<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;AkYHQXY7fSp7ImA9WhRRFE4.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198</id><updated>2011-11-27T15:55:30.805-08:00</updated><category term="Super time line timeline forensics log2time timescanner sleuthkit sleuth kit Smith Petreski Methodology" /><title>DC Smith on Information Security</title><subtitle type="html">David C. Smith is the information security officer at Georgetown University and a co-owner of HCP Forensic Services at &lt;a href=http://www.hcp-fs.com&gt;http://www.hcp-fs.com&lt;/a&gt;.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://dcinfosec.blogspot.com/" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>23</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/DcSmithOnInformationSecurity" /><feedburner:info uri="dcsmithoninformationsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;AkINQX47fip7ImA9Wx5SEEw.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-8230768697190730509</id><published>2010-08-05T07:29:00.000-07:00</published><updated>2010-08-05T07:29:50.006-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-05T07:29:50.006-07:00</app:edited><title>DEFCON 18 Presentation</title><content type="html">Wow, time has flown by... &amp;nbsp;The presentation went great! &amp;nbsp;Sam and I were really amazed to see the connection to our presentation by lots of folks at DEFCON. &amp;nbsp;Conference was a bit crowded and hard to see the presentations that you wanted to see, but you have probably already read all those reports.&lt;br /&gt;
&lt;br /&gt;
Here is the presentation that Sam and I presented on July 30th. &amp;nbsp;Please feel free to email or let us know your thoughts!&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://gushare.georgetown.edu/xythoswfs/webui/_xy-6803290_1"&gt;Defcon 18 Presentation - DC Smith Sam Petreski - Forensic Methodology&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-8230768697190730509?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9noyww9HZy52gTIDkz9B84LyeEU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9noyww9HZy52gTIDkz9B84LyeEU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9noyww9HZy52gTIDkz9B84LyeEU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9noyww9HZy52gTIDkz9B84LyeEU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/1ILJGEUQaZ0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/8230768697190730509/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=8230768697190730509" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8230768697190730509?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8230768697190730509?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/1ILJGEUQaZ0/defcon-18-presentation.html" title="DEFCON 18 Presentation" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/08/defcon-18-presentation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQFRn8-fCp7ImA9WxFWF0o.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-6782457918940388143</id><published>2010-06-05T15:18:00.001-07:00</published><updated>2010-06-05T15:18:37.154-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-05T15:18:37.154-07:00</app:edited><title>It is official...</title><content type="html">Posted @ defcon.org today:&lt;br /&gt;
&lt;span class="Apple-style-span" style="color: #aaaa99; font-family: Helvetica, Arial, sans-serif; font-size: 14px; line-height: 17px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;h2 class="title" id="" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #336699; display: block; font-size: 1.6em; font-weight: 700; letter-spacing: -0.02em; line-height: 1.3em; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; max-width: 58%; min-width: 135px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 20px; padding-right: 0px; padding-top: 0px; position: relative; text-shadow: rgb(153, 204, 153) -1px -1px 0px; text-transform: uppercase; vertical-align: baseline; width: 580px; z-index: 4;"&gt;A NEW APPROACH TO FORENSIC METHODOLOGY - !!BUSTED!! CASE STUDIES&lt;/h2&gt;&lt;h4 class="byLine" style="background-attachment: initial; background-clip: initial; background-color: #336699; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: black; display: block; font-size: 1.2em; font-weight: 700; letter-spacing: -0.02em; line-height: 1.3em; margin-bottom: 10px; margin-left: 15px; margin-right: 0px; margin-top: -8px; max-width: 58%; min-width: 135px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 1px; padding-left: 10px; padding-right: 15px; padding-top: 4px; position: relative; text-shadow: none; text-transform: uppercase; vertical-align: baseline; width: 580px; z-index: 9;" title="DEFCON 18: Smith and Petreski - A New Approach to Forensic Methodology - !!BUSTED!! case studies"&gt;DAVID C. SMITH&lt;span class="speakerTitle" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-size: 0.7em; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&amp;nbsp;GEORGETOWN UNIVERSITY AND HCP FORENSIC SERVICES&lt;/span&gt;&lt;br /&gt;
SAMUEL PETRESKI&lt;span class="speakerTitle" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-size: 0.7em; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&amp;nbsp;GEORGETOWN UNIVERSITY AND REMOTE IT CONSULTING&lt;/span&gt;&lt;/h4&gt;&lt;div class="abstract" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-size: 14px; margin-bottom: 30px; margin-left: 20px; margin-right: 0px; margin-top: 20px; max-width: 58%; min-width: 58%; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; position: relative; vertical-align: baseline; width: 580px; z-index: 2;"&gt;Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case. The analysts are then measured based on the total findings, the time required to process the case, the initial information gathered, and the estimated time to process the case. The expected result is to be varied based on experience and individual characteristics, such as organization, discipline, and the attention to detail of each analyst. Imagine this same experiment but with only 8 hours to process the case, because that is the way it happens in real life.&lt;br /&gt;
&lt;br /&gt;
David Smith and Samuel Petreski have developed a methodology that fits within the Analysis phase in one of the standard Digital Forensic Analysis Methodologies - PEIA (Preparation, Extraction, Identification, and Analysis), to provide a structure for consistent results, better development of the requested goals, increase efficiency in fulfilling the goals, and develop an improved estimate of the time required to complete the request.&lt;br /&gt;
&lt;br /&gt;
This methodology involves the generation and validation of case goals, the evaluation of methods used to achieve the goals, a structure for estimating the effectiveness, time required, processing results of specific methods, and generalized organization and time management. The primary goal of this methodology is to address the structure and optimal path that would allow a digital forensic examiner to perform an examination with a high level of efficiency and consistent results.&lt;br /&gt;
&lt;br /&gt;
This presentation provides an introduction to this methodology and applies its key concepts to real sanitized digital investigations, such as tracking down a suspected executive's adult craigslist ad, performing an analysis on a compromised system involving social security numbers, and making the determination of intellectual property theft.&lt;br /&gt;
&lt;br /&gt;
&lt;span class="speakerBio" id="aeaoofnhgocdbnbeljkmbjdmhbcokfdb-mousedown" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #777766; font-size: 0.9em; font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;strong style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #bbbbbb; font-size: 13px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-shadow: black 0.7px 0.7px 0.7px; vertical-align: baseline;"&gt;David C. Smith&lt;/strong&gt;&amp;nbsp;works as the CSO for Georgetown University and a co-owner of HCP Forensic Services providing information security programs, digital forensics, and expert witness testimony. He has been in the technical field for over 20 years and enjoys engaging in complex technical problems.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="speakerBio" style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #777766; font-size: 0.9em; font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;strong style="background-attachment: initial; background-clip: initial; background-color: transparent; background-image: initial; background-origin: initial; background-position: initial initial; background-repeat: initial initial; border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; color: #bbbbbb; font-size: 13px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; outline-color: initial; outline-style: initial; outline-width: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-shadow: black 0.7px 0.7px 0.7px; vertical-align: baseline;"&gt;Samuel Petreski&lt;/strong&gt;&amp;nbsp;works as a Senior Security Analyst for Georgetown University and an owner of Remote IT Consulting. Samuel has worked mostly in higher-ed focusing on network architecture and administration, as well as building and administering scalable network security solutions. He posses over 10 years of experience in the IT field working in very diverse environments.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-6782457918940388143?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TonXXcjGl8FADN60i_hFi8D9wM8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TonXXcjGl8FADN60i_hFi8D9wM8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TonXXcjGl8FADN60i_hFi8D9wM8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TonXXcjGl8FADN60i_hFi8D9wM8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/iEzJbWzj644" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/6782457918940388143/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=6782457918940388143" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6782457918940388143?