Warung Bebas

Jumat, 09 Agustus 2013

Daily Blog #48: Saturday Reading 8/10/13

Hello Reader,
            It's Saturday! Hooray! The week is over and fedex pickup ends earlier today meaning you either have extra time in the lab or a some time at home. Either way, get some coffee and lets get our forensic reading going.

1. Joachim Metz has updated his volume shadow specification paper, not this week bu recently enough that I didn't read it until this week. If you are at all curious about how the volume shadow service data structures are stored then read this for what I believe to be the most detailed guide outside of whatever internal team at Microsoft developed it. In addition if you care more about the usage of volume shadow copies in your analysis and the existence of unallocated space in VSC's you should read this paper he presented which will answer questions you didn't even know you had.

2. Did you read yesterday's blog? No? Oh well we had another Forensic Lunch with David Nides, Kyle Maxwell, Joseph Shaw and the fine fellows I work with at G-C Partners. Tune in and keep up with what I think was a great hour of forensic discussion.

3. Andrea London has posted the slides for her talk at DefCon http://www.strozfriedberg.com/wp-content/uploads/2013/08/DefCon-2013.pdf tilted 'The Evidence Self Destructing Message Apps Leave Behind'. Her talk covers a wider base of these applications than I've seen covered before and it's a good read as she and Kyle O'Meara go deep into the file system internals and network traffic exchanged.

4. Lenny Zeltser posted a nice retrospective of how teaching Malware Analysis has grown, http://blog.zeltser.com/post/57795714681/teaching-malware-analysis-and-the-expanding-corpus-of. It's a nice short read and reinforced the idea that his advice remains the same 10 years later:
  • Too many variables to research without assistance
  • Ask colleagues, search Web sites, mailing lists, virus databases
  • Share your findings via personal Web sites, incidents and malware mailing lists

5. If you are doing USB device forensics and have a Windows 8 system that Woanware's USB Device Forensics application does not support yet then check out TzWork's USB Storage Parser. So far its the only tool that I have that take the multiple Windows 8 USB artifacts and combines them to a single report of activity.

6. Hal Pomeranz put out a new Command Line Kung Fu entry this week, http://blog.commandlinekungfu.com/2013/08/episode-169-move-me-maybe.html, always a good read.

7.  On an earlier Forensic Lunch you may have heard Rob Fuller talk about anti-forensic hard drive custom firmwares. Going more into that topic here is a great article about Hard Drive hacking and showing how these firmware changes are researched, implemented and performed. If you are dealing with an advanced subject you might want to be aware of these new possibilities! http://spritesmods.com/?art=hddhack

8. In this week Forensic Lunch we talked about parsing carved binary plists. For those of you looking to implement your own parsers or just try to understand the format better here are two sources. The first is the OSX code for binary plists, http://opensource.apple.com/source/CF/CF-550/CFBinaryPList.c, and a great write up on plist forensics by CCL http://www.cclgroupltd.com/images/property%20lists%20in%20digital%20forensics%20new.pdf.

That's all I have for this Saturday Reading. I hope these links are enough to get you through your day. Tomorrow is Sunday Funday and I have yet another challenge waiting for you to solve. This week we will have 'winners choice' where the winner can pick from a free ticket to PFIC or a year license to AccessData's Triage tool!

Tidur Bayi

Tidur Bayi - Tiap bayi memiliki pola tidur yang tak
sama dengan setiap bayi lainnya. Ada yang dapat tidur semalaman tanpa tbangun, ada
juga yang bangun beberapa kali karena ingin menyusu atau karna ganti popok. Kapan bayi akan mulai dapat tidur semalam tanpa terbangun pun berbeda-beda pada tiap bayi.Akan tetapi, tidur bayi nyenyak dapat Bunda usahakan dengan melakukan pembiasaan. Karena, pola

Bayi Tidur

Bayi Tidur - Beberapa bayi akan tidur dengan cukup serta lama selama hari-hari pertamanya dan hanya akan bangun sebentar karena mungkin kurang menarik untuk menyusu. Sementara bayi  lain malah terkadang sebaliknya, bangun, rewel serta harus sering disusui. Kedua bayi dengan kebiasaan tersebut adalah normal. Siklus tidur bayi sangatlah berhubungan dengan seberapakah sering ia menyusu. Setelah

Gangguan Kesehatan Wanita penyebab Sulit Hamil





Gangguan Kesehatan Wanita sangat beragam,
namun yang tentu tidak ingin dialami adalah gangguan kesehatan yang menyebabkan
seorang wanita sulit untuk mendapatkan keturunan. Berdasarkan sebuah penelitian
diketahui
bahwa sekitar 10-25%  pasangan di Amerika
Serikat tidak subur. Dan yang yang menjadi penyebab umum wanita yang tidak
subur adalah karena adanya masalah dengan ovulasi (pelepasan sel

Daily Blog #47: Forensic Lunch 8/9/13

Hello Reader,
Going to try something different today and see if I can embed our Forensic Lunch live stream in the blog!

Forensic Lunch is something we are trying to do every Friday where we talk about updates to research from around the community as well as our challenges and successes here in the G-C Lab. If all goes well you can watch the show either love or recorded in the embedded Youtube below!



Tomorrow is Saturday Reading and I have some good articles and papers to pass on and don't forget Sunday for our weekly forensic contest!
 

ZOOM UNIK::UNIK DAN UNIK Copyright © 2012 Fast Loading -- Powered by Blogger