<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Malta Info Security - Forensics</title>
    <link>http://maltainfosec.org/</link>
    <description>Creating an Information Security community on the Maltese islands</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Mon, 28 Jul 2008 22:55:25 GMT</pubDate>

    <image>
        <url>http://maltainfosec.org/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Malta Info Security - Forensics - Creating an Information Security community on the Maltese islands</title>
        <link>http://maltainfosec.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Security LiveCD Distros</title>
    <link>http://maltainfosec.org/archives/111-Security-LiveCD-Distros.html</link>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/111-Security-LiveCD-Distros.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=111</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=111</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;!-- s9ymdb:95 --&gt;&lt;!-- s9ymdb:95 --&gt;&lt;!-- s9ymdb:95 --&gt;&lt;img width=&quot;345&quot; height=&quot;88&quot; src=&quot;http://maltainfosec.org/uploads/images/nubuntu.PNG&quot; style=&quot;border: 0px none ; padding-left: 5px; padding-right: 5px;&quot; class=&quot;serendipity_image_center&quot; /&gt;&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;&lt;br /&gt;
With over a year of inactivity, the latest alpha of &lt;a href=&quot;http://nubuntu.org/&quot; target=&quot;_blank&quot;&gt;nUbuntu 8.04&lt;/a&gt; Security LiveCD has finally surfaced.&lt;br /&gt;
All of the latest security and penetration tools are included to make this you’re primary pentesting livecd.&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://securitydistro.com/gallery/104/nUbuntu-804-Alpha-Screenshots.php&quot;&gt;View Screenshots&lt;/a&gt;&lt;br /&gt;
&lt;a target=&quot;_blank&quot; href=&quot;http://nubuntu.org/downloads/click.php?id=4&quot;&gt;Direct Download&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;More info on the 10 best security Live CD Distros (Pen-test, Forensics &amp;amp; Recover) &lt;a target=&quot;_blank&quot; href=&quot;http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/&quot;&gt;here&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 28 Jul 2008 15:41:33 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/111-guid.html</guid>
    
</item>
<item>
    <title>Forensic memory dumpers for Windows</title>
    <link>http://maltainfosec.org/archives/108-Forensic-memory-dumpers-for-Windows.html</link>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/108-Forensic-memory-dumpers-for-Windows.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=108</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=108</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;Couple of interesting tools that seem to have been released recently:&lt;/p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.mantech.com/msma/MDD.asp&quot;&gt; ManTech Memory DD&lt;/a&gt; ManTech Memory DD captures a record of physical, or random access memory which is lost when the computer is shutdown. Released at no charge under the GPL license for government and private use, ManTech’s Memory DD (MDD) is capable of acquiring memory images from the following Microsoft® products: Windows® 2000, Windows Server 2003, Windows XP®, Windows Vista®, and Windows Server 2008.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;ManTech’s Memory DD 1.0 acquires a forensic image of physical memory and stores it as a raw binary file. To help verify data integrity and aid in the preservation of the evidence, the information captured by ManTech Memory DD is checked by the Message-Digest algorithm 5 (MD5), the common Internet standard used in security applications. The binary file can then be analyzed using external tools to identify items of interest to the examiner... can be downloaded &lt;a target=&quot;_blank&quot; href=&quot;https://sourceforge.net/projects/mdd/&quot;&gt;here&lt;/a&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blogs.technet.com/robert_hensing/archive/2008/07/03/memory-dumpers-for-windows.aspx&quot; target=&quot;_blank&quot; title=&quot;Source&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.msuiche.net/2008/06/14/capture-memory-under-win2k3-or-vista-with-win32dd/&quot;&gt;Suiche - of &#039;Sandman&#039; fame released a memory dumping tool&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The main difference between ManTech tool and win32dd, is that win32dd is mainly a kernel mode application — then it avoids to use user-land API to write to an output file, everything is done with native functions. Thus, it means a faster dumping… This point isn’t negligible when you have one million page to dump in one single.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blogs.technet.com/robert_hensing/archive/2008/07/03/memory-dumpers-for-windows.aspx&quot; target=&quot;_blank&quot; title=&quot;Source&quot;&gt;Source1&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://blog.layeredsec.com/2008/06/forensics-image-of-windows-memory.html&quot; target=&quot;_blank&quot;&gt;Source2&lt;/a&gt;&lt;a href=&quot;http://blogs.technet.com/robert_hensing/archive/2008/07/03/memory-dumpers-for-windows.aspx&quot; target=&quot;_blank&quot; title=&quot;Source&quot;&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 25 Jul 2008 09:33:14 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/108-guid.html</guid>
    
