<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;D0YAQHk6eyp7ImA9WxFbFEo.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870</id><updated>2010-07-06T22:59:01.713-05:00</updated><title>Binary Intelligence</title><subtitle type="html">...thoughts and news on digital forensics, pentesting, electronic investigations, and the computer underground.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.binint.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.binint.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>83</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/binint" /><feedburner:info uri="binint" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CUEBQHgyeCp7ImA9WxFWFE4.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-354829330154682339</id><published>2010-06-01T16:16:00.004-05:00</published><updated>2010-06-01T18:07:31.690-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-01T18:07:31.690-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="regripper" /><category scheme="http://www.blogger.com/atom/ns#" term="forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="triage" /><title>Turning RegRipper into WindowsRipper</title><content type="html">&lt;span class="Apple-style-span" style="line-height: 13px; "&gt;&lt;span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;a href="http://windowsir.blogspot.com/" target="_blank" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; outline-style: none; outline-width: initial; outline-color: initial; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; "&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Harlan Carvey&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; has given us a great tool in &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://regripper.net/" target="_blank" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; outline-style: none; outline-width: initial; outline-color: initial; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; "&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;RegRipper&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt; and it’s undeniable that many examiners have found it to be a useful addition to their toolbox. RegRipper has a very specific purpose – parse the Windows registry. With some modification, we can turn RegRipper into WindowsRipper, an extremely powerful Windows triage tool. Using WindowsRipper we can parse much more than just the registry. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 20px; "&gt;&lt;span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="line-height: 20px; "&gt;&lt;span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;a href="http://mattchurchill.net/2010/06/windowsripper/"&gt;&lt;span class="Apple-style-span"  style="font-family:'times new roman';"&gt;&lt;span class="Apple-style-span"  style="color:#999999;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Read on and watch the video to see just what WindowsRipper could become.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-354829330154682339?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/9w1DOesKM5k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/354829330154682339/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/06/turning-regripper-into-windowsripper.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/354829330154682339?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/354829330154682339?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/9w1DOesKM5k/turning-regripper-into-windowsripper.html" title="Turning RegRipper into WindowsRipper" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2010/06/turning-regripper-into-windowsripper.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIER3Y6fSp7ImA9WxFQGEs.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-737068313552759763</id><published>2010-05-14T14:44:00.003-05:00</published><updated>2010-05-14T14:48:26.815-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-14T14:48:26.815-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ip address" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>What Can Happen With Just an IP Address</title><content type="html">&lt;span class="Apple-style-span" style="font-family: Tahoma, Verdana, Arial, sans-serif; color: rgb(51, 51, 51); font-size: 12px; line-height: 21px; "&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;After the Facebook post last week, much of the backlash consisted of, "Who cares if someone has my IP address? That information is almost always out there." Well, &lt;a href="http://www.attackvector.org/?p=173"&gt;here is a great example&lt;/a&gt; of what someone can do with an IP address.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Here’s something to really think about.. I was able to obtain all of the information in this post for 16 cents and by just using an email and IP address from a piece of spam.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Family members, ages, schools, anniversary dates, marriage lengths, hobbies, interests, phone numbers, addresses, property records, property taxes, pictures of their house, pictures of them, pictures of their children and grandchildren, deeds on their house, bankruptcies, employment history, previous addresses, previous creditors, and bits of social security numbers.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;I’m pretty sure I’d be able to fake my way through one of those password reset forms.. you know, where you set up a “secret question” asking what your dogs name was, or where you went to school?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;Beyond that, I’m fairly confident that at this point, if I were to call his bank and pretend to be him, I could easily pass when they asked me personal questions.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 1.8em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; font-weight: inherit; font-style: inherit; vertical-align: baseline; "&gt;&lt;span class="Apple-style-span"  style="font-family:arial;"&gt;&lt;span class="Apple-style-span" style="font-size: medium;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-737068313552759763?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/t-NrwUzcMF0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/737068313552759763/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/05/what-can-happen-with-just-ip-address.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/737068313552759763?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/737068313552759763?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/t-NrwUzcMF0/what-can-happen-with-just-ip-address.html" title="What Can Happen With Just an IP Address" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>1</thr:total><feedburner:origLink>http://www.binint.com/2010/05/what-can-happen-with-just-ip-address.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck4NQn49eyp7ImA9WxFQGEs.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-9092249224280572942</id><published>2010-05-14T13:08:00.004-05:00</published><updated>2010-05-14T13:16:33.063-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-14T13:16:33.063-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="regripper" /><category scheme="http://www.blogger.com/atom/ns#" term="forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="registry" /><title>Run RegRipper Against a Mounted Drive</title><content type="html">&lt;div&gt;This post was written by guest blogger Adam James. Please feel free to post any questions or comments for him on this blog.&lt;/div&gt;&lt;div&gt;-------------------------------------------------&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Modifying RegRipper to automatically run against a selected mounted drive.&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When using RegRipper I began running into user to computer interface problems. Namely, for some reason I would select a hive file to process, but forget to tell RegRipper what plugin file to use against it. After doing this several dozen times and having to rerun the reports after realizing I had done it, I started thinking about ways to modify RegRipper to alleviate my obvious “stupid” user issues. I figured since I can’t remember to select the plugin types I want, why can’t the program just throw all the available plugins against the hive and determine which ones should work against it. Then that got me thinking… for that matter why am “I” having to know where all these registry hives are at. I have to extract them from an image, remember where I took them from, and then run RegRipper against each one. That is way too much work. I wish RegRipper would just do that all for me so I can do what I really care about, look at the great output from the program.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;To accomplish this task there were a couple of problems that needed to be solved. The rest of this post will be about how a proof of concept that I did solved these problems.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Problems:&lt;/div&gt;&lt;div&gt;1.RegRipper is intended to only run plugins against a single and specified type of registry hive. The plugins can be run against any single hive it is just not likely that any of the key value pairs will be successfully foundoHow if it is not of the correct type.&lt;/div&gt;&lt;div&gt;2.RegRipper expects the user to know the location of each registry hive that needs to be processed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Potential Solutions:&lt;/div&gt;&lt;div&gt;1.Modify RegRipper to allow the user to select one or more registry hives. Have RegRipper attempt to determine each hive’s type and then run only the plugins that are intended for that hive against it. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is pretty easy… right? All we need to do is (a)come up with some code to determine a hive file type, (b)programmatically determine what hive type a plugin is supposed to run against, (c)allow the user to select multiple hives, and then (d)iterate through all of the hives. That doesn’t seem too bad. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;a.To determine the hive type, Harlan has already provided us with code in rip.pl that tries to guess the hive type, so that is done, we just need to add it to RegRipper. For my proof of concept I came up with a similar way, I just used different keys. (starts at line 563 of code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;b.To determine the hive each plugins should be run against the basic design of the RegRipper could be used. In each plugin the developer can specify what hive types the plugin should be run against. You could just pull the %config=&gt;hive value from the plugin and use that. When reviewing the plugins I noticed that some could be potentially run against multiple hive types. I figured to keep closer to the current user experience it might be a better idea to still allow users to create their own plugin files, so I came up with my own format. Instead of putting just the plugin name in the plugin file, place the hive type you want to run it against in front of it. ie: “system:usbstor”. I had to modify the main RegRipper code to parse the new plugin file format, and also keep it backward compatible with the current plugin file format. (starts at line 434 of the code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;c.To allow the user to select multiple hive files an additional perl module is required. I used the FileOp::OpenDialog which allows the user to select multiple files. (line 251 of the code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;d.Since selecting multiple files with the OpenDialog returns an array of file names looping through them is easy to implement. (line 267 of the code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So the first problem has been successfully solved and I no longer have to remember to change the plugin file type each time I run RegRipper against a new hive. As a side benefit I can run RegRipper against all of my exported hive files all at once if I want to also. Now on to the next problem.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2.Modify RegRipper to allow it to be run against a mounted drive. Have the program find all of the relevant hive files on the system and process them in a systematic manner.&lt;/div&gt;&lt;div&gt;Now this one looks a little more difficult… maybe? Ok, so we need to (a)allow the user to select a drive letter to run against, (b)grab the basic hive files from windows\system32\config, (c)parse the software hive for a list of profiles and grab the NTUSER.DAT file for each profile, (d)then iterate through all of the identified registry files. Shouldn’t be too tough, I guess.&lt;/div&gt;&lt;div&gt;a.To allow the user to specify running RegRipper against a mounted drive I added a checkbox to the GUI. When this box is checked the BrowseForFolder option from the FileOp perl module is used. (line 605 of the code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;b.Grabbing the basic hives from the mounted drive is a little more difficult than it first looks. Sure the standard location is C:\Windows\System32\config. I first tried this, but when running it on actual cases ran into some issues. Seems some of our corporate clients for some reason have created their own golden images that put the %systemroot% at somewhere other than C:\Windows such as C:\Win. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now this creates a little bit of an issue, as it messes up what should have been an easy step. To resolve this on Windows XP the %systemroot% can be determined from the boot.ini file in a fairly straightforward manner. (starts at line 639 of the code) To resolve this issue in Vista and beyond is a little more difficult. The boot configurations are now stored in a registry hive called the BCD. So you have to parse the GUID and element key/value pairs to get the value that specifies the %systemroot%. (starts at line 614 of the code) If you want to replicate what is in the code I provided a link at the end of this post that should provide the relevant information about the BCD.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Lastly I tossed in some extra code just in case the boot.ini and BCD registry hives can’t be found to default to windows\system32\config. Cause it never hurts to try if nothing else was found. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;c.To determine the profiles on the system Harlan has already provided the code in the profilelist plugin. I used a modification of that code to grab all of the NTUSER.DAT files. (starts at line 690 of the code).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;d.The issue of iterating through multiple hive files was solved in the previous problem. For this I just had to make sure each hive file found was placed in an array to be processed. (line 267 of the code, again)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For me the proof of concept works. It is definitely a rough cut in my opinion, but the source is all there and this post explains the process if anyone wants to make improvements. I am not totally sure I really like the output file that this proof on concept results in, but it is a start. Drastically changing the output options of RegRipper is probably a more difficult undertaking than making it run against a mounted drive, so it may not be worth it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Links&lt;/div&gt;&lt;div&gt;&lt;a href="http://regripper.net/?page_id=150"&gt;http://regripper.net/?page_id=150&lt;/a&gt; (download the code)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://search.cpan.org/~jenda/Win32-FileOp-0.14.1/FileOp.pm"&gt;http://search.cpan.org/~jenda/Win32-FileOp-0.14.1/FileOp.pm&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ezinearticles.com/?Windows-Vista-Boot-Process-Overview&amp;amp;id=794745"&gt;http://ezinearticles.com/?Windows-Vista-Boot-Process-Overview&amp;amp;id=794745&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.geoffchappell.com/viewer.htm?doc=notes/windows/boot/bcd/index.htm&amp;amp;tx=5"&gt;http://www.geoffchappell.com/viewer.htm?doc=notes/windows/boot/bcd/index.htm&amp;amp;tx=5&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-9092249224280572942?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/smtB7v08zuY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/9092249224280572942/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/05/run-regripper-against-mounted-drive.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/9092249224280572942?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/9092249224280572942?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/smtB7v08zuY/run-regripper-against-mounted-drive.html" title="Run RegRipper Against a Mounted Drive" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2010/05/run-regripper-against-mounted-drive.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUMSXc6cCp7ImA9WxFQFUQ.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-5467522543147424858</id><published>2010-05-09T13:12:00.008-05:00</published><updated>2010-05-11T10:04:48.918-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-11T10:04:48.918-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vpn" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Free VPN Accounts</title><content type="html">&lt;div&gt;The last post about Facebook including users' IP addresses in notification emails got a lot of traffic. We also sent quite a bit of traffic to &lt;a href="http://myiptest.com/"&gt;myiptest.com&lt;/a&gt; through the link provided in the story. Adrian from &lt;a href="http://myiptest.com/"&gt;myiptest.com&lt;/a&gt; contacted me about VPN access as he also helps run &lt;a href="http://hideipvpn.com/"&gt;hideipvpn.com&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The benefits of using a VPN or proxy service is clear. Your personal IP address won't be seen by the sites you visit and it can help protect your privacy. If you were using a VPN/proxy service, you wouldn't have been affected by the Facebook notification email problem. If you need more info on VPNs, visit the Wikipedia articles for &lt;a href="http://en.wikipedia.org/wiki/Virtual_private_network"&gt;VPN&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Proxy_server"&gt;Proxy servers&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I have not used the services of &lt;a href="http://hideipvpn.com/"&gt;hideipvpn.com&lt;/a&gt; yet and hadn't heard of them before, but I did check out their &lt;a href="http://www.hideipvpn.com/privacy-policy/"&gt;privacy policy&lt;/a&gt; and &lt;a href="http://www.hideipvpn.com/terms-of-service/"&gt;terms of service&lt;/a&gt;. Both seem to be standard and I didn't see anything concerning, but I always suggest checking them out for yourself. As with anything else, use at your own risk. You can also see some reviews of their service &lt;a href="http://myvpnreviews.com/hideipvpn/#reviews"&gt;here&lt;/a&gt; and &lt;a href="http://hide-ip-tools.com/hideipvpn/"&gt;here&lt;/a&gt;. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Adrian was kind enough to set aside 25 free accounts for readers of this blog. For full disclosure, he also promised me use of a premium/paid account.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Since there is no reason to turn down a free account, go&lt;a href="https://billing.hideipvpn.com/cart.php?a=add&amp;amp;pid=10&amp;amp;promocode=BININT"&gt; grab one from here&lt;/a&gt;. If you don't make it in time to get one of these accounts, check out the &lt;a href="http://www.hideipvpn.com/blog/"&gt;hideipvpn.com blog&lt;/a&gt; for future chances. You can also &lt;a href="http://twitter.com/hideipvpn"&gt;follow them on Twitter&lt;/a&gt;. Please let me know how things go and leave me a comment about what you think of their service.