Hiren's BootCD Pro 1.5

對於有在幫人組裝電腦,或者是硬體維修的朋友而言,Hiren's BootCD 稱之為萬用光碟實在當之無愧,


除了提供了各式硬碟工具(硬碟備份、硬碟分割、硬碟檔案救援),也提供了為數不少的硬體測試工具(螢幕、顯示卡、硬碟),甚至是 BIOS 密碼回復,檔案管理,硬體資訊查詢等功能,凡舉在 DOS 你能想到的軟體,作者都已經細心的將軟體整合在其中,不管你是不是系統維修人員,在家中,一片 Hiren's BootCD 絕對能夠給予使用者在操作時提供最便利的功能,讓你一片在手搞定各種電腦!


Hiren's BootCD Pro 1.5 是基於原來版本v10修改的,重新修改了結構以及選單,讓軟體能更方便以及有更好的描述,有些軟體也更新至較新版本,還有新增很多其他有用的工具。



Partition Tools

Partition Magic Pro 8.05
Best software to partition hard drive

Acronis Disk Director 10.0.2160
Popular disk management functions in a single suite

Paragon Partition Manager 7.0.1274
Universal tool for partitions

Partition Commander 9.01
The safe way to partition your hard drive,with undo feature

Ranish Partition Manager 2.44
a boot manager and hard disk partitioner.

The Partition Resizer 1.3.4
move and resize your partitions in one step and more.

Smart Fdisk 2.05
a simple harddisk partition manager

SPecial Fdisk 2000.03v
SPFDISK a partition tool.

eXtended Fdisk 0.9.3
XFDISK allows easy partition creation and edition

GDisk 1.1.1
Complete replacement for the DOS FDISK utility and more.

Super Fdisk 1.0
Create, delete, format partitions drives without destroying data.

Partition Table Editor 8.0
Partition Table and Boot Record Editor

EASEUS Partition Master 4.1.1
Partition Resize/Move/Copy/Create/Delete/Format/Convert, Explore, etc.

USB Format Tool
Format/make bootable any USB flash drive to FAT, FAT32, or NTFS partition.


Backup Tools

ImageCenter 5.6 (Drive Image 2002)
Best software to clone hard drive

Norton Ghost 11.5
Similar to Drive Image (with usb/scsi support)

Acronis True Image 8.1.945
Create an exact disk image for complete system backup and disk cloning.

Partition Saving 3.71
A tool to backup/restore partitions. (SavePart.exe)

COPYR.DMA Build013
A Tool for making copies of hard disks with bad sectors

DriveImageXML 2.13
backup any drive/partition to an image file, even if the drive is currently in use

Drive SnapShot 1.39
creates an exact Disk Image of your system into a file while windows is running.

Ghost Image Explorer 11.5
to add/remove/extract files from Ghost image file

DriveImage Explorer 5.0
to add/remove/extract files from Drive image file

WhitSoft File Splitter 4.5a
a Small File Split-Join Tool

InfraRecorder 0.50
An Open source CD/DVD burning software, also create/burn .iso images

FastCopy 1.99r4
The Fastest Copy/Delete Software on Windows

Smart Driver Backup 2.12
Easy backup of your Windows device drivers (also works from PE)

Double Driver 2.1
Driver Backup and Restore tool

DriverBackup! 1.0.3
Another handy tool to backup drivers

RegBak 1.0
a light-weight and simple utility to create backups of Windows registry files


Recovery Tools

Active Partition Recovery 3.0
To Recover a Deleted partition.

Active Uneraser 3.0
To recover deleted files and folders on FAT and NTFS systems.

Ontrack Easy Recovery Pro 6.10
To Recover data that has been deleted/virus attack

Winternals Disk Commander 1.1
more than just a standard deleted-file recovery utility

TestDisk 6.11.3
Tool to check and undelete partition from Dos/Windows

DiyDataRecovery Diskpatch 2.1.100
An excellent data recovery software.

Prosoft Media Tools 5.0 v1.1.2.64
Another excellent data recovery software with many other options.

PhotoRec 6.11.3
Tool to Recover File and pictures from Dos/Windows

Active Undelete 5.5
a tool to recover deleted files

Restoration 3.2.13
a tool to recover deleted files

GetDataBack for FAT 4.0
Data recovery software for FAT file systems

GetDataBack for NTFS 4.0
Data recovery software for NTFS file systems

Recuva 1.32
Restore deleted files from Hard Drive, Digital Camera Memory Card, usb mp3 player...

Partition Find and Mount 2.3.1
Partition Find and Mount software is designed to find lost or deleted partitions

Unstoppable Copier 4.2
Allows you to copy files from disks with problems such as bad sectors,
scratches or that just give errors when reading data.


Testing Tools

System Speed Test 4.78
it tests CPU, harddrive, ect.

PC-Check 6.05
Easy to use hardware tests

Ontrack Data Advisor 5.0
Powerful diagnostic tool for assessing the condition of your computer

The Troubleshooter 7.02
all kind of hardware testing tool

CPU/Video/Disk Performance Test 5.7
a tool to test cpu, video, and disk

Test Hard Disk Drive 1.0
a tool to test Hard Disk Drive

Disk Speed1.0
Hard Disk Drive Speed Testing Tool

S&M Stress Test 1.9.1
cpu/hdd/memory benchmarking and information tool, including temperatures/fan speeds/voltages

IsMyLcdOK (Monitor Test) 1.02
Allows you to test CRT/LCD/TFT screens for dead pixels and diffective screens


RAM (Memory) Testing Tools

GoldMemory 5.07
RAM Test utility

Memtest86+ 4.00
PC Memory Test

MemTest 1.0
a Memory Testing Tool

Video Memory Stress Test 1.7.116
a tool to thoroughly test your video RAM for errors and faults


Hard Disk Tools

Hard Disk Diagnostic Utilities
Seagate Seatools Graphical v2.13b
SeaTools for Dos 1.10
Western Digital Data Lifeguard Tools 11.2
Western Digital Diagnostics (DLGDIAG) 5.04f
Maxtor PowerMax 4.23
Maxtor amset utility 4.0
Maxtor(or any Hdd) Low Level Formatter 1.1
Fujitsu HDD Diagnostic Tool 7.00
Fujitsu IDE Low Level Format 1.0
Samsung HDD Utility(HUTIL) 2.10
Samsung Disk Diagnose (SHDIAG) 1.28
Samsung The Drive Diagnostic Utility (ESTOOL) 3.00g
IBM/Hitachi Drive Fitness Test 4.16
IBM/Hitachi Feature Tool 2.15
Gateway GwScan 5.12
ExcelStor's ESTest 4.50
MHDD 4.6
WDClear 1.30
Toshiba Hard Disk Diagnostic 2.00b

HDD Regenerator 1.71
to recover a bad hard drive

HDAT2 4.53
main function is testing and repair (regenerates) bad sectors for detected devices

Ontrack Disk Manager 9.57
Disk Test/Format/Maintenance tool.

