watching you watching us . .


Full Disk Encryption – Breaking Hard Disk Encryption

Good article and more importantly a great discussion in the comments! the article is centered around on the topic of Hard Disk Encyption after a less significant announcement of a “new..” ElcomSoft Forensic Disk Decryptor can decrypt BitLocker, PGP, and TrueCrypt.

“If the PC being investigated is turned off, the encryption keys can be retrieved from the hibernation file. The encrypted volume must be mounted before the computer went to sleep. If the volume is dismounted before hibernation, the encryption keys may not be derived from the hibernation file.”

“most (if not all) encryption software hashes your password immediately, yielding a hex based result which is still easily searched by looking for strings.”

“You are not missing anything. Its a non issue for most. Just don’t use sleep.”

“OpenBSD’s malloc fills junk bytes into allocated and freed chunks via the J option. By default OpenBSD encrypts the swap (where hybernation state is kept), and has done so for many years.”

“DMA is just one such way of manipulating the memory beneath the CPU level there is also the Memory Managment Unit and the I/O mechanisms that rule the roost via the interupt mechanisms that run at what you might consider Ring -1. And these are what you might consider the upper layers of this gulf of insecurity. There are other tricks such as the actual CPU microcode or equivalent in all the other state machines.”

“Breaking Hard-Disk Encryption”
Bruce Schneier, 27 December 2012 – last access 24 January 2013 – ( Article )



Reverse Engineering Android Applications

Interesting article by Carl Benedict, introducing and dicussing Android applications, development and dissection, using some tools for reverse enginnering. Good focus on the Android permission-based system and how it allows access to resources, and where to alter these controls.

“Under the Hood: Reversing Android Applications”
Carl Benedict, 20 January 2012
Infosec Institute Resources – last access 23 January 2012 – ( Full Article )


pktool – a tool used for manipulating .apk files,

jad – a Java decompiler (Windows only),

JD-Core + JD-GUI – another Java decompiler, supporting newer Java versions and features,

dex2jar – a tool for converting .dex files to .class files, (dex2jar)


Solid State Disks, Update, Forensic Implications ?

Solid State Drive adoption in computers, tablets and devices, is presenting new challenges to the CF community. Good article by Mike Sheward explaining to some depth some of the current Forensic concerns and issues with SSD. Interesting testing and hash results with FTK imager and a write blocker.

“Rock Solid: Will Digital Forensics Crack SSD’s?”
Mike Sheward, 5 January 2012 – last access 23 January 2012 – ( Full Article )

Police E-Crime Unit Suspend 2000+ Counterfeit and Fraudulent E-Commerce Websites

It is unclear as to the origins of the suspended e-commerce sites, presumably they were all/mostly based in the UK, unfortunatley this information is not given for analysis.

The press release states that the Metropolitan Police E-Crime Unit suspended more than 2,000 e-commerce website deemded to be selling fake or non-existent goods. The e-commerce websites were offering low price goods from manufacturers such as GHD, Ugg, Tiffany and Nike. The goods were either counterfeit or never arrived, some sites also harvested credit card, bank details and personal information given by customers.

It is also unclear as to if the sites were suspended, siezed (pending further investgation and prosecution) or shut down.

If many gangs registered sites in bulk, how many actual gangs or criminals are under investigation, facing possible prosecution ? Would more information be beneficial to help the consumer/potential victim be better prepared, other than advising the usual update AV.. dedicated credit card for e-shopping.. etc ? Would releasing more details hinder further or current investigation or help consumers to avoid similar ilegal sites ?

“.. Police officers worked with domain registrars to identify the rogue traders and then used Nominet’s powers to seize and shut down the offending domains .. the E-Crime Unit said many gangs registered sites in bulk solely to dupe customers. He said the campaign to close the criminal sites would continue in the run-up to Christmas .. consumers should check a website’s credentials to ensure it was approved and reputable .. also consider using a credit card for payments over £100 and perhaps reserve one card for online shopping ..”

“The E-Crime Unit took similar action in 2010 when it shut down about 1,800 sites.”

So happy shopping with the usual rules, ie. you don’t get something for nothing, and if you pay peanuts you get monkeys.

Police crackdown on fake shopping sites
BBC News, created 21 November 2011. – (Full Article) – last access 23 November 2011

E-Crime Unit take down fraudulent websites
Metropolitan Police, created 18 November 2011. – (Full Article) – last access 23 November 2011


Zetas gang beheads 4th internet blogger, anonymous outcry or Anonymous stepping in ?

Mexico gangsters have beheaded a 4th internet blogger by the name of Rascatripas (or Belly Scratcher) who was involved in moderating a blog called En Vivo, which posted news of criminal activities of the Zetas, a Mexican narcotics and extortion gang.

Recently a person said to be a member of Anonymous, has posted a video on YouTube claiming that the Zetas had kidnapped another Anonymous member.. threatening Zetas to return the victim unharmed or Anonymous will publish identities of Zetas and details of their protectors, in government and business.

Rumours of it being a possible hoax, have paralleled Anonymous publicising to drop the threat, due to the danger it posed to innocent lives.. although with comments like “wait and see” and more recently “expect us”, the jury is out.

Also, Police arrested two people in southern Veracruz state in September for posting rumors on Twitter about impending gangster attacks on schools. Following this Veracruz’s governor introduced a bill that would have outlawed such postings for “disturbing the public tranquility.” The bill was later dropped and the Twitter users released.

Gang sends message with blogger beheading
By Dudley Althaus, Houston Chronicle, 10 November 2011 – (Full Article) – last access 12 November 2011

Anonymous – Operation Zetas Hunt
TheAnonMessage, Youtube, posted 7 November 2011 – (Video) – last access 12 November 2011

‘Hackers’ threaten Mexican drug cartel in YouTube film
BBC News Technology, 31 Ocotber 2011 – (Full Article) – last access 12 November 2011

Anonymous Veracruz message to ZETA – English Mirror
lesleyblooddotcom, Youtube, posted 29 October 2011. – (English Translated Video) – last access 12 November 2011


Measuring the black web

Current article in The Economist, discusses a paper published (and previously mentioned on CFL): Click Trajectories: End-to-End Analysis of the Spam Value Chain (PDF)

Snippets of the Economist article “.. well-worn assertion is that cybercrime revenues exceed those from the global trade in illegal drugs..

In the absence of figures from the practitioners, experts tend to fall back on surveys of victims, often compiled by firms that sell security software..

Few cybercrime surveys cite the methodology they used..

Stefan Savage, Mr Kanich’s PhD supervisor, says that the security industry sometimes plays “fast and loose” with the numbers, because it has an interest in “telling people that the sky is falling”..

in the grand scheme of criminal threats, hacker kingpins do not appear to be on a par with Colombian drug lords..”

Measuring the black web
Cybercrime, The Economist, 15 October 2011 (Print Article) – (Full Online Article) – last access 14 October 2011

I beg the question, a definition of the “Black web” ?


Securing Freedom, What Tactics Should and Currently are Being Used to Combat Criminal Exploitation of the Internet, and is it Legal or Proportionate ?