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6782457918940388143?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/iEzJbWzj644/it-is-official.html" title="It is official..." /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/06/it-is-official.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUEQH44eip7ImA9WxFWEUk.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-6039492124459072731</id><published>2010-05-29T06:36:00.000-07:00</published><updated>2010-05-29T06:36:41.032-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-29T06:36:41.032-07:00</app:edited><title>What's Up?</title><content type="html">Been working a lot, getting very excited about our Defcon 18 presentation and tool release. &amp;nbsp;We haven't heard back from Black Hat, but always thought it was a really long shot. &amp;nbsp;A better description is that it is part methodology, part process, and part expert system. &lt;br /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;The primary goals are to improve the initial request,&amp;nbsp;develop better agreed upon investigation goals, and improved time estimation. &amp;nbsp;Then in the analysis phase, better&amp;nbsp;guidance in choosing the optimal methods and a&amp;nbsp;structure&amp;nbsp;for time management. &amp;nbsp;Fun, eh?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Between that and wrapping up about 6 cases with my two teams (&lt;a href="http://www.hcp-fs.com/"&gt;HCP Forensic&lt;/a&gt;s and &lt;a href="http://security.georgetown.edu/"&gt;GU InfoSec&lt;/a&gt;) it has been a crazy couple of weeks. &amp;nbsp;I still have complete the last two rounds of my testing for the Tableau TD1 as well!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-6039492124459072731?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3DShlaB4QNNYjCnPOKslQ2KMXvk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3DShlaB4QNNYjCnPOKslQ2KMXvk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3DShlaB4QNNYjCnPOKslQ2KMXvk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3DShlaB4QNNYjCnPOKslQ2KMXvk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/F4uSdfwNsSI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/6039492124459072731/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=6039492124459072731" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6039492124459072731?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6039492124459072731?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/F4uSdfwNsSI/whats-up.html" title="What's Up?" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/05/whats-up.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04FRXY_eSp7ImA9WxFQGU8.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-417740150924686633</id><published>2010-05-15T06:25:00.000-07:00</published><updated>2010-05-15T06:25:14.841-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-15T06:25:14.841-07:00</app:edited><title>Tableau TD1 Forensic Imager Initial Review</title><content type="html">Yea, I finally got paid from wrapping up a case, worst was 90+ over due and best was 45+ days over due BUT the profit from these cases was earmarked to purchase new equipment. &amp;nbsp;The first purchase was from &lt;a href="http://forensicpc.com/"&gt;ForensicPC.com&lt;/a&gt;&amp;nbsp;and was the &lt;a href="http://www.forensicpc.com/proddetail.asp?prod=TD1"&gt;Tableau TD1 Forensic Imager&lt;/a&gt;. I priced it around and found I could have shaved $20 from the total price, but I had to wait on a full quote from a site that didn't have a online cart. &amp;nbsp;I also purchased it with the Pelican 1450 case (other sites had a mark-up, but free case).&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_jflhnU0XH58/S-6fnc_YlKI/AAAAAAAACGQ/1i4ImFt8Kq8/s1600/td1_front_right_angle_175x151.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_jflhnU0XH58/S-6fnc_YlKI/AAAAAAAACGQ/1i4ImFt8Kq8/s320/td1_front_right_angle_175x151.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Forensic PC ordering process was just okay, I submitted on a Saturday after depositing the check and they processed the order on Monday. &amp;nbsp;I got an email stating that I went from order received to paid, but then didn't hear anything for 8 days. &amp;nbsp;I wrote a note about the status and got an apology email saying that I should have got a message (maybe spam filtered) telling me about the delay on the TD1 and the case. &amp;nbsp;Since I filter spam and not delete, I checked and there was no message. &amp;nbsp;I did get emails on the ship status and tracking and it arrived yesterday - Whoo-hoo!&lt;br /&gt;
&lt;br /&gt;
Ok, enough overhead on the story. &amp;nbsp;I unpacked and inventoried everything and was impressed with the unit size and features. &amp;nbsp;I had previously used the Voom HC II and noticed a few differences that what I was used to. &amp;nbsp;First, speed. &amp;nbsp;I ran it through some testing (full&amp;nbsp;output&amp;nbsp;spreadsheet to come when complete) and the speed was impressive at 6GB+ on my equipment with MD5 and SHA1. &amp;nbsp;My initial tests were mostly functionality and not to quantify the speed but happy right away with the overall speed with SATA disk to disk, disk to file, and wipe. Second, I like the setup and input of examiner and case info. &amp;nbsp;I thought it might suck with slow typing but since I am used to IPhones it was that bad (I read that you can use a USB keyboard, but that is a future test). &lt;br /&gt;
&lt;br /&gt;
Now a little of the not-thrilled-about / maybe-getting-used-to. &amp;nbsp;Voom HC2 had NTFS format and could create a full size disk-to-file, e.g. 80GB drive to a 80GB file. &amp;nbsp;Sure it had a funky thing with once you mount a Voom HC2 NTFS drive on any system it was not&amp;nbsp;recognizable by the Voom again, but I like having large files without a follow up conversion. &amp;nbsp;TD1 can create FAT32 formats and the underneath structure of the TD1 seems that it is based on "chunks" and configuring the size of the chunks. &amp;nbsp;I processed some images and am not sure that it will be a big deal with me. &amp;nbsp;All my tools cover multiple files and TD1 puts them in nice directories with the dates.&lt;br /&gt;
&lt;br /&gt;
I did update the firmware first thing out of the box and the process was pretty nice. &amp;nbsp;Connected with a firewire 400 port and ran some Tableau windows software. The software saw my TD1 and recommended the firmware update. &amp;nbsp;It ran without any issue, and I powered down,&amp;nbsp;unplugged&amp;nbsp;everything, and powered back up to reread the firmware. &amp;nbsp;Tableau markets the ease of upgrade and would agree.&lt;br /&gt;
&lt;br /&gt;
I should be able to post my validation, functionality, and speed results in the next couple of weeks. &amp;nbsp;I got to get more progress on Sam and I's Defcon presentation.&lt;br /&gt;
&lt;br /&gt;
-Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-417740150924686633?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QC7PLA4rUO-U5gDNQUytgaEyCPI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QC7PLA4rUO-U5gDNQUytgaEyCPI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QC7PLA4rUO-U5gDNQUytgaEyCPI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QC7PLA4rUO-U5gDNQUytgaEyCPI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/0u9nScQdXY8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/417740150924686633/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=417740150924686633" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/417740150924686633?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/417740150924686633?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/0u9nScQdXY8/tableau-td1-forensic-imager-initial.html" title="Tableau TD1 Forensic Imager Initial Review" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_jflhnU0XH58/S-6fnc_YlKI/AAAAAAAACGQ/1i4ImFt8Kq8/s72-c/td1_front_right_angle_175x151.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/05/tableau-td1-forensic-imager-initial.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEARno7fSp7ImA9WxFQGE0.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-6676318056018793225</id><published>2010-05-13T18:30:00.000-07:00</published><updated>2010-05-13T18:30:47.405-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-13T18:30:47.405-07:00</app:edited><title>Defcon 18 Presentation</title><content type="html">Good news, Sam and I got an announcement this morning that we have been accepted by Defcon for our presentation "A New Approach to Forensic Methodology - !!BUSTED!! case studies". &amp;nbsp;We are pretty excited and always love Vegas - it is the bomb.&lt;br /&gt;
&lt;br /&gt;
The presentation is shaping up nicely and Sam is working on the software component that will really demonstrate our practical&amp;nbsp;methodology. &amp;nbsp;Again, very excited. &amp;nbsp;Buzz me if you want some up front information, but I'll probably hold off on posting some of the more interesting details until we get most of the work behind us.&lt;br /&gt;
&lt;br /&gt;
Ok, a&amp;nbsp;completely&amp;nbsp;different topic. &amp;nbsp;I am loving my setup for my primary system at home. &amp;nbsp;A quick review:&lt;br /&gt;
Intel i7 chip, custom cooling, overclocked to i7-965 using the Easy Tune app from Gigabyte MB. &amp;nbsp;Stress tested with Prime95 keeping the CPU / system temp under 80C at full load, 43C and 46C typical load. &amp;nbsp;Windows 7 64-bit, 8GB of mem, 4 1TB drive, 1 1.5 TB drive, ESATA for Thermaltake BlackX.&lt;br /&gt;
&lt;br /&gt;
