Warung Bebas

Selasa, 02 Oktober 2012

Updates and DFIR Conferences

Hello Readers,
                        I know I've been silent, our workload and conferences have kept me quite busy. Updates for you:

Book News
Computer Forensics, A beginners guide is out to copy edit or will be soon. Looking at an early Q1 2013 release to bookstores. I've been working on this book for way to long but having a child while writing a book will do that.

Hacking Exposed, Computer Forensics Third Edition we just signed the contract for this. Look for a new edition in 2014 with a lot of new content and new sections. We really want to keep this series not only relevant but expand its scope from the US legal system to the world.

Conference News
I spoke at Derbycon this past weekend, but not on forensics. I spoke on running a successful red team, which is both my professional past as well as part of the work I do at the National Collegiate Cyber Defense Competition. People seemed to enjoy the content and here are my slides!

My derbycon slides with notes!

I'll be speaking next at BsidesDFW on November 3, 2012 on Anti Anti forensics. I won't be staying very long after as I have to catch a plane to Utah but I do plan to go to the movie screening the night before so hopefully I'll see you there!

My last planned presentation of the year is at Paraben's Forensic Innovations Conference so if you're going I hope to see you there. I'll be doing my Anti-Anti Forensics talk again but this time be doing a live demonstration of the updated tool we've been showing in the blog here. which leads me to my next update

NTFS $Logfile Parser

After a good response from our beta testers we are feeling confident in elimination of bugs in what we are getting ready to release as version 1.0. In addition we got some great fixes after testing our parser on the NIST CFReDS project's deleted file recovery test images. If you are looking to validate a new tool or test a current one the NIST CFReDS images are great and well documented as a control.

We've decided to call the parser ANJP, Advanced NTFS Journal Parser, to have a clear and distinct acronym from anything else. We plan to expand our research into Ext3 and HFS+ after this and will have AEJP and AHJP parsers released at a later date to expand what we believe is a vital piece of information missing from your examinations. There is a lot of research around Ext3/HFS+ regarding recovering deleted files from the journal, but we can't find much focus on mapping out file creations, time stamps changing or files being renamed. All things possibly unique to the interest of the DFIR community. Our plan is to expand out our research so you can take advantage of all the data available to you.

So what will be in version 1.0?
  • Identification of deleted files with full metadata, in our testing on the NIST CFReDS images we recovered all deleted file records with full metadata.
  • Identification of files being created with full metadata
  • Identification of files being renamed with metadata before and after the rename.
  • Log2timeline output

But Dave, what about all the other cool things you've mentioned? 
There is much more we can determine from the NTFS $logfile, but we've realized that understanding it isn't as simple as just reading the csv it outputs. We don't want to release a tool that becomes a source for false positives and bad testimony so we are going to do follow the Viaforensics model (thanks for thinking this up guys!). We are going to be offering a one day training class that explains NTFS, the MFT and most importantly the $logfile. That class will explain how to parse the log, the event records, the redo/undo operation codes and how to stitch those together to find the information we provide in version 1.0.

Extending beyond that we will then explain how to take the Update Sequence Arrays, timestamp changes, file id/directory ids and tie them back into the MFT, recovering resident files, identifying the approximate number of external drives changes, determining how many systems an external drive was plugged into and be able to make good, reliable conclusions from them for use in your case work.  At the end of the class you'll get a copy of the super duper version 1.0 that gives you way more information that you will be qualified to draw opinions from. There won't be a dongle or a license or any other such thing. If you decide to give a copy to someone we just hope they don't testify to its results without taking our class.

In the future as we continue our research we may be able to reduce the possibility for error in the additional evidence sources and when we will / as we do we will update the publicly released tool to include those. Until then we think everyone is best served by this model that gets the most reliable evidence in everyone's hands ASAP and giving those who want to go deeper a chance to.

I hope to have version 1.0 released in the next week or two and I'll be posting it here when I do.

If you are running a conference and want us to do the ANJP training at your event let us know, we want to get as many people as possible using this as possible! When you see what all we can determine from the $logfile we think you'll agree.

What conferences do you get the most from?
I am planning my 2013 conference schedule and I've asked twitter and I want to ask you the reader, what conferences do you get the most from? I'm planning on CEIC, PFIC and possibly blackhat but  otherwise I want to hear your suggestions! Leave a comment and lets talk.