Norton Disk Doctor 2002
a tool to repair a damaged disk, or to diagnose your hard drive.

Norton Disk Editor 2002
a powerful disk editing, manual data recovery tool.

Hard Disk Sentinel 0.04
Hard Disk health, performance and temperature monitoring tool.

Active Kill Disk 4.1
Securely overwrites and destroys all data on physical drive.

SmartUDM 2.00
Hard Disk Drive S.M.A.R.T. Viewer.

Victoria 3.33e and 3.52rus
a freeware program for low-level HDD diagnostics

HDD Erase 4.0
Secure erase using a special feature built into most newer hard drives

HDD Scan 3.2
HDDScan is a Low-level HDD diagnostic tool, it scans surface find bad sectors etc.

HDTune 2.55
Hard disk benchmarking and information tool.

Data Shredder 1.0
A tool to Erase disk and files (also wipe free space) securely


System Information Tools

PCI and AGP info Tool (1811)
The PCI System information & Exploration tool.

System Analyser 5.3w
View extensive information about your hardware

Navratil Software System Information 0.60.38
High-end professional system information tool

Astra 5.44
Advanced System info Tool and Reporting Assistant

HWiNFO 5.3.0
a powerful system information utility

SysChk 2.46
Find out exactly what is under the hood of your PC

CPU Identification utility 1.18
Detailed information on CPU (CHKCPU.EXE)

CTIA CPU Information 2.7
another CPU information tool

Drive Temperature 1.0
Hard Disk Drive temperature meter

PC Wizard 2009.1.911
Powerful system information/benchmark utility designed especially for detection of hardware.

SIW 2009-10-22
Gathers detailed information about your system properties and settings.

CPU-Z 1.52
It gathers information on some of the main devices of your system

GPU-Z 0.3.6
A lightweight utility designed to give you all information about your video card and GPU

PCI 32 Sniffer 1.4 (1811)
device information tool (similar to unknown devices)

UnknownDevices 1.4.20 (1811)
helps you find what those unknown devices in Device Manager really are

USBDeview 1.47
View/Uninstall all installed/connected USB devices on your system


MBR (Master Boot Record) Tools

MBRWork 1.07b
a utility to perform some common and uncommon MBR functions

MBRTool 2.3.200
backup, verify, restore, edit, refresh, remove, display, re-write...

DiskMan 4.2
all in one tool for cmos, bios, bootrecord and more

BootFix Utility
Run this utility if you get 'Invalid system disk'

MBR SAVE / RESTORE 2.1
BootSave and BootRest tools to save / restore MBR

Boot Partition 2.60
add Partition in the Windows NT/2000/XP Multi-boot loader

Smart Boot Manager 3.7.1
a multi boot manager

MBRWizard 2.0b
Directly update and modify the MBR (Master Boot Record)

Grub4Dos installer 1.1
an universal boot loader GRUB for DOS installer

MbrFix 1.3
To backup, restore, fix the boot code in the MBR


BIOS / CMOS Tools

CMOS 0.93
CMOS Save / Restore Tool

BIOS Cracker 5.0
BIOS password remover (cmospwd)

BIOS Utility 1.35.0
BIOS Informations, password, beep codes and more.

!BIOS 3.20
a powerfull utility for bios and cmos

DISKMAN4
a powerful all in one utility

UniFlash 1.40
bios flash utility

Kill CMOS
a tiny utility to wipe cmos

Award DMI Configuration Utility 2.43
DMI Configuration utility for modifying/viewing the MIDF contents.


MultiMedia Tools

Picture Viewer 1.94
Picture viewer for dos, supports more then 40 filetypes.

QuickView Pro 2.58
movie viewer for dos, supports many format including divx.

MpxPlay 1.56
a small Music Player for dos


Password Tools

Active Password Changer 3.0.420
To Reset User Password on windows NT/2000/XP/2003/Vista (FAT/NTFS)

Offline NT/2K/XP Password Changer
utility to reset windows nt/2000/xp administrator/user password.

Registry Reanimator 1.02
Check and Restore structure of the Damaged Registry files of NT/2K/XP

NTPWD
utility to reset windows nt/2000/xp administrator/user password.

Registry Viewer 4.2
Registry Viewer/Editor for Win9x/Me/NT/2K/XP

ATAPWD 1.2
Hard Disk Password Utility

TrueCrypt 6.3
On-the-fly disk encryption tool, can create a virtual encrypted disk within a file and mount it as a real disk, can also encrypt an entire HDD/Partition/USB Drive

Content Advisor Password Remover 1.01
It Removes Content Advisor Password from Internet Explorer

Password Renew 1.1
Utility to (re)set windows passwords

WindowsGate 1.1
Enables/Disables Windows logon password validation

WinKeyFinder 1.73
Allows you to View and Change Windows XP/2003 Product Keys, backup and restore
activation related files, backup Microsoft Office 97, 2000 SP2, XP/2003 keys etc.

XP Key Reader 2.7
Can decode the XP-key on Local or Remote systems

ProduKey 1.38
Recovers lost the product key of your Windows/Office

WirelessKeyView 1.30
Recovers all wireless network keys (WEP/WPA) stored in your computer by WZC

MessenPass 1.27
A password recovery tool that reveals the passwords of several instant messangers

Mail PassView 1.52
Recovers mail passwords of Outlook Express, MS Outlook, IncrediMail, Eudora, etc.

