windowsir.blogspot.com/2011/08/jump-list-analysis-pt-ii.html"&gt;II&lt;/a&gt;, &lt;a href="http://windowsir.blogspot.com/2011/09/jump-list-analysis-pt-iii.html"&gt;III&lt;/a&gt;&lt;br /&gt;&lt;a href="http://windowsir.blogspot.com/2011/06/meetup-tools-and-other-stuff.html"&gt;DestList stream structure&lt;/a&gt; documented&lt;br /&gt;Harry Parsonage's &lt;a href="http://computerforensics.parsonage.co.uk/linkfiles/linkfiles.htm"&gt;&lt;i&gt;The Meaning of LIFE&lt;/i&gt;&lt;/a&gt; paper - a MUST READ for anyone conducting LNK analysis &lt;br /&gt;&lt;a href="http://www.faqs.org/rfcs/rfc4122.html"&gt;RFC 4122&lt;/a&gt; - UUID  description; sec 4.1.2 describes the structure format found in Harry's  paper; section 4.1.6 describes how the Node field is populated&lt;br /&gt;Perl &lt;a href="http://search.cpan.org/%7Ecaugustin/UUID-Tiny-1.03/lib/UUID/Tiny.pm"&gt;UUID::Tiny&lt;/a&gt; module - Excellent source of information for parsing version 1 UUIDs&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;轉自 http://windowsir.blogspot.com/2011/12/jump-list-analysis.html &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-2113807593071206053?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/2113807593071206053/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=2113807593071206053&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2113807593071206053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2113807593071206053'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/jump-list-analysis.html' title='Jump List Analysis'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-7_oKEQuD6MQ/TvseN4J8qtI/AAAAAAAAAf0/TLWwvIoWy38/s72-c/images.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-2885971840729519923</id><published>2012-01-07T20:22:00.000+08:00</published><updated>2012-01-07T20:22:01.529+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>How to Use Advanced Google Search Techniques to Resolve your Investigations</title><content type='html'>If you’re like me, you probably use Google many times a day. But,  chances are, unless you are a technology geek, you probably still use  Google in its simplest form. If your current use of Google is limited to  typing a few words in, and changing your query until you find what  you’re looking for, then I’m here to tell you that there’s a better way –  and it’s not hard to learn. On the other hand, if you &lt;i&gt;are&lt;/i&gt; a  technology geek, and can use Google like the best of them already, then I  suggest you bookmark this article of Google search tips. You’ll then  have the tips on hand when you are ready to pull your hair out in  frustration when watching a neophyte repeatedly type in basic queries in  a desperate attempt to find something.&lt;br /&gt;The following Google tips are based on my own experience and things that I actually find useful. The list is by no means comprehensive. But, I assure you that by learning and using the 12 tips below, you’ll rank up there with the best of the Google experts out there. I’ve kept the descriptions of the search tips intentionally terse as you’re likely to grasp most of these simply by looking at the example from Google anyways. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;12 Expert Google Search Tips&lt;/b&gt;&lt;br /&gt;&lt;ol start="1"&gt;&lt;li&gt;&lt;b&gt;Explicit Phrase:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lets say you are looking for content about internet marketing. Instead of &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; just typing &lt;i&gt;Bill Clinton&lt;/i&gt;  into the Google search box, you will &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; likely be better off  searching explicitly for the phrase. To do this, &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; simply enclose the  search phrase within double quotes.&lt;/li&gt;&lt;/ol&gt;Example: "Bill Clinton"&lt;br /&gt;&lt;ol start="2"&gt;&lt;li&gt;&lt;b&gt;Exclude Words:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lets say you want to search for  content about a certain phone number, but &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you want to exclude any  results that contain the term &lt;i&gt;eBay&lt;/i&gt;. To do &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; this, simply use the "-" sign in front of the word you want to &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exclude.&lt;/li&gt;&lt;/ol&gt;Example Search: 555-1212 -eBay&lt;br /&gt;&lt;ol start="3"&gt;&lt;li&gt;&lt;b&gt;Site Specific Search:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Often, you want to search a  specific website for content that matches a &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; certain phrase. Even if  the site doesn’t support a built-in search &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; feature, you can use  Google to search the site for your term. Simply use &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the  "site:somesite.com" modifier. This will allow you to search &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the  entire site for the given search term.&lt;/li&gt;&lt;/ol&gt;Example: "ipod 32gb touch" site:&lt;a href="http://www.craigslist.org/"&gt;www.craigslist.org&lt;/a&gt;&lt;br /&gt;Example: "Brittany Spears" site:&lt;a href="http://www.facebook.com/"&gt;www.facebook.com&lt;/a&gt;&lt;br /&gt;&lt;ol start="4"&gt;&lt;li&gt;&lt;b&gt;Similar Words and Synonyms:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Let’s say you want to  include a word in your search, but want to include &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; results that  contain similar words or synonyms. To do this, use the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "~" in front  of the word.&lt;/li&gt;&lt;/ol&gt;Example: "Apple Ipad 32gb" ~Ipod 32 gb&lt;br /&gt;&lt;ol start="5"&gt;&lt;li&gt;&lt;b&gt;Specific Document Types:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you’re looking to find  results that are of a specific type, you can use &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the modifier  "filetype:". For example, you might want to find &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; only PowerPoint  presentations related to internet marketing.&lt;/li&gt;&lt;/ol&gt;&amp;nbsp;Example: "internet marketing" filetype:ppt&lt;br /&gt;&lt;br /&gt;&lt;ol start="6"&gt;&lt;li&gt;&lt;b&gt;This OR That:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; By default, when you do a search,  Google will include all the terms &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; specified in the search. If you  are looking for any one of one or more &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; terms to match, then you can  use the OR operator. (Note: The OR has to be &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; capitalized).&lt;/li&gt;&lt;/ol&gt;Example: internet marketing OR advertising&lt;br /&gt;&lt;ol start="7"&gt;&lt;li&gt;&lt;b&gt;Phone Listing:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Let’s say someone calls you on your  mobile number and you don’t know who &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; it is. If all you have is a  phone number, you can look it up on Google &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; using the phonebook  feature.&lt;/li&gt;&lt;/ol&gt;Example: phonebook:617-555-1212 (note: the provided number does not work – you’ll have to use a real number to get any results).&lt;br /&gt;&lt;ol start="8"&gt;&lt;li&gt;&lt;b&gt;Area Code Lookup:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If all you need to do is to look-up  the area code for a phone number, just &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enter the 3-digit area code  and Google will tell you where it’s from.&lt;/li&gt;&lt;/ol&gt;Example: 617&lt;br /&gt;&lt;ol start="9"&gt;&lt;li&gt;&lt;b&gt;Numeric Ranges:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This is a rarely used, but highly  useful tip. Let’s say you want to find &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; results that contain any of a  range of numbers. You can do this by using &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the X..Y modifier (in  case this is hard to read, what’s between the X and &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Y are two  periods.) This type of search is useful for years (as shown &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; below),  prices, or anywhere where you want to provide a series of numbers. &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;Example: president 1940..1950&lt;br /&gt;&lt;ol start="10"&gt;&lt;li&gt;&lt;b&gt;Stock (Ticker Symbol):&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Just enter a valid ticker  symbol as your search term and Google will give &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you the current  financials and a quick thumb-nail chart for the stock.&lt;/li&gt;&lt;/ol&gt;Example: GOOG&lt;br /&gt;&lt;ol start="11"&gt;&lt;li&gt;&lt;b&gt;Calculator:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The next time you need to do a quick  calculation, instead of bringing up &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the Calculator applet, you can  just type your expression in to Google.&lt;/li&gt;&lt;/ol&gt;Example: 48512 * 1.02&lt;br /&gt;&lt;ol start="12"&gt;&lt;li&gt;&lt;b&gt;Word Definitions:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you need to quickly look up the definition of a word or phrase, simply &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; use the "define:" command.&lt;/li&gt;&lt;/ol&gt;Example: define:plethora&lt;br /&gt;Hope this list of Google search tips proves useful in your future  Google searches. If there are any of your favorite Google expert power  tips that I’ve missed, please feel free to share them in the comments.  If you would like to learn more about using this powerful tool you can  check out the &lt;a href="http://www.mcafeeinstitute.com/social-networking-online-webinar-private" target="_blank"&gt;Social Networking Investigations Webinar&lt;/a&gt;&amp;nbsp;at the &lt;a href="http://www.mcafeeinstitute.com/" target="_blank"&gt;McAfee Institute&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;轉自 http://www.mcafeenetwork.com/forum/topics/how-to-use-advanced-google-search-techniques-to-resolve-your-inve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-2885971840729519923?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/2885971840729519923/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=2885971840729519923&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2885971840729519923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2885971840729519923'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/how-to-use-advanced-google-search.html' title='How to Use Advanced Google Search Techniques to Resolve your Investigations'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-7342492871685410351</id><published>2012-01-06T21:47:00.000+08:00</published><updated>2012-01-06T21:47:00.047+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><category scheme='http://www.blogger.com/atom/ns#' term='記憶體'/><title type='text'>Ripping Volume Shadow Copies Sneak Peek</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I was hesitant to do a  sneak peak about a different approach to examine Volume Shadow Copies  (VSCs). I personally don’t like sneak peeks and would rather wait to see  the finished product. I think it’s along the lines of starting a movie  then stopping it after 15 minutes and being forced to finish watching  months later. If I don’t like sneak peeks then why am I putting others  through it? I previously mentioned how I wanted to spend my furlough  days by putting together some posts about another approach to examining  VSCs. Well last week was my furlough week and my family wrote a new  version to the carol The Twelve Days of Christmas. Four out of town  trips, three sick kids, two family emergencies, and one blogger  quarantined to his room. Needless to say I had to spend my time focused  on my family. I won’t have time to write the VSCs blog posts until next  month so I at least wanted to show one example on how I use this method.