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Update&lt;/b&gt;: Be aware that during the sign-up process your passwords will be emailed to you in plain text. They also seem to be stored on the &lt;a href="http://hideipvpn.com"&gt;hideipvpn.com&lt;/a&gt;'s servers in plain text. Use a unique password for this site and make sure you don't use it anywhere else.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It also looks like they never validate your Google Checkout or Paypal account since it will never be charged.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-5467522543147424858?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/WHI9TfrLhbM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/5467522543147424858/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/05/free-vpn-accounts.html#comment-form" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/5467522543147424858?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/5467522543147424858?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/WHI9TfrLhbM/free-vpn-accounts.html" title="Free VPN Accounts" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>4</thr:total><feedburner:origLink>http://www.binint.com/2010/05/free-vpn-accounts.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMCQn46fCp7ImA9WxFQE0k.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-4053445164098026382</id><published>2010-05-07T16:13:00.004-05:00</published><updated>2010-05-08T13:14:23.014-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-05-08T13:14:23.014-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="fail" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Facebook Leaks IP Addresses</title><content type="html">&lt;div&gt;&lt;b&gt;Update&lt;/b&gt;: It looks like Facebook fixed the default behavior of the sent emails. Your IP Address is no longer included in the notification emails. I will give Facebook credit that they solved this in less than 24 hours. Now, if they can just shore up some of the other issues...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Original Post&lt;/b&gt;:&lt;/div&gt;Facebook has nice email notifications whenever a friend comments on your status, sends you a message, or a variety of other reasons. The emails have subjects similar to "John Doe commented on your wall post." The unfortunate thing is that this email also appears to contain John Doe's (or your other friend's) IP address.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The email headers contain a line similar to:&lt;/div&gt;&lt;div&gt; &lt;span class="Apple-style-span"   style="  white-space: pre-wrap; font-family:monospace;font-size:medium;"&gt;X-Facebook: from zuckmail ([MTAuMzAuNDcuMjAw])&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-family:monospace;"&gt;&lt;span class="Apple-style-span"  style="white-space: pre-wrap; font-size:medium;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Copy this line out and feed it to this page:&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.myiptest.com/staticpages/index.php/trace-email-sender"&gt;http://www.myiptest.com/staticpages/index.php/trace-email-sender&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You will get the IP address of your friend and clicking on it will get a geolocation-based map. This will also show you if your friend used their cell phone to post and who they use as their service provider.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This information is great when a &lt;a href="http://gawker.com/5435993/facebook-fugitive-taunts-cops-with-pictures-and-status-updates"&gt;fugitive is taunting law enforcement&lt;/a&gt; through their Facebook page, but not when a wife is trying to hide from an abusive husband and assumes Facebook is the best form of communication. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This isn't the end of the world compared to some of Facebook's other privacy problems, however, there is simply no need for Facebook to include these IP addresses and it should be quickly fixed.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-4053445164098026382?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/rZ9KJbF7o0Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/4053445164098026382/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/05/facebook-leaks-ip-addresses.html#comment-form" title="29 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4053445164098026382?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4053445164098026382?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/rZ9KJbF7o0Y/facebook-leaks-ip-addresses.html" title="Facebook Leaks IP Addresses" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>29</thr:total><feedburner:origLink>http://www.binint.com/2010/05/facebook-leaks-ip-addresses.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cDQ345eip7ImA9WxBXFE4.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-3263882906788851497</id><published>2010-01-25T11:00:00.002-06:00</published><updated>2010-01-25T11:04:32.022-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-25T11:04:32.022-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="blog" /><category scheme="http://www.blogger.com/atom/ns#" term="authors" /><title>Looking for new Authors</title><content type="html">Hi all...&lt;br /&gt;&lt;br /&gt;I just don't seem to write as many posts as I'd like, but I don't want this space to go to waste. If you have some topics you'd like to write about, please let me know. I'd love to add some new authors to this blog.&lt;br /&gt;&lt;br /&gt;Let me know at matt @ binint.com or DM on Twitter &lt;a href="http://www.twitter.com/_remnant_"&gt;@_remnant_&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-3263882906788851497?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/Kqrz5NUspms" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/3263882906788851497/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2010/01/looking-for-new-authors.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3263882906788851497?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3263882906788851497?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/Kqrz5NUspms/looking-for-new-authors.html" title="Looking for new Authors" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2010/01/looking-for-new-authors.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUBQHo9eCp7ImA9WxBTE0Q.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-3812367233527499373</id><published>2009-12-09T15:25:00.005-06:00</published><updated>2009-12-09T16:20:51.460-06:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-09T16:20:51.460-06:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Guide to Changing Your Facebook Privacy Options</title><content type="html">Facebook is rolling out the new Privacy options today. There are a couple good things and a couple bad things. I suggest &lt;a href="http://www.eff.org/deeplinks/2009/12/facebooks-new-privacy-changes-good-bad-and-ugly"&gt;reading this article by the EFF&lt;/a&gt; for a good breakdown on the new changes. Sadly, your friends still have some bearing over how your information is used. In my opinion, Applications still get way too much leeway on what personal information they are able to see, collect, and use.&lt;br /&gt;&lt;br /&gt;To maximize your privacy, I suggest the following changes. This guide should walk you through each screen and make sure you don't miss anything important.&lt;br /&gt;&lt;br /&gt;The basic Privacy Settings screen looks like this:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Sznqo_g1_aM/SyAHuwdUjJI/AAAAAAAAABE/BsyIjcyPFQY/s1600-h/ScreenHunter_01+Dec.+09+14.22.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 245px;" src="http://2.bp.blogspot.com/_Sznqo_g1_aM/SyAHuwdUjJI/AAAAAAAAABE/BsyIjcyPFQY/s400/ScreenHunter_01+Dec.+09+14.22.jpg" alt="" id="BLOGGER_PHOTO_ID_5413335251962596498" border="0" /&gt;&lt;/a&gt;Start with the first group, &lt;span style="font-weight: bold;"&gt;Profile Information&lt;/span&gt;. There are several settings to update and every choice within this group should be set to "Friends Only". You'll have to click the Edit Settings button for Photo Albums and set each album to "Friends Only" as well.&lt;br /&gt;&lt;br /&gt;&lt;img src="file:///C:/Users/Matt/AppData/Local/Temp/moz-screenshot.png" alt="" /&gt;&lt;img src="file:///C:/Users/Matt/AppData/Local/Temp/moz-screenshot-1.png" alt="" /&gt;The next group is &lt;span style="font-weight: bold;"&gt;Contact Information&lt;/span&gt;. This is how my settings look, but you may want to adjust for your own tastes.&lt;br /&gt;&lt;br /&gt;&lt;img src="file:///C:/Users/Matt/AppData/Local/Temp/moz-screenshot-2.png" alt="" /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Sznqo_g1_aM/SyAJlZqncSI/AAAAAAAAABM/9E3UJrqUkU4/s1600-h/ScreenHunter_02+Dec.+09+14.30.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 570px; height: 287px;" src="http://3.bp.blogspot.com/_Sznqo_g1_aM/SyAJlZqncSI/AAAAAAAAABM/9E3UJrqUkU4/s400/ScreenHunter_02+Dec.+09+14.30.jpg" alt="" id="BLOGGER_PHOTO_ID_5413337290248778018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The next group is &lt;span style="font-weight: bold;"&gt;Applications and Websites&lt;/span&gt;. The options here are:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Sznqo_g1_aM/SyALi_U8jzI/AAAAAAAAABU/q9KifZkPEyo/s1600-h/ScreenHunter_04+Dec.+09+14.40.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 104px;" src="http://2.bp.blogspot.com/_Sznqo_g1_aM/SyALi_U8jzI/AAAAAAAAABU/q9KifZkPEyo/s400/ScreenHunter_04+Dec.+09+14.40.jpg" alt="" id="BLOGGER_PHOTO_ID_5413339447842082610" border="0" /&gt;&lt;/a&gt;For "What you share", click on Learn More and you'll see an info screen. Click the link in the very last sentence or just &lt;a href="http://www.facebook.com/editapps.php"&gt;&lt;span style="text-decoration: underline;"&gt;go here&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Click on "Edit Settings" for each application. Change the options to "Friends Only". You might want to look at the "Additional Permissions" to see if the application can post to your stream.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Sznqo_g1_aM/SyANQ0km3cI/AAAAAAAAABg/vMqcFgZbF-A/s1600-h/ScreenHunter_05+Dec.