A few recent broadcasts not too be missed..

Stephen Grey investigates the use of computer hacking by the police and security agencies to combat criminal exploitation of the internet and asks if it is legal.

“.. RIPA .. range of surveillance powers.. unspecified hardware/software, keyloggers..

software installed on suspect computers could be considered breaking section 3 of Computer Misuse Act, by altering data..

lack of clarity from authorities, Article 8 Human Rights Act, scope of states power must be disclosed and made clear what authorities will or won’t use ..

William Hague, who speaks for the government on computer security issues, said: “Any export of goods that could be used for internal repression is something we would want to stop” .. He also admitted the law governing software exports was a grey area ..”

UK firm denies ‘cyber-spy’ deal with Egypt
Stephen Grey, File on 4, BBC Radio 4, 20 September 2011 – (Full Broadcast) – last access 23 September 2011


Excellently delivered by Eliza, offering public insight into reasons behind securing freedom and perceived hypocrisy.

Her second Reith lecture of 2011, the former director-general of the British Security Service (MI5), Eliza Manningham-Buller, discusses policy priorities since 9/11. She reflects on the Arab Spring, and argues that the West’s support of authoritarian regimes did, to some extent, fuel the growth of al-Qaeda.

The Reith Lectures – Securing Freedom: 2011 : Freedom
Eliza Manningham-Buller, BBC Radio 4, 20 September 2011 – (Full Broadcast) – last access 23 September 2011

Her first and the previous Reith Lecture:

The Reith Lectures – Securing Freedom: 2011 : Security
Eliza Manningham-Buller, BBC Radio 4, 13 September 2011 – (Full Broadcast) – last access 23 September 2011


New CESG initiative builds on IISP Skills Framework in drive for greater professionalism in Information Assurance

“.. As part of the UK Government’s investment in cyber security, a consortium comprising the IISP (Institute of Information Security Professionals), CREST (Council for Registered Ethical Security Testers) and Royal Holloway’s Information Security Group (ISG) has been appointed by CESG to provide certification for UK Government Information Assurance (IA) professionals. The consortium has been awarded a licence to issue the CESG Certified Professional Mark based on the IISP Skills Framework, as part of a certification scheme driven by CESG, the IA arm of GCHQ ..

step forward in professionalising key Information Assurance roles needed by the public sector. It is also an important development along the path of securing the UK against cyber attack and protecting government and individuals’ data. CESG looks forward to continuing close co-operation with the IISP, CREST and Royal Holloway in delivering this IA Certification Service ..”

New CESG initiative builds on IISP Skills Framework in drive for greater professionalism in Information Assurance
PR-Inside, 22 September 2011 – last access 23 September 2011 – (Full article)

New CESG initiative builds on IISP Skills Framework
Forensic Focus, 22 September 2011 – last access 23 September 2011 – (Full article)


Some Current Law addressing the Distribution and Creation of Malware and Viruses

“.. In the UK, the introduction of malware is covered by section 3 of the Computer Misuse Act [2]. The Act states that a crime is committed if a person “does any act which causes an unauthorized modification of the contents of any computer” and the perpetrator intends to “cause a modification of the contents of any computer” which may “impair the operation of any computer”, “prevent or hinder access to any program or data held in any computer” or “impair the operation of any such program or the reliability of any such data” ..

Malware is generally distributed unintentionally subsequent to its initial creation. Thus an ICP or an ISP would not be found criminally liable under either the Computer Fraud and Abuse Act or the Computer Misuse Act for most cases of dissemination ..”

What the Law Says about Distributing a Virus or Malware
Craig S Wright, InfoSec Island, 20 September 2011 – last access 22 September 2011 – (Full article)


“.. The Japanese parliament has quietly passed legislation to make the creation or distribution of a virus or similar malware a criminal offense ..

the distribution of a virus created, for example, in the US, in Japan by a Japanese citizen, would come within the scope of the criminal law ..

what happens if the malware distribution takes place without the knowledge of the user of the computer, such as when a botnet is involved..

Legislators in Japan are less concerned about the semantics, however, as they say this is the country’s response to support the International Convention on Cybercrime, a treaty ratified by more than 30 countries and which mandates international co-operation in investigating crimes in cyberspace ..”

Creating or distributing malware in Japan is now a crime
InfoSecurity Magazine, 20 June 2011 – last access 22 September 2011 – (Full article)


Phishing Web-Based Email Services with HTML 5

Just came across a research paper from May 2011, thanks to Joe Sylve for the work.

“.. overview of a new technique that could be used for phishing web-based email services such as Google’s Gmail and Yahoo’s Mail ..”

Phishing Web-Based Email Services with HTML 5
Joe Sylve
Department of Computer Science, University of New Orleans, 11 May 2011 – last access 22 September 2011 – (Full article)


Hacked Dutch security firm, DigiNotar has filed for voluntary bankruptcy and the SSL certificate debacle

Hacked Dutch security firm, DigiNotar has filed for voluntary bankruptcy..

“Hacked security firm closes its doors”
BBC News UK, 20 September 2011 – last access 21 September 2011 – ( Full Article )

“SSL certificate debacle includes CIA, MI6, Mossad and Tor”
Chester Wisniewski, NakedSecurity, 5 September 2011 – last access 21 September 2011 – ( Full Article )


Skype for iPhone and iPod Touch: iOS Vulnerability allows comprimising the device address on reciveing a text message, just add JavaScript

Exploit in Skype on an iPhone or iPod touch, allows comprimise of your device’s address book simply by the attacker sending you a chat message. When the exploit code in the message is run, the victim’s iPhone will automatically make a new connection to a server, grabbing a larger payload, to execute and upload the iPhones entire address book file to the server.

“.. Type some JavaScript commands into the user name of a Skype account, use it to send a chat message to someone using the latest version of Skype on an iPhone or iPod touch, and load a small program onto a webserver. Within minutes, you’ll have a fully-searchable copy of the victim’s address book.

.. failure by Skype to sanitize potentially dangerous JavaScript commands from the text that gets sent in chat messages ..

It’s already been 48 hours since this vulnerability was first documented, and the vulnerable app is still available in the iTunes Store. It will be interesting to see how long it takes Apple and Skype to close the gaping hole ..”

“Skype for iPhone makes stealing address books a snap”
Dan Goodin, Malware, The Register UK, 20 September 2011 – last access 21 September 2011 – ( Full Article )


Review of Disclosure in Criminal Proceedings (Judiciary of England and Wales)

” This is a review (“the review”) conducted at the request of and for the Lord Chief Justice, prompted by concerns as to the operation of the disclosure regime contained in the Criminal Procedure and Investigations Act 1996, as amended (“the CPIA”). ”

Review of Disclosure in Criminal Proceedings (Judiciary of England and Wales)
The Rt Hon. Lord Justice Gross
September 2011

Full Report:


The UK Forensic Science Society: Launch of the Digital Forensic Component Standards

The Society has announced the extension of its accreditation scheme to include two new Component Standards to address digital forensics:

  • Computer Network Evidence Recovery and Analysis
  • Digital Evidence Analysis Recovery and Preservation

These two new Standards plus the Core Standard of Interpretation, Evaluation and Presentation of Evidence (IEPE) make up the new Digital Component Standards.