Asterisk Logger 1.04
Reveal passwords hidden behind asterisk characters


NTFS (FileSystems) Tools

NTFS Dos Pro 5.0
To access ntfs partitions from Dos

NTFS 4 Dos 1.9
To access ntfs partitions from Dos

Paragon Mount Everything 3.0
To access NTFS, Ext2FS, Ext3FS partitions from dos

NTFS Dos 3.02
To access ntfs partitions from Dos

EditBINI 1.01
to Edit boot.ini on NTFS Partition
Browsers / File Managers

Volkov Commander 4.99
Dos File Manager with LongFileName/ntfs support
(Similar to Norton Commander)

Dos Command Center 5.1
Classic dos-based file manager.

File Wizard 1.35
a file manager - colored files, drag and drop copy, move, delete etc.

File Maven 3.5
an advanced Dos file manager with high speed PC-to-PC file
transfers via serial or parallel cable

FastLynx 2.0
Dos file manager with Pc to Pc file transfer capability

Dos Navigator 6.4.0
Dos File Manager, Norton Commander clone but has much more features.

Mini Windows 98
Can run from Ram Drive, with ntfs support,
Added 7-Zip, Disk Defragmenter, Notepad / RichText Editor,
Image Viewer, .avi .mpg .divx .xvid Movie Player, etc...

Mini Windows Xp
Portable Windows Xp that runs from CD/USB/Ram Drive, with Network and SATA support

7-Zip 9.07 beta
File Manager/Archiver Supports 7z, ZIP, GZIP, BZIP2, TAR, RAR, CAB, ISO, ARJ, LZH, CHM, MSI, WIM, Z, CPIO, RPM, DEB and NSIS formats

Opera Web Browser 8.53
One of the fastest, smallest and smartest full-featured web browser


Other Tools

Ghost Walker 11.5
utility that changes the security ID (SID) for Windows NT, 2000 and XP

DosCDroast beta 2
Dos CD Burning Tools

Universal TCP/IP Network 6.4
MSDOS Network Client to connect via TCP/IP to a Microsoft based
network. The network can either be a peer-to-peer or a server based
network, it contains 91 different network card drivers

HxD 1.7.7.0
Hex Editor provides tools to inspect and edit files, main memory, disks/disk images

Virtual Floppy Drive 2.1
enables you to create and mount a virtual floppy drive on your NT/2000/XP/Vista

FileDisk Mount Tool 25
to mount ISO/BIN/NRG/MDF/IMA images on windows.

Streams 1.56
Reveal/Delete NTFS alternate data streams

NewSID 4.10
utility that changes the security ID (SID) for Windows NT, 2000 and XP


Dos Tools

USB CD-Rom Driver 1
Standard usb_cd.sys driver for cd drive

Universal USB Driver 2
Panasonic v2.20 ASPI Manager for USB mass storage

ASUSTeK USB Driver 3
ASUS USB CD-ROM Device Driver Version 1.00

SCSI Support
SCSI Drivers for Dos

SATA Support
SATA Driver (gcdrom.sys) and JMicron JMB361 (xcdrom.sys) for Dos

1394 Firewire Support
1394 Firewire Drivers for Dos

Interlnk support at COM1
To access another computer from COM port

Interlnk support at LPT1
To access another computer from LPT port

and too many great dos tools
very good collection of dos utilities
extract.exe pkzip.exe pkunzip.exe lha.exe gzip.exe
uharcd.exe imgExtrc.exe xcopy.exe diskcopy.com mouse.com
undelete.com edit.com fdisk.exe fdisk2.exe fdisk3.exe
lf.exe delpart.exe wipe.com zap.com format.com
deltree.exe more.com find.exe hex.exe debug.exe
split.exe mem.exe attrib.com sys.com smartdrv.exe
xmsdsk.exe killer.exe share.exe scandisk.exe scanreg.exe
guest.exe doskey.exe duse.exe move.exe setver.exe
intersvr.exe interlnk.exe loadlin.exe lfndos.exe doslfn.com

Cleaners

SpaceMonger 1.4
keeping track of the free space on your computer

WinDirStat 1.1.2.80
a disk usage statistics viewer and cleanup tool for Windows.

CCleaner 2.25
Crap Cleaner is a freeware system optimization and privacy tool
Optimizers

PageDfrg 2.32
System file Defragmenter For NT/2k/XP

NT Registry Optimizer 1.1j
Registry Optimization for Windows NT/2000/2003/XP/Vista

DefragNT 1.9
This tool presents the user with many options for disk defragmenting

JkDefrag 3.36
Free disk defragment and optimize utility for Windows 2000/2003/XP/Vista/Windows 7


Network Tools

Angry IP Scanner 2.21
Scan IP addresses in any range as well as any their ports

CurrPorts 1.80
displays the list of all currently opened TCP and UDP ports on your computer

TCPView 2.54
Lists TCP and UDP endpoints, including the Local/Remote addresses of TCP connections

Winsock 2 Fix for 9x
to fix corrupted Winsock2 information by poorly written Internet programs

XP TCP/IP Repair 1.0
Repair your Windows XP Winsock and TCP/IP registry errors


Process Tools

Dependency Walker 2.2
Checks for missing/invalid DLL/modules/functions for any exe/dll/ocx/sys.

IB Process Manager 1.04
a little process manager for 9x/2k, shows dll info etc.

Process Explorer 11.33
shows you information about which handles and DLLs processes have opened or loaded

OpenedFilesView 1.46
View opened/locked files in your system, sharing violation issues

Pocket KillBox 2.0.0.978
can be used to get rid of files that stubbornly refuse to allow you to delete them

ProcessActivityView 1.10
Detailed process access information read/write/opened files etc

Unlocker 1.8.8
This tool can delete file/folder when you get this message - Cannot delete file:
Access is denied, The file is in use by another program etc.


Registry Tools

RegScanner 1.80
Tool to find/search in the Registry of Windows

Registry Editor PE 0.9c
Easy editing of remote registry hives and user profiles

Registry Restore Wizard 1.0.4
Restores a corrupted system registry from Xp System Restore


Startup Tools

Autoruns 9.56
Displays All the entries from startup folder, Run, RunOnce, and other Registry keys,
Explorer shell extensions,toolbars, browser helper objects, Winlogon notifications,
auto-start services, Scheduled Tasks, Winsock, LSA Providers, Remove Drivers
and much more which helps to remove nasty spyware/adware and viruses.