Ok, the part I like: &amp;nbsp;I have become a big fan of Sun VirtualBox. &amp;nbsp;I can't put my finger on it, but my total experience is that it seems less invasive that VMware and gives me everything I want. &amp;nbsp;VMs have 1GB ram and&amp;nbsp;different levels of CPU cores assigned. &amp;nbsp;VM's include DeveloperXP, Ubuntu-64 (developer and workstation), Forensic XP, SIFT Workstation imported from VMware, Dirty XP (checking out dubious sites and software), and Georgetown XP. &amp;nbsp;I also have a&amp;nbsp;separated&amp;nbsp;malware XP and Ubuntu systems with additional protections.&lt;br /&gt;
&lt;br /&gt;
Best news, it runs like a champ - I don't feel any pain when running VMs and AV / Secunia PSI. &amp;nbsp;I can schedule snapshots and file them away. &amp;nbsp;Da Bomb-bay!&lt;br /&gt;
&lt;br /&gt;
BTW, see you in Vegas for Defcon and BlackHat - I love the vendor parties!!!&lt;br /&gt;
&lt;br /&gt;
&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0470460296&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-6676318056018793225?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/V0HS61rVZ4wYu6Vo37ZV7rRCJUs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/V0HS61rVZ4wYu6Vo37ZV7rRCJUs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/V0HS61rVZ4wYu6Vo37ZV7rRCJUs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/V0HS61rVZ4wYu6Vo37ZV7rRCJUs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/7igMnca7wY4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/6676318056018793225/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=6676318056018793225" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6676318056018793225?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/6676318056018793225?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/7igMnca7wY4/defcon-18-presentation.html" title="Defcon 18 Presentation" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/05/defcon-18-presentation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A04BSHwyeSp7ImA9WxFQEUk.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-2840916395594611911</id><published>2010-05-06T05:45:00.000-07:00</published><updated>2010-05-06T05:45:59.291-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-06T05:45:59.291-07:00</app:edited><title>Facebook Arrays</title><content type="html">Helping a friend out with a Facebook application and I had to deal with an array of array export from a multiquery FQL. &amp;nbsp;Sheeesh, fields and values mis-matched all over the place! &amp;nbsp;However, using dynamic PHP arrays it makes it a little easier with the following code.&lt;br /&gt;
&lt;br /&gt;
#Multiout is the array&amp;nbsp;delivered&amp;nbsp;from the FQL&lt;br /&gt;
&lt;br /&gt;
foreach($multiout as $fqlset) {&amp;nbsp;#Strip the wrapper array&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;$messagebody = $fqlset[fql_result_set]; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;foreach ($messagebody as $messageArray) { &amp;nbsp; #Strip the message vs. metadata&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;foreach ($messageArray as $key =&amp;gt; $value) { &amp;nbsp;#Finally get to drop the 'record name' and value&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$ordered_array[$key][] = $value;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;} &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;}&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
At the end of the process, you have an ordered array that was combined by the multiquery.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-2840916395594611911?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jkhAI2x3_zCbyldBNwN9rAzOpMQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jkhAI2x3_zCbyldBNwN9rAzOpMQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jkhAI2x3_zCbyldBNwN9rAzOpMQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jkhAI2x3_zCbyldBNwN9rAzOpMQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/yUtdRmviUOI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/2840916395594611911/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=2840916395594611911" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2840916395594611911?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2840916395594611911?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/yUtdRmviUOI/facebook-arrays.html" title="Facebook Arrays" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/05/facebook-arrays.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck4FRH4zfip7ImA9WxFRGEQ.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-3474708624096308924</id><published>2010-05-03T05:48:00.000-07:00</published><updated>2010-05-03T05:48:35.086-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-03T05:48:35.086-07:00</app:edited><title>Why I think a lot of online (potentially you) blogger are idiots!</title><content type="html">Yes, idiots - you know, filling the ID-10-T form in triplicate. &amp;nbsp;Yes, yes, I'll choose most dictionary first listing, "an utterly foolish or senseless person", and not the psychology term "a person of the lowest order in a former classification of mental retardation, having a mental age of less than three years old and an intelligence quotient under 25". &amp;nbsp;I don't think they are that bad.&lt;br /&gt;
&lt;br /&gt;
Ok, as you might know, I am a fan of &lt;a href="http://en.wikipedia.org/wiki/Critical_thinking"&gt;critical thinking (link to the wiki description)&lt;/a&gt;&amp;nbsp;and it appear that more and more arguments are relying on emotional arguments and arguments without sound logic or reasoning. &amp;nbsp;A little bit of everyone dies when we have nothing but emotional arguments to make points (that is supposed to be funny, cause I didn't have any reasoning or logic and tried to&amp;nbsp;convince&amp;nbsp;you of a point). &lt;br /&gt;
&lt;br /&gt;
What happened to making points with reason to educate, pontificate, or discuss subjects? &amp;nbsp;You then create your counter points and summarize and if your argument has merit, then you might convince someone of your point-of-view. &amp;nbsp;I don't even care how lame or how much I disagree, I'll listen or read and process. &lt;br /&gt;
&lt;br /&gt;
Also, it used to be easy to avoid because you could learn the&amp;nbsp;fanatical&amp;nbsp;conversations and steer clear of the subjects, like &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=certifications+good+or+bad+blog&amp;amp;aq=f&amp;amp;aqi=&amp;amp;aql=&amp;amp;oq=&amp;amp;gs_rfai="&gt;IT certification&lt;/a&gt;&amp;nbsp;(google search), Microsoft vs. Novell, or Windows or *nix, and so on. &lt;br /&gt;
&lt;br /&gt;
Final thoughts:&lt;br /&gt;
1. &amp;nbsp;If you win an argument with emotional arguments, say with "You don't want our country nuked, do you", aren't you just going to lose the argument to someone else with something similar? &amp;nbsp;Say "Less baby seals will get clubbed by saving electricity and going green all over".&lt;br /&gt;
&lt;br /&gt;
2. &amp;nbsp;Research it! &amp;nbsp;What are your most valid points and what are the best counter points for you to address? &lt;br /&gt;
&lt;br /&gt;
3. &amp;nbsp;Respect it! &amp;nbsp;Treat people like idiots and they will either be pissed off or act like idiots.&lt;br /&gt;
&lt;br /&gt;
-Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-3474708624096308924?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zeUxM_d0PS99_CFrFkapYlg6DJU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zeUxM_d0PS99_CFrFkapYlg6DJU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zeUxM_d0PS99_CFrFkapYlg6DJU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zeUxM_d0PS99_CFrFkapYlg6DJU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/Dp639xzi8yU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/3474708624096308924/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=3474708624096308924" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3474708624096308924?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3474708624096308924?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/Dp639xzi8yU/why-i-think-lot-of-online-potentially.html" title="Why I think a lot of online (potentially you) blogger are idiots!" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/05/why-i-think-lot-of-online-potentially.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4NRHw5cSp7ImA9WxFRFk4.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-5197336830821439217</id><published>2010-04-30T06:43:00.000-07:00</published><updated>2010-04-30T06:43:15.229-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-30T06:43:15.229-07:00</app:edited><title>Submitted to Black Hat and Defcon - Forensic Methodology</title><content type="html">Whew, done with that. &amp;nbsp;Sam and I have submitted our Digital Forensics Methodology presentation to Black Hat and Defcon and we are looking forward to a Vegas trip. &amp;nbsp;Vendor parties, fantastic presentations, booze, and gambling are coming our way. &amp;nbsp;I am not sure we will get accepted to Black Hat based on going for a bunch of years and knowing their program, but why not. &amp;nbsp;Should be fun and I have contributed lately. &lt;br /&gt;
&lt;br /&gt;
Another project that is poking up, is that I finally got a update on my CDROM project. &amp;nbsp;Broken and slashed CDs involve getting structural&amp;nbsp;integrity, clearing the media for read, and then the right software the multiple errors, and my project&amp;nbsp;manipulating&amp;nbsp;the cdrom with ATA command set and drivers to 1x speeds and slower. &lt;br /&gt;
&lt;br /&gt;