Launch event in the afternoon on 19th October 2011:


Digital Forensics – ISO 27001, ISO 17025, ISO 17020 – Compliance, Accreditation and Best Practice

The United Kingdom Accreditation Service (UKAS) accredits against ISO 17025 and ISO 17020 and this is seen as an integral part of the quality framework and an expectation for those supplying forensic science services.

ISO 17025 can be applied to accredit any general laboratory and ASCLD-LAB, special purpose forensic laboratories.

Digital forensics is also key in implementing and maintaining an effective information security management system (ISMS) as specified by the ISO27001.

Control A.13.2.3 of the ISO 27001 Standard requires: in the event of a security incident any evidence presented in a criminal or civil action against an individual or company must fully conform to all relevant legislation. While this requirement is fairly obvious, it is crucial to the success of the legal process that the digital evidence is collected as accurately and reliably as possible.

The best practice as defined in clause 13.2.3 of the ISO 27002 Code of Practice (not a management standard, only best practice, cannot be accredited) recommends the preparation of an investigation procedure which includes the forensic collection of digital evidence together with the originals of all documents and witness details.

All such plans are major contributors to ensuring conformance to Clause 7.3 of the ISO 27001 Standard on preventative action which is of course essential to the maintenance of the ISMS continual process improvement.


Report of digital forensic standards, processes and accuracy measurement

Results from a UK based academic survey on Digital Investigation Process and Accuracy, conducted in an attempt to determine the current state of digital investigations, the process of examination (examination phases), and how those examinations are being verified as accurate.

“2010 report of digital forensic standards, processes and accuracy measurement”
Joshua Isaac James, Pavel Gladyshev, Centre for Cybercrime Investigation, University College Dublin, 21 July 2011 – last access 23 July 2011 – ( Full Article )


Forging memory, a new development in Malware Rootkits

Apart from Rootkits modifying and hiding; files, registries, processes.. from detection software, some often typically modify memory. Anti-rootkit tools inspect memory areas in attempts to identify modifications and flag.

A particular rootkit also modifies a memory location to prevent actual disk access by detection software. This technique is not new, however it is the first found in the Wild and being adopted by Malware authors.

“.. a new rootkit appeared that at first glance seemed more similar to initial variants of TDL3 than to the updated TDL4 variants we have seen this year. Like TDL3, it also parasitically infected a driver by inserting code in the resource directory of the PE file. In this case the name of the file it infected was hard-coded to volsnap.sys. Also similar to the early variants of TDL3, this rootkit also hooked some pointers in the dispatch table (IRP hook) of the driver below disk on the device stack of the hard disk.

But it was very interesting to see some of the anti-rootkit tools not showing the dispatch table hooks that are usually pretty straightforward to identify. Also this malware would not allow an external debugger (WinDbg) to break.

The reason for hooks not being reported was that the memory being read by the tools was not the actual memory ..”

“Memory Forging Attempt by a Rootkit”
Rachit Mathur, McAfee Blog Center, 21 April 2011 – last access 8 June 2011 – ( Full Article )


Going After the Money, Tracing Spammers with an End to End Analysis of the Spam Value Chain

Interesting publication of a paper at the IEEE Symposium on Security and Privacy 2011 (California). The research (involving 15 authors) investigated purchasing spam products and amongst other things, focused on tracing the payments.

” .. The paper performs holistic analysis that quantifies the full set of resources employed to monetize spam email—including naming, hosting, payment and fulfillment—using extensive measurements of three months of diverse spam data, broad crawling of naming and hosting infrastructures, and over 100 purchases from spam-advertised sites. We relate these resources to the organizations who administer them and then use this data to characterize the relative prospects for defensive interventions at each link in the spam value chain. In particular, we provide the first strong evidence of payment bottlenecks in the spam value chain; 95% of spam-advertised pharmaceutical, replica and software products are monetized using merchant services from just a handful of banks ..

the so-called “spam value chain” involves; botnets, domain registration, name server provisioning, hosting services, and proxy services ..

spammers must also process orders, which requires “payment processing, merchant bank accounts, customer service, and fulfillment.” ..

95% of spam-advertised pharmaceutical, replica, and software products are monetized using merchant services from just a handful of banks ..

13 banks handling 95% of the 76 orders for which they received transaction information .. just three banks handled the majority of transactions: Azerigazbank in Azerbaijan, DnB NOR in Latvia (although the bank is headquartered in Norway), and St. Kitts-Nevis-Anguilla National Bank in the Caribbean ..

all software orders and 85% of pharmaceutical orders used the correct Visa “Merchant Category Code,” which identifies what’s been sold. “A key reason for this may be the substantial fines imposed by Visa on acquirers when miscoded merchant accounts are discovered ‘laundering’ high-risk goods,” ..

orders were fulfilled from 13 suppliers in four countries: the United States–Massachusetts, Utah, and Washington, all for herbal purchases, as well as West Virginia for pharmaceuticals–plus India, China, and New Zealand. Most pharmaceuticals came from India, while most herbal products came from the United States, likely due to weak regulations ..”

“3 Banks Service Majority Of Spam-Driven Sales”
Mathew J. Schwartz, InformationWeek 25 May 2011 – last access 8 June 2011 – ( Full Article )

“Click Trajectories: End-to-End Analysis of the Spam Value Chain”
Kirill Levchenko et al., IEEE Symposium on Security and Privacy 2011, Oakland, California, 24 May 2011 – last access 8 June 2011 – ( Full Journal )


Who’s Keeping an Eye on Strauss-Kahn, “Prevent Flight” Forensic Services ?

Interesting article in Time regarding IMF chief Dominique Strauss-Kahn who is currently on Bail in New York. Is this to be a new development in Digital Forensic services ?

“..IMF chief Dominique Strauss-Kahn on bail was moved from temporary lodgings on lower Broadway to a large townhouse in Tribeca. Keeping watch over him will be multiple “armed monitors” courtesy of security firm Stroz Friedberg.

– snip –

terms of Strauss-Kahn’s bail order, filed with the New York State Supreme Court on May 20, DSK is “confined to home detention 24 hours per day at an address in Manhattan.” He is permitted to leave the home only for court appearances, medical and legal appointments and religious observances, and the court must have six hours notice.

The people responsible for ensuring Strauss-Kahn’s compliance work for Stroz Friedberg LLC, a cyber security and computer forensics firm. According to “in-home detention protocols” prepared by the company, Stroz Friedberg employees will monitor Strauss-Kahn 24 hours a day, maintain a log of all visitors, search all visitors for weapon and have sole discretion to limit the type and number of visitors to DSK’s residence, along with any other measures that “may be required to prevent flight.”

– snip –

Stroz Friedberg previously kept watch over Bernard Madoff (2009). Ed Stroz made sure to emphasize this is not the firm’s “core expertise,” but rather a sideline business that coincidentally presented itself.

