<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-36666403</atom:id><lastBuildDate>Wed, 01 Feb 2012 10:14:58 +0000</lastBuildDate><category>data recovery</category><category>Guidance Software</category><category>Scott Burkeman</category><category>Hard disk data storage</category><category>CSITech</category><category>Research</category><category>write blocking</category><category>graduates</category><category>Adroit Photo Forensics</category><category>Digital Evidence Collection Kit</category><category>Computer Forensic Investigation</category><category>storage</category><category>privacy</category><category>graduate</category><category>stalking</category><category>cold boot attack</category><category>mobile telephone connection records</category><category>bitlocker</category><category>business continuity</category><category>cell phone forensics</category><category>file carving</category><category>Criminal Justice and Immigration Bill</category><category>Kaminsky</category><category>encryption</category><category>cyberstalking</category><category>George Chlapoutakis</category><category>McMurdie</category><category>validating</category><category>tactical</category><category>David Benford</category><category>dominik weber</category><category>computer forensics</category><category>Forensic 4cast</category><category>Lance Mueller</category><category>hotplug</category><category>computer forensics events</category><category>Greg Smith</category><category>Google history</category><category>Projects</category><category>clifford stoll</category><category>review</category><category>Challenges</category><category>security metrics</category><category>Appointments-UK</category><category>training</category><category>blogs</category><category>Graham Brown-Martin</category><category>reporting</category><category>future</category><category>cv</category><category>scalability</category><category>write blocker review</category><category>ntfs</category><category>Chris Pamplin</category><category>Images</category><category>Si Biles</category><category>FTK</category><category>computer forensics jobs</category><category>EnCase</category><category>PIN</category><category>document analysis</category><category>Cystinosis</category><category>Experience</category><category>craig ball</category><category>forensics</category><category>employment</category><category>David Sullivan</category><category>data recovery training</category><category>Jon Rowe</category><category>online</category><category>Google forensics</category><category>Nick Furneaux</category><category>interview</category><category>expet witness</category><category>ACPO Good Practice Guide</category><category>Lee Whitfield</category><category>computer forensics costs prices</category><category>forensic focus stats</category><category>computer forensics licensing</category><category>tagview</category><category>Russell May</category><category>Columnists</category><category>interviews</category><category>DOMEX</category><category>expert witness</category><category>EnScripts</category><category>geotags</category><category>simon biles</category><category>key recovery</category><category>feeds</category><category>e-fense Live Response</category><category>forensic software</category><category>cell site analysis</category><category>education</category><category>technology</category><category>forensic hardware</category><category>Bright Forensics</category><category>computer security</category><category>Simson Garfinkel</category><category>Nessus</category><category>Tableau</category><category>Zimmermann</category><category>digital evidence</category><category>push button</category><category>passwords</category><category>truecrypt</category><category>forums</category><category>Scott Moulton</category><category>Search Warrants</category><category>iso</category><category>Infosecurity</category><category>chris hargreaves</category><category>Students</category><category>Sam Raincock</category><category>Programming</category><category>telecoms</category><category>procedures</category><category>live forensics</category><category>computer forensics education</category><category>harassment</category><category>mobile forensics</category><category>Advanced Forensic Sessions</category><category>survey</category><category>Pinpoint Labs</category><category>write blockers</category><category>peer review</category><category>UK Register of Expert Witnesses</category><category>data protection</category><category>single sign on</category><category>forensic reports</category><category>terms of engagement</category><category>image</category><category>disaster recovery</category><category>SIM</category><category>Tony Sammes</category><category>recruitment</category><category>4N6 Investigation</category><category>hard disk reliability</category><category>holographic memory</category><category>wiebetech</category><category>sharing knowledge</category><category>Matthew Shannon</category><category>V200 SIM Dialer</category><category>sterilization</category><category>cuckoo's egg</category><category>games consoles</category><category>Cloud Computing</category><category>recruiters</category><category>cold boot</category><category>careers</category><category>Agile Risk Management</category><category>vulnerability