Silent Runners Revision 60
A free script that helps detect spyware, malware and adware in the startup process

Startup Control Panel 2.8
a tool to edit startup programs

Startup Monitor 1.02
it notifies you when any program registers itself to run at system startup

HijackThis 2.0.2
a general homepage hijackers detector and remover and more
Tweakers

Dial a Fix 0.60.0.24
Fix errors and problems with COM/ActiveX object errors and missing registry entries,
Automatic Updates, SSL, HTTPS, and Cryptography service (signing/verification)
issues, Reinstall internet explorer etc. comes with the policy scanner

Ultimate Windows Tweaker 2.0
A TweakUI Utility for tweaking and optimizing Windows Vista

TweakUI 2.10
This PowerToy gives you access to system settings that are not exposed in the Windows Xp

Xp-AntiSpy 3.97.5
it tweaks some Windows XP functions, and disables some unneeded Windows services quickly

Shell Extensions Manager (ShellExView) 1.45
An excellent tool to View and Manage all installed Context-menu/Shell extensions

EzPcFix 1.0.0.16
Helpful tool when trying to remove viruses, spyware, and malware

RemoveWGA 1.2
Windows Genuine Advantage Notifications Removal tool

RRT - Remove Restrictions Tool 3.0
To Re-enable Ctrl+Alt+Del, Folder Options and Registry tools etc.


Antivirus Tools

Kaspersky Virus Removal Tool 7.0.0.290 (1811)
Free on-demand virus scanner from Kaspersky Lab to remove viruses.

Spybot - Search & Destroy 1.6.2 (1811)
Application to scan for spyware, adware, hijackers and other malicious software.

Malwarebytes' Anti-Malware 1.41 (1811)
anti-malware application that can thoroughly remove even the most advanced malware.

SpywareBlaster 4.2 (1811)
Prevent the installation of spyware and other potentially unwanted software.

SmitFraudFix 2.424
This removes Some of the popular Desktop Hijack malware

ComboFix (1811)
Designed to cleanup malware infections and restore settings modified by malware

CWShredder 2.19
Popular CoolWebSearch Trojan Remover tool

RootkitRevealer 1.7.1
Rootkit Revealer is an advanced patent-pending root kit detection utility.

SuperAntispyware 4.30 (1811)
Remove Malware, Rootkits, Spyware, Adware, Worms, Parasites (a must have tool)


相關連結


EVEREST Ultimate Edition 5.30.2009



EVEREST Ultimate Edition 可提供如下的資訊:

硬體資訊:

* 主機板及 CPU(可顯示晶片組、BIOS、AGP 設定值、記憶體設定值…等相關資訊)

* 顯示卡及顯示器

* 儲存裝置

* 網路介面卡、多媒體裝置以及輸入裝置

* 其他硬體資訊


軟體資訊:

* 作業系統

* 已安裝的軟體

* 網路


安全資訊:

* Windows 安全(可顯示已安裝的更新或系統還原狀態…等資訊)

* 已安裝的安全性軟體之相關資訊


偵斷測試:

* 系統穩定度測試

* 硬體監視

* CPU 及 FPU 之測試

* 記憶體測試

* 磁碟測試


系統需求:

* 支援的作業系統

o Windows 95/98/Me

o Windows NT4/2000

o Windows XP

o Windows XP x64 Edition

o Windows PE

o Windows Server 2003

o Windows Vista

o Windows Vista x64 Edition

o Windows Server 2008

o Windows 7

o Windows Server 2008 R2

* CPU:至少 Pentium(或以上)

* 系統記憶體:至少 32 MB(或以上);若要測試 CPU、FPU 或記憶體,則需要 128 MB(或以上)

* 硬碟可用空間:至少 12 MB(或以上)





EVEREST Ultimate Edition Download (參考資訊:滄者極限討論區)


CHFI (Computer Hacking Forensic Investigator) 電腦駭客鑑識偵查員

CHFI (Computer Hacking Forensic Investigator)為電腦駭客鑑識偵查員的認證,簡單的說就是「數位鑑識」會用到的技術證照….

何謂「電腦鑑識」

在 牛津辭典中 Computer Forensics (電腦鑑識)的定義為 "the application of forensic science technique to computer-base material.",主要的過程在於應用嚴謹的程序及科技的方法去處理數位資訊設備相關鑑識工作,當公司或個人遇到資訊相關緊急事故時,如何還原事情發生的真相,即為電腦鑑識領域的範疇。


根據加州柏克萊大學的研究,目前公司中有超過93%的資訊產出是以數位格式分散貯存在各個系統中,同時相同的研究也指出在 所有的資訊犯罪、侵權案例中,有超過85%的案例均會留下數位遺趾 (Foot print)。因此如何以科技的方法,在具有證據力的前題下將所有的數位資訊證據正確搜集及分析,則為電腦鑑識主要工作項目。


在鑑識領域 中的一句名言 "有一分證據,說一分話",因此電腦鑑識必需根據現有系統中所保留的任何資訊來研究分析,找出跟事件有關聯的資訊證據而無法無中生有,因此電腦鑑識工作者往往需要花費大量的時間去將資訊整理及分析,而所運用的科技方法主要在於達成一個目標,"只要證據存在就可以找得出來"。


電腦駭客鑑識偵查員的認證是由EC -Council所推出,在臺灣總代理是翊利得資訊,包括翊利得資訊、資策會都有開CHFI的課程。因為 CHFI是EC-Council道德駭客認證(CEH)的進階認證,為了滿足資安技術人員的進階需求,從3年前剛推出的1年1班,到最近的1年3~4班。 顯見越來越多政府或企業重視數位採證的技術。


CHFI是1個5天的課程,認證課程面向較廣,首先是了解何謂鑑識,從基本設備、鑑識實驗 室的環境規畫等;再者,就得先了解檔案與系統格式,才知道怎麼把已經被刪除或消失的證據找出來。接下來,鑑識人員就得知道如何按部就班做鑑識,並了解進行鑑識時,所有會發生的困難與挑戰。而怎麼寫鑑識報告,甚至進一步成為法庭上的專家證人,也都會在CHFI的篇章中詳細介紹到。