– snip –

Although the Strauss-Kahn case has kept them in the news, Stroz sees digital and cyber security as the most important growth area for the firm in the coming years.

– snip –

Stroz says, “but we’re kind of evolving into the firm you have to have if you’re a serious industry out there. Who isn’t at risk for litigation, regulatory scrutiny, trade secret theft, insider problems? And when that happens, that is not a normal business issue. And you don’t get good at this unless you’re kind of a jungle cat out there seeing things.”


“Who’s Keeping an Eye on Strauss-Kahn?”
Nate Rawlings, TIME, 26 May 2011,8599,2074075,00.html – last access 27 May 2011 – ( Full Article )


Covert hard drive fragmentation – Steganography Ad-dress

Snippets of recent article in the New Scientist..

“.. hide data on a hard drive without using encryption. Instead of using a cipher to scramble text, the method involves manipulating the location of data fragments.

– snip –

..possible to encode a 20-megabyte message on a 160-gigabyte portable hard drive. It hides data so well that its existence would be “unreasonably complex” to detect

– snip –

Encryption .. shows someone might have something to hide..

– snip –

steganography, hiding data in plain sight.. But these techniques are well known and easily detected, says Khan. So, with colleagues at the National University of Science and Technology in Islamabad, Pakistan, he has developed an alternative.

Their technique exploits the way hard drives store file data in numerous small chunks, called clusters. The operating system stores these clusters all over the disc, wherever there is free space between fragments of other files.

Khan and his colleagues have written software that ensures clusters of a file, rather than being positioned at the whim of the disc drive controller chip, as is usually the case, are positioned according to a code. All the person at the other end needs to know is which file’s cluster positions have been encoded.

The code depends on whether sequential clusters in a file are situated adjacent to each other on the hard disc or not. If they are adjacent, this corresponds to a binary 1 in the secret message. If sequential clusters are stored in different places on the disc, this encodes a binary 0 (Computers and Security, DOI: 10.1016/j.cose.2010.10.005). The recipient then uses the same software to tell them the file’s cluster positions, and hence the message. The researchers intend to make their software open source.

“An investigator can’t tell the cluster fragmentation pattern is intentional- it looks like what you’d get after addition and deletion of files over time,” says Khan. Tests show the technique works, as long as none of the files on the hard disc are modified before handover.

“The real strength of this technique is that even a completely full drive can still have secret data added to it – simply by rearranging the clusters,” adds Khan.

Others are impressed with the technique but see limitations.

“This type of steganography could be used by spies, police or informants – but the risk is that it requires direct contact to physically exchange the USB device containing the secret data,” says Wojciech Mazurcyk, a steganographer at Warsaw University of Technology in Poland. “So it lacks the flexibility of internet steganography. Once you embed the secret data on the disk it is not easy to modify it.”

– snip –

“It’s how security vulnerability disclosure works,” says Khan. “We have identified that this is possible. Now security agencies can devise techniques to detect it.” He adds that his team have had no issues with either US or Pakistani security agencies over their development of this secret medium – despite current political tensions between the two nations.

“The use of steganographic techniques like this is likely to increase,” says Fred Piper, director of information security at Royal Holloway, University of London. “Eavesdroppers can learn much from the fact that somebody is encrypting a message.”


“Covert hard drive fragmentation embeds a spy’s secrets”
Paul Marks, New, 21 April 2011 – last access 29 April 2011 – ( Full Article )


Operation Ore suspect Jeremy Clifford awarded damages after 8 years of battle

“.. A man wrongly accused in Britain’s largest ever child pornography investigation has won damages in the High Court after an eight-year legal battle.

Jeremy Clifford, 51, from Watford, was arrested and falsely charged in 2003 as part of Operation Ore. His credit card details had been found among those of thousands of British people on a list maintained by Landslide, a commercial provider of illegal pornography based in the US.

Hertfordshire Constabulary seized a computer that had belonged to Mr Clifford and discovered 10 illegal thumbnail images in its temporary internet files folder.

However, a senior High Court judge found on Friday that the arresting officer had been told by a computer forensics expert that the images were not sufficient evidence to charge.

“The images could have been received unsolicited by and even without the knowledge of the operator of the computer, for example as ‘pop-ups’,” said Mr Justice Mackay.

Despite this, the officer, Detective Constable Brian Hopkins, pressed three charges of possession of indecent images of children. Mr Justice Mackay said he cut a “rather pathetic figure” in the witness box, having initially claimed he could not give evidence because of a psychiatric condition.

– snip –

The finding was based on evidence the court heard from an internal investigation launched after Mr Clifford was formally cleared of all the allegations before trial. It found that Hertfordshire Constabulary’s forensics expert, George Fouhey, had advised against pressing charges ..”

“Judge hits police with massive bill over false Operation Ore charges”
Court correspondent, Policing, The Register UK, 4 April 2011 – last access 5 April 2011 – ( Full Article )


Solid-State Disk Behavior Underlying Digital Forensics

“.. SSDs are different. Writing a virgin cell merely requires a write cycle. Rewriting a cell requires two cycles: an erase cycle and a write cycle. The erase cycle is governed by the physics, and takes time. Performance is improved by “pre-clearing” no longer needed cells (e.g., free space on the disk) during otherwise unused device cycles.

– snip –

A recent paper from Graeme Bell and Richard Boddington of Murdoch University in Perth, Solid State Drives: The Beginning of the End for Current Practices of Digital Forensic Recovery, documented several consequences of this implementation approach with respect to standard best practices for digital forensic acquisitions. In short, the autonomous pre-clearing function rendered free space unrecoverable on short order from the time that the drive was powered-on.

– snip –

As noted by Bell and Boddington, the automatic nature of the resetting function on space determined by the controller to be unallocated has several implications for standard forensics procedures:

data in unallocated space will quickly disappear on such a device (Quick format will actually cause the drive contents to be erased on short order)
the data recorded by a forensic acquisition with a write-blocker will be inconsistent with a subsequent acquisition until the reset process has completed. The cryptographic checksums (e.g., MD-5, SHA-1) generated on successive acquisitions will thus be inconsistent ..”

“Solid-State Disk Behavior Underlying Digital Forensics”
Robert Gezelter, , 7 March 2011 – last access 1 April 2011 – ( Full Article )

“Solid State Drives: The Beginning of the End for Current Practice in Digital Forensic Recovery?”
Graeme B. Bell and Richard Boddington, 2010
Journal of Digital Forensics, Security and Law, Vol. 5(3)


StarLogger Keylogger Found on New Samsung Laptops

Keylogger software discovered by Mohamed Hassan on two new Samsung laptops…

“.. Samsung installed a commercial keylogger on brand-new laptops to monitor customer usage, the company admitted after a user exposed the practice in a security newsletter.

– snip –

While setting up a new Samsung R525 laptop in early February, Hassan ran a full-system scan using an unnamed “licensed commercial security software” before installing anything else. The scan found two instances of a commercial keylogger, called StarLogger, installed within the Windows directory..