&lt;br /&gt;&lt;br /&gt;There are times when I  get a system that has been altered and&amp;nbsp;one change is removing financial  software from the system. This is pretty important because if I’m trying  to locate financial data then I need to know what software is on the  system so I know what kind of files&amp;nbsp;to look for. There is a chance some  file types might initially be missed if I’m not aware a certain program  was installed at some point in the past. Different registry keys can  help determine what programs were installed or executed but you can get a  more complete picture about a system by looking at those same registry  keys at different points in time. Performing registry analysis in this  manner has allowed me to quickly identify uninstalled financial  applications which reduced the time needed to find the data. Anyone who  has used Harlan’s &lt;a href="http://regripper.wordpress.com/"&gt;RipXP&lt;/a&gt;  understands the value in seeing registry keys at different points in  time. I used the same concept with one exception: numerous registry keys  can be queried at the same time when dealing with VSCs.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;The system I used for  this demonstration was a live Windows 7 Ultimate 32 bit system. In the  past I also used it against Windows 7 and Vista. forensic images&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Obtaining General Operating System Information&lt;/u&gt;&lt;/b&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;I discussed previously one&amp;nbsp;initial examination step is to get a better understanding about the system I’m facing. I use a &lt;a href="http://journeyintoir.blogspot.com/2011/07/obtaining-information-about-operating.html"&gt;batch script with Regripper&lt;/a&gt;  to obtain a wealth of information about how the system was configured  when it was last powered on. The configuration information is from only  one point in time but if the system has VSCs then that means the same  information can be obtained from different points in time. Seeing the  same configuration information enables you to see how the system changed  slightly over time including what software was installed or  uninstalled. To do this I made some modifications to the general  operating system batch script which lets me&amp;nbsp;run it against VSCs I&amp;nbsp;have  access to.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;I’m not going to discuss accessing VSCs in this post. For information on how to access VSCs I’d check out Harlan’s &lt;a href="http://windowsir.blogspot.com/2011/12/even-more-stuff.html"&gt;Even More Stuff&lt;/a&gt;  post since he provides a link to his slide deck he gave to the online  DFIR meet-up on the topic. My Windows 7 system had 19 VSCs and for the  demonstration I only used&amp;nbsp;the following:&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ShadowCopy19 12/13/2011 6:13:35 PM&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ShadowCopy16 12/01/2011 8:08:50 AM&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ShadowCopy3 11/28/2011 11:19:40 AM&lt;br /&gt;&lt;/span&gt; &lt;span style="font-size: small;"&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - ShadowCopy1 8/26/2011 12:15:34 PM&lt;br /&gt;&lt;br /&gt;The screen shot below  shows the main menu to the vsc-parser (most selections have sub menus).  To review the system to identify software of interest I’m interested in  selection 2: “Obtain General Operating System Information from Volume  Shadow Copies”.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;  &lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-gliHt1CTXlI/Tu_-bxBG_hI/AAAAAAAAAas/lDfEn_UkMVA/s1600/1+automation-menu.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="106" src="http://4.bp.blogspot.com/-gliHt1CTXlI/Tu_-bxBG_hI/AAAAAAAAAas/lDfEn_UkMVA/s640/1+automation-menu.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;The selection will  immediately execute my Regripper batch file against every VSC I have  access to. The picture below shows the script running against my four  VSCs. I highlighted the samparse and uninstall plug-ins that executed.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;br /&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-W1E6wS6Dyo8/Tu_-maW8bzI/AAAAAAAAAa0/aRfUJILuU-w/s1600/2+samparse-uninstall+from+vscs.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-W1E6wS6Dyo8/Tu_-maW8bzI/AAAAAAAAAa0/aRfUJILuU-w/s640/2+samparse-uninstall+from+vscs.jpg" width="542" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;The output from the script is nicely organized into different folders based on what the information is.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;br /&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-zGve2hLX94Q/Tu_-vAeWV2I/AAAAAAAAAa8/5UIsIfa72sA/s1600/3+general-os+output+folder.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="274" src="http://4.bp.blogspot.com/-zGve2hLX94Q/Tu_-vAeWV2I/AAAAAAAAAa8/5UIsIfa72sA/s640/3+general-os+output+folder.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;I’m interested in the  software on the system which means I need the reports in the  software-information folder. A report was created for each VSC I had  access to (notice how the file name contains the VSC number it came  from).&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;br /&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-3pnKa-KXAt8/Tu_-4Lc71hI/AAAAAAAAAbE/pDsx0YHPNDk/s1600/4+vsc+uninstall+output.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-3pnKa-KXAt8/Tu_-4Lc71hI/AAAAAAAAAbE/pDsx0YHPNDk/s640/4+vsc+uninstall+output.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Now at this point I can  review the reports and notice the slight differences between each VSCs. I  tend to look at the most recent VSC then work my way to the oldest VSC.  It makes it easier to see how the system slightly changed over time  from the forensic image I examined first.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;br /&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-Vqu_krETi8A/Tu_-_r1fMiI/AAAAAAAAAbM/Tcad3EiGQtc/s1600/5+uninstall+key.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="266" src="http://2.bp.blogspot.com/-Vqu_krETi8A/Tu_-_r1fMiI/AAAAAAAAAbM/Tcad3EiGQtc/s640/5+uninstall+key.jpg" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;On a case I used this  technique and it helped me to identify a financial application that was  removed from the system. In the end it saved some a lot of time because  this was one of my initial steps and I knew right off the bat I was  looking for specific file types. Some may be wondering why I decided to  highlight the samparse plug-in as well. At another time the same  technique helped me verify a user account existed on the system and  narrow down the timeframe when it was removed from the system.&lt;br /&gt;&lt;br /&gt;I showed an example  running Regripper against registry hives stored in VSCs on a live  Windows 7 system. However, the approach is not only limited to registry  hives or Regripper since you can pretty much parse any data stored in a  VSC.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;轉自 http://journeyintoir.blogspot.com/2011/12/ripping-volume-shadow-copies-sneak-peek.html&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-7342492871685410351?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/7342492871685410351/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=7342492871685410351&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7342492871685410351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7342492871685410351'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/ripping-volume-shadow-copies-sneak-peek.html' title='Ripping Volume Shadow Copies Sneak Peek'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-gliHt1CTXlI/Tu_-bxBG_hI/AAAAAAAAAas/lDfEn_UkMVA/s72-c/1+automation-menu.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-5740297461896138580</id><published>2012-01-04T22:41:00.000+08:00</published><updated>2012-01-04T22:41:00.087+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><title type='text'>Android邏輯數據手動提取和分析</title><content type='html'>&lt;h3 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;Android邏輯數據手動提取和分析&lt;/span&gt;&lt;/b&gt;&lt;/h3&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;h5 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;1. SMS、MMS相關信息的手動提取&lt;/span&gt;&lt;/b&gt;&lt;/h5&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;首先，通過鏡像或者具備ROOT權限的程序將以下文件夾完整提取：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237155997.png"&gt;&lt;img alt="image" border="0" height="89" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237344605.png" style="background-image: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="253" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;以下分別對各個目錄進行解釋：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;App_parts:&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt; &lt;/li&gt;&lt;/ul&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;手機中收發的彩信附件，如圖片：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237358344.png"&gt;&lt;img alt="image" border="0" height="76" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/20110812223737687.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="238" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;該文件是以附件添加/收到的時間命名的，時間戳採用毫秒換算，由於不熟悉C語言&lt;img alt="哭泣的脸" class="wlEmoticon wlEmoticon-cryingface" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237389508.png" style="border-style: none;" /&gt;，只能用Excel做一個換算式：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237398504.png"&gt;&lt;img alt="image" border="0" height="115" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237407259.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="244" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;文件解析為圖片：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122237542492.png"&gt;&lt;img alt="image" border="0" height="273" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122238026650.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="299" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;Databases&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt; &lt;/li&gt;&lt;/ul&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;該文件夾下包含兩個文件：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122238065108.png"&gt;&lt;img alt="image" border="0" height="127" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/20110812223810709.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="445" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;分別包含手機APN信息：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122238356149.png"&gt;&lt;img alt="image" border="0" height="83" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122238408685.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="595" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;手機短信、彩信中包含的所有號碼信息（推薦號碼/典型號碼）：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122238459029.png"&gt;&lt;img alt="image" border="0" height="416" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/20110812223857183.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="217" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;以保存（已發送/已接收）的彩信結構：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122239249569.png"&gt;&lt;img alt="image" border="0" height="299" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122239449898.