EC-council 介紹:
EC- Council(國際電子商務顧問局)全稱為International Council of E-Commerce Consultants,是一家以會員制為基礎的專業機構,總行設于紐約,主要來自哈彿大學、紐約市立大學、加利福尼亞大學、澳洲昆士蘭中央大學等大學教授,講師以及從事電子商務的企業界人士組成;還有來自Microsoft、IBM、SONY、Cisco等國際著名機構的代表。EC-Council的目 的是支持和加強在設計、建立、管理、推廣電子商務事業上發展的個人及機構的機能,向電子商務人士提供專業認證,向會員提供電子商務教育,技術等優惠技術。 EC-Council在企業界建立了國際通訊網路,成為電子商務專業人士的全球代言人。


EC-Council認證目前全世界取得證照人數超過五千人,許多是公司派訓人員參加,顯示各公司對於此認證的重視程度。國內所有中大型的企業都需要這樣的證照,可以防護企業網路安全,目前台灣才剛引進此種認證,目前國內有少數人員取得此種認證,未來此證照將有迫切需求。

WinDD 1.3 簡介&下載

WinDD 1.3


相容性列表:

Raw memory dump:

* Windows 2000 (32-Bits)

* Windows XP (32-Bits and 64-Bits)

* Windows 2003 (32-Bits and 64-Bits)

* Windows Vista (32-Bits and 64-Bits)

* Windows 2008 (32-Bits and 64-Bits)

* Windows 7 (32-Bits and 64-Bits)

* Windows 2008 R2 (32-Bits and 64-Bits)

Microsoft crash dump:

* Windows XP (32-Bits and 64-Bits)

* Windows 2003 (32-Bits and 64-Bits)

* Windows Vista (32-Bits and 64-Bits)

* Windows 2008 (32-Bits and 64-Bits)

* Windows 7 (32-Bits and 64-Bits)

* Windows 2008 R2 (32-Bits and 64-Bits)


特性:

* Raw dump generation

* Standalone Microsoft crash dump generation

* Network support (client + server)

* SMB path support

* MD5, SHA-1 and SHA-256 hash support

* Support 3 mapping methods for both full crash dump and raw memory dump generation

* Support 3 content rules

* Fast

* 32-bits and 64-bits support

* Can hibernate the system.

* Can generate a Blue Screen of the Death

* Support of machine with more than 4GB of RAM.

Microsoft Windows has an internal limitation which does not allow to generate a Microsoft Full Crash dump if the local machine has more than 2GB of physical memory. Of course, this limitation does not affect windd but it was funny and a good surprise to see Windbg correctly works with 8GB Microsoft crash dump (successfuly tested by Jimmy).




WinDD 1.3 下載

Mozilla Firefox 3 History File Format

Firefox 從版本3開始,使用新的文件格式來儲存瀏覽的歷史紀錄,而不是把這些紀錄存於mork文件格式,紀錄改為保存在一個SQLite資料庫



文件位置(File Locations)

Windows XP

C:\Documents and Settings\<username>\Application Data\Mozilla\Firefox\Profiles\<profile folder>\places.sqlite

Windows Vista

C:\Users\<user>\AppData\Roaming\Mozilla\Firefox\Profiles\<profile folder>\places.sqlite

GNU/Linux

/home/<user>/.mozilla/firefox/<profile folder>/places.sqlite

Mac OS X

/Users/<user>/Library/Application Support/Firefox/Profiles/default.lov/places.sqlite



文件標頭(File Header)

Firefox 3 history files start with

53 51 4C 69 74 65 20 66 6F 72 6D 61 74 20 33

which represents the ascii string SQLite format 3. This is normal for any Sqlite database file, so it may be more appropriate to verify that the file is a Firefox 3 history file by looking for the database tables within the file. For example, at offset 120701 (0x1D77D) the hex value

43 52 45 41 54 45 20 54 41 42 4C 45 20 6D 6F 7A 5F 62 6F 6F 6B 6D 61 72 6B 73

can be found. This represents the ascii string CREATE TABLE moz_bookmarks. At offset 120973 (0x1D88D) the hex value

43 52 45 41 54 45 20 49 4E 44 45 58 20 6D 6F 7A 5F 62 6F 6F 6B 6D 61 72 6B 73 5F 69 74 65 6D 69 6E 64 65 78

can be found. This represents the ascii string CREATE TABLE moz_bookmarks_itemindex.



資料庫表(Database Tables)

The places.sqlite file is essentially a database with multiple tables: moz_anno_attributes

moz_annos

moz_bookmarks

moz_bookmarks_roots

moz_favicons

moz_historyvisits

moz_inputhistory

moz_items_annos

moz_keywords

moz_places



參考來源:wiki

DEFT v5 鑑識工具

DEFT開發出最新的鑑識工具DEFT V5x,DEFT V5x是Live CD,提供鑑識人員於取證時完整的鑑識工具(當然還是有缺拉),除了Windows介面下的鑑識工具更新之外,以Linux環境開機後也收錄更多GUI工具,已經快有之前Helix Live CD的影子了,詳細更新內容如下:


DEFT v5 computer and network forensic packages list:

  • sleuthkit 3.01, collection of UNIX-based command line tools that allow you to investigate a computer
  • autopsy 2.21, graphical interface to the command line digital investigation tools in The Sleuth Kit
  • dhash 2, multi hash tool
  • aff lib 3.5.2, advanced forensic format
  • gpart, tool which tries to guess the primary partition table of a PC-type hard disk
  • guymager 0.4.2-1, a fast and most user friendly forensic imager
  • dd rescue 1.13, copy data from one file or block device to another
  • dcfldd 1.3.4.1, copy data from one file or block device to another with more functions
  • linen 6.01, Linux version of the industry- standard DOS-based EnCase acquisition tool
  • foremost 1.5.6, c onsole program to recover files based on their headers, footers, and internal data structures
  • photorec 6.11, easy carving tool
  • mount manager 0.2.6, advanced and user friendly mount manager
  • scalpel 1.60, carving tool
  • wipe
  • hex dump, combined hex and ascii dump of any file
  • outguess, a stegano tool
  • ophcrack 3.3.0, Windows password recovery
  • Xplico 0.6 DEFT edition, advanced network analyzer
  • Wireshark 1.2.2, network sniffer
  • ettercap 0.7.3, network sniffer
  • nessus 4, vulnerability and security scanner, client
  • nessusd 4, vulnerability and security scanner, server
  • nmap 5, the best network scanner
  • kismet 2008.05 R1, sniffer and intrusion detection system that work with any wireless card
  • dmraid, discover software RAID devices
  • testdisk, tool to recover damaged partitions
  • vinetto, tool to examine Thumbs.db files
  • trID 2.02 DEFT edition, tool to identify file types from their binary signatures
  • readpst 0.6.41, a tools to read ms-Outlook pst files
  • snmpwalk
  • chkrootkit, Checks for signs of rootkits on the local system
  • rkhunter 1.3.4, rootkit, backdoor, sniffer and exploit scanner
  • john 1.7.2, john the ripper password cracker
  • clam, antivirus 4.15
  • mc, UNIX file manager