– snip –

A support supervisor then confirmed that Samsung knowingly put this software on the laptop to “monitor the performance of the machine and to find out how it is being used,”


“Samsung installs keylogger on its laptop computers”
M. E. Kabay and Mohamed Hassan Mohamed Hassan, Network World – Security Strategies Alert, 30 March 2011 – last access 31 March 2011 – ( Full Article )

“Samsung responds to installation of keylogger on its laptop computers”
M. E. Kabay and Mohamed Hassan Mohamed Hassan, Network World – Security Strategies Alert, 30 March 2011 – last access 31 March 2011 – ( Full Article )

“Samsung Installs Stealthy KeyLogger on Brand-New Laptops”
Fahmida Y. Rashid, eWeek, 30 March 2011 – last access 31 March 2011 – ( Full Article )


Dell takes digital forensics mobile

“.. Dell on Thursday launched another installment of its digital forensics bundle so law enforcement can collect data faster from crime scenes.

The company took its digital forensic bundle—Spektor Forensic Intelligence software from Evidence Talks and rugged hardware—and extended it to mobile devices. The goal: Examine data at a crime scene and collect data on the fly from various storage devices ..”

Larry Dignan, ZD Net, 24 March 2011 – last access 25 March 2011 – ( Full Article )


Ways to circumvent shutdown of normal communications

“.. With a tin can, some copper wire and a few dollars’ worth of nuts, bolts and other hardware, a do-it-yourselfer can build a makeshift directional antenna. A mobile phone, souped-up with such an antenna, can talk to a network tower that is dozens of kilometres beyond its normal range (about 5km, or 3 miles).

– snip –

their existence has recently been valuable to the operation of several groups of revolutionaries in Egypt, Libya and elsewhere. To get round government shutdowns of internet and mobile-phone networks, resourceful dissidents have used such makeshift antennae to link their computers and handsets to more orthodox transmission equipment in neighbouring countries.

– snip –

Creative ideas for circumventing cyber-attacks even extend to the redesign of apparently innocent domestic equipment. Kenneth Geers, an American naval-intelligence analyst at a NATO cyberwar unit in Tallinn, Estonia, describes a curious microwave oven. Though still able to cook food, its microwaves (essentially, short radiowaves) are modulated to encode information as though it were a normal radio transmitter. Thus, things turn full circle, for the original microwave oven was based on the magnetron from a military radar. From conflict to domesticity to conflict, then, in a mere six decades ..”

“Unorthodox links to the internet”
Science and Technology, The Gaurdian UK, 17 March 2011 – last access 23 March 2011 – ( Full Article )


Reliably Erasing Data From Flash-Based Solid State Drives

Interesting paper by Wei at all.

“.. Sanitizing storage media to reliably destroy data is an essential aspect of overall data security. We have empirically measured the effectiveness of hard drive-centric sanitization techniques on flash-based SSDs. For sanitizing entire disks, built-in sanitize commands are effective when implemented correctly, and software techniques work most, but not all, of the time. We found that none of the available software techniques for sanitizing individual files were effective. To remedy this problem, we described and evaluated three simple extensions to an existing FTL that make file sanitization fast and effective. Overall, we conclude that the increased complexity of SSDs relative to hard drives requires that SSDs provide verifiable sanitization operations ..”

“Reliably Erasing Data From Flash-Based Solid State Drives”
Michael Wei, Laura M. Grupp, Frederick E. Spada, and Steven Swanson – last access 16 March 2011 – ( The Paper )

“.. In research that has important findings for banks, businesses and security buffs everywhere, scientists have found that computer files stored on solid state drives are sometimes impossible to delete using traditional disk-erasure techniques.

Even when the next-generation storage devices show that files have been deleted, as much as 75 percent of the data contained in them may still reside on the flash-based drives, according to the research, presented at the Usenix FAST 11 conference in California. In some cases, the SSDs, or sold-state drives, incorrectly indicate the files have been “securely erased” even though duplicate files remain in secondary locations.

The difficulty of reliably wiping SSDs stems from their radically different internal design. Traditional ATA and SCSI hard drives employ magnetizing materials to write contents to a physical location that’s known as the LBA, or logical block address. SSDs, by contrast, use computer chips to store data digitally and employ an FTL, or flash translation layer, to manage the contents. When data is modified, the FTL frequently writes new files to a different location and updates its map to reflect the change ..”

“Flash drives dangerously hard to purge of sensitive data”
Dan Goodin, The Register UK, 21 February 2011 – last access 16 March 2011 – ( News Article )


The Sleuth Kit v3.2.1

New version of Brian Carrier’s TSK released (version 3.2.1), 27 February 2011

“.. The Sleuth Kit and Autopsy Browser. Both are open source digital investigation tools (a.k.a. digital forensic tools) that run on Windows and Unix systems (such as Linux, OS X, Cygwin, FreeBSD, OpenBSD, and Solaris). They can be used to analyze NTFS, FAT, HFS+, Ext2, Ext3, UFS1, and UFS2 file systems and several volume system types.

The Sleuth Kit (TSK) is a C library and a collection of command line tools. Autopsy is a graphical interface to TSK. TSK can be integrated into automated forensics systems in many ways, including as a C library and by using the SQLite database that it can can create ..”

Brain Carrier, The Sleuth Kit, 27 February 2011 – last access 5 March 2011 – ( More Info / Download )


Stuxnet worm’s true origins ?

Interesting article on the possibile origins of Stuxnet… ?

“.. The worm, Stuxnet, is a Trojan horse said to have disabled Iran’s nuclear weapons program. The New York Times said late last year, “Meanwhile, the search for other clues in the Stuxnet program continues — and so do the theories about its origins.” The Times updated their take on January 15, 2011 calling Stuxnet, “the most sophisticated cyberweapon ever deployed…experts who have picked apart the computer worm describe it as far more complex — and ingenious — than anything they had imagined when it began circulating around the world, unexplained, in mid-2009 ..

– snip –

No one is looking back to a time in the mid-70s, when an obscure program called Promis first reared its head. Promis, according to sources, is at the root of Stuxnet. Promis was a computer program that promised to help US prosecutors track criminals and legal maneuverings through the system, “Prosecutor’s Management Information System.” The people-tracking software was later marketed by a firm named Inslaw, under the auspices of William Hamilton, a former NSA officer who still markets a version of the product today.

– snip –

By the late 1980s, Promis programs had been sold to Britain, Australia, South Korea and Canada. Allies harmless enough, right? But then up next was the KGB. There are multiple claims as to who sold Promis to the Russians. Several, including a source of mine, said it was newspaper mogul Robert Maxwell in assistance to Israel. Another acquaintance, former double agent David Dastych (Polish intell working for the CIA during the Cold War) said that an American intelligence officer admitted to him, “Yes, we gave Promis to the Russians and Chinese to back door their intell. Worked like a charm.” Both claims may overlap. In fact, the KGB is said to have used Promis for over 15 years. At first, there was nothing to suspect since malicious malware had not really been coined. Few back then understood the power of the computer, and so the Trojan horse entered the realms of international espionage, the microscopic spy ..”