Hey - ask me questions, I'll do my best.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-5197336830821439217?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LBE5FiDCcXFLuo4hn9-whbD6Pow/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LBE5FiDCcXFLuo4hn9-whbD6Pow/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LBE5FiDCcXFLuo4hn9-whbD6Pow/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LBE5FiDCcXFLuo4hn9-whbD6Pow/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/qi4S6rETrjQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/5197336830821439217/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=5197336830821439217" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5197336830821439217?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5197336830821439217?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/qi4S6rETrjQ/submitted-to-black-hat-and-defcon.html" title="Submitted to Black Hat and Defcon - Forensic Methodology" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/submitted-to-black-hat-and-defcon.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08CRXY8eSp7ImA9WxFREkU.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-3747215787797183891</id><published>2010-04-26T05:44:00.000-07:00</published><updated>2010-04-26T05:44:24.871-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-26T05:44:24.871-07:00</app:edited><title>Forensic Tools - Constant debates</title><content type="html">I get this every now and then - "what tools do I use"? &amp;nbsp;Meh, of course I am more about the process and using the right tool for the job, BUT I&amp;nbsp;recognize&amp;nbsp;the familiar tool bias (you like what you know) and personal bias towards the way I like to approach problems. &amp;nbsp;I like to check work from&amp;nbsp;multiple&amp;nbsp;tools and note that in my summary of findings. &amp;nbsp;So I am answering this from the primary tool perspective. &amp;nbsp;With that said, here I go on about the overall forensic tool kit.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;Overall forensic tool kit - X-ways Forensics, combined with the $199 version of DTSearch. &amp;nbsp;I used to be almost 100% Encase, then migrating to Access Data FTK, but now mostly X-ways. &amp;nbsp;I feel it is as flexible as it can be, I don't have to do a&amp;nbsp;monolithic&amp;nbsp;import to get thing going. &amp;nbsp;I just mount the image read-only and start the DTindex and open in X-ways and start processing. &amp;nbsp; I have been using Access Data FTK as the backup and when I have multiple cases that need processing at the same time, and I still check my work with Carrier's Sleuth Kit. &amp;nbsp;I believe I use tools fairly agnostic, but I just have not needed to reach back to my older version of Encase. Also, I never get into flame wars about how your choice rocks and everyone else is bad - I just but things in a category of the good and bad parts of using whatever tool you are talking about.&lt;br /&gt;
&lt;br /&gt;
SIFT workstation, I love version 2.0 and have been warming to the idea of VM forensic kits with shared folders that allow to use the combination of win32 and *nix tools without large copy times or loading external drives.&lt;br /&gt;
&lt;br /&gt;
Oh, running late - follow up later&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-3747215787797183891?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fGBV7Wdx1nu3mCuQngJtqHE1TAU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fGBV7Wdx1nu3mCuQngJtqHE1TAU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fGBV7Wdx1nu3mCuQngJtqHE1TAU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fGBV7Wdx1nu3mCuQngJtqHE1TAU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/kx-PITdTwEs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/3747215787797183891/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=3747215787797183891" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3747215787797183891?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3747215787797183891?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/kx-PITdTwEs/forensic-tools-constant-debates.html" title="Forensic Tools - Constant debates" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/forensic-tools-constant-debates.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkMAQ30_fCp7ImA9WxFREE8.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-7189804603710155168</id><published>2010-04-23T06:14:00.000-07:00</published><updated>2010-04-23T06:14:02.344-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-23T06:14:02.344-07:00</app:edited><title>Rootkit Dissection</title><content type="html">Following 'some links I came across a pretty good article of a &lt;a href="http://www.void.gr/kargig/blog/2009/08/21/theres-a-rootkit-in-the-closet/"&gt;rootkit dissection&lt;/a&gt;&amp;nbsp;which totally fall into the category of stuff I like to read - the process used to develop information. &amp;nbsp;Knowing me personally, I frequently drone on about the "how" to process things and using &lt;a href="http://en.wikipedia.org/wiki/Critical_thinking"&gt;critical thinking&lt;/a&gt; to solve issues and fully understand the problem | incident | root cause.&lt;br /&gt;
&lt;br /&gt;
If you are not familiar with critical thinking, I believe it is the foundation for being successful at solving open-set solutions - solutions that have many methods of deriving the solution with various degrees of success such as digital investigations, hardware troubleshooting, or &lt;a href="http://itexpertvoice.com/home/lessons-in-troubleshooting-focus-and-systematic-coverage-are-key/"&gt;simply fixing your windows installation problem.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I recommend reading the "simply fixing your windows installation link", uhh it has in-depth troubleshooting and Sherlock Holmes quotes.&lt;br /&gt;
&lt;br /&gt;
I think both links show the use of critical thinking and understanding the logic&amp;nbsp;associated&amp;nbsp;to solving complex issues. &amp;nbsp;I'll post some of my favorite moments in troubleshooting, both good (solved) and bad (made an ass out of myself).&lt;br /&gt;
&lt;br /&gt;
Note, I have not read any of these books so check the reviews. &amp;nbsp;I had read books and written papers in college on critical thinking, but I really learned it from a dude named Garth, a mentor I had in high school. &amp;nbsp;He incorporated critical thinking with&amp;nbsp;philosophy and social behavior and I still vividly remember&amp;nbsp;some of the conversations we had 28 years ago. &amp;nbsp;Here's to you Garth, I am glad you refused to buy beer for underage kid and instead changed my life.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0595437087&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;&amp;nbsp;&amp;nbsp;&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0132203049&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0130647608&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-7189804603710155168?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ExM5BD5vhQjslaVy_gwrCl8OvtY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ExM5BD5vhQjslaVy_gwrCl8OvtY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ExM5BD5vhQjslaVy_gwrCl8OvtY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ExM5BD5vhQjslaVy_gwrCl8OvtY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/kgIqLCug9vc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/7189804603710155168/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=7189804603710155168" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7189804603710155168?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7189804603710155168?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/kgIqLCug9vc/rootkit-dissection.html" title="Rootkit Dissection" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/rootkit-dissection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkAMQn44fyp7ImA9WxFSGU0.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-8036219667986459834</id><published>2010-04-21T18:45:00.000-07:00</published><updated>2010-04-21T18:46:23.037-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-21T18:46:23.037-07:00</app:edited><title>Working Hard</title><content type="html">Way to much going on - I've started a&amp;nbsp;mandatory security training program and am spending a large portion of my week presenting and (hopefully) empowering individuals to make intelligent security decisions.&lt;br /&gt;
&lt;br /&gt;
I've been working on Defcon presentation with a forensic&amp;nbsp;methodology&amp;nbsp;that is&amp;nbsp;representative of the on-the-job training I give my forensic specialists. &amp;nbsp;Here is the abstract that I have assembled that help&amp;nbsp;clarify&amp;nbsp;the issues that am looking to improve upon.&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Verdana; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;A new approach to Forensic Methodology and !!BUSTED!! case studies.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. &amp;nbsp;Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case.&amp;nbsp; The analysts are then measured based on the total findings, the time required to process the case, the initial information gathered, and the estimated time to process the case. &amp;nbsp;The expected result is to be varied based on experience and individual characteristics, such as organization, discipline, and the attention to detail of each analyst. &amp;nbsp;Imagine this same experiment but with only 8 hours to process the case, because that is the way it happens in real life.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;David Smith and Samuel Petreski have developed a methodology that fits within the Analysis phase in one of the standard Digital Forensic Analysis Methodologies - PEIA (Preparation, Extraction, Identification, and Analysis), to provide a structure for consistent results, better development of the requested goals, increase efficiency in fulfilling the goals, and develop an improved estimate of the time required to complete the request.