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="848" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;快速回覆短信：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122239501288.png"&gt;&lt;img alt="image" border="0" height="281" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122239555154.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="486" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;全部短信內容：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240033523.png"&gt;&lt;img alt="image" border="0" height="204" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240202197.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="860" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;提取出的數據經時間戳轉化後與原信息無異。&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240283356.png"&gt;&lt;img alt="image" border="0" height="244" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240317486.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="148" /&gt;&lt;/a&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240366402.png"&gt;&lt;img alt="image" border="0" height="114" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240387316.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="244" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;h5 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;2. 通訊錄手動提取和解析&lt;/span&gt;&lt;/b&gt;&lt;/h5&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;手機中設置同步的Gmail帳戶：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240409037.png"&gt;&lt;img alt="image" border="0" height="89" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240447670.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="489" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;最近500條通話記錄：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122240582138.png"&gt;&lt;img alt="image" border="0" height="328" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122241271194.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="612" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;所有聯繫人：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122241459901.png"&gt;&lt;img alt="image" border="0" height="306" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122242198810.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="688" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;所有事件（如聯繫人生日）保存信息：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122242254562.png"&gt;&lt;img alt="image" border="0" height="459" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/20110812224238700.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="408" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;聯繫人分組：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122242473887.png"&gt;&lt;img alt="image" border="0" height="298" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122242551949.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="622" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;所有聯繫人對應Gmail服務器的同步地址：&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122243173716.png"&gt;&lt;img alt="image" border="0" height="304" src="http://images.cnblogs.com/cnblogs_com/ysun/201108/201108122243468169.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="625" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;從以上分析可以看出，Android系統的邏輯數據與應用程序一樣，存儲結構都比較簡單，且基本不採用加密，取證人員掌握簡單的取證技術均可實現手動提取和分析。&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;  &lt;/span&gt;&lt;/b&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;作者後期還將繼續針對Android和iOS等智能手機系統的取證進行深入探究，歡迎各位從事計算機取證工作的朋友及時批評指正，共同探討學習。&lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;轉自 http://www.cnblogs.com/ysun/archive/2011/08/12/2136766.html &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-5740297461896138580?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/5740297461896138580/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=5740297461896138580&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5740297461896138580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5740297461896138580'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/android.html' title='Android邏輯數據手動提取和分析'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-7728885578148105323</id><published>2012-01-02T22:39:00.001+08:00</published><updated>2012-01-04T12:05:12.678+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>EnCase v7 簡介</title><content type='html'>&lt;div id="cnblogs_post_body" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Guidance 將於今年年底之前發佈EnCase v7，今日拿到了v7測試版本，下面對新功能進行簡要介紹並截圖說明。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;（Version 7.0.20.13）&lt;/span&gt;&lt;br /&gt;&lt;h3&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;新用戶界面&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;EnCase v7相對於傳統的v5、v6界面有了較大改變，一改以往的四格和多級Tab界面，而採用了單頁面多窗口的「瀏覽器式」風格，估計會讓很多v6用戶感到極不適應。&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819112752.png"&gt;&lt;img alt="image" border="0" height="452" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819172473.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;新建案例窗口，案例信息採用模板方式，調查人員可根據自己需要定製案例信息模板&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819203746.png"&gt;&lt;img alt="image" border="0" height="370" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819259597.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;主界面窗口&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819293345.png"&gt;&lt;img alt="image" border="0" height="369" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819326113.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;添加證據界面，新版本將Neutrino整合，可直接添加智能手機，這也是v7的一大新功能。&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/20110523181937850.png"&gt;&lt;img alt="image" border="0" height="303" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819402746.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;Entries部分，之前的多級標籤式結構已經變為單級標籤+前後頁面導航&lt;/span&gt;&lt;/h2&gt;&lt;h3&gt;&lt;span style="font-size: small;"&gt;&lt;u&gt;新功能和改進&lt;/u&gt;&lt;/span&gt;&lt;/h3&gt;&lt;span style="font-size: small;"&gt;1. 新的案例信息界面（見上節）&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;2. 關聯Hash Library：新的散列庫功能允許用戶指定一個Primary和一個Secondary散列庫，方便在調查時使用多個散列集以及針對特定案件指定特定散列集。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;3. 添加案例部分，界面進行了較大改進，把原來的Source樹形結構+Sessions、物理內存、進程內存三個複選框改為了嚮導式選擇，並提供DCO支持。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;4. 獲取：新的證據文件界面如下，如需對加載驅動器進行獲取，則需要進行Evidence Process，這也是v7的一個新功能，將簽名校驗、哈希計算等整合在「案例處理器」中（案例處理器後述），個人認為這是EnCase 「FTK化」的標誌之一&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819435730.png"&gt;&lt;img alt="image" border="0" height="353" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819472335.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;Evidence Processor&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819487710.png"&gt;&lt;img alt="image" border="0" height="202" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819501623.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="458" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;獲取選項，可以看到新的證據文件格式Ex01&lt;/span&gt;&lt;/h2&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;5.   新證據文件格式Ex01：Guidance秉承了他們只要更新版本就會有大改動的「優良傳統」，此次推出了Ex01格式，官方解釋是由於E01已不能夠滿 足新版本EnCase的需求，且v7很多功能都需要新的證據文件格式配合（如Indexing），新的Ex01較E01的主要改變在於，內部數據塊全部加 密，加密方式為AES，同時，原有的壓縮選項由三項改為兩項「啟用」和「禁用」，證據文件散列自校驗支持MD5、SHA-1以及MD5+SHA-1。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;6.  證據文件處理器：Evidence Processor，新功能，整合了Recover  Folders、文件簽名分析、查找加密文件（與Passware合作）、散列分析、展開符合文件、查找電子郵件、查找互聯網信息、關鍵字搜索（值得一提 的新功能，不需建立全局關鍵詞或者案例關鍵詞，直接輸入關鍵詞便可進行查找，便於初期分析）、&lt;b&gt;索引&lt;/b&gt;（值得一提，全新的索引引擎，可以添加Noise File，並且支持在殘留區和未分配空間索引，Guidance開發經理號稱這個是他們自己開發的一項與眾不同的技術）。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 需注意的是，v7的Evidence Processor&lt;u&gt;是支持多線程處理的&lt;/u&gt;。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231819562490.png"&gt;&lt;img alt="image" border="0" height="287" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/2011052318200110.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;Evidence Processor 中的索引選項&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;7.&amp;nbsp; 智能手機支持：雖說相對於Oxygen和Paraben還具有一定差距，但畢竟EnCase不是Cell Phone Forensic軟件，所以能提供這樣的功能客觀地說已經比較難得，不過這部分在最終發佈時可能還會採取單獨的模塊銷售。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820032811.png"&gt;&lt;img alt="image" border="0" height="147" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820064465.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820112857.png"&gt;&lt;img alt="image" border="0" height="387" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820167836.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;智能手機報告生成器，可自動對添加的手機證據文件生成報告，值得一提的是，可以把手機（或GPS）當中的地理位置信息或包含地理位置信息的圖片直接生成為kmz, 可使用Google Earth直接打開查看，非常方便&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820202946.png"&gt;&lt;img alt="image" border="0" height="214" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820255973.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;Tag，"FTK化"的又一典型標誌&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;8. 報告&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;在v7中，報告功能得到了極大增強，用戶可以定製自己的模板，Guidance甚至允許用戶直接使用代碼編輯報告模板（相似於html代碼，使用非常簡單）&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820334657.png"&gt;&lt;img alt="image" border="0" height="245" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820427222.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="644" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;報告模板代碼編輯頁面&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820494892.png"&gt;&lt;img alt="image" border="0" height="484" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231820586094.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="462" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;br /&gt;&lt;h2&gt;&lt;span style="font-size: small;"&gt;可隨時預覽的報告&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-size: small;"&gt;9. 打包，v7允許用戶將案例、證據文件、Primary&amp;amp;Secondary Cache打包保存或轉移，（//這應該是EnCase轉向網絡調查方向的一個標誌），可供用戶選擇的有副本、存檔和自定義模式。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231821024095.png"&gt;&lt;img alt="image" border="0" height="283" src="http://images.cnblogs.com/cnblogs_com/ysun/201105/201105231821048814.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="image" width="552" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;另外，v7中，EnScript語言也進行了一些改動，在此不再贅述。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;span style="font-size: small;"&gt;總之，EnCase v7功能上的改動很大，後續使用感受擇日再發。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.cnblogs.com/ysun/archive/2011/05/23/2054580.html &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-7728885578148105323?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/7728885578148105323/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=7728885578148105323&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7728885578148105323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/7728885578148105323'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2012/01/guidance-encase-v7v7-version-7.html' title='EnCase v7 簡介'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-4649124184633181275</id><published>2011-12-31T22:38:00.000+08:00</published><updated>2011-12-31T22:38:00.737+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>使用Winacq製作磁碟映像檔</title><content type='html'>&lt;div id="cnblogs_post_body"&gt;EnCase從6.16版本開始，提供了命令行工具Winacq用於獲取E01鏡像文件，並且，該命令可以支持處理器多核、多線程獲取。Winacq命令使用參數如下：&lt;br /&gt;&lt;br /&gt;-p 證據文件路徑&lt;br /&gt;-m 證據文件名稱&lt;br /&gt;-c 案例名稱&lt;br /&gt;-e 調查員姓名&lt;br /&gt;-r 證據編號&lt;br /&gt;-d 壓縮方式（0=不壓縮，1=最快，2=最好，默認為0）&lt;br /&gt;-n 備註&lt;br /&gt;-s 最大文件大小（設置分隔大小，最小1MB，最大1048576MB，默認640MB）&lt;br /&gt;-b 塊大小（默認64，最小1，最大1024）&lt;br /&gt;-f 配置文件&lt;br /&gt;-t 計算MD5值（默認true，可選true和false）&lt;br /&gt;-l 計算SHA-1值（設置同上）&lt;br /&gt;-wrk 設置工作線程數（默認10，最小1，最大20）&lt;br /&gt;-rdr 設置讀取線程數（默認5，最小1，最大5）&lt;br /&gt;-hsh 使用獨立線程計算散列&lt;br /&gt;-dev 需獲取的物理磁盤的編號&lt;br /&gt;-cdrom 指定獲取光驅&lt;br /&gt;-vol 需獲取的卷標&lt;br /&gt;-h 幫助信息&lt;br /&gt;&lt;br /&gt;轉自 http://www.cnblogs.com/ysun/archive/2010/05/31/1748297.html &lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-4649124184633181275?