scanners</category><category>dan gaskell</category><category>Stephen Mason</category><category>network forensics</category><category>copyright</category><category>certification</category><category>Helix 3 Enterprise</category><category>wiping</category><category>jobs</category><category>Diffie</category><category>Digital Safety Conference</category><category>twitter</category><category>Robert Botchek</category><category>computer forensics recruitment</category><category>Hoffmann</category><category>compliance</category><category>computer forensics training</category><category>sean mclinden</category><category>standards</category><category>X-Ways</category><category>global computer forensics</category><category>memory acquisition</category><category>metadata</category><category>F-Response</category><category>electronic signatures</category><category>Ben Levitan</category><category>computer forensics podcasts</category><category>Windows Search forensics</category><title>Forensic Focus Blog</title><description>Thoughts and musings on computer forensics from &lt;a href="http://www.forensicfocus.com"&gt;Forensic Focus&lt;/a&gt;</description><link>http://forensicfocus.blogspot.com/</link><managingEditor>noreply@blogger.com (admin)</managingEditor><generator>Blogger</generator><openSearch:totalResults>176</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="forensicfocusblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://www.forensicfocus.com/blog/feed.php" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://www.forensicfocus.com/blog/feed.php" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5883448360522872715</guid><pubDate>Tue, 24 Jan 2012 12:18:00 +0000</pubDate><atom:updated>2012-01-24T04:18:53.850-08:00</atom:updated><title>Harry Onderwater</title><description>A few days ago the Dutch forensics community - indeed, the wider forensics community - lost one of its founding fathers, Harry Onderwater.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s1600/harry.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s1600/harry.jpg" /&gt;&lt;/a&gt;Having worked for many years for the Dutch police in Amsterdam, Harry then moved to the Centrale Recherche Informatie Dienst (&lt;span id="lblTitle"&gt;National Criminal Intelligence Service) where he became one of the first investigators in the newly emerging field of computer crime, building a reputation for excellence not just in the Netherlands but also further afield throughout Europe and the USA. Later in his career he became Corporate Security Manager at KPMG in the Netherlands where he also played a leading role in digital forensics.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;It is difficult to describe Harry without resorting to cliché, but he truly was a larger than life character. Behind his imposing physical presence - which must surely have worked to his advantage in his many years on the force - lay a consummate professional and gentleman. Kind hearted, generous and possessing a wonderful sense of humour, Harry was always a joy to deal with. To the vast majority of those who met Harry through work, there is little doubt he will be remembered first and foremost as a friend rather than a colleague.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;On a personal note, I would like to offer my sincere condolences to Harry's family and close friends. He has left us all too soon and will be deeply missed.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;Bedankt, Harry, voor alles.&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span id="lblTitle"&gt;Jamie&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5883448360522872715?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ET9KKGGyRiU:YwSdgjfF004:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ET9KKGGyRiU:YwSdgjfF004:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ET9KKGGyRiU:YwSdgjfF004:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2012/01/harry-onderwater.html</link><author>noreply@blogger.com (admin)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-OVo9iL3NhZM/Tx6gvKAM9-I/AAAAAAAAAFg/FxvPXQvoIIE/s72-c/harry.jpg" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7403047671448154593</guid><pubDate>Tue, 29 Nov 2011 16:01:00 +0000</pubDate><atom:updated>2011-11-29T08:01:40.137-08:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks ― Not on a Budget</title><description>by Sean L. Harrington&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"A couple of weeks ago, Brian Glass 
posted a very helpful comment, Forensic Toolkit v3 Tips and Tricks — on a
 Budget.  His comment focused on how to “get close to SSD performance on
 the cheap” and he discussed the practice of partitioning a large hard 
drive, but using only the outer sectors of the platter, and frequent 
defragmentation.  In my comment, today, I want to encourage readers to 
adopt Glass’ advice, and, if you have the budget, to consider a few 