Stuxnet worm’s true origins are exposed
PJ Wilcox, /, 22 February 2011 – last access 3 March 2011 – ( Full Article )


Further to this article:

“.. So we start with a Windows dropper. The payload goes onto the gray box, damages the centrifuge, and the Iranian nuclear program is delayed — mission accomplished. That’s easy, huh? I want to tell you how we found that out. When we started our research on Stuxnet six months ago, it was completely unknown what the purpose of this thing was. The only thing that was known is very, very complex on the Windows part, the dropper part, used multiple zero-day vulnerabilities. And it seemed to want to do something with these gray boxes, these real-time control systems ..

this is a directed attack. It’s completely directed. The dropper is prowling actively on the gray box if a specific configuration is found, and even if the actual program that it’s trying to infect is actually running on that target. And if not, Stuxnet does nothing ..

And if you have heard that the dropper of Stuxnet is complex and high-tech, let me tell you this: the payload is rocket science. It’s way above everything that we have ever seen before. Here you see a sample of this actual attack code. We are talking about — round about 15,000 lines of code. Looks pretty much like old-style assembly language ..

The big digital warhead — we had a shot at this by looking very closely at data and data structures. So for example, the number 164 really stands out in that code; you can’t overlook it. I started to research scientific literature on how these centrifuges are actually built in Natanz and found they are structured in what is called a cascade, and each cascade holds 164 centrifuges. So that made sense, it was a match ..

And it even got better. These centrifuges in Iran are subdivided into 15, what is called, stages. And guess what we found in the attack code? An almost identical structure ..

This attack is generic. It doesn’t have anything to do, in specifics, with centrifuges, with uranium enrichment. So it would work as well, for example, in a power plant or in an automobile factory. It is generic. And you don’t have — as an attacker — you don’t have to deliver this payload by a USB stick, as we saw it in the case of Stuxnet. You could also use conventional worm technology for spreading. Just spread it as wide as possible. And if you do that, what you end up with is a cyber weapon of mass destruction. That’s the consequence that we have to face. So unfortunately, the biggest number of targets for such attacks are not in the Middle East. They’re in the United States and Europe and in Japan. So all of the green areas, these are your target-rich environments ..

My opinion is that the Mossad is involved, but that the leading force is not Israel. So the leading force behind that is the cyber superpower. There is only one, and that’s the United States — fortunately, fortunately. Because otherwise, our problems would even be bigger ..”

Cracking Stuxnet, a 21st-century cyber weapon
Ralph Langner, TED2011, March 2011 – Full Talk


EnCase EnScript to export MFT slack

Useful EnCase EnScript for extracting contents of Slack space in the MFT from Lance Mueller.

“.. MFT slack, that is, the data that may exist between the end of a logical MFT record and the end of the physical MFT record. A typical MFT record can be anywhere between 400 to 700 bytes in length, but the MFT allocates 1024 bytes for each record. This can cause data to be left from previous records, the same way data remains in file slack at the end of a cluster.

– snip –

The EnScript will process every MFT found in the case. The EnScript only exports data in the MFT record slack area with an ASCII value between 0x20 (space) and 0x7E (tilde). A folder is created in the case default export folder named “MFT Slack” and a file with a record number is created for every MFT record that contains slack. The reason this method was used, was so if you review the exported data and find something of interest, you can quickly map it back to the exact MFT record where it came from. If a MFT record has no data in slack, then no export file is created for that record. ..”

Lance Mueller, ForensicKB, 21 February 2011 – last access 27 February 2011 – ( Full Article and to download the EnScript )


Time Stamps on NTFS, examination of the MFT

Interesting article on examining Time Stamps (defeating Timestomp? Filetime ?), in terms of highlighting differences between SI and FN attributes. In this article a Perl script is refered to (previously written by Harlan Carvey) to output results…

“.. Chronological data about the files on a Windows system are stored in something called the Master File Table or $MFT ..

– snip –

there are two places in the MFT that store this chronological data. One is the $Standard_Information ($S_I) attribute, and the other is the $File_Name ($F_N) attribute ..”

Cepogue, The Digital Standard, 23 February 2011 – last access 26 February 2011 – ( Full Article )


U.S. – China: Cyber War Scenario in the Eyes of a Chinese Student

Interesting article in the Atlantic from the perception of a Chinese student…

“.. Stuxnet is a computer worm that gained notoriety in 2010 as it took down about one fifty of Iran’s nuclear centrifuges. The New York Times describes it as may be “the most sophisticated cyberweapon ever deployed”. Many experts believe that it was developed by either the United States or Israel. And the official Chinese media asserted that Stuxnet is a joint U.S.-Israel project. (Interestingly, to lend itself credibility, one news report from the leading Chinese news agency is entitled “New York Times Confirms U.S.-Israel Development of Computer Worm Targeted at Iran”.)

Does the United States’ (possible) active use of cyber weapons legitimize their use by other countries? And more pertinent to my concern, is China’s insistence on the United States’ involvement in Stuxnet a sign of Beijing’s intention to capitalize on the legitimacy conferred by Stuxnet?

– snip –

Cyber attacks from China have been going on for more than a decade. The high-profile Titan Rain and Operation Aurora made it clear that networks belonging to the U.S. government, the defense industry, and other companies have suffered large-scale, sustained and highly sophisticated cyber attacks from computers located in China, though Beijing has denied any involvement. As with Stuxnet, the nature of cyber attacks makes it hard to trace to their origin, and even if an origin is found, there is no international legal authority that could hold the state responsible for the cyber activities of its individuals. The states can plead “plausible deniability” which is what makes it possible for many cyber attackers to operate with impunity, as seen in the case of Russian attacks on Estonia.

Regarding the China threat, many American security experts worry that in a dispute over Taiwan, China would disable and exploit U.S. computer networks. But some, like James Mulvenon, Deputy Director of Defense Group and a specialist on the Chinese military, go further to say that he observed a potential expansion of the People’s Liberation Army’s (PLA) intrusion set. He argues that the list of targets for both computer network exploitation and attack activities would encompass a wide range of countries and regions, including the East and South China Seas.

Moreover, experts point to China’s systematic training of its cyber warriors and its recruitment strategy. The cyber warriors are firstly trained in military institutions such as the PLA National University of Defense Technology, which built the “Tianhe 1A” supercomputer that surpassed U.S.’ Cray XT5 Jaguar as the world’s fastest computer by a large margin at the end of last year. Second, the PLA has included computer network operations (CNOs) in its military exercises since 2005 and aims at disabling target networks with its first attacks, according to Dr. Zheng Dacheng, a Taiwanese expert on the Chinese military.

In addition to trained cyber warriors, China can fully utilize the talents of its civilians who require the kind of security clearance for which only about 20% of U.S. population would qualify if the same cyber missions were carried out by United States, according to Kevin G. Coleman, security technology expert at Technolytics Institute.

– snip –

China’s efforts in cyber space have mainly been internally rather than externally focused. This would support the regime’s main concern of domestic stability, rather than an intensified confrontation with a foreign entity.