+09+14.47.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 140px;" src="http://4.bp.blogspot.com/_Sznqo_g1_aM/SyANQ0km3cI/AAAAAAAAABg/vMqcFgZbF-A/s400/ScreenHunter_05+Dec.+09+14.47.jpg" alt="" id="BLOGGER_PHOTO_ID_5413341334740590018" border="0" /&gt;&lt;/a&gt;Also, on the top right of this screen there is the drop down box labeled "Show". Make sure you go through all of those screens so that you don't miss any applications.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;A quick note about Applications... make sure you delete any Applications you aren't using. Every application has access to your personal information and this really isn't a good thing. &lt;/span&gt;&lt;a style="font-style: italic;" href="http://consumerist.com/2009/11/mafia-wars-ceo-brags-about-scamming-users-from-day-one.html"&gt;Take it straight from the creator of Mafia Wars.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The next group within Applications and Websites is "What Your Friends Can Share About You". Uncheck everything and then click Save Changes.&lt;br /&gt;&lt;br /&gt;The last two sections, "Blocked Applications" and "Ignore Application Invites" probably don't need to be edited.&lt;br /&gt;&lt;br /&gt;The fourth main section is &lt;span style="font-weight: bold;"&gt;Search&lt;/span&gt;. In this section you will need to Uncheck "Allow Indexing" and set "Appear in Search Results" to "Friends of Friends" or "Friends Only". This section will help restrict the general public from finding your profile. Again, the point of this article and the settings presented is to protect your privacy.&lt;br /&gt;&lt;br /&gt;The last main section is &lt;span style="font-weight: bold;"&gt;Block List&lt;/span&gt; and probably doesn't need to be edited at this time.&lt;br /&gt;&lt;br /&gt;Now we've walked through the main sections to protect your privacy. This is a great first step, but as the &lt;a href="http://www.eff.org/deeplinks/2009/12/facebooks-new-privacy-changes-good-bad-and-ugly"&gt;EFF article&lt;/a&gt; points out&lt;br /&gt;&lt;blockquote&gt;Looking even closer at the new Facebook privacy changes, things get downright ugly when it comes to controlling who gets to see personal information such as your list of friends. Under the new regime, Facebook treats that information — along with your name, profile picture, current city, gender, networks, and the pages that you are a "fan" of — as "publicly available information" or "PAI."&lt;/blockquote&gt;To help minimize what you're sharing with the public, you'll have to change some of this info as well.&lt;br /&gt;&lt;br /&gt;To begin, click on "Edit My Profile" underneath your profile picture. Uncheck "Show my sex in my profile" and make sure the dropdown box underneath your birthday is set to "Don't show my birthday in my profile".&lt;br /&gt;&lt;br /&gt;Next find the box on the lefthand pane that shows your friends. Click on the pencil and uncheck the box that says "Show my friends on my profile".&lt;br /&gt;&lt;br /&gt;Your profile picture is displayed publicly despite your Photo Album settings. If you're not comfortable showing your picture to the world, change it to something else.&lt;br /&gt;&lt;br /&gt;The final pieces of information will have to be removed entirely if you don't want them publicly displayed. Current City, Networks, Recent Activity, and Fan Pages are all publicly available. I deleted everything (although I really didn't have much to begin with).&lt;br /&gt;&lt;br /&gt;To see how your new Profile looks to the public, click on Privacy Settings, Profile Information, and then Preview Profile. If there is any information displayed that you don't want, go back through the settings and remove it. Again, some things must be manually deleted.&lt;br /&gt;&lt;br /&gt;After following these steps, the only information I have publicly displayed is my name, my fake profile picture, and one &lt;a href="http://www.facebook.com/pages/Continuum-Worldwide/186513690763"&gt;Fan Page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Sznqo_g1_aM/SyAc0rzLNsI/AAAAAAAAAB4/sabDHPKyaJA/s1600-h/ScreenHunter_07+Dec.+09+15.54.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 241px;" src="http://4.bp.blogspot.com/_Sznqo_g1_aM/SyAc0rzLNsI/AAAAAAAAAB4/sabDHPKyaJA/s400/ScreenHunter_07+Dec.+09+15.54.jpg" alt="" id="BLOGGER_PHOTO_ID_5413358443535480514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Good luck changing your settings. If there was something I missed, please let me know in the comments. If you have trouble changing a setting, let me know that as well and I'll try to help you out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-3812367233527499373?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/DJneCcvKh3c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/3812367233527499373/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/12/guide-to-changing-your-facebook-privacy.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3812367233527499373?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3812367233527499373?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/DJneCcvKh3c/guide-to-changing-your-facebook-privacy.html" title="Guide to Changing Your Facebook Privacy Options" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Sznqo_g1_aM/SyAHuwdUjJI/AAAAAAAAABE/BsyIjcyPFQY/s72-c/ScreenHunter_01+Dec.+09+14.22.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/12/guide-to-changing-your-facebook-privacy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUINQXs6fCp7ImA9WxNVGUw.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-1391493776976228766</id><published>2009-10-30T10:44:00.002-05:00</published><updated>2009-10-30T10:46:30.514-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-30T10:46:30.514-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="interview" /><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><title>News Story</title><content type="html">Here is a news story that Jim and I participated in on Facebook and securing your private information.&lt;br /&gt;&lt;br /&gt;http://www.wowt.com/home/headlines/67332677.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-1391493776976228766?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/WITqBR9vzfo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/1391493776976228766/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/news-story.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1391493776976228766?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1391493776976228766?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/WITqBR9vzfo/news-story.html" title="News Story" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/10/news-story.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8ARX48cSp7ImA9WxNVE08.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-4551648670107157807</id><published>2009-10-23T14:23:00.003-05:00</published><updated>2009-10-23T14:57:24.079-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-23T14:57:24.079-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="facebook" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Facebook Security - Relying on Friends</title><content type="html">&lt;a href="http://www.readwriteweb.com/archives/how_safe_are_facebook_applications.php"&gt;Another article&lt;/a&gt; came along regarding Facebook security and hijacked applications. What I found most interesting was this quote:&lt;br /&gt;&lt;blockquote&gt;On top of all these security issues, in August many Facebook users were surprised to discover &lt;a href="http://www.readwriteweb.com/archives/what_facebook_quizzes_know_about_you.php"&gt;the vast amounts of personal information they were revealing by their use of Facebook quizzes&lt;/a&gt;. Even if you limit access to your profile through privacy settings, Facebook quiz applications can see everything on your profile page when you take a quiz...or even when your friend takes one. To make matters worse, Facebook does not screen developers for trustworthiness &lt;a href="http://www.readwriteweb.com/archives/does_that_facebook_app_have_a_privacy_policy_probably_not.php"&gt;nor do they require developers to comply with a privacy policy&lt;/a&gt;.&lt;/blockquote&gt;&lt;span style="font-style: italic;"&gt;"&lt;span style="font-weight: bold;"&gt;...or even when your friend takes one&lt;/span&gt;.&lt;/span&gt;" I've always thought that it's kind of shady that quizzes and applications can access my friends' personal data. I shy away from the apps and quizzes for this specific reason. But, are my friends providing me the same courtesy? By being on Facebook, am I putting my personal information security in my friends' hands? Facebook has done better with increased privacy settings, and hopefully users have changed those settings to be more restrictive.&lt;br /&gt;&lt;br /&gt;If I was a malicious user, I would absolutely create as many quizzes as I could that would take advantage of the automatic data mining capabilities of Facebook.&lt;br /&gt;&lt;br /&gt;It seems like a recurring theme on this blog lately, but be careful of what you post online.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-4551648670107157807?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/hUKRg-iBss0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/4551648670107157807/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/facebook-security-relying-on-friends.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4551648670107157807?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4551648670107157807?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/hUKRg-iBss0/facebook-security-relying-on-friends.html" title="Facebook Security - Relying on Friends" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/10/facebook-security-relying-on-friends.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4BRHg9eSp7ImA9WxNVEEs.