</item>
<item>
    <title>Recovering passwords from RAM</title>
    <link>http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html</link>
            <category>Articles</category>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=92</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=92</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    A joint group of people from &lt;a href=&quot;http://citp.princeton.edu/memory/&quot; target=&quot;_blank&quot;&gt;Princeton&lt;/a&gt; have recently managed to prove the fact that RAM chips, when cooled to a very low temperature, can continue to retain the contents of RAM for up to several minutes after they have been physically removed from a computer. &lt;br /&gt;
&lt;br /&gt;
The group, then built their own tools and programs to read off the contents of the memory after the computers were rebooted - proving that disk encryption technologies (such as Truecrypt for instance) can be defied. This is demonstrated in a video posted on youtube (see extended body of article)&lt;br /&gt;
&lt;br /&gt;
The concept can also be also easily demonstrated following a simple experiment outlined on the groups page &lt;a href=&quot;http://citp.princeton.edu/memory/exp/&quot; &gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Q. What can users do to protect themselves?&lt;br /&gt;
A. The most effective way for users to protect themselves is to fully shut down their computers several minutes before any situation in which the computers’ physical security could be compromised. On most systems, locking the screen or switching to “suspend” or “hibernate” mode does not provide adequate protection. (Exceptions exist; some systems may not be protected even when powered off. Check with the developer of your disk encryption software for further guidance.)&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Following up this, according to Ivan Krstic, director of security architecture at OLPC (One Laptop per Child) - the recently announced MacBook Air is resistant to what is now known as the &quot;Cold-Boot Encyption Attack&quot; simply because the machines DDR2 RAM (2gb) is soldered on and cannot be physically removed. In addition, if Apple release an EFI firmware upgrade to zero the contents of the RAM at every boot, then the MacBook  &lt;blockquote&gt;&quot;...would become one of the only—if not the only—mainstream laptop featuring full-disk encryption that&#039;s highly-resistant to the troublesome Princeton attack.&quot;&lt;/blockquote&gt; &lt;br /&gt;
&lt;br /&gt;
(&lt;a href=&quot;http://www.eweek.com/c/a/Security/MacBook-Air-Resistant-to-ColdBoot-Encryption-Attack/&quot; &gt;source&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
Microsoft also reacts to this vis-a-vis their BitLocker technology in Vista. &lt;a href=&quot;http://www.eweek.com/c/a/Security/MacBook-Air-Resistant-to-ColdBoot-Encryption-Attack/1/&quot; target=&quot;_blank&quot; &gt;Ryan Naraine&lt;/a&gt; reports on this here.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Microsoft suggests that the most secure method to use BitLocker is in hibernate mode and with multi-factor authentication.&lt;br /&gt;
According to Robert Hensing, a software engineer in Microsoft&#039;s SWI (Secure Windows Initiative) team, this class of attack is not new and was actually raised at the 2006 Hack in the Box conference in Kuala Lumpur, Malaysia.&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.theregister.co.uk/2008/02/22/eff_unbitlocker/&quot; &gt;&lt;br /&gt;
The Register&lt;/a&gt; also has their views on this...BitLocker, meet BitUnlocker.&lt;br /&gt;
&lt;br /&gt;
A question directed to Digital Forensic experts - Is this a blessing in disguise? What&#039;s your take on it?&lt;br /&gt;
&lt;br /&gt;
Update: More information on the discussion can be found &lt;a href=&quot;http://computer.forensikblog.de/en/2008/02/acquisition_6_the_guillotine.html&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/92-Recovering-passwords-from-RAM.html#extended&quot;&gt;Continue reading &quot;Recovering passwords from RAM&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 27 Feb 2008 09:37:00 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/92-guid.html</guid>
    