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/4649124184633181275/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=4649124184633181275&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4649124184633181275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4649124184633181275'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/winacq.html' title='使用Winacq製作磁碟映像檔'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-6732246159475986360</id><published>2011-12-30T20:46:00.000+08:00</published><updated>2011-12-30T20:46:00.226+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>vdi與vmdk/vhd/raw之間的轉換</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="-moz-font-feature-settings: normal; -moz-font-language-override: normal; border-collapse: separate; color: black; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="-moz-font-feature-settings: normal; -moz-font-language-override: normal; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: 1.4em; margin: 0px; padding: 2px 4px;"&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;Virtual Disk Conversion&lt;/strong&gt;&lt;br /&gt;VirtualBox  uses VDI files for primary hdd image. After you export the VM it will  become a VMDK. I f you want to convert it back to VDI, or just want to  convert image type you can do it with the following command:&lt;br /&gt;&lt;strong&gt;Syntax:&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt; &lt;div class="geshifilter" style="background-color: #f8f8f8; border-color: rgb(204, 204, 204); border-style: solid; border-width: 1px; color: #222222; display: block; line-height: 1.3; margin: 0.5em; overflow: auto; padding: 0.5em;"&gt;&lt;pre class="text geshifilter-text" style="line-height: 1.3; margin: 0px; padding: 0px;"&gt;#VBoxManage.exe internalcommands converthd -srcformat FORMAT1 -dstformat FORMAT2 SRCFILE DSTFILE&lt;/pre&gt;&lt;/div&gt;&lt;div style="-moz-font-feature-settings: normal; -moz-font-language-override: normal; font-size-adjust: none; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: 1.4em; margin: 0px; padding: 2px 4px;"&gt;&lt;strong&gt;Example:&lt;/strong&gt;&lt;/div&gt;&lt;div class="geshifilter" style="background-color: #f8f8f8; border-color: rgb(204, 204, 204); border-style: solid; border-width: 1px; color: #222222; display: block; line-height: 1.3; margin: 0.5em; overflow: auto; padding: 0.5em;"&gt;&lt;pre class="text geshifilter-text" style="line-height: 1.3; margin: 0px; padding: 0px;"&gt;v:\VM\HD&amp;gt;"c:\Program Files\Oracle\VirtualBox\VBoxManage.exe" internalcommands co&lt;br /&gt;nverthd -srcformat VMDK -dstformat VDI V:\VM\HD\W2003_Ent_R2_SP2.vmdk v:\VM\HD\W&lt;br /&gt;2003_Ent_R2_SP2_DC.vdi&lt;/pre&gt;&lt;/div&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;轉自&amp;nbsp; http://www.cnblogs.com/ysun/archive/2011/10/11/2206737.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-6732246159475986360?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/6732246159475986360/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=6732246159475986360&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6732246159475986360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/6732246159475986360'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/vdivmdkvhdraw.html' title='vdi與vmdk/vhd/raw之間的轉換'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-5407154193239144455</id><published>2011-12-29T20:44:00.000+08:00</published><updated>2011-12-29T20:44:01.603+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>iOS 4 (iPhone/iPad/iPod Touch) 密碼破解</title><content type='html'>&lt;div id="cnblogs_post_body" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;蘋果iOS 4中，文件系統是加密的，且用戶可以通過設置鎖屏密碼來保護自己的iOS設備&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;不知道有沒有手機取證調查人員記得，在iOS 3中，可以通過刪除keychain和springboard兩個文件來實現清空密碼，但在iOS 4中，這個方法無效，只會導致所有賬戶保存設置丟失。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;span style="font-size: small;"&gt;那麼，手機取證調查人員如何才能繞過或者破解iOS 4設備的密碼呢？&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;span style="font-size: small;"&gt;CelleBrite近期推出了Physical Analyzer 2.2.1版本，該版本新增了針對iOS 4設備的密碼破解功能&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;&lt;span style="color: red;"&gt;可以完整恢復iPhone 4、iPad等iOS 4設備（含4.3.3、4.3.4和4.3.5）的密碼，並能夠對1G系統區和用戶數據區進行完整img鏡像&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;span style="font-size: small;"&gt;其他不再贅述，上圖。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;  &lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553321196.png"&gt;&lt;img alt="SNAGHTML334e6d5" border="0" height="399" src="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553327358.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="SNAGHTML334e6d5" width="464" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553334916.png"&gt;&lt;img alt="SNAGHTML3357b76" border="0" height="399" src="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553348886.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="SNAGHTML3357b76" width="465" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553347872.png"&gt;&lt;img alt="SNAGHTML3369398" border="0" height="400" src="http://images.cnblogs.com/cnblogs_com/ysun/201109/201109021553352639.png" style="background-image: none; border-color: -moz-use-text-color; border-style: none; border-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="SNAGHTML3369398" width="465" /&gt;&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.cnblogs.com/ysun/archive/2011/09/02/2163884.html &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-5407154193239144455?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/5407154193239144455/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=5407154193239144455&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5407154193239144455'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5407154193239144455'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/ios-4-iphoneipadipod-touch.html' title='iOS 4 (iPhone/iPad/iPod Touch) 密碼破解'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-9151717154553989297</id><published>2011-12-28T20:40:00.000+08:00</published><updated>2011-12-28T20:40:00.331+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>SQLite資料庫取證工具</title><content type='html'>&lt;div id="cnblogs_post_body" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;由於目前大部分智能手機數據存儲都採用SQLite數據庫，所以SQlite數據庫的恢復成了是否能夠恢復被刪除數據的關鍵。&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;目前針對SQLite數據庫，國內尚無成熟的解決方案，更沒有專用的取證工具；而國外目前有兩款專門用於SQLite數據庫取證的工具： Epilog 和 SQLite Forensic Reporter&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;&lt;u&gt;Epilog&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;這款軟件從界面上看很強大，據其官方演示（有興趣的可以Youtube搜關鍵詞epilog），該軟件可進行SQLite結構解析、日誌恢復和完整數據結構恢復。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;strong&gt;&lt;u&gt;SQLite Forensic Reporter&lt;/u&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;該軟件號稱目前最專業的SQLite取證軟件，主要功能：&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;文件頭識別和恢復&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;自動化表結構分析&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;多種編碼內置解析&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;兩款軟件，前者可以在網上找到試用版，後者需要郵件向作者申請試用，有興趣的朋友可以自行嘗試。&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.cnblogs.com/ysun/archive/2011/09/01/2162287.html &lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-9151717154553989297?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/9151717154553989297/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=9151717154553989297&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9151717154553989297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/9151717154553989297'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/sqlite.html' title='SQLite資料庫取證工具'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-8481349052454378662</id><published>2011-12-27T20:37:00.000+08:00</published><updated>2011-12-27T20:37:00.456+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Mena Step Innovative Solutions | Magic Berry IPD Parser</title><content type='html'>&lt;h5 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span&gt;&lt;span style="background-color: grey;"&gt;&lt;span style="color: white;"&gt;&lt;strong&gt;Download Magicberry ver 3.1.0&amp;nbsp; NOW &lt;span style="background-color: white;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="background-color: #666699;"&gt;&lt;span style="color: white;"&gt;&lt;span&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h5&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;MagicBerry is the blackberry IPD reader that can read and extract the following database from the mobile IPD backup file:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;SMS Messages, Phone Call Logs, Address Book, Service Book, Tasks, memos, Calendar and export them.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The project is under continual development and currently the release is on Beta testing.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-8481349052454378662?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/8481349052454378662/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=8481349052454378662&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8481349052454378662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8481349052454378662'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/mena-step-innovative-solutions-magic.html' title='Mena Step Innovative Solutions | Magic Berry IPD Parser'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-8557831553776583162</id><published>2011-12-25T20:35:00.000+08:00</published><updated>2011-12-25T20:35:00.072+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Elcomsoft iOS Forensic Toolkit</title><content type='html'>&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;  Enhanced Forensic Access to iPhone/iPad/iPod Devices running Apple iOS&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;  Perform the complete forensic analysis of encrypted user data stored in  certain iPhone/iPad/iPod devices running any version of iOS. Elcomsoft  iOS Forensic Toolkit allows eligible customers acquiring bit-to-bit  images of devices’ file systems, extracting phone secrets (passcodes,  passwords, and encryption keys) and decrypting the file system dump.  Access to most information is provided in real-time.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.elcomsoft.com/eift.html &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-8557831553776583162?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/8557831553776583162/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=8557831553776583162&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8557831553776583162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8557831553776583162'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/elcomsoft-ios-forensic-toolkit.html' title='Elcomsoft iOS Forensic Toolkit'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-969680277758032826</id><published>2011-12-23T21:32:00.000+08:00</published><updated>2011-12-23T21:32:00.706+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識概述'/><category scheme='http://www.blogger.com/atom/ns#' term='新聞'/><title type='text'>和亞桑傑通聯　美大兵證實洩密維解</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;法新社馬里蘭州米德堡20日電：美國大兵曼寧（Bradley Manning）遭控向維基解密（WikiLeaks）網站洩密。軍方調查人員今天首次端出直接連結曼寧和維解創辦人亞桑傑（Julian Assange）的證據。 &lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;調查人員出庭作證時表示，曼寧電腦硬碟裡發現亞桑傑的聯絡資訊。曼寧案庭訊將決定他是否需至軍事法庭受審。&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;數位鑑識專家也表示發現曼寧和另1名網路帳號為「亞桑傑」的電腦使用者交談證據。&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;庭訊在馬里蘭州米德堡（Fort Meade）基地舉行，目前已進入第4天。今天的證詞是截至目前政府在建立曼寧和此案關聯上，所拿最具說服力的證據。此案也是美國史上最重大情資外洩案之一。&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;美軍電腦犯罪調查小組（CCIU）的約聘人員強生（Mark Johnson）表示，曼寧電腦硬碟裡有亞桑傑的聯絡資料。