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-8351763003380243607</id><published>2009-10-20T13:07:00.003-05:00</published><updated>2009-10-20T13:39:15.661-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-20T13:39:15.661-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="social networking" /><category scheme="http://www.blogger.com/atom/ns#" term="links" /><title>"Bad" Social Networking Links</title><content type="html">Wow. We all know that social networking can be "bad". Here are a few recent articles.&lt;a href="http://www.wired.com/dangerroom/2009/10/exclusive-us-spies-buy-stake-in-twitter-blog-monitoring-firm/"&gt;&lt;br /&gt;&lt;/a&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.wired.com/dangerroom/2009/10/exclusive-us-spies-buy-stake-in-twitter-blog-monitoring-firm/"&gt;Exclusive: U.S. Spies Buy Stake in Firm That Monitors Blogs, Tweets&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.net-security.org/article.php?id=1324"&gt;How Social Networking Can Hurt You&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/343900/How_Hackers_Find_Your_Weak_Spots?source=rss_security"&gt;How Hackers Find Your Weak Spots&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/343290/Your_Own_Worst_Enemy?source=rss_security"&gt;Opinion: Twitter, Facebook Security Depends on Vigilant Developers, Sensible Users&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/10/hacked_facebook_apps_lead_to_m.html?wprss=securityfix"&gt;Researcher: Hackers Hijack Some Facebook Apps&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cnn.com/2009/CRIME/10/19/social.networking.crimes/index.html"&gt;Facebook, Twitter users beware: Crooks are a mouse click away&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cnn.com/2009/TECH/science/10/13/social.networking.class/index.html"&gt;Does your social class determine your online social network?&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-8351763003380243607?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/Ketlor-En-Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/8351763003380243607/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/bad-social-networking-links.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8351763003380243607?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8351763003380243607?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/Ketlor-En-Q/bad-social-networking-links.html" title="&quot;Bad&quot; Social Networking Links" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/10/bad-social-networking-links.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkENSXw-eyp7ImA9WxNWGEQ.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-156999035817215930</id><published>2009-10-18T15:03:00.004-05:00</published><updated>2009-10-18T15:44:58.253-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-18T15:44:58.253-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="social engineering" /><category scheme="http://www.blogger.com/atom/ns#" term="interview" /><title>Interview and Interrogation - Balloon Boy</title><content type="html">Stan B. Walters is well known as "The Lie Guy". He gets a fair amount of press and I've attended his Kinesic Interview and Interrogation course. Stan often uses current events to illustrate his techniques and talking points. In his &lt;a href="http://www.thelieguyblog.com/my_weblog/2009/10/balloon-boy-reading-the-signs-of-deception.html"&gt;most recent blog post&lt;/a&gt;, he takes on the "Balloon Boy" family.&lt;br /&gt;&lt;br /&gt;We now know that the &lt;a href="http://www.cnn.com/2009/US/10/18/colorado.balloon.investigation/index.html"&gt;balloon stunt was a hoax&lt;/a&gt;. Stan mentions that "it all came down to the verbal and nonverbal cues of deception generated by the Heenes." Unfortunately, he doesn't go into any detail on what he thinks those cues were. However, there are a few listed in the CNN article linked above.&lt;br /&gt;&lt;br /&gt;Stan talks about narrative based interviews as a way of gathering information. You can learn a lot from just listening to someone talk and watching their body language. He also mentions that the interviewer needs to be aware of what signals they are giving back to the interviewee. These are a lot of the same points I tried to make in the &lt;a href="http://www.social-engineer.org/framework/Podcast/001_-_Interrogation_and_Interview_Tactics"&gt;Social Engineering Podcast&lt;/a&gt; and Stan's post is a good read.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-156999035817215930?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/WAh_M3sf1JE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/156999035817215930/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/interview-and-interrogation-balloon-boy.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/156999035817215930?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/156999035817215930?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/WAh_M3sf1JE/interview-and-interrogation-balloon-boy.html" title="Interview and Interrogation - Balloon Boy" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/10/interview-and-interrogation-balloon-boy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04BQHo5cCp7ImA9WxNWFEk.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-3886271635774504100</id><published>2009-10-13T09:51:00.003-05:00</published><updated>2009-10-13T09:59:11.428-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-13T09:59:11.428-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="cell phone forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="cellebrite" /><title>Cellebrite Gets Early Info</title><content type="html">I've been waiting for an Android phone to hit Verizon for a while, so I've been following some mobile phone blogs. &lt;a href="http://www.boygeniusreport.com/2009/10/13/verizon-employees-see-the-motorola-sholes-and-calgary-emerge-in-internal-tools/"&gt;This post&lt;/a&gt; from Boy Genius Report was interesting to me on the cell phone forensics front.&lt;br /&gt;&lt;br /&gt;One of Cellebrite's selling points for forensic use is that they often get previews of new devices in order to get their units up to speed for use in the carrier's stores. The photos in the BGR post (if real) certainly give some credibility to that statement. I wonder if other cell forensic suites get similar updates.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-3886271635774504100?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/9EA6JjLr2XU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/3886271635774504100/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/cellebrite-gets-early-info.html#comment-form" title="9 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3886271635774504100?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3886271635774504100?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/9EA6JjLr2XU/cellebrite-gets-early-info.html" title="Cellebrite Gets Early Info" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>9</thr:total><feedburner:origLink>http://www.binint.com/2009/10/cellebrite-gets-early-info.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEBR3w4fSp7ImA9WxNXF0k.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-5874350645826220935</id><published>2009-10-04T08:18:00.005-05:00</published><updated>2009-10-05T08:17:36.235-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-05T08:17:36.235-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="social engineering" /><category scheme="http://www.blogger.com/atom/ns#" term="interview" /><category scheme="http://www.blogger.com/atom/ns#" term="podcast" /><title>Social Engineer Interview Podcast</title><content type="html">I mentioned a few posts back that I've been helping contribute content over at Social-Engineer.org. Today they released their &lt;a href="http://www.social-engineer.org/framework/Podcast/001_-_Interrogation_and_Interview_Tactics"&gt;first podcast&lt;/a&gt; and I was lucky enough to be the interview guest. The podcast builds on &lt;a href="http://www.binint.com/2008/12/successful-interview-tips.html"&gt;this post&lt;/a&gt; I did a while back about interviewing techniques.&lt;br /&gt;&lt;br /&gt;I think the podcast presents some useful information. Even though the topic is interrogation, pieces of the conversation should be useful in everyday interaction.&lt;br /&gt;&lt;br /&gt;Give it a listen and let me know what you think. If you RSS and don't want to come back here to leave comments, hit me up on Twitter &lt;a href="http://www.twitter.com/_remnant_"&gt;@_remnant_&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;Thanks to everyone over at Social-Engineer.org for making a great site and some fun times.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-5874350645826220935?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/aafbdWqa6B8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/5874350645826220935/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/10/social-engineer-interview-podcast.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/5874350645826220935?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/5874350645826220935?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/aafbdWqa6B8/social-engineer-interview-podcast.html" title="Social Engineer Interview Podcast" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/10/social-engineer-interview-podcast.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEFSXc-fyp7ImA9WxNQFks.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-6377914945210617876</id><published>2009-09-22T18:31:00.004-05:00</published><updated>2009-09-22T18:36:58.957-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-22T18:36:58.957-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="ftk" /><category scheme="http://www.blogger.com/atom/ns#" term="4cast" /><category scheme="http://www.blogger.com/atom/ns#" term="review" /><title>FTK3 Review</title><content type="html">For those forensic folk that may have not have seen this, I did a review of FTK3 for the good folks over at Forensic 4Cast. Check it out here, &lt;a href="http://4cast.whitfields.org/?p=438"&gt;http://4cast.whitfields.org/?p=438&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Also, follow the 4Cast guys on Twitter at &lt;a href="http://twitter.com/Schizophreud"&gt;@Schizophreud&lt;/a&gt; and &lt;a href="http://twitter.com/englishgit"&gt;@englishgit&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-6377914945210617876?