</item>
<item>
    <title>Windows Forensic Analysis - Harlan Carvey</title>
    <link>http://maltainfosec.org/archives/42-Windows-Forensic-Analysis-Harlan-Carvey.html</link>
            <category>Books</category>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/42-Windows-Forensic-Analysis-Harlan-Carvey.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=42</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=42</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;img width=&#039;86&#039; height=&#039;110&#039; border=&#039;0&#039; hspace=&#039;5&#039; align=&#039;left&#039; src=&#039;http://maltainfosec.org/uploads/images/windowsforensicanalysis.serendipityThumb.jpg&#039; alt=&#039;&#039; /&gt;&lt;br /&gt;
Here&#039;s a book I give my thumbs up for. Excellent content, well structured and rather easy to follow and understand. Personally I find particular chapters to be a great reference. The author &lt;a href=&quot;http://www.linkedin.com/in/hcarvey&quot; &gt;Harlan Carvey&lt;/a&gt; has his own &lt;a href=&quot;http://windowsir.blogspot.com/&quot; &gt;blog-spot&lt;/a&gt; and there is also a review of this book which can be found &lt;a href=&quot;http://www.andrewhay.ca/archives/142&quot; &gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
A review... &lt;br /&gt;&lt;a href=&quot;http://maltainfosec.org/archives/42-Windows-Forensic-Analysis-Harlan-Carvey.html#extended&quot;&gt;Continue reading &quot;Windows Forensic Analysis - Harlan Carvey&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Sun, 15 Jul 2007 19:04:00 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/42-guid.html</guid>
    
</item>
<item>
    <title>Digital Forensic Resources</title>
    <link>http://maltainfosec.org/archives/64-Digital-Forensic-Resources.html</link>
            <category>Forensics</category>
    
    <comments>http://maltainfosec.org/archives/64-Digital-Forensic-Resources.html#comments</comments>
    <wfw:comment>http://maltainfosec.org/wfwcomment.php?cid=64</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://maltainfosec.org/rss.php?version=2.0&amp;type=comments&amp;cid=64</wfw:commentRss>
    

    <author>nospam@example.com (Donald Tabone)</author>
    <content:encoded>
    &lt;!-- s9ymdb:68 --&gt;&lt;img width=&#039;110&#039; height=&#039;74&#039; style=&quot;border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://maltainfosec.org/uploads/images/hd.serendipityThumb.jpg&quot; alt=&quot;&quot; /&gt; &lt;strong&gt;Forensic URL&#039;s worth bookmarking:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.f3.org.uk&quot; target=&quot;_blank&quot;&gt;F3 - The First Forensic Forum&lt;/a&gt; &lt;br /&gt;
&lt;a href=&quot;http://www.ntsecurity.nu/onmymind/2006/2006-06-01.html&quot;  target=&quot;_blank&quot;&gt;Forensic memory dumping intricacies&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.forensicswiki.org/wiki/Main_Page&quot;  target=&quot;_blank&quot;&gt;This is a Forensics Wiki devoted to information about digital forensics&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.gmgsystemsinc.com/fau/&quot;  target=&quot;_blank&quot;&gt;Forensic Acquisitions Utilities&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.stegoarchive.com/&quot;  target=&quot;_blank&quot;&gt;A wealth of information on Steganography&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.spy-hunter.com/stegspydownload.htm&quot;  target=&quot;_blank&quot;&gt;Spyhunter home of StegSpy&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.outguess.org/download.php&quot;  target=&quot;_blank&quot;&gt;Outguess home of Stegdetect&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://security.fh-offenburg.de/mi-4n6.php&quot;  target=&quot;_blank&quot;&gt;Live-Forensic-CD based on Knoppix&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://dban.sourceforge.net/&quot;  target=&quot;_blank&quot;&gt;Darik&#039;s Boot and Nuke for wiping hard-disks&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://security.fh-offenburg.de/forensics_en.php&quot;  target=&quot;_blank&quot;&gt;Computer Forensics - Prof. Dr. Daniel Hammer&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.opensourceforensics.org/&quot;  target=&quot;_blank&quot;&gt;The Open Source Digital Forensics site&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.x-ways.net/winhex/&quot;  target=&quot;_blank&quot;&gt;WinHex is in its core a universal hexadecimal editor&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.forensicfocus.com/&quot; target=&quot;_blank&quot;&gt;Computer Forensics News and Information&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.forensicstore.com&quot; target=&quot;_blank&quot;&gt;Computer Forensic Store&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Reverse Hash Lookups&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://md5.benramsey.com/&quot; target=&quot;_blank&quot;&gt;http://md5.benramsey.com/&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://www.md5crack.com/&quot; target=&quot;_blank&quot;&gt;http://www.md5crack.com/&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://rainbowcrack.com&quot; target=&quot;_blank&quot;&gt;http://rainbowcrack.com&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://passcracking.com&quot; target=&quot;_blank&quot;&gt;http://passcracking.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
last updated: 6-12-07&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 01 Jan 2007 12:00:00 -0700</pubDate>
    <guid isPermaLink="false">http://maltainfosec.org/archives/64-guid.html</guid>
    
</item>

</channel>
</rss>