DEFT extra 2.0:

  • System Information
  • Drive Manager
  • Reg Scanner
  • Win Audit
  • ReSysInfo
  • USB Deview
  • Bluethoot View
  • User Assist view
  • WRR
  • My Event View
  • MSI
  • Curr Proces
  • Live Acquisition
  • FTK imager
  • Winen
  • MDD
  • Forensics Tool
  • WFT
  • Zero View
  • WFA
  • File Alyser
  • Nigilant32
  • USB history
  • Shell command
  • PC on/off time
  • Password Recovery
  • Asterix logger
  • PassworFox
  • Chrome Pass
  • IE PassView
  • Wireless Key View
  • Mail pass view
  • Incredimail Message Extractor
  • Networking
  • Web Browser
  • IE Cookie View
  • IE History View
  • Mozilla Cookie View
  • Mozilla History View
  • Mozilla Cache view
  • Opera Cache View
  • Chrome Cache View
  • Index.dat Analyzer 2.0
  • Historian
  • FoxAnalisis
  • Utility tool
  • Skype Log View
  • Home Keylogger
  • HexEdit
  • SDHash
  • WipeDisk
  • USBWriteProtector
  • Testdisk
  • LTF View
  • AVI screen
  • Hower Snap
  • VNC Viewer
  • Sumatra PDF
  • Putty
  • Pre-Search
  • Photorec
  • Notepad++
  • WinMD5sum
  • Abiword
  • Undelete Plus
  • Hash calc
  • IP Net Info
  • SysInternal
  • Access Enum
  • autoruns
  • diskView
  • Regmon
  • WinOBj
  • Filemon
  • ProceXp
  • TCPView
  • Rootkit Revealer

DEFT v5 features list:
  • incorruptibility of the partitions
  • incorruptibility of the swap spaces
  • linux Kernel 2.6.31
  • LXDE
  • apt-get system
  • vino
  • rdesktop
  • samba client
  • open SSH client & server
  • ntfs3g
  • lvm support
  • brasero
  • record my desktop
  • wicd network manager
  • speedcrunch
  • htop


工具畫面截圖:

Boot

Dhash 2 text mode

Desktop

Software list

Dhash 2

Autopsy

Mount manager



DEFT V5x下載

電腦啟動過程簡介

以下以Windows作業系統為例介紹電腦的啟動過程:


1. Power-On Self Test ,接上電源後自我檢測

(1) 當按下電源開關時,電源就開始向主機板及其他裝置供電,電壓穩定後,CPU就從特定的位置開始執行指令

(2) 之後系統BIOS的啟動程式碼進行POST(Power-On Self Test,接上電源後自我檢測)


2. BIOS 初始檢測

(1) 系統BIOS將開始尋找顯示卡及其他裝置的BIOS程式,找到之後呼叫這些BIOS內部的初始化程式碼來初始化相關的裝置。

(2) 尋找完所有其他裝置的BIOS後,系統BIOS將顯示出它自己的啟動畫面,其中包括有系統BIOS的類型、序號及版本號等內容。

(3) 接者系統BIOS將檢測和顯示CPU的類型和工作頻率,然後開始測試所有的RAM,並同時在螢幕上顯示記憶體測試的進度。


3. BIOS 硬體檢測

(1) 記憶體測試之後系統BIOS將開始檢測系統中安裝的一些標準硬體裝置,包括硬碟、CD-ROM、排序埠、平行怖、軟碟機等裝置,另外絕大多數較新版本的系統BIOS在這一過程中還要自動檢測和設置記憶體的定時參數,硬碟參數和存取模式等。

(2) 標準裝置檢測完畢後,系統BIOS內部的支援隨插即用程式碼將開始檢測和設定系統中安裝的隨插即用裝置,每找到一個裝置之後,系統BIOS都會在螢幕上顯示出裝置的名稱和型號等資訊,同時為該裝置分配中斷,DMA通道和I/O埠等資源。

(3) 所有硬體都已經檢測設定完畢後,多數系統BIOS會重新整理螢幕並在上方顯示出一個表格,其中概略的列出了系統中安裝的各種標準硬體裝置,以及它們使用的資源和一些相關的工作參數。


4. 更新ESCD(Extended system Configuration Data,擴充系統組態資料)

接下來系統BIOS將更新ESCD(Extended system Configuration Data,擴充系統組態資料。ESCD示系統BIOS用來與作業系統交換硬體設定資訊的一種手段,這些資料被存放在CMOS之中。


5. 選擇啟動順序

ESCD更新完畢後,系統BIOS的啟動程式碼將進行他的最終一項工作,即根據使用者指定的啟動順序從軟碟、硬碟或光碟機啟動。

以從C碟啟動為例,系統BIOS將讀取並執行硬碟上的主開機記錄,主開機記錄接者從分區表中找到第一個使用中的磁碟分割,然後讀取並執行這個使用中的磁碟分個的分區開機記錄,而分區開機記錄將負責讀取並執行IO.SYS,並進一步開機即啟動磁區。


參考文獻馬林著「資料重現」

WinHex 15.2 繁體中文版

這套就不用多說了吧,功能強到爆還免費,以下為官方簡介:


WinHex: Computer Forensics & Data Recovery Software,
Hex Editor & Disk Editor
Windows 2000/XP/2003/Vista*/2008*/7*






winhex

WinHex is in its core a universal hexadecimal editor, particularly helpful in the realm of computer forensics, data recovery, low-level data processing, and IT security. An advanced tool for everyday and emergency use: inspect and edit all kinds of files, recover deleted files or lost data from hard drives with corrupt file systems or from digital camera cards. Features include (depending on the license type):
  * Disk editor for hard disks, floppy disks, CD-ROM & DVD, ZIP, Smart Media, Compact Flash, ...
  * Native support for FAT, NTFS, Ext2/3, ReiserFS, Reiser4, UFS, CDFS, UDF
  * Built-in interpretation of RAID systems and dynamic disks
  * Various data recovery techniques
  * RAM editor, providing access to physical RAM and other processes' virtual memory
  * Data interpreter, knowing 20 data types
  * Editing data structures using templates (e.g. to repair partition table/boot sector)
  * Concatenating and splitting files, unifying and dividing odd and even bytes/words
  * Analyzing and comparing files
  * Particularly flexible search and replace functions
  * Disk cloning (under DOS with X-Ways Replica)
  * Drive images & backups (optionally compressed or split into 650 MB archives)
  * Programming interface (API) and scripting
  * 256-bit AES encryption, checksums, CRC32, hashes (MD5, SHA-1, ...)
  * Erase (wipe) confidential files securely, hard drive cleansing to protect your privacy
  * Import all clipboard formats, incl. ASCII hex values
  * Convert between binary, hex ASCII, Intel Hex, and Motorola S
  * Character sets: ANSI ASCII, IBM ASCII, EBCDIC, (Unicode)
  * Instant window switching. Printing. Random-number generator.
  * Supports files >4 GB. Very fast. Easy to use. Extensive online help. (more)
Having all the bits and bytes in a computer at your fingertips has become a reality. Try before you buy, as long as you need, for free. Computer forensics edition of WinHex with even more features: X-Ways Forensics.




官方最新的1.56版 下載
15.2繁體中文版     下載


如何重設MySQL的root密碼(5.1.42)


針對Windows版本的MySQL(5.1.42),解密步驟:


1.登入windows系統(系統管理員身份)。


2.如果MySQL是啟動的,先將它關閉。


3.打開命令列視窗cmd。如果在上一步驟,沒有關閉MySQL,可以用 net start 查看MySQL是否還在啟動狀態。在啟動狀態的話,就用net stop mysql的指令將MySQL的服務停止。


4.切換到MySQL的安裝路徑的bin資料夾內,如果是預設路徑,應該在c:\Program Files\MySQL\MySQL Server XX\bin之下。


5.執行mysqld --skip-grant-tables,這個指令用以啟動MySQL,但會跳過權限檢查。


6.上個指令執行完後,命令視窗就停在MySQL的運行狀態,不能再輸入指令了,所以要重新打開一個新的cmd命令列視窗。 同樣切換到MySQL的安裝路徑的bin資料夾內,執行MySQL


7.在mysql>的模式下,執行


update mysql.user set password=PASSWORD('1111') where user='root';


flush privileges;


quit;

上面的步驟就可將忘記的密碼重設。


8.回到dos命令模式,執行 mysqladmin -u root -p shutdown,輸入剛改過的密碼1111。關掉目前MySQL無權限的模式。


9.再正常啟動MySQL。


Capture2010-1-25-下午 12.29.08.jpg


參考資料:


如果忘記mysql的root密碼(Windows)?


mysql忘記root密碼搞定方法(windows)


如何重設忘記的mysql密碼(mysql 5.1.42)


Process 解說網站

常常遇到作業系統中的Process(程序)不知道是什麼用途的話可以到這些網站查詢查詢~

1.ProcessLibrary: http://www.processlibrary.com/

ScreenShot00086.png

輸入所要查詢的程式名稱後會顯示正常或不正常程式的說明。

ScreenShot00087.png

2.Process info: http://process-info.org/

ScreenShot00088.png

查詢後一樣會列出查詢程式的相關資訊,但是資訊較為雜亂。

ScreenShot00089.png

另外如果你查的程式不是Process而是File的話可以到這邊~

What the file: http://whatisthatfile.com/index.php

ScreenShot00090.png

ScreenShot00091.png

F-response TACTICAL 簡介

F-Response 是一個在線取證工具,可以用於通過局域網絡獲取在線狀態下的數據,不會使原始數據發生改變。最近,F-Response最新發佈了TACTICAL版本。

同以往的版本不同,F-response最新發佈的TACTICAL 帶有兩個軟件狗。這些狗都是成對提供的。每個狗上都清晰地標記著"調查員專用 Examiner"和「嫌疑機專用 Subject」,以便區分在不同的計算機上插入。


當進行調查時,需要將「嫌疑機專用」狗插入需要檢查的計算機usb接口中。「調查員專用」狗需要插入調查員使用的分析計算機中。嫌疑機專用狗目前可以在Windows (包括Windows 7), OS X, 和 Linux系統下運行。調查員專用狗僅支持Windows系統。.

軟件

對嫌疑計算機的處理與原來的FK版本有些相似。

FK版本需要在嫌疑計算機中插入軟件狗,查找該機的IP地址,並在聯網的調查員計算機中輸入得到的IP地址,同時輸入用戶名和口令以繼續連接。

而使用TACTICAL,可以將「嫌疑機專用」狗插入局域網中的任何一台需要調查的計算機中,運行軟件。

軟件會通過網絡發送一個"信號", 當你在調查員計算機中插入「調查員專用」狗,運行軟件,點擊「自動連接」,調查員計算機會自動發現「信號」並與「嫌疑計算機」自動連接。無需輸入用戶名和密碼進行校驗。

當嫌疑計算機與調查員計算機之間的連接被成功建立,調查員可以看到嫌疑計算機中所包含的存儲設備列表。這包括內置硬盤、RAID陣列,外接的usb存儲設備等。

F-Response 嫌疑機專用狗也同時被列在存儲設備列表中。這可以防止在調查中因疏忽造成差錯。需要連接或加載磁盤/卷,用戶僅需右鍵點擊相應的磁盤選擇Login to F-Response Disk即可。

連接成功後,調查員可以隨意使用各自熟悉使用的工具進行分析。筆者測試了 X-Ways, EnCase, FTK Imager等工具, 每種工具都能夠象分析本地硬盤一樣地分析遠程嫌疑計算機中的硬盤。