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/44G4Hj--dIk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/6377914945210617876/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/09/ftk3-review.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6377914945210617876?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6377914945210617876?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/44G4Hj--dIk/ftk3-review.html" title="FTK3 Review" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/09/ftk3-review.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cNQn8zcSp7ImA9WxNQFUU.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-1358335405564009350</id><published>2009-09-20T21:32:00.014-05:00</published><updated>2009-09-21T19:58:13.189-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-21T19:58:13.189-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Twitter" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Burglary by the Tweets</title><content type="html">It's not hard to look around and see that people are posting way too much personal information online. There are tons of &lt;a href="http://www.mindhacks.com/blog/2009/09/connected_by_threads.html"&gt;articles&lt;/a&gt; &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=Security&amp;amp;articleId=9125058&amp;amp;taxonomyId=17&amp;amp;pageNumber=1"&gt;about it&lt;/a&gt; and now we can even &lt;a href="http://yro.slashdot.org/story/09/09/20/1753254/MIT-Project-Gaydar-Shakes-Privacy-Assumpitons?from=rss"&gt;find out if you're gay or straight&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Most of the information seems harmless and a lot of people don't care if others know about their personal lives. But how much trouble can it get you in to? One couple thinks their &lt;a href="http://news.cnet.com/8301-1009_3-10260183-83.html"&gt;Twitt&lt;/a&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10260183-83.html"&gt;er posts &lt;/a&gt;&lt;a href="http://news.cnet.com/8301-1009_3-10260183-83.html"&gt;led to their burglary&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Is it that easy?! Let's find out...&lt;br /&gt;&lt;br /&gt;Chirpcity.com let's you search tweets by location. I chose a random city from the list and then searched for all tweets mentioning "vacation".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Sznqo_g1_aM/SreEqRPT6mI/AAAAAAAAAA8/pHD1gHUsZ7U/s1600-h/search1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 461px; height: 187px;" src="http://2.bp.blogspot.com/_Sznqo_g1_aM/SreEqRPT6mI/AAAAAAAAAA8/pHD1gHUsZ7U/s400/search1.jpg" alt="" id="BLOGGER_PHOTO_ID_5383917741261711970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;How lucky that the first result includes a potential victim. I don't want to get a real person in trouble here and create a ready-made victim, so I'm blocking out all identifying information. Plus, I don't think this person is actually going to be gone for five weeks during the school year as their Twitter feed also says they're a student. See how quickly we can learn about someone?&lt;br /&gt;&lt;br /&gt;Ok, so let's go look at Twitter profile.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Sznqo_g1_aM/SreCkhJaFSI/AAAAAAAAAA0/QcUFJsFJycM/s1600-h/search2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 480px; height: 252px;" src="http://2.bp.blogspot.com/_Sznqo_g1_aM/SreCkhJaFSI/AAAAAAAAAA0/QcUFJsFJycM/s400/search2.jpg" alt="" id="BLOGGER_PHOTO_ID_5383915443429446946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Now we're getting somewhere. Our second webpage gave us their last name and website address. If we wanted to learn more we could check out their webpage to hopefully see what kind of stuff they might have we could steal. Now we just need to find out where they live. Cue Zabasearch.com!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Sznqo_g1_aM/SreB4-4uO3I/AAAAAAAAAAs/GUuX0d_Zjbk/s1600-h/search3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 480px; height: 84px;" src="http://3.bp.blogspot.com/_Sznqo_g1_aM/SreB4-4uO3I/AAAAAAAAAAs/GUuX0d_Zjbk/s400/search3.jpg" alt="" id="BLOGGER_PHOTO_ID_5383914695498283890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This was the most recent entry was for this person. I blacked out all the personal info so it doesn't look like much, but I now have a middle initial and possible address. I guess I could double check with other &lt;a href="http://lifehacker.com/software/feature/how-to-track-down-anyone-online-329033.php"&gt;people searching sites&lt;/a&gt;. For a low monthly fee I could even  subscribe to a data mining site and have instant information that includes much more than this!&lt;br /&gt;&lt;br /&gt;Using free resources and five minutes of my time I located a potential victim and her address. I suppose it would be worth it to spend another 30 minutes and drive by the address to scope it out. Of course, if I really was a criminal I would have found multiple victims to go check out.&lt;br /&gt;&lt;br /&gt;I guess it really is that easy. Be careful everybody!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-1358335405564009350?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/QogSkafskdY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/1358335405564009350/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/09/burglary-by-tweets.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1358335405564009350?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1358335405564009350?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/QogSkafskdY/burglary-by-tweets.html" title="Burglary by the Tweets" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Sznqo_g1_aM/SreEqRPT6mI/AAAAAAAAAA8/pHD1gHUsZ7U/s72-c/search1.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/09/burglary-by-tweets.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIGQHg9eyp7ImA9WxNQEk0.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-4626464616967382076</id><published>2009-09-17T12:27:00.001-05:00</published><updated>2009-09-17T12:28:41.663-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-17T12:28:41.663-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="skype" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Skype Replacement?</title><content type="html">What does everyone use for instant messaging and VOIP? Skype is such a great product but has been plagued lately by some bad press.&lt;br /&gt;&lt;br /&gt;It's EULA has been &lt;a href="http://www1.cs.columbia.edu/%7Esmb/blog//2009-09/2009-09-12.html"&gt;plaguing people&lt;/a&gt; for a while and the &lt;a href="http://www.megapanzer.com/2009/09/12/detailed-article-from-an-antimalware-vendor-about-the-skypetrojan/"&gt;new trojan&lt;/a&gt; causes worries as well. With all &lt;a href="http://www.computerworld.com/s/article/9138151/Report_Skype_founders_sue_Skype?source=rss_security"&gt;the lawsuits&lt;/a&gt;, will Skype even be around in two years?&lt;br /&gt;&lt;br /&gt;Right now there seem to be more benefits than pitfalls, as communications are encrypted and it's one of the most recognizable IM/VOIP platforms.&lt;br /&gt;&lt;br /&gt;But for the future, are there any other good programs I should check out?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-4626464616967382076?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/MmoryqO-MPU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/4626464616967382076/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/09/skype-replacement.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4626464616967382076?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/4626464616967382076?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/MmoryqO-MPU/skype-replacement.html" title="Skype Replacement?" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/09/skype-replacement.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUAAR30yfip7ImA9WxNQEk0.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-8380698911893066892</id><published>2009-09-17T12:11:00.003-05:00</published><updated>2009-09-17T12:15:46.396-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-17T12:15:46.396-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="backontrack" /><title>How time flies by...</title><content type="html">It looks like it's been a few months since the last post. Both Jim and I have been busy with work and other outside projects. I plan to start posting more often and get the site back on track.&lt;br /&gt;&lt;br /&gt;One of the side projects Jim and I have been involved with is www.social-engineer.org. We've both contributed content to the framework and plan on being active there as well.&lt;br /&gt;&lt;br /&gt;More soon...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-8380698911893066892?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/TBFTddxXXA8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/8380698911893066892/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/09/how-time-flies-by.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8380698911893066892?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8380698911893066892?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/TBFTddxXXA8/how-time-flies-by.html" title="How time flies by..." /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/09/how-time-flies-by.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMBRn08cSp7ImA9WxJVF04.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-1334233043454441810</id><published>2009-07-04T13:59:00.003-05:00</published><updated>2009-07-04T14:40:57.379-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-04T14:40:57.379-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ps3" /><category scheme="http://www.blogger.com/atom/ns#" term="game systems" /><category scheme="http://www.blogger.com/atom/ns#" term="encryption" /><title>PS3 Forensics and Decryption</title><content type="html">As we &lt;a href="http://www.binint.com/2009/03/ps3-forensics.html"&gt;talked previously on here before about PS3 forensics&lt;/a&gt;, I thought I would do a quick followup. There has been some advancement in the area of decrypting PS3s, though the process is not currently in a state that it could be considered a first stop for the average investigation.