other enhancements to improve performance..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/23/forensic-toolkit-v3-tips-and-tricks-%E2%80%95-not-on-a-budget/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/23/forensic-toolkit-v3-tips-and-tricks-%E2%80%95-not-on-a-budget/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7403047671448154593?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pLLzBuKDzhc:PCi4Ydmxjf0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pLLzBuKDzhc:PCi4Ydmxjf0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pLLzBuKDzhc:PCi4Ydmxjf0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/forensic-toolkit-v3-tips-and-tricks-not.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4805731595649540964</guid><pubDate>Tue, 29 Nov 2011 16:01:00 +0000</pubDate><atom:updated>2011-11-29T08:01:19.664-08:00</atom:updated><title>Is your client an attorney? Be aware of possible constraints (Part 2)</title><description>by Sean L. Harrington&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"In my first post several weeks ago, I 
discussed some of the special obligations that digital forensics 
investigators may have while in the employ of a lawyer. I elaborated 
briefly on the duty to zealously guard the attorney-client privilege, to
 correctly apply the work product doctrine, and to conduct 
investigations in a way that does not compromise the integrity of the 
case or the rights, privileges, or immunities of the retaining party. In
 this second part of the series, I will explore another important factor
 for consideration by examiners: the legality of investigative 
techniques..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/22/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-2-of-a-multi-part-series/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/22/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-2-of-a-multi-part-series/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4805731595649540964?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nuaIp9beTqE:NpTCitw5CYM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nuaIp9beTqE:NpTCitw5CYM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nuaIp9beTqE:NpTCitw5CYM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/is-your-client-attorney-be-aware-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1146106822009451141</guid><pubDate>Tue, 29 Nov 2011 16:00:00 +0000</pubDate><atom:updated>2011-11-29T08:00:56.984-08:00</atom:updated><title>iPhone Tracking – from a forensic point of view</title><description>Posted by 4rensiker&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"iPhoneTracking is sexy! Every mobile 
forensic suite, at least the ones dealing with iPhones, are providing it
 proudly. iPhoneTracking also has been a hot topic in the media all 
around the globe. People stated that there is a way to display every 
step of an iPhone user ever since the device got bought. Hmm...sounds 
great for all kind of investigations! Let’s see..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/20/iphone-tracking-from-a-forensic-point-of-view/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/20/iphone-tracking-from-a-forensic-point-of-view/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1146106822009451141?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_VqQHiw5Gd8:rNEfbZLM4FI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=_VqQHiw5Gd8:rNEfbZLM4FI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=_VqQHiw5Gd8:rNEfbZLM4FI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/iphone-tracking-from-forensic-point-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5114270280613497869</guid><pubDate>Tue, 29 Nov 2011 16:00:00 +0000</pubDate><atom:updated>2011-11-29T08:00:35.371-08:00</atom:updated><title>Android Forensics Study of Password and Pattern Lock Protection</title><description>Posted by Oxygen Software&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"Let’s see what Pattern Lock is, how to
 access, determine or even get rid of it? We’ll also speak about 
Password Lock Protection and find out what it has in common with Pattern
 Lock. And finally we’ll try to understand how these locks are related 
to forensic investigation process. Generally pattern lock is a set of 
gestures that phone user performs to unlock his smartphone when he needs
 to use it. It seems to be complicated, but actually it is not..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/18/android-forensics-study-of-password-and-pattern-lock-protection/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/18/android-forensics-study-of-password-and-pattern-lock-protection/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-5114270280613497869?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pzvRLDeSAng:8XpcUHjYpXo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=pzvRLDeSAng:8XpcUHjYpXo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=pzvRLDeSAng:8XpcUHjYpXo:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/android-forensics-study-of-password-and.html</link><author>noreply@blogger.com (admin)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-8663633981843469801</guid><pubDate>Tue, 29 Nov 2011 15:59:00 +0000</pubDate><atom:updated>2011-11-29T08:00:04.971-08:00</atom:updated><title>Skype in eDiscovery</title><description>by Stuart Clarke, 7Safe&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"The EDRM (Electronic Discovery 
Reference Model) is a widely accepted workflow, which guides those 
involved in eDiscovery. Typically, the identification and collection 
phases see email and common office documents harvested, but as 