Chinese citizens’ limited access to foreign websites is often seen as one of the defenses China has in a future cyber war scenario. Aside from the infamous Great Firewall, China only has nine ports through which the Chinese Internet is connected to the foreign Internet (as last reported in 2008, after which all information on this is withheld). Therefore, it is conceivable that China could cut itself off the Internet and operate a de facto Intranet. However, it also means that in the case of a large-scale outbreak of domestic instability, the government can cut its people off from the outside world (as what happened in Egypt).

If the first use is the main purpose of China’s cyber setup, then the defense effort would be severely undermined because the government and big state-owned-enterprises are whitelisted to have full and unrestricted access to foreign networks, and many big private firms use satellite or microwave connections which do not go through the state’s control mechanism, thus they will not be effectively immune from a cyber attack.

The domestically-focused use of this cyber structure actually occurred in Xinjiang after the July 2009 riots when the Internet was shut down for 10 months. In fact, The National Defense Mobilization Law, enacted in July 2010, stipulates that the state has broad authority in times of national defense mobilization and can, according to Article 63(1), take control of the telecommunication industry, the media, the information networks, and the energy and the water supply systems, among other things.

– snip –

Perhaps most importantly, however, the United States is not vulnerable because of threats from China, but because it has done a poor job of building cyber-defenses. Recall the embarrassment when the Pentagon revealed last December that live video feeds from its $4.5 million Predator drones were hijacked using $26 software downloaded from the Internet. Regardless of what China does or intends to do, if United States does not take appropriate measures to defend itself, then it would continue to be exposed to threats from various state and non-state actors.

Currently, with Cyber Command protecting the military networks and DHS protecting the rest of the government, everyone else is left on their own, and America’s critical infrastructures are not getting the best security technology this country has to offer. In China, however, cyber security has increasingly become a huge business. It has now contracted out the network security of the government and other crucial state-owned-enterprises to (semi-) private security firms: Venus Tech is responsible for the network security of the Ministry of Finance, National Grid, Civil Aviation Administration, etc.; NSFOCUS secures China Telecom, National People’s Congress, etc.; Feitian is responsible for securing Bank of China, the State Secrets Bureau, Ministry of Commerce, Sinopec, etc.; and Zhonghangjiaxin develops security systems for part of the People’s Liberation Army’s General Staff Department and Headquarter of the Armed Police ..”

Ella Chou, The Atlantic, 8 February 2011 – last access 9 February 2011 – ( Full Article )


FBI serves 40 search warrants in Anonymous crackdown – coincided with the arrests of five UK youths accused of participating in the DDoS spree

“.. FBI agents executed more than 40 search warrants on Thursday as part of an investigation into coordinated web attacks carried out by the hacking collective known as Anonymous. The search warrants coincided with the early morning arrests of five UK youths accused of participating in the DDoS spree.

Word of the crackdown first surfaced in the US four weeks ago. Metropolitan Police in the UK confirmed their investigation in mid December.

“The FBI also is reminding the public that facilitating or conducting a DDoS attack is illegal, punishable by up to 10 years in prison, as well as exposing participants to significant civil liability,” the agency said in a press release.

Thursday’s arrests were part of an international police probe carried out by law enforcement agencies throughout Europe and the US. A French official told the Associated Press that a 15-year-old suspected of masterminding the attacks was arrested in December. The unidentified teen has since been released, but his computer was confiscated.

That same month, a 16-year-old boy in the Netherlands was arrested for allegedly carrying out attacks on Visa and MasterCard after the credit card companies stopped processing payments to WikiLeaks.

Researchers have said members of Anonymous modified a piece of open-source software to create what they call the Low Orbit Ion Cannon. The tool allows large groups of online protestors to simultaneously unleash torrents of data on websites they want to bring down ..”

Dan Goodin, The Register UK, 28 January 2011 – last access 2 February 2011 – ( Full Article )


Reports of London Stock Exchange Investigating Cyber Attacks

Reports of London Stock Exchange investigating cyber attacks.. not clear if they are isolated or related incidents ? although was it an inside job, was it a bug..

” .. The British and United States stock exchanges have reportedly enlisted the help of the security services after finding out they were the victims of cyber attacks.

According to media reports, the London Stock Exchange (LSE) is investigating a terrorist cyber attack on its headquarters last year, while US officials have traced an attack on one of its exchanges to Russia.

A report from The Times said that it had been told by ‘well-placed intelligence sources’ that the London Stock Exchange was trying to find the source of the attack, while a cyber security expert is reported as saying that the threat is ‘advanced and persistent’.

The Associated Press said that officials suspect the attacks were designed to spread panic among markets and destabilise western financial institutions .. ”

SCmagazine UK, Dan Raywood, 1 February 2011 – last access 2 February 2011 – ( Full Article )

– snip –

” .. GCHQ director Iain Lobban said last year that worms have already been designed to cause significant disruption to government systems, while former White House security advisor Richard Clarke told the RSA Conference Europe that the US and UK are woefully underprepared for an attack on critical infrastructure.

Uri Rivner, head of new technologies at RSA Security speculated that the attack may have been an inside job .. ”

Phil Muncaster,, 31 January 2011 – last access 2 February 2011 – ( Full Article )


Fun and games with Windows FILETIME and how to efficiently detect timestamp alterations

Interesting article by Lance Mueller on Filestamps (NTFS and FAT).

” .. an examiner should be familiar how the time values are stored on NTFS volumes AND the need to examine these dates manually, since many of the common forensic tools do not display the dates with any precision beyond one second, when there is any suspicion of tampering .. ”

Lance Mueller, ForensicKB, 21 January 2011 – last access 23 January 2011 – ( Full Article )

Beyond C.S.I.: The Rise of Computational Forensics ?

Another fine article picked out by Bruce in the last issue of cryptogram.

Interesting story on Brandon Mayfield, in particular what happened to Mayfield. Mayfield being a Lawyer and if the Algerian hadn’t come to light, it might have proved a very interesting case. Some snippets and link to full article below:

” .. If the Shoe Print Fits

– snip –

On 6 May 2004, a Portland, Oregon, lawyer named Brandon Mayfield was arrested for his alleged involvement in the terrorist bombings of four commuter trains in Madrid. The attacks killed 191 people and injured 2000 others. But Mayfield had never been to Spain, and his passport at the time was expired. The sole evidence against him was a partial fingerprint found on a plastic bag in a van used by the bombers. The FBI’s Integrated Automated Fingerprint Identification System had identified Mayfield as a possible match, and three FBI fingerprint experts as well as an outside analyst confirmed the identification.

– snip –

The analysts knew that Mayfield had converted to Islam, was married to an Egyptian woman, and had once represented a man in a child custody case who later turned out to be part of a jihadist group. That information swayed the FBI inquiry in Mayfield’s direction.