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The process requires a couple drives, the original PS3, and an amount of time. I will not be testing it out myself, but if anyone wants to try please leave a comment on how it works for you. &lt;a href="http://www.ps3news.com/forums/ps3-hdd-news/ps3-hdd-studio-2-08-available-yet-another-ps3-hdd-tool-106734.html"&gt;You can see all the details up here.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-1334233043454441810?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/H_blfjHBAbw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/1334233043454441810/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/07/ps3-forensics-and-decryption.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1334233043454441810?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1334233043454441810?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/H_blfjHBAbw/ps3-forensics-and-decryption.html" title="PS3 Forensics and Decryption" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/07/ps3-forensics-and-decryption.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUNQnc9eSp7ImA9WxJQF0g.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-8059802008915156127</id><published>2009-05-31T01:52:00.002-05:00</published><updated>2009-05-31T02:01:33.961-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-31T02:01:33.961-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="links" /><category scheme="http://www.blogger.com/atom/ns#" term="backtrack" /><title>Forensics on Backtrack 4</title><content type="html">Up at the &lt;a href="http://www.offensive-security.com/blog/"&gt;Offensive Security blog&lt;/a&gt;, we &lt;a href="http://www.offensive-security.com/blog/backtrack/backtrack-forensics/"&gt;put up a little introduction to the forensic additions to Backtrack in this new version&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I have been really enjoying the new BT, a very well put together OS. (And to think, I used to be a BSD head.) The forensic additions to it are really simple, but do the job. I tested them out quite a bit, and everything came back clean. As it is a new forensic tool, I don't suggest anyone use it until they test it out.&lt;br /&gt;&lt;br /&gt;Any problems with the forensic side are on me. Let me know if anything comes up, but I am confident that it is going to be very useful. The &lt;a href="http://www.offensive-security.com"&gt;offsec&lt;/a&gt; and &lt;a href="http://www.remote-exploit.org/"&gt;remote-exploit&lt;/a&gt; crew really put together something special here.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-8059802008915156127?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/H9KTmuFspAk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/8059802008915156127/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/05/forensics-on-backtrack-4.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8059802008915156127?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8059802008915156127?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/H9KTmuFspAk/forensics-on-backtrack-4.html" title="Forensics on Backtrack 4" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/05/forensics-on-backtrack-4.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EFSHgzeip7ImA9WxJQF0w.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-3123886475917626572</id><published>2009-05-30T15:29:00.002-05:00</published><updated>2009-05-30T15:33:39.682-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-30T15:33:39.682-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="news" /><category scheme="http://www.blogger.com/atom/ns#" term="exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="links" /><category scheme="http://www.blogger.com/atom/ns#" term="backtrack" /><title>Backtrack 4</title><content type="html">&lt;p&gt;&lt;a mce_href="http://hackersforcharity.org/hackers-for-charity/get-involved/#informer" href="http://hackersforcharity.org/hackers-for-charity/get-involved/#informer"&gt;Informer&lt;/a&gt; subscribers have &lt;a href="http://hackersforcharity.org/308/backtrack-4-pre-final/"&gt;access to the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Pre&lt;/span&gt;-Final version of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;BT&lt;/span&gt;4&lt;/a&gt;!&lt;/p&gt;With this install, all future updates will be released though a simple apt-get upgrade. So if you don't have a subscription to Informer already, do so now then not have to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;DL&lt;/span&gt; an updated version again.&lt;br /&gt;&lt;br /&gt;New version has an installer, forensic boot mode, etc etc. I have been using it for a bit here, and it is a great update to the older versions. There are a &lt;a href="http://www.offensive-security.com/blog/"&gt;ton of videos on how to interact with it up at the Offensive-Security blog&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-3123886475917626572?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/QbcZA_Oz7_w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/3123886475917626572/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/05/backtrack-4.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3123886475917626572?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/3123886475917626572?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/QbcZA_Oz7_w/backtrack-4.html" title="Backtrack 4" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/05/backtrack-4.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4NQnczfCp7ImA9WxJTGU4.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-8382679610899619257</id><published>2009-04-28T10:35:00.001-05:00</published><updated>2009-04-28T10:36:33.984-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-28T10:36:33.984-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="exploit" /><title>POC for Acrobat</title><content type="html">New &lt;a href="http://www.securityfocus.com/bid/34736/info"&gt;POC for Acrobat was posted&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-8382679610899619257?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/tw_mXmSvw2Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/8382679610899619257/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/04/poc-for-acrobat.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8382679610899619257?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/8382679610899619257?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/tw_mXmSvw2Y/poc-for-acrobat.html" title="POC for Acrobat" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/04/poc-for-acrobat.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUcFRHo-cSp7ImA9WxJTGU4.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-1020491807011382819</id><published>2009-04-28T09:34:00.004-05:00</published><updated>2009-04-28T10:36:55.459-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-04-28T10:36:55.459-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="interview" /><category scheme="http://www.blogger.com/atom/ns#" term="links" /><title>That Security Show</title><content type="html">Been very tied up the last month or so. Sorry for the lack of updates.&lt;br /&gt;&lt;br /&gt;Wanted to &lt;a href="http://blog.marcusjcarey.com/2009/04/that-security-show-johnny-long.html"&gt;share a link to an interview j0e did with Johnny Long for Marcus Carey's That Security Show&lt;/a&gt;. Really well done, and worth a watch. Everyone involved in the production of this show is top notch. I have had the pleasure of meeting them all in person at one time or another, and I can say they are all as good of people in person as they appear to be online.&lt;br /&gt;&lt;br /&gt;Take a few mins to watch the show. And check out &lt;a href="http://johnny.ihackstuff.com/hackers-for-charity/"&gt;Hackers for Charity&lt;/a&gt; while you are at it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-1020491807011382819?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/4dcxzhWrTNE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/1020491807011382819/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/04/that-security-show.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1020491807011382819?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/1020491807011382819?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/4dcxzhWrTNE/that-security-show.html" title="That Security Show" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/04/that-security-show.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4ESXszfSp7ImA9WxVbEUs.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-6368342760858727274</id><published>2009-03-27T10:30:00.001-05:00</published><updated>2009-03-27T10:31:48.585-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-27T10:31:48.585-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Researchers can ID anonymous Twitterers</title><content type="html">&lt;p class="first"&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p class="first"&gt;Web sites that strip personally identifiable information about their users and then share that data may be compromising their    users' privacy, according to researchers at the University of Texas at Austin. &lt;/p&gt; &lt;p&gt;They took a close look at the way anonymous data can be analyzed and have come to some troubling conclusions. In a &lt;a href="http://33bits.org/2009/03/19/de-anonymizing-social-networks/"&gt;paper&lt;/a&gt; set to be delivered at an upcoming security conference, they showed how they were able to map out the connections on public    social networks such as Twitter and Flickr. They were then able to identify people who were on both networks by looking at    the many connections surrounding their network of friends. The technique isn't 100 percent effective, but it may make some    users uncomfortable about whether they should allow their data to be shared in an anonymous format. &lt;/p&gt;            &lt;p&gt;Web site operators often share data about users with partners and advertisers after stripping it of any personally identifiable    information such as names, addresses or birth dates. Arvind Narayanan and fellow researcher Vitaly Shmatikov found that by    analyzing these "anonymized" data sets, they could identify Flickr users who were also on Twitter about two-thirds of the    time, depending on how much information they have to work with.