這個版本的推出,使在線取證變得更加簡單了。過去的FK版本使用相對比較繁瑣,需要連接、設置,並輸入用戶名、口令用於驗證。現在,僅需插入軟件狗,分別運行客戶端、服務端軟件,即可成功加載遠程存儲設備,非常簡便。

轉自計算機取證

Windows 7 快速鍵整理


  Win+Up 最大化
  Win+Down 還原 / 最小化
  Win+Left 通過AeroSnap靠左顯示
  Win+Right 通過AeroSnap靠右顯示
  Win+Shift+Left 跳轉左邊的顯示器
  Win+Shift+Right 跳轉右邊的顯示器
  Win+Home 最小化 / 還原所有其他窗口
  Win+T 選中任務欄首個項目
  再次按下則會在任務欄上循環切換
  Win+Shift+T 則是後退
  Win+Space 使用Aero Peek顯示桌面
  Win+G 呼出桌面小工具
  Win+P 外界顯示器(擴展桌面等)
  Win+X 移動中心
  Win+#(# = 數字鍵) 運行任務欄上第N個程序  
  比如: Win+1 使用第一個程序, Win+2 使用第二個...  
  Win + +
  Win + -(plus or minus key) 放大/縮小   
  資源管理器 
  Alt+P 顯示/隱藏 預覽面板   
  任務欄  
  Shift + 左鍵單擊某程序圖標 運行
  中鍵單擊某程序圖標 運行
  Ctrl + Shift + 左鍵單擊某程序圖標 以管理員身份運行
  Shift + 右鍵擊某程序圖標 顯示窗口菜單(還原 / 最小化/ 移動 / 等)
  Note: 通常可以右鍵窗口的任務欄預覽呼出此菜單
  Shift + 右擊某程序圖標(分組顯示窗口模式下) 呼出還原所有窗口/ 最小化所有窗口/關閉所有窗口等菜單
  Ctrl + 左鍵單擊某程序圖標(分組顯示窗口模式下) 在窗口或標籤中循環切換

Windows 7 GodMode


據國外媒體報導,近來炒得沸沸揚揚的上帝模式(GodMode)不僅適用於Windows 7和Windows Vista系統,而且適用於未來的Windows 8系統。

據悉,Windows 7上帝模式首先由國外的一個博客發現。該博客感嘆於此項隱藏功能的神奇,遂將其命名為「GodMode」。你可以用任何名稱創造新的文件夾,再加上特定的字串,就能直接進入各種設定的控制面板。

例如,在桌面新建一個文件夾,命名為 GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}。你會發現:圖標變成了「控制面板」,文件夾裡面有相當豐富的內容。

微軟公司技術專家帕特里克·羅傑斯(Patrick Rogers)透露:「請放心使用這種系統技巧。這只是一種可以使文件系統文件夾進入控制面板的簡便方法。事實上,用戶可以通過各種上帝模式完整地設置Windows系統。從Windows Vista時代開始,每個控制面板項目都有一個便於開發者訪問Windows核心功能的規範名(Canonical Name)。當你創建一個文件夾,並且給予它一個規範名,那麼它的圖標就會變為指向某一任務的控制面板項目。」

Windows部門總裁史蒂文-辛諾夫斯基(Steven Sinofsky)已經公開聲明,Windows 7系統中還存在數個類似存取各種設置的隱藏功能,包括選擇電源設置和指紋識別傳感器。

羅傑斯還公佈了一份完整的控制面板規範名(Control Panel Canonical Name)列表。有趣的是,某些控制面板規範名僅適用於「Windows 7及其以後版本」(Windows 7 and later),這就意味著Windows 8系統也將存在類似的系統設置技巧。

羅傑斯還表示:「微軟MSDN網站已經面向Windows Vista和Windows 7用戶提供規範名列表,你可以隨時享受在文件系統創建控制面板的樂趣。」
下面節選的一些控制面板規範名:

- 行動中心(Windows 7及其以後版本) {BB64F8A7-BEE7-4E1A-AB8D-7D8273F7FDB6}
- 備份和存儲(Windows 7及其以後版本) {B98A2BEA-7D42-4558-8BD1-832F41BAC6FD}
- 識別設備 (Windows 7及其以後版本) {0142e4d0-fb7a-11dc-ba4a-000ffe7ab428}
-憑證管理(Windows 7及其以後版本) {1206F5F1-0569-412C-8FEC-3204630DFB70}
- 桌面工具 (Windows 7及其以後版本) {37efd44d-ef8d-41b1-940d-96973a50e9e0}
- 設備和打印機 (Windows 7及其以後版本) {A8A91A66-3A7D-4424-8D24-04E180695C7A}
- 展示 (Windows 7及其以後版本) {C555438B-3C23-4769-A71F-B6D3D9B6053A}
- 入門 (Windows 7及其以後版本) {CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}
- 家庭組 (Windows 7及其以後版本) {67CA7650-96E6-4FDD-BB43-A8E774F73A57}
- 紅外線 (Windows 7及其以後版本) {A0275511-0E86-4ECA-97C2-ECD8F1221D08}
- 通知圖標 (Windows 7及其以後版本) {05d7b0f4-2121-4eff-bf6b-ed3f69b894d9}
-多點觸摸手繪板(Windows 7及其以後版本) {F82DF8F7-8B9F-442E-A48C-818EA735FF9B}
- 調製調解器 (Windows 7及其以後版本) {40419485-C444-4567-851A-2DD7BFA1684D}
- 還原 (Windows 7及其以後版本) {9FE63AFD-59CF-4419-9775-ABCC3849F861}
- 地區和語言 (Windows 7及其以後版本) {62D8ED13-C9D0-4CE8-A914-47DD628FB1B0}
- 遠程桌面 Microsoft.RemoteAppAndDesktopConnections (Windows 7 and later only) {241D7C96-F8BF-4F85-B01F-E2B043341A4B}
- 聲音 (Windows 7及其以後版本) {F2DDFC82-8F12-4CDD-B7DC-D4FE1425AA4D}
- 語音識別 (Windows 7及其以後版本) {58E3C745-D971-4081-9034-86E34B30836A}
- 疑難解決 (Windows 7及其以後版本) {C58C4893-3BE0-4B45-ABB5-A63E4B8C8651}