&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;軍方檢察官展示硬碟檔案1則訊息的螢幕快照，當中顯示：「你可以直接連絡我們在冰島的調查編輯－354 862 3481－24小時都可－找亞桑傑。」&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;調查人員也指出，他們回復曼寧和1名為「亞桑傑」的電腦使用者之間的交談紀錄，當中在討論維基解密。&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.cdnews.com.tw/cdnews_site/docDetail.jsp?coluid=109&amp;amp;docid=101766046 &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-969680277758032826?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/969680277758032826/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=969680277758032826&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/969680277758032826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/969680277758032826'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/blog-post.html' title='和亞桑傑通聯　美大兵證實洩密維解'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-475002936247826977</id><published>2011-12-23T20:34:00.000+08:00</published><updated>2011-12-23T20:34:00.399+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>BlackBerry Backup Extractor: extract and convert IPD BlackBerry backups</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;We're working on a rescue tool for missing BlackBerry data. If you  have lost or broken your BlackBerry, our software can automatically  extract the contacts, emails, saved emails, memos, call history,  calendar, SMS messages, tasks and other data from your BB's IPD backup  file. This BlackBerry IPD reader is free.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;When run, the application will extract all sent and received email  messages cached on the device into a "Messages" folder. Saved messages  will go into a "Saved Email Messages" folder. Other BlackBerry content  will go into "Content Store".&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Screenshot of the Blackberry converter&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;img alt="Blackberry Backup Extractor screenshot" src="http://s.blackberryconverter.com/res/i/home/blackberry-backup-extractor.png" title="Blackberry Backup Extractor" /&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can read more about our &lt;a href="http://www.blackberryconverter.com/"&gt;Blackberry converter&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Free BlackBerry IPD reader download&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can download the &lt;a href="http://www.reincubate.com/res/labs/bbbe/bbbe-latest.zip"&gt;BlackBerry IPD Backup extractor here&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.reincubate.com/labs/blackberry-backup-extractor-extract-and-convert-ipd-blackberry/ &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-475002936247826977?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/475002936247826977/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=475002936247826977&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/475002936247826977'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/475002936247826977'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/blackberry-backup-extractor-extract-and.html' title='BlackBerry Backup Extractor: extract and convert IPD BlackBerry backups'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-4620000129663843411</id><published>2011-12-22T20:30:00.001+08:00</published><updated>2011-12-22T20:30:02.286+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>iPhone Backup Extractor</title><content type='html'>Recover lost iPhone contacts, calendar events, photos, SMS messages, notes, location data and more.&lt;br /&gt;&lt;br /&gt;轉自 http://www.iphonebackupextractor.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-4620000129663843411?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/4620000129663843411/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=4620000129663843411&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4620000129663843411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/4620000129663843411'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/iphone-backup-extractor.html' title='iPhone Backup Extractor'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-922655705690943319</id><published>2011-12-21T20:28:00.001+08:00</published><updated>2011-12-21T20:28:00.218+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>BlackBerry Desktop Software</title><content type='html'>&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;Manage the link between your computer and your BlackBerry device&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;BlackBerry® Desktop Software for PC coordinates the link between your  smartphone, tablet, email accounts, calendars and more. With BlackBerry  Desktop Software 6.0, managing this  link is even easier.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-weight: normal;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;轉自http://us.blackberry.com/apps-software/desktop/&lt;/span&gt;&lt;/h2&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-922655705690943319?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/922655705690943319/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=922655705690943319&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/922655705690943319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/922655705690943319'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/blackberry-desktop-software.html' title='BlackBerry Desktop Software'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-478661709562679580</id><published>2011-12-20T20:26:00.001+08:00</published><updated>2011-12-20T20:26:00.291+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='手機鑑識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Elcomsoft Blackberry Backup Explorer</title><content type='html'>&lt;h2 style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Explore Information Stored in BlackBerry Backups&lt;/span&gt;&lt;/h2&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Extract essential information stored in BlackBerry backups. Elcomsoft  Blackberry Backup Explorer allows forensic specialists investigating the  content of BlackBerry devices by extracting, analyzing, printing or  exporting the content of a BlackBerry backup produced with BlackBerry  Desktop Software.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自 http://www.elcomsoft.com/ebbe.html&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-478661709562679580?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/478661709562679580/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=478661709562679580&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/478661709562679580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/478661709562679580'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/elcomsoft-blackberry-backup-explorer.html' title='Elcomsoft Blackberry Backup Explorer'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-5476906854564969314</id><published>2011-12-19T20:44:00.000+08:00</published><updated>2011-12-19T20:44:01.303+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='資安工具'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><category scheme='http://www.blogger.com/atom/ns#' term='記憶體'/><category scheme='http://www.blogger.com/atom/ns#' term='登錄檔'/><title type='text'>IOC Editor</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;MANDIANT IOC Editor is a free editor for &lt;a href="http://www.mandiant.com/managed_services/indicators_of_compromise"&gt;Indicators of Compromise (IOCs)&lt;/a&gt;.  IOCs are XML documents that help incident responders  capture diverse  information about threats including attributes of malicious files,  characteristics of registry changes, artifacts in memory, and so on.   IOCe provides an interface into managing data within these IOCs  including:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Manipulating the logical structures that define the IOC&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Applying meta-information to IOCs including detailed descriptions or arbitrary labels&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Converting IOCs into XPath filters&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Managing lists of "Terms" that are used within IOCs&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;轉自&amp;nbsp; https://blog.mandiant.com/archives/2050?utm_source=rss&amp;amp;utm_medium=rss&amp;amp;utm_campaign=redline-openioc-build-effective-indicators &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-5476906854564969314?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/5476906854564969314/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=5476906854564969314&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5476906854564969314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5476906854564969314'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/ioc-editor.html' title='IOC Editor'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-8988746805792402163</id><published>2011-12-16T20:42:00.001+08:00</published><updated>2011-12-16T20:42:01.205+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Lantern Lite</title><content type='html'>Katana Forensics, Inc. &amp;nbsp;The creators of the leading iOS Forensic  analysis software”Lantern” &amp;nbsp;has created a free imager for iOS Devices.  Katana believes that imaging should be free. &amp;nbsp;Analysis is where critical  thinking is accomplished. &amp;nbsp;Imaging shouldn’t also be only in the domain  of just one sector of forensics, but should also be available to all to  include the Security sector that needs to analyze mobile devices more  and more.&lt;br /&gt;&lt;br /&gt;Lantern Lite!!! &amp;nbsp;The first Mac based GUI iOS Imager that is  completely free. &amp;nbsp;This site is dedicated to those that perform digital  forensics. This application is intended to be free and not meant for  those corporations that don’t innovate. &amp;nbsp;The code released here is all  GPL. &amp;nbsp;Any use, part or in whole by a proprietary program must therefore  release their code as well.&lt;br /&gt;&lt;br /&gt;What will Lantern Lite do?&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul class="list2 list_color_green"&gt;&lt;li&gt;Fully automated&lt;/li&gt;&lt;li&gt;Automated device identification&lt;/li&gt;&lt;li&gt;Brute force a simple passcode&lt;/li&gt;&lt;li&gt;Image a device&lt;/li&gt;&lt;li&gt;decrypt an image&lt;/li&gt;&lt;li&gt;Decrypt the keychain (later versions)&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;What devices will Lantern Lite Support?&lt;br /&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul class="list2 list_color_green"&gt;&lt;li&gt;iPhone 3GS&lt;/li&gt;&lt;li&gt;iPhone 4 (GSM &amp;amp; CDMA)&lt;/li&gt;&lt;li&gt;iPod Touch 4G&lt;/li&gt;&lt;li&gt;iPod Touch 3G&lt;/li&gt;&lt;li&gt;iPad 1G&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;What version of iOS will be supported?&lt;br /&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul class="list2 list_color_green"&gt;&lt;li&gt;iOS 4&lt;/li&gt;&lt;li&gt;iOS 5&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;Will there be any improvements to Lantern Lite?&lt;br /&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;ul class="list2 list_color_green"&gt;&lt;li&gt;Since this is an open source application, the community can add changes&lt;/li&gt;&lt;li&gt;Future developments will include, iOS 3 support&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;br /&gt;轉自 http://lanternlite.org/lantern-lite&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-8988746805792402163?