technology moves forward is this enough? Many of us are experiencing a 
rise in audio discovery projects using solutions including phonetics and
 speech to text. In time this is likely to move onto rich media, in 
particular video. As a forensic analyst, I know only too well the 
variety of different data sources which are overlooked in electronic 
disclosure exercises, yet I appreciate the strong argument of 
proportionality. Nevertheless, it is relatively straightforward to 
circumvent some proportionality claims with the appropriate skill sets 
and techniques. Throughout this article I will discuss proof of concept 
solutions dealing with Skype in eDiscovery..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/09/skype-in-ediscovery/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/09/skype-in-ediscovery/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-8663633981843469801?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=djgw-IRNGko:_HjDWOi3AeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=djgw-IRNGko:_HjDWOi3AeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=djgw-IRNGko:_HjDWOi3AeI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/skype-in-ediscovery.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1322486998535877758</guid><pubDate>Tue, 29 Nov 2011 15:59:00 +0000</pubDate><atom:updated>2011-11-29T07:59:31.863-08:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks – On a budget</title><description>Posted by Brian K. Glass&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"While researching FTK 3X and Oracle, 
you just recently discovered that the best configuration of your Oracle 
database would be on a solid state drive (SSD). Solid state drives give 
the maximum level of performance to Oracle databases and in turn speed 
up your FTK 3X responsiveness. You are a conscientious analyst and 
decide to try reinstalling your database on a SSD. You approach your 
boss, who is not a techno geek, and ask him to purchase a 256GB high 
performance SSD..."&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/11/06/forensic-toolkit-v3-tips-and-tricks-on-a-budget/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/11/06/forensic-toolkit-v3-tips-and-tricks-on-a-budget/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1322486998535877758?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SNe9B8FEwLA:hvx9bEDn3yg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=SNe9B8FEwLA:hvx9bEDn3yg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=SNe9B8FEwLA:hvx9bEDn3yg:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/forensic-toolkit-v3-tips-and-tricks-on.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2601029190217035185</guid><pubDate>Tue, 29 Nov 2011 15:58:00 +0000</pubDate><atom:updated>2011-11-29T07:58:48.201-08:00</atom:updated><title>Anonymous, what does it mean?</title><description>Posted by forens245&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-style: italic;"&gt;"Anonymous, a word which 
Merriam-Webster describes as: of unknown authorship or origin, not named
 or identified, or lacking individuality, distinction, or 
recognizability. There are some in this world that wish to remain 
anonymous, not named or identified. Sure I am one of these people, but I
 have my reasons. With the work that I do, clinging to my anonymity is 
how I keep myself safe, out of harm’s way. There are many people that 
would like to see me hang for what I’ve uncovered about them..."&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/11/01/anonymous/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2601029190217035185?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=UNrD5id9Z5E:e03s0FfbA1U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=UNrD5id9Z5E:e03s0FfbA1U:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=UNrD5id9Z5E:e03s0FfbA1U:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/11/anonymous-what-does-it-mean.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-8591696364600822950</guid><pubDate>Fri, 07 Oct 2011 15:28:00 +0000</pubDate><atom:updated>2011-10-07T08:28:34.256-07:00</atom:updated><title>YouDetect – Implementing the principles of statistical classifiers and cluster analysis for the purposes of classifying illegally acquired multimedia files</title><description>&lt;div&gt;

&lt;div align="center" style="text-align: left;"&gt;
&lt;strong&gt;Author: Jonathan Murphy, 7Safe&lt;/strong&gt;&lt;/div&gt;
&lt;div align="center" style="text-align: left;"&gt;
&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;strong&gt;&lt;/strong&gt;Whilst all instances of the illegal acquisition of 
multimedia are not known, it is not possible to gain a complete loss 
value, but a loss of $12.5 billion has been suggested by the IPI. 
Continued response as a means of protecting the media companies and the 
income they receive from legal sales continues as copyright enforcement 
attempts to eradicate illegal downloading. This is forcing those who 
support the legal downloading material to invent new and more creative 
means to adapt technology to achieve an end to their means. ‘YouTube 
Downloader’ (YTD) is a proof of concept which allows the user to 
download videos (of any nature) from a number of video streaming 
websites simply by entering the URL of the video they wish to download. 