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;This methodology involves the generation and validation of case goals, the evaluation of methods used to achieve the goals, a structure for estimating the effectiveness, time required, processing results of specific methods, and generalized organization and time management. &amp;nbsp;The primary goal of this methodology is to address the structure and optimal path that would allow a digital forensic examiner to perform an examination with a high level of efficiency and consistent results.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;This presentation provides an introduction to this methodology and applies its key concepts to real sanitized digital investigations, such as tracking down a suspected executive's adult craigslist ad, performing an analysis on a compromised system involving social security numbers, and making the determination of intellectual property theft.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;Should be fun. &amp;nbsp;BTW, I love this book:&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0321240693&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-8036219667986459834?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/a58I_6GYIgrzw_eRAWltjLYPwEQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/a58I_6GYIgrzw_eRAWltjLYPwEQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/a58I_6GYIgrzw_eRAWltjLYPwEQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/a58I_6GYIgrzw_eRAWltjLYPwEQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/CZNOitu3I_M" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/8036219667986459834/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=8036219667986459834" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8036219667986459834?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8036219667986459834?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/CZNOitu3I_M/working-hard.html" title="Working Hard" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/working-hard.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cCSXs8eyp7ImA9WxFSFkU.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-8061228256709291243</id><published>2010-04-19T04:45:00.000-07:00</published><updated>2010-04-19T05:44:28.573-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-19T05:44:28.573-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Super time line timeline forensics log2time timescanner sleuthkit sleuth kit Smith Petreski Methodology" /><title>Super Timeline - Rob Lee &amp; crew</title><content type="html">So now you have probably heard about Super Timeline from Rob Lee's SAN page -&amp;nbsp;&lt;a href="http://blogs.sans.org/computer-forensics/2010/03/19/digital-forensic-sifting-super-timeline-analysis-and-creation/"&gt;http://blogs.sans.org/computer-forensics/2010/03/19/digital-forensic-sifting-super-timeline-analysis-and-creation/&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Good stuff, I don't know if you had tried log2time, but my first thought was wow, it would be great if it could go and find all of the artifact log files. &amp;nbsp;Well, they did that too - TimeScanner was added to search the drive and send the output to log2time, sweet! &amp;nbsp;Combined in the future is what I have read.&lt;br /&gt;
&lt;br /&gt;
Rob Lee combined this with &lt;a href="http://blogs.sans.org/computer-forensics/2009/02/24/digital-forensic-sifting-registry-and-filesystem-timeline-creation/"&gt;Carvey's registry time perl scrip&lt;/a&gt;t, fls from the Sleuth Kit, and jacks it all together with old school &lt;a href="http://www.sleuthkit.org/sleuthkit/man/mactime.html"&gt;mactime.pl&lt;/a&gt;, also from the SleuthKit. &amp;nbsp;Rob makes putting this easier by having these components in the SIFT Workstation (info found in the Super Timeline page).&lt;br /&gt;
&lt;br /&gt;
Ok, intro done... &amp;nbsp;I have run some tests against older cases and loved the results*. &amp;nbsp;It USED to be a lot of work to get log source 1 and &amp;nbsp;log source 2, consolidate them, and review. &amp;nbsp;Then make a determination if log source 3 was needed. &amp;nbsp;This makes it much quicker and moves it up the SP index (SPI) appropriately, since the SPI is a combination of factors, including estimated time and estimated&amp;nbsp;effectiveness&amp;nbsp;in meeting the case goals. &amp;nbsp;SPI is an artifact from the digital forensic methodology I have been teaching my staffs and formalizing into a presentation for &lt;a href="http://defcon.org/"&gt;Defcon 18&lt;/a&gt;&amp;nbsp;and &lt;a href="http://www.blackhat.com/"&gt;Black Hat 2010&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
*For legal purposes - I didn't find any data that changed any of my conclusions, but enhanced the &amp;nbsp;conclusions that I or my teams generated.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-8061228256709291243?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LaX-hAcegmGBasziXUNjosK-pWY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LaX-hAcegmGBasziXUNjosK-pWY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LaX-hAcegmGBasziXUNjosK-pWY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LaX-hAcegmGBasziXUNjosK-pWY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/hcMNkNJ4cXc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/8061228256709291243/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=8061228256709291243" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8061228256709291243?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8061228256709291243?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/hcMNkNJ4cXc/super-timeline-rob-lee-crew.html" title="Super Timeline - Rob Lee &amp; crew" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/super-timeline-rob-lee-crew.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4NSX4-fCp7ImA9WxFSFUQ.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-5908774040709442873</id><published>2010-04-18T05:33:00.000-07:00</published><updated>2010-04-18T05:33:18.054-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-18T05:33:18.054-07:00</app:edited><title>Defcon 18 and Black Hat</title><content type="html">Anyone else getting excited (although it is really early) for Defcon 18 and Black Hat in Las Vegas? &amp;nbsp;I am! &amp;nbsp;I'm also working on a presentation with Sam Petreski on a new approach to forensic methodology, which I feel is really interesting. &amp;nbsp;I haven't presented at Defcon or Shmoocon in a couple of years, although I have good stuff that I am working on. &amp;nbsp;FOLLOW-THRU!&lt;br /&gt;
&lt;br /&gt;
It gets away from the classic framework&amp;nbsp;methodologies&amp;nbsp;like:&lt;br /&gt;
&lt;a href="http://www.google.com/url?sa=t&amp;amp;source=web&amp;amp;ct=res&amp;amp;cd=1&amp;amp;url=http%3A%2F%2Fwww.usdoj.gov%2Fcriminal%2Fcybercrime%2Fforensics_chart.pdf&amp;amp;ei=q4x8SfqyA4-ctwe8s_DDDg&amp;amp;usg=AFQjCNEgSvwNY7-Ua0SQ7Trzno-XmBt6IA&amp;amp;sig2=QDxXQPl04ybqdfQnNo3Myg"&gt;Classic DOJ PEIA&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.digital-evidence.org/papers/opensrc_legal.pdf"&gt;Classic B Carrier&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://paper.ijcsns.org/07_book/200810/20081025.pdf"&gt;Fantastic whitepaper comparing methodologies&lt;/a&gt;&lt;br /&gt;
(Unfortunatley all PDF's so be careful with your patches)&lt;br /&gt;
&lt;br /&gt;
But instead focuses on the analysis phases of the forensic specialist, from the initial information gathering to preparing to develop the report - i.e. when the "man" sits in front of the forensic PC loaded with tools and the images to examine.&lt;br /&gt;
&lt;br /&gt;
Here is the abstract which helps develop the methodology.&lt;br /&gt;
&lt;span class="Apple-style-span" style="font-family: Verdana; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;A new approach to Forensic Methodology and !!BUSTED!! case studies.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to process the case. &amp;nbsp;Based on the information gathered, each of the three analysts is asked to provide an estimate to complete the investigation and can proceed with up to 20 hours to process the case.&amp;nbsp; The analysts are then measured based on the total findings, the time required to process the case, the initial information gathered, and the estimated time to process the case. &amp;nbsp;The expected result is to be varied based on experience and individual characteristics, such as organization, discipline, and the attention to detail of each analyst. &amp;nbsp;Imagine this same experiment but with only 8 hours to process the case, because that is the way it happens in real life.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;David Smith and Samuel Petreski have developed a methodology that fits within the Analysis phase in one of the standard Digital Forensic Analysis Methodologies - PEIA (Preparation, Extraction, Identification, and Analysis), to provide a structure for consistent results, better development of the requested goals, increase efficiency in fulfilling the goals, and develop an improved estimate of the time required to complete the request.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;This methodology involves the generation and validation of case goals, the evaluation of methods used to achieve the goals, a structure for estimating the effectiveness, time required, processing results of specific methods, and generalized organization and time management. &amp;nbsp;The primary goal of this methodology is to address the structure and optimal path that would allow a digital forensic examiner to perform an examination with a high level of efficiency and consistent results.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-size: x-small;"&gt;&lt;i&gt;This presentation provides an introduction to this methodology and applies its key concepts to real sanitized digital investigations, such as tracking down a suspected executive's adult craigslist ad, performing an analysis on a compromised system involving social security numbers, and making the determination of intellectual property theft.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