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/8988746805792402163/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=8988746805792402163&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8988746805792402163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8988746805792402163'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/lantern-lite.html' title='Lantern Lite'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-2214688741498555612</id><published>2011-12-11T16:09:00.000+08:00</published><updated>2011-12-11T16:09:00.338+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識概述'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='鑑識工具'/><title type='text'>Windows 8 Forensic Overview</title><content type='html'>&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;I  finally submitted my term paper for my Forensics class, While there are some things to be  said for waiting until the last minute, my problem was as I delved into the four  points I wanted to cover, I found Windows 8 exhibiting some interesting  behavior, I also noticed that some of the things I thought would change, did not.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I  will be making my paper available for download soon, but I need to  clean up a few things, and will let you know when you can grab it.  Meanwhile, here is a few things that I want to pass on.&amp;nbsp;&lt;/span&gt;  &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;When I initially started this paper I took a dive into Windows Registry I was at a loss with what to look for. I posted questions onto Twitter with some guidance of where to look. Eventually I stumbled across the Registry Key called TypedURLsTime, trying to decipher the value contained in the data field I posted to Twitter the information I was looking at.&amp;nbsp;&amp;nbsp;&lt;a href="https://twitter.com/#%21/keydet89"&gt;&lt;span style="color: blue;"&gt;Harlan Carvey&lt;/span&gt;&lt;/a&gt;&amp;nbsp;explained that this data is&amp;nbsp;&lt;a href="http://msdn.microsoft.com/en-us/library/cc765906.aspx"&gt;&lt;span style="color: blue;"&gt;filetime data&lt;/span&gt;&lt;/a&gt;; I came to rely on the experience of Harlan and others as I asked questions, I am grateful for their experience and willingness to answer my questions and be patient with me. Harlan, went as far to help as sending me a copy of his Windows Registry Forensics book, this is an incredible resource for anyone interested in looking at and understanding the registry.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Building off what I learned from Harlan's book&amp;nbsp;&lt;a href="http://www.amazon.com/Windows-Registry-Forensics-Advanced-Forensic/dp/1597495808/ref=sr_1_2?s=books&amp;amp;ie=UTF8&amp;amp;qid=1296129169&amp;amp;sr=1-2"&gt;&lt;span style="color: blue;"&gt;Windows Registry Forensics&lt;/span&gt;&lt;/a&gt;&amp;nbsp;I was able to confirm that the primary registry hives, SAM, System, Security, Software, NTUser and UsrClass all were retained within Windows 8. &amp;nbsp;I returned to the Registry Keys for the typedURLs and TypedURLsTime and did some more digging around. Here are the keys below for reference, as you can see URL10 is in both locations, one showing the location visited and the other the filetime that is was accessed.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-C60XfV6iv9U/TtxdAyl306I/AAAAAAAAIm4/-KEY_wZXsKI/s1600/TypedUrl.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://3.bp.blogspot.com/-C60XfV6iv9U/TtxdAyl306I/AAAAAAAAIm4/-KEY_wZXsKI/s320/TypedUrl.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-_VHS2Ag6U24/TtxdBCVpxfI/AAAAAAAAInA/veAMyKDPA84/s1600/typedurlstime.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://4.bp.blogspot.com/-_VHS2Ag6U24/TtxdBCVpxfI/AAAAAAAAInA/veAMyKDPA84/s320/typedurlstime.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Through some more analysis of the registry I came across the following keys, which appear to be related to the&amp;nbsp;&lt;a href="http://www.instantfundas.com/2011/06/windows-8-immersive-metro-ui-start-page.html"&gt;&lt;span style="color: blue;"&gt;Immersive Browser&lt;/span&gt;&lt;/a&gt;&amp;nbsp;that Microsoft is pushing in Windows 8. I attempted to test the typedurls-immersive-browser key, but this feature was not accessible in this build.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-vwESGUWykCo/Tt0fmkkaf1I/AAAAAAAAInQ/MCA6WaSel2U/s1600/ImmersiveSettings.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-vwESGUWykCo/Tt0fmkkaf1I/AAAAAAAAInQ/MCA6WaSel2U/s1600/ImmersiveSettings.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;While listening to&amp;nbsp;&lt;a href="http://channel9.msdn.com/Events/BUILD/BUILD2011/SAC-861T"&gt;&lt;span style="color: blue;"&gt;Wade Wegner presentation&lt;/span&gt;&lt;/a&gt;&amp;nbsp;at the 2011 Build conference, Microsoft touted the ability to allow applications and user to save data to the cloud. With the option of using your Windows Live ID as your user name to facilitate this idea I decided to look a little more regarding this. I found the following while digging into the directory structure of a Live user:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;C:\Users\&lt;b&gt;USERID&lt;/b&gt;\AppData\Local\Microsoft\Windows\Live\Roaming\2d5b1639895c2556\CloudSync&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Within this directory there were numerous files with the SDF file type, some of the files are named the same as the immersive browser keys in the previous images.&amp;nbsp;I decided to look further into the registry to see if I could find any reference to the CloudSync option and I came across the following:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-Cy45_Poo364/Tt0fmQRLhoI/AAAAAAAAInI/8wZlh6xsxmg/s1600/Cloudsync.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Cy45_Poo364/Tt0fmQRLhoI/AAAAAAAAInI/8wZlh6xsxmg/s1600/Cloudsync.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;It appears that the Immersive Browser and CloudSync Registry keys will need to be analyzed further. I am planning on looking into them more over the next few weeks, will update blog with the information.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;When I was typing out this blog I had I was going to delve deeper into Jump Lists, but they appear to be similar to the Windows 7 area, and felt that my research could be utilized in a different approach. It does not appear that Metro Applications keep a jump list; instead they keep their information in the respective program folder within AppData. I noticed this behavior while utilizing the PicStream Metro App. Digging into the file path I found the following folder structure:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-GVeEofUqyWw/Tt0nz5dHobI/AAAAAAAAInY/YRuwwnPnb_M/s1600/metro-picstream.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-GVeEofUqyWw/Tt0nz5dHobI/AAAAAAAAInY/YRuwwnPnb_M/s1600/metro-picstream.png" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Within each of those sub directories there was a regular file and a file slack for each image I viewed through Picstream application. Further research should define the naming convention of the INetCache sub directories.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span"&gt;Within the Windows 8 Operating system, they have introduced&lt;/span&gt;&lt;a href="http://www.itproportal.com/2011/11/28/how-use-windows-8-file-history-system/"&gt;&lt;span style="color: blue;"&gt;&amp;nbsp;file history&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"&gt;&amp;nbsp;backup which changes the way that backups were previously used. In previous versions of windows, backups could only be maintained and restored using the default system. Within windows 8 this solution is more robust and allows backups to be stored both on removable media and remote network shares. By default this will backup folders such as Music, Documents, Videos, Contacts and Favorites.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;There are a few artifacts that are established when file history is turned on, this includes File History folder, Registry Value, and Windows Events. The file history folder can be found at C:\Users\&lt;b&gt;USERID&lt;/b&gt;\AppData\Local\Microsoft\Windows\FileHistory within this folder there is a configuration folder and a data folder. The data folder is a temporary staging directory for the files that are to be backed up. The Configuration folder contains at least 2 files, they are an EDB file named Catalog#.edb and a XML file names Config#. These files are created both Locally and on the drive being used as backup. As of this writing I have not be able to explore the EDB file. The Config file on the other hand offers the following information:&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="Text" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-left: 28.1pt; text-indent: -0.25in;"&gt; &lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-hRCnUlCSv5A/Tt10su3y9XI/AAAAAAAAInw/2VRevwAVksM/s1600/filehistoryconfig.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="417" src="http://3.bp.blogspot.com/-hRCnUlCSv5A/Tt10su3y9XI/AAAAAAAAInw/2VRevwAVksM/s640/filehistoryconfig.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;If the File History option has been turned on there is also a registry key that is created, this key is only found on users that have turned on this feature. The Registry key can be found at:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;i&gt;HKU\Software\Microsoft\Windows\CurrentVersion\FileHistory&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Within this directory there is a key named ProtectedUpToTime that shows the last time this process backed up the files. This value can be deciphered utilizing a 64 Bit Hex Value - Big Endian values. The DCode application can handle this.&lt;/span&gt;  &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-8AQq4B1pZic/Tt0ssSF4KFI/AAAAAAAAIno/kfqYFnl0wzE/s1600/Protecteduptotime.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="184" src="http://2.bp.blogspot.com/-8AQq4B1pZic/Tt0ssSF4KFI/AAAAAAAAIno/kfqYFnl0wzE/s320/Protecteduptotime.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-QLP0hQhDYF8/Tt0ssBDDPvI/AAAAAAAAIng/AlONOenWKrw/s1600/Dcode-Protected.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="228" src="http://2.bp.blogspot.com/-QLP0hQhDYF8/Tt0ssBDDPvI/AAAAAAAAIng/AlONOenWKrw/s400/Dcode-Protected.png" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;There is also another area in the HKLM registry that may provide more information and keys of importance, this is t. This is the FHSVC which is the File History Service and can be found here:&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;HKLM\System\Controlset001\Services\fhsvc.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://3.bp.blogspot.com/-imhx9pM2sLA/Tt19lt5saCI/AAAAAAAAIoI/J8m6GqFhe_s/s1600/FHSVCKey.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="244" src="http://3.bp.blogspot.com/-imhx9pM2sLA/Tt19lt5saCI/AAAAAAAAIoI/J8m6GqFhe_s/s320/FHSVCKey.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; Keys in the FHSVC folder&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-BY2qaNwgzVE/Tt19lWX21-I/AAAAAAAAIoA/quH1FkUtb3E/s1600/FHSVCFiles.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="196" src="http://2.bp.blogspot.com/-BY2qaNwgzVE/Tt19lWX21-I/AAAAAAAAIoA/quH1FkUtb3E/s640/FHSVCFiles.png" width="640" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Keys in the Config files&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-2xrL8oOxwz0/Tt19lJ5pCyI/AAAAAAAAIn4/URklcjLprUc/s1600/FHSVCConfig.