Whilst the application is specifically named after the website, 
YouTube.com, videos from many other websites can be acquired in this 
manner. The software allows the user to convert this video to a variety 
of multimedia formats including .mp3 and .avi. The individual can then 
view on these files on any supporting media device or computer. In the 
case of copyrighted material, the individual who uploaded the material 
to YouTube in the first instance, as well as the individual who then 
‘reproduced’ the material by extracting the video file have infringed on
 copyright law. As of September 2011, YTD has received approximately 85 
million downloads via software download website, ‘CNET.com’ making it 
the most commonly used tool of its type by a significant margin. Yet, 
for something which significantly assists and supports illegal 
downloading and multimedia piracy so significantly, little has been done
 to develop a suitable response...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/10/07/youdetect-implementing-the-principles-of-statistical-classifiers-and-cluster-analysis-for-the-purposes-of-classifying-illegally-acquired-multimedia-files-i/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-8591696364600822950?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1ch_BaEbyBE:y8Kb3CU_r0M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=1ch_BaEbyBE:y8Kb3CU_r0M:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=1ch_BaEbyBE:y8Kb3CU_r0M:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/youdetect-implementing-principles-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6214501929797589238</guid><pubDate>Fri, 07 Oct 2011 08:38:00 +0000</pubDate><atom:updated>2011-10-07T01:38:12.504-07:00</atom:updated><title>Advice for Digital Forensics Job Seekers</title><description>&lt;i&gt;by Joe Alonzo&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
You see the job advertisements posted 
on the web everyday, Digital Forensics Analyst, Internet Investigator, 
Computer Forensic Associate.  You hit the Apply Now button, often never 
hearing back from said company.&lt;br /&gt;
&lt;br /&gt;
Your background may consist of computer 
programming/IT, network security or possibly even a background in law 
enforcement.  You ask yourself, “How do I get the attention of this 
organization and get them to hire me?”&lt;br /&gt;
&lt;br /&gt;
Working for the leader in 
Computer Forensics and eDiscovery recruiting and seeing all the good and
 bad candidates have done, I can give you some great insight on how to 
get your dream job...&lt;br /&gt;
&lt;br /&gt;
&lt;a class="postlink" href="http://articles.forensicfocus.com/2011/10/07/advice-for-digital-forensics-job-seekers/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/2011/10/07/advice-for-digital-forensics-job-seekers/"&gt;Read more&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-6214501929797589238?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nHF3geT9tHI:qSChrlYyOJY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nHF3geT9tHI:qSChrlYyOJY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nHF3geT9tHI:qSChrlYyOJY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/advice-for-digital-forensics-job.html</link><author>noreply@blogger.com (admin)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4072655358153339268</guid><pubDate>Tue, 04 Oct 2011 11:56:00 +0000</pubDate><atom:updated>2011-10-04T04:56:49.901-07:00</atom:updated><title>Forensic Toolkit v3 Tips and Tricks – Re-indexing a case</title><description>&lt;i&gt;by Brian K.Glass&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is the first in a series of articles that will cover topics concerning AccessData&amp;nbsp;Forensic Toolkit (FTK)&amp;nbsp;version 3.&lt;br /&gt;
&lt;br /&gt;

So you’ve created a case in FTK 3.X / Oracle and added 20 forensic 
images of seized computers and assorted media which previously had been 
successfully processed and indexed. You’ve worked on this case for 
weeks, painstakingly searching and bookmarking thousands of keywords 
provided by Inspector R. Runner who has been investigating the Acme 
Corporation.&lt;br /&gt;
&lt;br /&gt;

Monday morning you come to work and fire up your FTK cluster, open 
your case, go to Indexed Search, type in the keywords Wile E. Coyote and
 Ka-Blam!! You get an error message saying a Search Request Error has 