Interested in more? &amp;nbsp;Here are some books Amazon recommends - don't worry, I won't put a book out that I haven't read and think is worth it.&lt;br /&gt;
&lt;br /&gt;
&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=0321268172&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;Don't ever get called into a deposition or court without reading this book! &amp;nbsp;It is the bomb-bay and after understanding the concepts, it will be you go-to-book when you have a follow-up.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;iframe align="left" frameborder="0" marginheight="0" marginwidth="0" scrolling="no" src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;amp;o=1&amp;amp;p=8&amp;amp;l=bpl&amp;amp;asins=1597494224&amp;amp;fc1=000000&amp;amp;IS2=1&amp;amp;lt1=_blank&amp;amp;m=amazon&amp;amp;lc1=0000FF&amp;amp;bc1=000000&amp;amp;bg1=FFFFFF&amp;amp;f=ifr" style="align: left; height: 245px; padding-right: 10px; padding-top: 5px; width: 131px;"&gt;&lt;/iframe&gt;Uh, yea. &amp;nbsp;Another must read. &amp;nbsp;I have it on my kindle now for quick(er) reference as well. &amp;nbsp;I seem to absorb more each time I read it and really like the 2nd edition.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-5908774040709442873?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0Asyl_yaTo2jlLF8DR9anLqgqAU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0Asyl_yaTo2jlLF8DR9anLqgqAU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0Asyl_yaTo2jlLF8DR9anLqgqAU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0Asyl_yaTo2jlLF8DR9anLqgqAU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/P3ODGML2Oec" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/5908774040709442873/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=5908774040709442873" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5908774040709442873?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5908774040709442873?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/P3ODGML2Oec/defcon-18-and-black-hat.html" title="Defcon 18 and Black Hat" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/defcon-18-and-black-hat.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIBRX0zcSp7ImA9WxFSFUg.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-1451790861305920066</id><published>2010-04-17T18:35:00.000-07:00</published><updated>2010-04-17T18:35:54.389-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-17T18:35:54.389-07:00</app:edited><title>How can you not love Bruce Schneier's CryptoGram?</title><content type="html">&lt;div&gt;I am not sure if you are getting this newsletter, but always a thrill-a-minute. &amp;nbsp;I can't say I go with him on all of his positions, but always thought provoking and well thought out.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;http://www.schneier.com/crypto-gram-1004.html - &lt;a href="http://www.schneier.com/crypto-gram-1004.html"&gt;link&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Great this month is his analysis on the story of "Facebook Chief Executive Mark Zuckerberg declared the age of privacy to be over". &amp;nbsp;Yes, I am pretty tired of hearing "users are idiots", so it was refreshing to have a position article on that the moneymakers of the world are working really easy for you to lose your privacy.&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: Arial; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-1451790861305920066?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ihHkAvp8I0jdN6a34FpuNj9hSZQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ihHkAvp8I0jdN6a34FpuNj9hSZQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ihHkAvp8I0jdN6a34FpuNj9hSZQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ihHkAvp8I0jdN6a34FpuNj9hSZQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/1T-YezLVybg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/1451790861305920066/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=1451790861305920066" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1451790861305920066?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1451790861305920066?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/1T-YezLVybg/how-can-you-not-love-bruce-schneiers.html" title="How can you not love Bruce Schneier's CryptoGram?" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/how-can-you-not-love-bruce-schneiers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4FRXw5fyp7ImA9WxFSFUg.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-8784564807959514194</id><published>2010-04-17T18:25:00.000-07:00</published><updated>2010-04-17T18:25:14.227-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-17T18:25:14.227-07:00</app:edited><title>Perl script for renaming music files</title><content type="html">Ok, I used one of the free ipod backup programs and it copied all of the file with native format, e.g. UBOT.m4a - great, now I have to write a perl program to read the metadata and rename the files.&lt;br /&gt;
&lt;br /&gt;
Quick and dirty, but here you go:&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;#!/usr/local/bin/perl&lt;br /&gt;
use MP4::Info;&lt;br /&gt;
use MP3::Info;&lt;br /&gt;
&lt;br /&gt;
MP3s();&lt;br /&gt;
MP4s();&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
sub stripUnwanted&lt;br /&gt;
{&lt;br /&gt;
my $filename=shift;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;$filename =~ tr{\\\/}{-};&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;$filename =~ tr{*?}{X};&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;$filename =~ tr{“&amp;gt;&amp;lt;[]|:;,’=\"}{_};&lt;br /&gt;
return $filename; &lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
sub MP3s {&lt;br /&gt;
@files = &amp;lt;*.mp3&amp;gt;;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;foreach $file (@files) { &amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;my $tag &amp;nbsp;= get_mp3tag($file);&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$artist = $tag-&amp;gt;{ARTIST};&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$title = $tag-&amp;gt;{TITLE};&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$artist = stripUnwanted($artist);&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$title = stripUnwanted($title);&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;print "Artist: $artist - Title: $title\n";&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;rename ($file, "$artist-$title.mp3");&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;} &amp;nbsp; &lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
sub MP4s {&lt;br /&gt;
@files = &amp;lt;*.m4*&amp;gt;;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;foreach $file (@files) { &amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;my $mp4 = new MP4::Info $file;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$artist = $mp4-&amp;gt;artist;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$title = $mp4-&amp;gt;title;&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$artist = stripUnwanted($artist);&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;$title = stripUnwanted($title);&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;print "$artist - $title\n";&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;rename ($file, "$artist-$title.m4a");&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;}&lt;br /&gt;
}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-8784564807959514194?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uyAjf41hIujJxdUvziuzSj7i3sE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uyAjf41hIujJxdUvziuzSj7i3sE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uyAjf41hIujJxdUvziuzSj7i3sE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uyAjf41hIujJxdUvziuzSj7i3sE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/vzCmXCwiHn4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/8784564807959514194/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=8784564807959514194" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8784564807959514194?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/8784564807959514194?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/vzCmXCwiHn4/perl-script-for-renaming-music-files.html" title="Perl script for renaming music files" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/perl-script-for-renaming-music-files.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UFSH09cSp7ImA9WxFTGU4.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-2838231031125752026</id><published>2010-04-10T15:40:00.000-07:00</published><updated>2010-04-10T15:40:19.369-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-04-10T15:40:19.369-07:00</app:edited><title>Back on track - working on lots of projects..</title><content type="html">I'm back and have lots of good info to share. &amp;nbsp;I am working on my Defcon presentation and better password dictionary development.&lt;br /&gt;
&lt;br /&gt;