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="72" src="http://2.bp.blogspot.com/-2xrL8oOxwz0/Tt19lJ5pCyI/AAAAAAAAIn4/URklcjLprUc/s640/FHSVCConfig.png" width="640" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Another area worth looking at in gathering File History information is within the System Events. The following Event Sources provide us with auditing information related to the File History:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;ul style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;" type="disc"&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-Catalog&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-ConfigManager&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-Core&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-Engine&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-EventListener&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal"&gt;&lt;span style="font-size: small;"&gt;FileHistory-Service&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;The final features of Windows 8 that I am going to cover in this blog are the&amp;nbsp;&lt;a href="http://paper.li/Zibit_Datalab/1323015609"&gt;&lt;span style="color: blue;"&gt;Refresh and Recovery&lt;/span&gt;&lt;/a&gt;&amp;nbsp;options. The Recovery feature will bring your windows to a factory state, similar to re-installing the operating system, the refresh feature acts like a restore point, but will clean everything needed for the OS to run, leaving individual files, and applications from the Microsoft store untouched, deleting any other 3rd party application.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;When looking at a refreshed image of the windows operating system within AccessData FTK Imager, there are three items that are quickly noticed. These are two partitions and an unpartitioned space.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-mCZVhZJUuis/Tt2LZkwdHbI/AAAAAAAAIoQ/PPAbmAOvLxk/s1600/RecoveryFtk.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="125" src="http://4.bp.blogspot.com/-mCZVhZJUuis/Tt2LZkwdHbI/AAAAAAAAIoQ/PPAbmAOvLxk/s320/RecoveryFtk.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Partition 1 is a 350MB partition that contains the information needed to boot up the operating system. There are a few interesting files that can be found in this partition that can provide some more clues about what has happened on with the operating system and if the device has been recovered or refreshed. When comparing this partition against machines that have had the refresh/recover option ran against them and those that have not we can see some differences in files.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-2o2I2E8q4n8/Tt2PZ__PCHI/AAAAAAAAIog/ZXVpnp-A9yA/s1600/RestoreExpanded.png" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-2o2I2E8q4n8/Tt2PZ__PCHI/AAAAAAAAIog/ZXVpnp-A9yA/s320/RestoreExpanded.png" width="296" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/-Tppf5hp1DA0/Tt2PZcib__I/AAAAAAAAIoY/H7k9kFnQ7gk/s1600/BaseExpanded.png" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="276" src="http://3.bp.blogspot.com/-Tppf5hp1DA0/Tt2PZcib__I/AAAAAAAAIoY/H7k9kFnQ7gk/s320/BaseExpanded.png" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;The screen shot on the left is from a machine that has not been refreshed or restored, while the one on the right has been refreshed. From my analysis of this partition from a refreshed or recovered is there will be more unallocated spaces in a recovered machine. On all images there is a folder called Recovery in the System32 folder, within this directory there is a file called ReAgent.xml, this file is used to recover or refresh.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;On a Refreshed/Recovered machine there is a new folder named Log under the recovery folder. In that folder is a file called Reload.XML. The Reload.xml is an updated ReAgent.xml file; it will also have a different timestamp from the ReAgent. This folder and file will give a good idea if the machine has been refreshed or restored. Out of the 24 lines in these xml files, the only line different is:&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/-CP6yD1DtmNs/Tt2SSqFiYoI/AAAAAAAAIoo/eblzNOiGRow/s1600/refreshreloaddiff.png" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="27" src="http://2.bp.blogspot.com/-CP6yD1DtmNs/Tt2SSqFiYoI/AAAAAAAAIoo/eblzNOiGRow/s400/refreshreloaddiff.png" width="400" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;For a non-refreshed or recovered system the state and status would both be 0.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;Partition 2 is the main system partition that is mapped to the C: Drive. This partition also allows us to know if the machine was refreshed or restored. A restored machine will have a lot of unallocated spaces of various sizes that can still be data carved against. The directories and files shown between a Restored and a Non-Restored machine will be similar, but against a refreshed machine there will be two new Directories that contain data. These folders are the $SysReset and Windows.old, as can be seen below.&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;/span&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt; &lt;span style="font-size: small;"&gt;&lt;a href="http://1.bp.blogspot.com/-PwUOhWXJRew/Tt2V0TfssGI/AAAAAAAAIo4/Qlq-fgwExKo/s1600/refreshed.png" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="400" src="http://1.bp.blogspot.com/-PwUOhWXJRew/Tt2V0TfssGI/AAAAAAAAIo4/Qlq-fgwExKo/s400/refreshed.png" width="241" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/-DNchUjZA_cU/Tt2V0BmubPI/AAAAAAAAIow/nWP1JObKUUM/s1600/baseline.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="400" src="http://4.bp.blogspot.com/-DNchUjZA_cU/Tt2V0BmubPI/AAAAAAAAIow/nWP1JObKUUM/s400/baseline.png" width="341" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span"&gt;Within these folders we can still access the previous data that was on the drive, this data still remains in its file structure under the Windows.Old folder. Within the $SysReset there are two directories that contain what appears to be potential useful information. Within the Logs folder there are three files that will provide some usable data. The SystemResetPlatform.log and the setupact.log provides details of what was changed, the MigLog.xml will contain the Users that were retained and their current mappings. This can be beneficial after a reset a user account is deleted. &amp;nbsp;There two files located in the Framework/Migration/Preserve that also may provide evidence at a later date, they seem to deal with the Microsoft Store, and since this feature is currently not available I am unable to investigate.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="MsoNormal" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; margin-bottom: 0.0001pt;"&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt; Over the next few months I will research more artifacts that might be left behind in Windows 8, and the behaviors that the new operating system brings with it. As more features are unlocked there is potential for more locations that must be analyzed to find the big picture.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;轉自 http://randomthoughtsofforensics.blogspot.com/2011/12/windows-8-forensic-overview.html&amp;nbsp;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-2214688741498555612?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/2214688741498555612/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=2214688741498555612&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2214688741498555612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/2214688741498555612'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/windows-8-forensic-overview.html' title='Windows 8 Forensic Overview'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-C60XfV6iv9U/TtxdAyl306I/AAAAAAAAIm4/-KEY_wZXsKI/s72-c/TypedUrl.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-5445629745780125854</id><published>2011-12-09T20:07:00.000+08:00</published><updated>2011-12-09T20:07:00.472+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='鑑識概述'/><category scheme='http://www.blogger.com/atom/ns#' term='系統常識'/><category scheme='http://www.blogger.com/atom/ns#' term='資料還原'/><title type='text'>Back to Basics, CD and DVD basic forensics</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;At G-C (my company) we try to have an internal training topic for about  30 minutes to an hour every day (that I'm in the office). Often times we  will go over case studies of recently solved cases but other times we  get back to basics because you can't assume everyone knows everything  you do. One class we recently did was on CD/DVD forensics and since it  was received well I thought I should do a similar thing here on the  blog. I admit I was watching the barefoot contessa's 'back to basics'  show before i wrote this so the title is most likely influenced by  delicious food. &lt;br /&gt;&lt;br /&gt;I think a lot of people have forgotten about DVDs and CDs as important  forensic evidence with the widespread use of cheap reusable USB storage  (commercially introduced in December 2000 (Thanks wikipedia!)), but back  when I got started (1999) it was very much 'a thing'. There are four  important things we can determine forensically from a CD/DVD.&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;1. The volume name of the CD (always)&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;2. When it was burned (always)&lt;br /&gt;3. What software made the CD (sometimes)&lt;br /&gt;4. The previous burns (always)&lt;br /&gt;and some easter eggs.&lt;br /&gt;&lt;br /&gt;1. The volume name of the CD&lt;/span&gt; &lt;span style="font-size: small;"&gt;&lt;br /&gt;All of the CDs I reviewed start with a ISO9660 session on the disk which  began at an offset of 8000. You can see in the screenshot below that  standard identifier has been set as 'CD001' which is the default for  most burners when a ISO9660 session is selected. However what we care  about is right after that the name of the CD is ' Oct 28 11 09:33'. &lt;br /&gt;&lt;/span&gt;  &lt;/div&gt;&lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-Vv8OSau7pts/TtsAXTT5tpI/AAAAAAAAAEY/tnHYPj_BUuM/s1600/exhibit1.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://4.bp.blogspot.com/-Vv8OSau7pts/TtsAXTT5tpI/AAAAAAAAAEY/tnHYPj_BUuM/s400/exhibit1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You may think, why do I care about this, this is the volume name that I  can see in any tool? Well if you have a multi session disk the volume  name will be set to the current session, this may be the only way you  have to determine the labels of the prior sessions. We will talk more  about sessions in 4. &lt;/span&gt;  &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;2. When it was burned&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Near the end of the ISO9660 session block are four time stamps, I've  always seen them set to the same time. This is the time the CD/DVD was  created.&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://2.bp.blogspot.com/-wZl2xb3NzAk/TtsAr-l5M_I/AAAAAAAAAEw/n94GBeUrpss/s1600/exhibit3.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="82" src="http://2.bp.blogspot.com/-wZl2xb3NzAk/TtsAr-l5M_I/AAAAAAAAAEw/n94GBeUrpss/s400/exhibit3.jpg" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;Let's break the timestamp down to a more readable form:&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;2011102808333500è&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;2011102808333500è&lt;br /&gt;2011102808333500è&lt;br /&gt;2011102808333500è&lt;br /&gt;&lt;br /&gt;As you can see each of them terminates with ascii character è which is  hex E8. Breaking down an individual entry we can see that the time is:&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;2011 10 28 08 33 3500&lt;br /&gt;So October  28, 2011 at 8:33:35am is when the CD was burned, notice this  is one hour off of the CD label time. Note that this time is only as  accurate as the system clock that burned the CD/DVD.