Kata Bijak: Niat menciptakan nasib kita

Kata bijak motivasi:

Niat menciptakan nasib kita

Kata kata indah bergambar dan kata mutiara:Niat menciptakan nasib kita
Kata kata indah bergambar dan kata mutiara kehidupan : Niat menciptakan nasib kita
Kata kata bijak kehidupan,Gambar Motivasi, Kata Mutiara kehidupan, Kata kata Indah










Kata kata indah bergambar: Niat akan menciptakan Nasib Kita

"Niat adalah pondasi dasar dari sebuah Tindakan dan Kesuksesan seseorang.
Nasib seseorang dipengaruhi oleh tindakan-tindakannya,sedangkan Tindakan berawal dari niat.
Jika niat kita saja belum baik,bagaimana kita akan sukses?"

Kata kata Indah:Manusia akan mati tapi...

Kata kata indah:

Bakat tetap Abadi


Kata kata indah bergambar dan kata mutiara :Manusia akan mati tapi Bakat tetap Abadi
Kata kata indah bergambar dan kata mutiara kehidupan : Manusia akan mati tapi Bakat tetap Abadi
Kata kata bijak kehidupan,Gambar Motivasi, Kata Mutiara kehidupan, Kata kata Indah









"Jiwa dan Raga boleh saja sudah hilang,namun yang namanya bakat masih akan terus terkenang.
Seseorang musisi hebat akan selalu terkenang dengan musik-musiknya.
Seorang sutradara akan terus dikenang dengan film-filmnya"

Kata Mutiara: Kuasai Pikiran Anda

Kata mutiara:

Kuasailah Pikiran atau anda akan dikuasainya


Kata kata indah bergambar dan kata mutiara:Kuasai Pikiran
Kata kata indah bergambar dan kata mutiara kehidupan : Kuasai Pikiran Anda
Kata kata bijak kehidupan,Gambar Motivasi, Kata Mutiara kehidupan, Kata kata Indah










Kata mutiara motivasi:Kuasai Pikiran Anda

"Pikiran adalah pusat dari apa yang kita lakukan, pusat dari seseorang.
Sesorang berperilaku negatif itu karena pikirannya,seseorang berperilaku positif itu juga karena pikirannya.
Jadi,kuasailah pikiran anda agar anda selalu berperilaku positif dan sukses semakin mendekati anda"

Blood Sugar 140: Where did the 140 mg/dL threshold come from?

This post (that is going to be a series to keep post lengths manageable) has been brewing for quite a while, but I was reminded of it because Jenny Ruhl came out with a diet book recently, and appeared recently as an "expert" on Jimmy Moore's Ask the Low Carb Experts podcast.  After listening to her previous podcast with Jimmy, I had some mixed reviews.  Jenny is certainly articulate, well-read (though I disagree with many of her interpretations) on the topic, and quite a bit more moderate/measured about controlling diabetes and the efficacy of low carb.   But she also seems to view all diabetes through her own MODY eyes.  MODY (Mature Onset Diabetes of the Young) is a rare genetic form (there are actually several rare genetic forms classified as MODY) that is lumped quite often under the category of Type 1.5.  One of these days I need to address some other things on Jenny's website, as it (and her book) is one of the more definitive internet sources for diabetes info in LC circles.    Her book, Blood Sugar 101, more specifically this Amazon review , as well as this page on her website, is where I took the title of this post from.  On the website she writes:
Read more »

Tema Windows 7 TRANSFORMER DECEPTICON


Limit Komputer | Mungkin kalau kalian penggemar Transformer, pasti sudah tahu yang namanya Decepticon? ya, decepticon merupakan tokoh antagonis atau musuh bebuyutan autobot di dalam film transformer. tema ini cukup berbeda dari tema Transformer yang pernah saya bagikan beberapa bulan yang lalu, karena tema ini sudah di lengkapi fitur-fitur baru. serta memiliki tampilan keren dan menarik. berikut beberapa kelebihannya

    1. Full Glass
    2. Toolbar keren
    3. Start menu transformer
    4. Icon start menu transformer
    5. Kursor transformer
    6. Sound Pack

      Tertarik?
       Pass : zikotechnofun




      back in the day, i watched full house on friday nights while eating little caesar's square pizza (remember when the pizza was square?!)...those twins turned out much more stylish then i will ever be...
       

      ZOOM UNIK::UNIK DAN UNIK Copyright © 2012 Fast Loading -- Powered by Blogger