That's it for now, but good stuff coming.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-2838231031125752026?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XKioQpUff1_hiP8KYhAOvitisnM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XKioQpUff1_hiP8KYhAOvitisnM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XKioQpUff1_hiP8KYhAOvitisnM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XKioQpUff1_hiP8KYhAOvitisnM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/Bb0AC_MdN_c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/2838231031125752026/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=2838231031125752026" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2838231031125752026?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2838231031125752026?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/Bb0AC_MdN_c/back-on-track-working-on-lots-of.html" title="Back on track - working on lots of projects.." /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2010/04/back-on-track-working-on-lots-of.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YGSXcyfip7ImA9WxdTFE8.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-3402990908850268737</id><published>2008-05-10T04:18:00.001-07:00</published><updated>2008-05-10T06:12:08.996-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-05-10T06:12:08.996-07:00</app:edited><title>Been a while...</title><content type="html">But I really need to stay on top of stuff.  A lot has happened that I did not blog out! &lt;br /&gt;&lt;br /&gt;I spoke at &lt;a href="http://www.shmoocon.org"&gt;Shmoocon&lt;/a&gt; about my forensic memory analysis for passwords.  Yep, what you think - I develop passwords out of the billions of possible strings on your forensic image.  It was pretty cool and the presentation is posted on the &lt;a href="http://www.shmoocon.org/2008/presentations/Forensic%20Image%20Analysis%20for%20Password%20Recovery.ppt"&gt;shmoo site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I got an idea from one of my mailing lists to go a bit deeper on.  Detecting time travel in the non-Time Cop way.  I am going to write a paper on detecting document alterations with changing of system time clocks. &lt;br /&gt;&lt;br /&gt;I know the forensic perception - a cat and mouse game where bad guy can make a change, good guy develops a way to detect the change, so bad guy makes a change a different way.  On and on, with the doubt of detection on the good guy, because maybe he just has not developed a way to detect the latest change.&lt;br /&gt;&lt;br /&gt;That's my next project, feel free to steal the idea and run with it - just give me a copy of the results!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-3402990908850268737?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nQeWvQWrqKgL8WoY87V8uB9WEb0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nQeWvQWrqKgL8WoY87V8uB9WEb0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nQeWvQWrqKgL8WoY87V8uB9WEb0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nQeWvQWrqKgL8WoY87V8uB9WEb0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/7tTTFm8XGqA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/3402990908850268737/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=3402990908850268737" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3402990908850268737?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/3402990908850268737?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/7tTTFm8XGqA/been-while.html" title="Been a while..." /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2008/05/been-while.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcCQXY5fyp7ImA9WB9SGEk.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-7353181910272134588</id><published>2007-10-08T04:01:00.000-07:00</published><updated>2007-10-08T04:14:20.827-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-10-08T04:14:20.827-07:00</app:edited><title>DC3 Challenge</title><content type="html">Finally getting somewhere with the &lt;a href="http://www.dc3.mil/challenge/"&gt;2007 DC3 Challenge&lt;/a&gt;.  Lots of damaged media and with my Defcon15 presentation - I gave away lots of tips for challenges 1,3,4,5. &lt;br /&gt;&lt;br /&gt;I have also made much more progress with my string extaction.  I found out that other systems do some levels of string extract, I like mine because I rank the strings based on entropy and password class.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-7353181910272134588?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/p7cyh0tFJdIzHu1whvozWiuk-AA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/p7cyh0tFJdIzHu1whvozWiuk-AA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/p7cyh0tFJdIzHu1whvozWiuk-AA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/p7cyh0tFJdIzHu1whvozWiuk-AA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/IXEumV-Z9A8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/7353181910272134588/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=7353181910272134588" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7353181910272134588?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7353181910272134588?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/IXEumV-Z9A8/dc3-challenge.html" title="DC3 Challenge" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/10/dc3-challenge.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8AQHc5eSp7ImA9WB5aGUg.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-7152508565610227306</id><published>2007-09-16T07:37:00.000-07:00</published><updated>2007-09-16T08:00:41.921-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-09-16T08:00:41.921-07:00</app:edited><title>HCP Case Work / Rainbow Tables</title><content type="html">It's been a busy, busy, week with working a couple of HCP case that look like they may go to trial.  Mickey and I have been compiling a ton of analysis to support our technical argument.  It is fairly interesting, developing metrics post-mortem to demonstrate that a service was delivered as promised.  &lt;br /&gt;&lt;br /&gt;I had planned on getting into a fairly technical post of risk assessment and specifically how to plan and implement.  I mean, anyone can find NIST 800-53 and a checklist, but is that really a risk assessment?  So, there will me more on that.&lt;br /&gt;&lt;br /&gt;Lastly, Rainbow tables.  I have been developing a huge secret stash and am willing to trade / swap information ideas and knowledge for table lookups.  I currently got LM-all, md5 1-7 az09+symbols14, Cisco Pix 1-7 az09+symbols14, ntlm 1-7 az09+symbols14, and about 10GB of WPA and WPA2 hashes.  Plus 5GB+ of targeted dictionaries.  &lt;br /&gt;&lt;br /&gt;-Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-7152508565610227306?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/wkSDCkHQUgrfb9I3qCB6qeROAAg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wkSDCkHQUgrfb9I3qCB6qeROAAg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/wkSDCkHQUgrfb9I3qCB6qeROAAg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/wkSDCkHQUgrfb9I3qCB6qeROAAg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/a9V1D-tDuI0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/7152508565610227306/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=7152508565610227306" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7152508565610227306?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/7152508565610227306?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/a9V1D-tDuI0/hcp-case-work-rainbow-tables.html" title="HCP Case Work / Rainbow Tables" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/09/hcp-case-work-rainbow-tables.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMBRnYzfip7ImA9WB5aFEo.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-5867781833294675181</id><published>2007-09-10T18:18:00.000-07:00</published><updated>2007-09-10T18:34:17.886-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-09-10T18:34:17.886-07:00</app:edited><title>Out of cycle post - Books</title><content type="html">Normally, I just post on the weekends but I was pretty excited about a book I just finished.  I FINALLY got around to finishing Reversing: Secrets of Reverse Engineering by Eldad Eialm and was blown away with the content.  I had been wanting to get deeper in reverse engineering and the ability to dissect malware, so this was great.&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;o=1&amp;p=8&amp;l=as1&amp;asins=0764574817&amp;fc1=000000&amp;IS2=1&amp;lt1=_blank&amp;lc1=0000FF&amp;bc1=000000&amp;bg1=FFFFFF&amp;f=ifr" style="width:120px;height:240px;" scrolling="no" marginwidth="0" marginheight="0" frameborder="0"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;Additionally, I have been wanted to write a book on digital forensic investigation, but focused on the whole range of investigation.  Basic forensics, media reconstruction, password cracking, interview skills, and investigation techniques.  Maybe some of the reporting and chain of custody stuff.  &lt;br /&gt;&lt;br /&gt;I really liked Real Digital Forensics, but my book would be more about building a security service, whether it is in higher ed like &lt;a href="http://security.georgetown.edu"&gt;Georgetown's Information Security Office&lt;/a&gt; or a small digital forensics company like &lt;a href="http://www.hcp-fs.com"&gt;HCP Forensics&lt;/a&gt;.&lt;br /&gt;&lt;iframe src="http://rcm.amazon.com/e/cm?t=duderman-20&amp;o=1&amp;p=8&amp;l=as1&amp;asins=0321240693&amp;fc1=000000&amp;IS2=1&amp;lt1=_blank&amp;lc1=0000FF&amp;bc1=000000&amp;bg1=FFFFFF&amp;f=ifr" style="width:120px;height:240px;" scrolling="no" marginwidth="0" marginheight="0" frameborder="0"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-5867781833294675181?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2EuEaNAzvZFzRD_-Ht0OjRWL0-w/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2EuEaNAzvZFzRD_-Ht0OjRWL0-w/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2EuEaNAzvZFzRD_-Ht0OjRWL0-w/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2EuEaNAzvZFzRD_-Ht0OjRWL0-w/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/LI3zjJWhWNU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/5867781833294675181/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=5867781833294675181" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5867781833294675181?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/5867781833294675181?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/LI3zjJWhWNU/out-of-cycle-post.html" title="Out of cycle post - Books" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/09/out-of-cycle-post.