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.networkworld.com/news/2009/032609-researchers-can-id-anonymous.html"&gt;From NetworkWorld.com.&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-6368342760858727274?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/gPZYxUfk_eY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/6368342760858727274/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/03/researchers-can-id-anonymous-twitterers.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6368342760858727274?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6368342760858727274?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/gPZYxUfk_eY/researchers-can-id-anonymous-twitterers.html" title="Researchers can ID anonymous Twitterers" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/03/researchers-can-id-anonymous-twitterers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YARHw9fSp7ImA9WxVUFUw.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-2559268968524712002</id><published>2009-03-19T20:43:00.003-05:00</published><updated>2009-03-19T22:19:05.265-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-19T22:19:05.265-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="interview" /><category scheme="http://www.blogger.com/atom/ns#" term="cyber security" /><category scheme="http://www.blogger.com/atom/ns#" term="exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="apple" /><title>No More Free Bugs</title><content type="html">&lt;a href="http://cansecwest.com/"&gt;CanSecWest&lt;/a&gt; is currently going on, and I am not there. No complaints however, as I am finishing up a week long training class in &lt;a href="http://www.x-ways.net/forensics/"&gt;X-Ways Forensics&lt;/a&gt;. (Verdict: top notch. Check out the program.)&lt;br /&gt;&lt;br /&gt;Catching up on the news tonight, I found these quotes &lt;a href="http://blogs.zdnet.com/security/?p=2941"&gt;from an interview with Charlie Miller&lt;/a&gt; (winner of the &lt;a href="http://dvlabs.tippingpoint.com/blog/2008/03/19/cansecwest-pwn-to-own-2008"&gt;PWN to OWN&lt;/a&gt; contest against OS X) very interesting:&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Did you consider reporting the vulnerability to Apple?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;I never give up free bugs. I have a new campaign. It’s called NO MORE FREE BUGS. Vulnerabilities have a market value so it makes no sense to work hard to find a bug, write an exploit and then give it away.  Apple pays people to do the same job so we know there’s value to this work. &lt;em&gt;No more free bugs&lt;/em&gt;.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;I have heard this rumbled about for a while. There is no disputing that there is a market for bugs, and it is sort of refreshing to hear someone be upfront about their reasons for finding bugs. A lot of people like to pretend that this work is done for "the good of the community". Really, there are a few reasons white hats find the bugs: a) To keep private to add value to their pentests, b) to release to the public to show off their skillz and c) to sell.&lt;br /&gt;&lt;br /&gt;I don't see any shame in that. Why should companies like Apple, MS, etc. expect customers to do their work for them? What is the value?&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;You talked earlier about the value of vulnerabilities.  Was it a surprise that he (Nils) basically gave up three “high-value” bugs for $5,000 each?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;It’s clear he’s incredibly talented.  I was shocked when I saw someone sign up to go after IE 8. You can get paid a lot more than $5,000 for one of those bugs.  I’ve talked to a lot of smart, knowledgeable people and no one knows exactly how he did it. He could easily get $50,000 for that vulnerability.  I’d say $50,000 is a low-end price point.&lt;/p&gt; &lt;p&gt;For the amount of time he spent to do what he did on IE and Firefox, he could have found and exploited five or 10 Safari bugs.  With the way they’re paying $5,000 for every verifiable bug, he could have spent that same time and resources and make $25,000 or $30,000 easily just by going after Safari on Mac.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Other thing that jumped out at me was some of the comments about targeting Macs.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Why Safari?  Why didn’t you go after IE or Safari?&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;It’s really simple. Safari on the Mac is easier to exploit.  The things that Windows do to make it harder (for an exploit to work), Macs don’t do.  Hacking into Macs is so much easier. You don’t have to jump through hoops and deal with all the anti-exploit mitigations you’d find in Windows.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt; &lt;p&gt;Take that quote, combine it with some &lt;a href="http://securityblog.verizonbusiness.com/2009/03/12/whats-with-all-the-glowing-apples/"&gt;recent commentary about the number of security professionals using Macs&lt;/a&gt;, and with &lt;a href="http://trac.metasploit.com/changeset/6353"&gt;meterpreter now being ported to the Mac&lt;/a&gt; (complete with the ability to take pics with built in iSight cameras), and times might get interesting. Going to my above statement about one of the main reasons for tracking down bugs being to show of your skillz, it makes one wonder how many infosec people one could bag at a con...&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-2559268968524712002?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/d4SKeV0xuEA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/2559268968524712002/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/03/no-more-free-bugs.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/2559268968524712002?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/2559268968524712002?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/d4SKeV0xuEA/no-more-free-bugs.html" title="No More Free Bugs" /><author><name>Jim</name><uri>http://www.blogger.com/profile/17421285492719864155</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="11807970692560542255" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/03/no-more-free-bugs.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08NQ3k4eCp7ImA9WxVUFUw.&quot;"><id>tag:blogger.com,1999:blog-7818304882757061870.post-6006126733290614633</id><published>2009-03-19T20:13:00.002-05:00</published><updated>2009-03-19T20:18:12.730-05:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-19T20:18:12.730-05:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="forensics" /><category scheme="http://www.blogger.com/atom/ns#" term="funny" /><title>When Forensics Bites Back</title><content type="html">This story is kind of funny, but kind of sad.&lt;br /&gt;&lt;blockquote&gt;MARCH 18--Meet Michelle Owen. Concerned that an ex-boyfriend had used her laptop to search for child pornography, the Indiana woman asked police to search the computer for illegal images, but had her plan backfire when cops discovered two videos of her engaged in illicit acts with a dog. Owen, 24, was charged last week with two felony bestiality counts in connection with the video files, which a detective found in the laptop's "recycle bin." At the time Owen asked cops to search the computer, she was locked up in the Johnson County Jail on a public intoxication charge (which violated the terms of her release in a prior drunk driving case). According to a &lt;a href="http://www.thesmokinggun.com/archive/years/2009/0318091dog2.html"&gt;police affidavit&lt;/a&gt;, a copy of which &lt;a href="http://www.thesmokinggun.com/archive/years/2009/0318091dog2.html"&gt;you'll find here&lt;/a&gt;, a cop told Owen that he had found videos of her on the laptop and asked if she "knew what those files might be." Owen, pictured in the below mug shot, replied, "The one with the dog." Cops believe that the dog in question, Toby, is a beagle. After asking if she was "going to be charged with this," Owen said that the videos "were just something she did when she was drunk and barely remembers it," adding that she tried to "delete them the next day when she was sober."&lt;/blockquote&gt;&lt;a href="http://www.thesmokinggun.com/archive/years/2009/0318091dog1.html"&gt;From TheSmokingGun.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7818304882757061870-6006126733290614633?l=www.binint.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/binint/~4/vowIkNrQQoo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.binint.com/feeds/6006126733290614633/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.binint.com/2009/03/when-forensics-bites-back.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6006126733290614633?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7818304882757061870/posts/default/6006126733290614633?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/binint/~3/vowIkNrQQoo/when-forensics-bites-back.html" title="When Forensics Bites Back" /><author><name>Matt C</name><uri>http://www.blogger.com/profile/07830283432031455955</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="01684713573506643708" /></author><thr:total>0</thr:total><feedburner:origLink>http://www.binint.com/2009/03/when-forensics-bites-back.html</feedburner:origLink></entry></feed>