– snip –

Spanish authorities, however, argued that the fingerprint belonged not to Mayfield but to an Algerian with a criminal record, Spanish residency, and terrorist links. They were right. It took almost three weeks from his arrest, but Mayfield was cleared of the charges and released from federal custody. The U.S. government eventually agreed to pay him US $2 million for the mistake and issued a formal apology.

– snip –

Nike Air Force 1 [sneaker] is the most often encountered at U. S. crime scenes, turning up in about 17 percent of cases.

– snip –

Pattern recognition and other computational methods can reduce the bias inherent in traditional criminal forensics

– snip –

What computational forensics—or any forensics method, really—cannot do is determine whether a suspect did or did not commit the offense. That’s a matter for a judge and jury to decide. At trial, the role of a forensics expert is to testify whether the profile drawn from the evidence matches that of the suspect or of an unrelated person.

– snip –

Among all the classical forensics methods, the committee concluded, only DNA analysis has been shown to be scientifically rigorous .. ”

Sargur N. Srihari,, December 2010 – last access 19 January 2011 – ( Full Article )


DEFT Linux 6 ready for download

DEFT 6 is based on Lubuntu with Kernel 2.6.35 (Light Ubuntu Linux) and DEFT Extra 3.0 (Windows)., 11 January 2011 – ( More Info ) – Download ISO

DEFT 6 computer and network forensic packages list:

* sleuthkit 3.2.0, collection of UNIX-based command line tools that allow you to investigate a computer
* autopsy 2.24, graphical interface to the command line digital investigation tools in The Sleuth Kit
* DFF 0.8
* dhash 2.0.1, multi hash tool
* aff lib 3.6.4, advanced forensic format
* disk utility 2.30.1, a partition manager tool
* guymager 0.5.7, a fast and most user friendly forensic imager
* dd rescue 1.14, copy data from one file or block device to another
* dcfldd, copy data from one file or block device to another with more functions
* dc3dd 7, patched version of GNU dd to include a number of features useful for computer forensics
* Xmount 0.4.4, convert on-the-fly between multiple input and output hard disk image types
* foremost 1.5.6, console program to recover files based on their headers, footers, and internal data structures
* photorec 6.11, easy carving tool
* mount manager 0.2.6, advanced and user friendly mount manager
* scalpel 1.60, carving tool
* wipe 0.21
* hex dump, combined hex and ascii dump of any file
* outguess 0.2 , a steganography tool
* ophcrack 3.3.0, Windows password recovery
* Xplico 0.6.1 DEFT edition, advanced network analyzer
* Wireshark 1.2.11, network sniffer
* ettercap 0.7.3, network sniffer
* nmap 5.21, the best network scanner
* dmraid, discover software RAID devices
* testdisk 6.11, tool to recover damaged partitions
* ghex, light gtk hex editor
* vinetto 0.6, tool to examine Thumbs.db files
* trID 2.02 DEFT edition, tool to identify file types from their binary signatures
* readpst 0.6.41, a tools to read ms-Outlook pst files
* chkrootkit, Checks for signs of rootkits on the local system
* rkhunter 1.3.4, rootkit, backdoor, sniffer and exploit scanner
* john 1.7.2, john the ripper password cracker
* catfish, file search
* galletta 1.0
* pasco 1.0
* md5sum, sha1sum, sha224sum, sha256sum, sha512sum
* md5deep, sha1deep, sha256deep
* skype log view, skype chat conversation viewer
* Xnview, viewer graphics, picture and photo files
* IE, Mozilla, Opera and Chrome cache viewer
* IE, Mozilla, Opera and Chrome history viewer
* Index.dat file analyzer
* pdfcrack, cracking tool
* fcrackzip, cracking tool
* clam, antivirus 4.15
* mc, UNIX file manager

DEFT extra 3.0: – ( More Info )


Android Forensics Application

“While security on Android phone is pretty decent, applications can (and do) share data.  We take advantage of this sharing (via ContentProviders) and extract the data for forensic purposes.”

Andrew Hoog
Open Source Android Digital Forensics Application, 1st March 2010


Eavesdropping on GSM Calls

” Speaking at the Chaos Computer Club (CCC) Congress in Berlin on Tuesday, a pair of researchers demonstrated a start-to-finish means of eavesdropping on encrypted GSM cellphone calls and text messages, using only four sub-$15 telephones as network “sniffers,” a laptop computer, and a variety of open source software. ”

Bruce Schneier, Schneier on Security, 5 January 2011 – ( Full Article )

I recommend subscribing to Bruce’s cryptogram newsletters, you can also visit his blog.


UK Forensic Science Service to be wound up

“.. The Forensic Science Service is to be wound up, the Government said today.

Crime Prevention Minister James Brokenshire said action needed to be taken as the service was making operational losses of £2 million per month and was likely to run out of money by January. The aim is that there will be “no continuing state interest in a forensics provider by March 2012”, Mr Brokenshire told MPs.

Mr Brokenshire said: “The current challenging forensics market has put the FSS back into serious financial difficulty.

“FSS is currently making operating losses of around £2 million per month. Its cash is due to run out as early as January next year. It is vital we take clear and decisive action to sort this out.”

In a written statement to MPs, he went on: “The police have advised us that their spend on external forensic suppliers will continue to fall over the next few years as forces seek to maximise efficiencies in this area. HMIC (Her Majesty’s Inspectorate of Constabulary) concur with this assessment ..”

Wesley Johnson, The Independent, 14 December 2010 – last access 15 December 2010 (Full Article )


Independent Research and Reviews of iPhone Forensic Tools

“.. This white paper is intended for forensic analysts, corporations and consumers who want to understand what personal information is stored on the iPhone and how to recover it. The research reveals the vast amount of personal information stored on Apple’s iPhone and reviews techniques and software for retrieving this information. For questions about our research or our services, please contact us.

Note: viaForensics is independent and is not compensated in any way by the makers of the software reviewed in this white paper.

1. About this white paper
2. iPhone Forensics Overview and Techniques
3. Cellebrite UFED
5. Oxygen Forensic Suite 2010 PRO
6. Micro Systemation XRY
7. Lantern
8. MacLock Pick
9. Black Bag Technology Mobilyze
10. Zdziarski Technique
11. Paraben Device Seizure
12. Mobile Sync Browser
13. CellDEK
14. EnCase Neutrino
15. iPhone Analyzer
16. Overall Rankings
17. Report Conclusions ..”

Andrew Hoog and Katie Strzempka, viaforensics, November 2010 – last access 26 November 2010 (Full Article )


Forensics: Recovering a 12-year old floppy disk with DD

“.. True story. Earlier this year I was handed a 12-year old floppy disk loaded with bad sectors and unmountable due to a missing/corrupted partition table. A lost cause? Nope. DD can still image the raw media, skipping unreadable sectors and padding the output file with zeros to keep file structures intact wherever possible.

I booted up a Helix Live CD and ran:
dcfldd if=/dev/fd0 of=floppy.img bs=4k conv=noerror,sync

After much grinding and hissing, DD finished with a fully intact 1.4MB floppy disk image. Almost made me want to scour through my old floppy collection. Almost ..”, 9 September 2009 – last access 30 September 2010 (Full Article )