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUMQH0yeyp7ImA9WB5aE0k.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-1885271696079087507</id><published>2007-09-09T05:42:00.000-07:00</published><updated>2007-09-09T06:58:01.393-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-09-09T06:58:01.393-07:00</app:edited><title>Locating passwords</title><content type="html">I have been thinking about passwords - your passwords.  I have your drive image, but can not break your password with conventional methods.&lt;br /&gt;&lt;br /&gt;At Defcon 15, I heard about this attack that is used by your favorite government agencies.  The idea is this: you type your passwords in all the time and there is the possibility that they get written to swap, temp files, dr watson logs, or the such.    So, why not scan your entire drive to look for "password like" strings to build a dictionary? &lt;br /&gt;&lt;br /&gt;It has been done on a smaller scale - it's an old trick to find good stuff in the memory dump logs, but I have also found passwords in logs, such as: Wrong password for user "secretStrongP@ssw0rd".&lt;br /&gt;&lt;br /&gt;So, I started writing some perl and c++ to process strings in images and dealing with the encoding.  Pretty interesting initial results, when looking for passwords with a strong password and basic entropy filters on .  I also did some searching and found a current project that has some progress - &lt;a href="http://search.cpan.org/%7Ebsi/Dicop-Workerframe-2.17/doc/Extract.pod"&gt;Dicop-workerframe.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Good stuff, and definitely food for thought, dude.  I'll post some of my work and results shortly.&lt;br /&gt;&lt;br /&gt;-Dave&lt;br /&gt;&lt;br /&gt;PS - Visit my forensic company, &lt;a href="http://www.hcp-fs.com"&gt;HCP Forensic Services&lt;/a&gt;.  We are really starting to grow and have very successful in getting the job right in the minimal amount of time.  Are all contracts like that, though?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-1885271696079087507?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/H7alDmoysSxpxBKTd6IgVrXWjcM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H7alDmoysSxpxBKTd6IgVrXWjcM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/H7alDmoysSxpxBKTd6IgVrXWjcM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H7alDmoysSxpxBKTd6IgVrXWjcM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/1tWylNnDB94" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/1885271696079087507/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=1885271696079087507" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1885271696079087507?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1885271696079087507?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/1tWylNnDB94/locating-passwords.html" title="Locating passwords" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/09/locating-passwords.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAEQX84cSp7ImA9WB5bGEg.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-2654980249761368537</id><published>2007-09-03T08:48:00.001-07:00</published><updated>2007-09-03T14:25:00.139-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-09-03T14:25:00.139-07:00</app:edited><title>SHA1 Password Cracking</title><content type="html">I looked online for a bit, but could not find any real reference to cracking SHA1 passwords.  Well, there are some like &lt;a href="http://www.openwall.com/john/"&gt;John the Ripper&lt;/a&gt; with the &lt;a href="http://www.openwall.com/john/contrib/john-1.6-nsldaps4.diff.gz"&gt;SHA1 patch&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I found a few posts asking how to pen test LDAP SHA1 databases, but other than JTR not much.&lt;br /&gt;&lt;br /&gt;So - here you go:&lt;br /&gt;&lt;br /&gt; Netscape LDAP SHA1 passwords are stored in base64 with {SHA} prepended e.g.&lt;br /&gt;{SHA}v83z5sps70VUO/u1dQnJKuyaOfs=, which is my personal super secret password.  With a little perl, it is easy to decode them to the SHA1 values we know and love, like: bfcdf3e6ca6cef45543bfbb57509c92aec9a39fb.&lt;br /&gt;&lt;br /&gt;Key perl statements from ascii to SHA1 base64 and hex:&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;font-size:85%;"  &gt;#! /usr/bin/perl&lt;br /&gt;#&lt;br /&gt;use Digest::SHA1;&lt;br /&gt;use MIME::Base64;&lt;br /&gt;my $secret = $ARGV[0];&lt;br /&gt;&lt;br /&gt;$ctx = Digest::SHA1-&gt;new;&lt;br /&gt;$ctx-&gt;add($secret);&lt;br /&gt;$hashedPasswd = '{SHA}' . $ctx-&gt;hexdigest,'';&lt;br /&gt;print 'userPassword: ' .  $hashedPasswd . "\n";&lt;br /&gt;&lt;br /&gt;$ctx = Digest::SHA1-&gt;new;&lt;br /&gt;$ctx-&gt;add($secret);&lt;br /&gt;$hashedPasswd = '{SHA}' . encode_base64($ctx-&gt;digest,'');&lt;br /&gt;print 'userPassword: ' .  $hashedPasswd . "\n";&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now you can use JTR and my choice - &lt;a href="http://en.wikipedia.org/wiki/Rainbow_table"&gt;rainbow tables&lt;/a&gt;.  Breaking the load over 4 or 5 machines I built out the SHA1 1-8 lowercase [a-z] [0-9], plus 14 symbols tables in about a week.&lt;br /&gt;&lt;br /&gt;It's about 26GB and will cover most bad user passwords.&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;font-size:85%;"  &gt;rtgen sha1 loweralpha-numeric-symbol14 1 8 x39x 2400 40000000 x00&lt;/span&gt;&lt;br /&gt;(Replace x39x) with your table number.  I took it from 0-39 for my tables.&lt;br /&gt;&lt;br /&gt;For a nice 6GB, you can get lowercase [a-z][0-9] for 1 to 7 characters, which will cover a lot.&lt;br /&gt;&lt;span style="font-weight: bold;font-family:arial;font-size:85%;"  &gt;rtgen sha1 loweralpha-numeric 1 8 x10x 2400 40000000 x00&lt;/span&gt;&lt;br /&gt;(Replace x10x) with your table number, 1-10.&lt;br /&gt;&lt;br /&gt;I stripped out the username and userpassword attributes from LDAP and stored them into a protected file, converting the base 64 password into hex.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;davesmith:bfcdf3e6ca6cef45543bfbb57509c92aec9a39fb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next, I stripped out the SHA1 hash to be stored in my working file - hashs.txt.&lt;br /&gt;&lt;br /&gt;Crack away!&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;span style="font-weight: bold;font-family:arial;font-size:85%;"  &gt;rcrack sha1*.rt -l hashs.txt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;So now, I see all of the weak passwords created by users, which is always tragic fun.  Match the cracked hashes to the usernames by matching in the original file - and you have pen tested your LDAP access.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-2654980249761368537?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jqRnIg9jBswOKBMjCZdL9dJ_jzA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jqRnIg9jBswOKBMjCZdL9dJ_jzA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jqRnIg9jBswOKBMjCZdL9dJ_jzA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jqRnIg9jBswOKBMjCZdL9dJ_jzA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/pKEpEj2bzh8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/2654980249761368537/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=2654980249761368537" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2654980249761368537?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/2654980249761368537?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/pKEpEj2bzh8/sha1-password-cracking.html" title="SHA1 Password Cracking" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/09/sha1-password-cracking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUcDRHs_cCp7ImA9WB5bEU4.&quot;"><id>tag:blogger.com,1999:blog-7711794229012152198.post-1696224229646609041</id><published>2007-08-26T06:56:00.000-07:00</published><updated>2007-08-26T07:04:35.548-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2007-08-26T07:04:35.548-07:00</app:edited><title>Start of Blog</title><content type="html">Hmm, starting another blog.  I promise I will keep this one more up to date with the mad skillz and freaky cases.&lt;br /&gt;&lt;br /&gt;It has been crazy lately - HCP Forensics has been taking off and Georgetown has been crushing my team with a huge workload.&lt;br /&gt;&lt;br /&gt;Real stuff:&lt;br /&gt;Got back from Defcon, where I gave my presentation and finally got over a killer cold.  My presentation, &lt;a href="http://www.defcon.org/html/defcon-15/dc-15-speakers.html#Smith"&gt;Cool stuff learned from the DC3 challenge&lt;/a&gt; was pretty rocking and I had lot of people stop me to say thanks.&lt;br /&gt;&lt;br /&gt;That's it for now...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7711794229012152198-1696224229646609041?l=dcinfosec.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EF7HcFgDvCMDtSn0Y1Kyoy2Okxc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EF7HcFgDvCMDtSn0Y1Kyoy2Okxc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EF7HcFgDvCMDtSn0Y1Kyoy2Okxc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EF7HcFgDvCMDtSn0Y1Kyoy2Okxc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/DcSmithOnInformationSecurity/~4/qYsnV77Qao0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://dcinfosec.blogspot.com/feeds/1696224229646609041/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7711794229012152198&amp;postID=1696224229646609041" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1696224229646609041?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7711794229012152198/posts/default/1696224229646609041?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/DcSmithOnInformationSecurity/~3/qYsnV77Qao0/start-of-blog.html" title="Start of Blog" /><author><name>DC Smith</name><uri>http://www.blogger.com/profile/12536214663598624177</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://dcinfosec.blogspot.com/2007/08/start-of-blog.html</feedburner:origLink></entry></feed>