&lt;br /&gt;&lt;br /&gt;3. What burned it&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Depending on what software burned the CD/DVD many of them will also  place the name and version of the software in the reserved space of the  ISO9660 session start. In our example we can see that the name of the  software that burned it is 'PRASSI2.1.374'. &lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt; &lt;div class="separator" style="clear: both; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; text-align: center;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://4.bp.blogspot.com/-iY00q9D7C0s/TtsAl2VH1kI/AAAAAAAAAEk/jSbgTbdugKM/s1600/exhibit2.jpg" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="58" src="http://4.bp.blogspot.com/-iY00q9D7C0s/TtsAl2VH1kI/AAAAAAAAAEk/jSbgTbdugKM/s400/exhibit2.jpg" width="400" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Doing some quick searches for 'Prassi cd burning software' reveals that  this is Primo Prassi version 2.1.374 a now defunct company whose  software was bundled with some CD/DVD burners. &lt;/span&gt;   &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Why do we care?  If you are trying to prove that a CD/DVD was burned on a  particular system matching the software name and version to what was  installed on the system can be one indicator that you can use.&lt;br /&gt;&lt;br /&gt;4. The previous burns &lt;/span&gt; &lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;If you are inspecting a rewritable CD/DVD and it has had more than one  write burned to it, then each of the writes are still available. There  are multiple layers of burnable media within a rewritable disk and when  inserted into a CD/DVD ROM your computer will only show the most recent  session. When you image the CD/DVD using a tool like FTK Imager all the  prior sessions will be viewable. This is why determining the name of the  session may be important as we detailed in 1. &lt;br /&gt;&lt;br /&gt;5. Easter Eggs&lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;Sometimes you'll find something unexpected. The ISO9660 specification  does not state what can't exist within the reserved space of the session  start and systems don't parse for unused areas. For instance within  MSDN DVDs you'll be Microsoft's name, address and phone number. What is  contained within the session start beyond what we've described here will  also depend on what the burning software programmer decided to place  within it.&lt;br /&gt;&lt;br /&gt;That's it, I hope this shined some light on a possibly forgotten set of  facts. Let me know what you think, your comments help to motivate me to  keep posting in between baby bottles.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;轉自 http://hackingexposedcomputerforensicsblog.blogspot.com/2011/12/back-to-basics-cd-and-dvd-basic.html&amp;nbsp;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-5445629745780125854?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/5445629745780125854/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=5445629745780125854&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5445629745780125854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/5445629745780125854'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/back-to-basics-cd-and-dvd-basic.html' title='Back to Basics, CD and DVD basic forensics'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Vv8OSau7pts/TtsAXTT5tpI/AAAAAAAAAEY/tnHYPj_BUuM/s72-c/exhibit1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-502182106846316692</id><published>2011-12-07T21:17:00.000+08:00</published><updated>2011-12-07T21:17:00.275+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><title type='text'>Malware Detection Checklist</title><content type='html'>&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span id="internal-source-marker_0.9564833278631798" style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Malware Detection Checklist&lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;The  following is a sample checklist that you can use as part of your  malware detection process. &amp;nbsp;All of the tasks listed in this checklist  are taken from chapter 6, “Malware Detection”, of &lt;/span&gt;&lt;b style="color: #cc0000;"&gt;&lt;span style="background-color: transparent; font-style: italic; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Windows Forensic Analysis 3/e&lt;/span&gt;&lt;/b&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;. &amp;nbsp;Please feel free to use this checklist, or modify it to suite your needs.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div dir="ltr" style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;table style="border-collapse: collapse; border: medium none;"&gt;&lt;colgroup&gt;&lt;col width="37"&gt;&lt;/col&gt;&lt;col width="258"&gt;&lt;/col&gt;&lt;col width="343"&gt;&lt;/col&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="background-color: #d9d9d9; border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="background-color: #d9d9d9; border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: bold; text-decoration: none; vertical-align: baseline;"&gt;Task&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="background-color: #d9d9d9; border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: bold; text-decoration: none; vertical-align: baseline;"&gt;Findings/Notes&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: bold; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Check for installed AV&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Review available Logs (MRT, Defender, McAfee, Application Event Logs, etc.)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Scan mounted image with AV&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Scan for packed files&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Digital Signatures (Sigcheck.exe)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;WFP Check (wfpchck.pl)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;ADS check (lads.exe)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;PE file “compile time check”&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;MBR check (mbr.pl)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Registry Analysis – autostart &amp;amp; artifact locations, modifications to firewall settings, etc. (RegRipper)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Registry Analysis – System hive, enum\Root\Legacy_* subkeys (RegRipper)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Check for web activity/history in LocalService/Default User profiles&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Check System Event Log; Event ID 7035 with user SID&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;Check Scheduled Tasks, Scheduled Task Log (SchedLgU.txt)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;User %Temp% dir: PE files, with .exe or .tmp extensions; Java .jar files/JavaFX key, updates to jusched.log, etc.)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 0px;"&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;MFT checks (mft.pl)&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="border: 1px dotted rgb(170, 170, 170); padding: 0px; vertical-align: top;"&gt;&lt;span style="font-size: small;"&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;span style="background-color: transparent; color: black; font-style: normal; font-variant: normal; font-weight: normal; text-decoration: none; vertical-align: baseline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-502182106846316692?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/502182106846316692/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=502182106846316692&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/502182106846316692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/502182106846316692'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/malware-detection-checklist.html' title='Malware Detection Checklist'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6844399733943221829.post-8770792893991499522</id><published>2011-12-04T20:38:00.000+08:00</published><updated>2011-12-04T20:38:00.161+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='惡意程式'/><category scheme='http://www.blogger.com/atom/ns#' term='密碼破解'/><title type='text'>sniffer工具 - Intercepter-NG</title><content type='html'>&lt;div style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;[Intercepter-NG] offers the following features: &lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&lt;/b&gt;&amp;nbsp; + Sniffing passwords\hashes of the types: &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp;ICQ\IRC\AIM\FTP\IMAP\POP3\SMTP\LDAP\BNC\SOCKS\HTTP\WWW\NNTP\CVS\TELNET\MRA\DC++\VNC\MYSQL\ORACLE&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Sniffing chat messages of ICQ\AIM\JABBER\YAHOO\MSN\IRC\MRA&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Promiscuous-mode\ARP\DHCP\Gateway\Smart Scanning&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Raw mode (with pcap filter)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + eXtreme mode&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Capturing packets and post-capture (offline) analyzing&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + Remote traffic capturing via RPCAP daemon&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + NAT&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + ARP MiTM&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + DNS over ICMP&amp;nbsp;MiTM&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + DHCP MiTM&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; + SSL MiTM + SSL Strip                 &lt;/span&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;Works on Windows NT(2K\XP\2k3\Vista\7).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;b style="color: black;"&gt;Videos&lt;br /&gt;&lt;/b&gt;&lt;span style="color: black;"&gt;&lt;a href="http://www.youtube.com/watch?v=bN1FBroIRAA"&gt;Intercepter Tutorial part 1&lt;br /&gt;&lt;/a&gt;              &lt;a href="http://www.youtube.com/watch?v=bN1FBroIRAA"&gt;Intercepter Tutorial part 2&lt;br /&gt;&lt;/a&gt;              &lt;a href="http://www.youtube.com/watch?v=bN1FBroIRAA"&gt;Sniffing DHCP based networks&lt;br /&gt;&lt;/a&gt;            &lt;a href="http://www.youtube.com/watch?v=bN1FBroIRAA"&gt;ICMP Redirect MiTM &lt;br /&gt;&lt;/a&gt;         &lt;/span&gt;&lt;a href="http://www.youtube.com/watch?v=bN1FBroIRAA" style="color: black;"&gt;DNS over ICMP Redirect MiTM&lt;br /&gt;Hacking SSL&lt;br /&gt;Stripping&amp;nbsp;SSL&lt;br /&gt;Sniffing ICQ MD5 Login&lt;/a&gt;&lt;span style="color: black;"&gt;&lt;/span&gt;&lt;br style="color: black;" /&gt;&lt;span style="color: black;"&gt;      &lt;/span&gt;&lt;span style="color: black;"&gt;&lt;a href="http://www.youtube.com/watch?v=DJAVwhDOqyk"&gt;Quick overview of new Intercepter-NG&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;span style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;span style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif; font-size: small;"&gt;&lt;b&gt;Download&lt;br /&gt;&lt;/b&gt;&lt;b&gt;&lt;a href="http://intercepter.nerf.ru/Intercepter-NG.v09.zip"&gt;Intercepter-NG 0.9&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: black; font-family: &amp;quot;Trebuchet MS&amp;quot;,sans-serif;"&gt;參考 http://intercepter.nerf.ru/&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6844399733943221829-8770792893991499522?l=jay-fva.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://jay-fva.blogspot.com/feeds/8770792893991499522/comments/default' title='張貼意見'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6844399733943221829&amp;postID=8770792893991499522&amp;isPopup=true' title='0 個意見'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8770792893991499522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6844399733943221829/posts/default/8770792893991499522'/><link rel='alternate' type='text/html' href='http://jay-fva.blogspot.com/2011/12/sniffer-intercepter-ng.html' title='sniffer工具 - Intercepter-NG'/><author><name>Mr.J</name><uri>http://www.blogger.com/profile/00993826299816041518</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_NsnHwsa6Lws/TMwOAdt1dpI/AAAAAAAAAa4/29-Bm58knWw/S220/Forensic-Sciences12.jpg