occurred (Figure 1.) What happened, it was working fine on Friday?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/30/forensic-toolkit-v3-tips-and-tricks-re-indexing-a-case/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4072655358153339268?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4MVSENb1W2U:Usvl2BioUb8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4MVSENb1W2U:Usvl2BioUb8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4MVSENb1W2U:Usvl2BioUb8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/10/forensic-toolkit-v3-tips-and-tricks-re.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2574137225521712991</guid><pubDate>Thu, 29 Sep 2011 12:30:00 +0000</pubDate><atom:updated>2011-09-29T05:33:53.637-07:00</atom:updated><title>Is your client an attorney? Be aware of possible constraints on your investigation. (Part 1 of a multi-part series)</title><description>&lt;i&gt;by Sean L. Harrington&lt;/i&gt; &lt;br /&gt;
&lt;br /&gt;
Significant legal and ethical challenges confront digital forensics 
investigators, for which some may not be well prepared.&amp;nbsp;Just as many 
lawyers may be confounded by technology in dealing with digital 
forensics matters, many digital forensics experts lack formal legal 
training, and are uninformed about their special obligations in the 
employ of a lawyer. These obligations include zealously guarding the 
attorney-client privilege, applying the work product doctrine, 
developing reports, exhibits, and testimony (that are both admissible 
and understandable to a lay jury or judge), and conducting their work in
 a way that does not compromise the integrity of the case or the rights,
 privileges, or immunities of the retaining party.&lt;br /&gt;
In certain situations, such as where digital forensics examiners serve as special masters (&lt;i&gt;see &lt;/i&gt;Fed.R.Civ.P. 53) or third-party neutrals (&lt;i&gt;see&lt;/i&gt; Model Rules of Prof’l Conduct R. 2.4 cmt. 1), they are regarded as officers of the court.&lt;br /&gt;
&lt;br /&gt;
The use of a third-party neutral has significant advantages. &lt;i&gt;&lt;i&gt;See, e.g.&lt;/i&gt;, &lt;/i&gt;Craig Ball,&lt;i&gt; &lt;i&gt;Neutral Examiners&lt;/i&gt;,&lt;/i&gt;
 Forensic Focus, 
http://www.forensicfocus.com/index.php?name=Content&amp;amp;pid=346. &amp;nbsp;First,
 as an officer of the court, the expert is subject to the court’s 
inherent powers, thereby providing an extra measure of accountability 
for misconduct (&lt;i&gt;e.g.,&lt;/i&gt; confidentiality breaches).&amp;nbsp; Second, a 
third-party neutral is ostensibly impartial, which impartiality 
presumptively aids in the fact-finding process and administration of 
justice. Third, the third-party neutral is aptly situated to resolve 
discovery disputes, including issues of confidentiality, relevance, and 
privilege, and, if necessary, obtain court intervention or &lt;i&gt;in camera&lt;/i&gt; review to resolve such disputes.&lt;br /&gt;
&lt;br /&gt;
But if the examiner is not appointed by the court, but rather is 
retained by a party to an adversarial proceeding, he or she is 
nevertheless obliged to ferret out the truth...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/24/is-your-client-an-attorney-be-aware-of-possible-constraints-on-your-investigation-part-1-of-a-multi-part-series/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2574137225521712991?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ikTazH9zlGk:OXBV6-OTUOY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ikTazH9zlGk:OXBV6-OTUOY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ikTazH9zlGk:OXBV6-OTUOY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/is-your-client-attorney-be-aware-of.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9134504120950719296</guid><pubDate>Thu, 22 Sep 2011 17:09:00 +0000</pubDate><atom:updated>2011-09-22T10:09:42.159-07:00</atom:updated><title>Publishing articles at Forensic Focus</title><description>Forensic Focus is always keen to publish articles, papers or blog posts 
of interest to the digital forensics community. Articles are published 
not only &lt;a class="postlink" href="http://articles.forensicfocus.com/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/"&gt;online&lt;/a&gt;
 but also included in the monthly newsletter (sent to over 12,00 
subscribers) and promoted via our homepage/RSS feed, Twitter, LinkedIn 
and Facebook accounts.&lt;br /&gt;
&lt;br /&gt;
This is an excellent way of raising your profile or promoting your blog 
and items for publication are welcome from anyone working or studying in
 the field.&lt;br /&gt;
&lt;br /&gt;
To register as an author and start publishing at Forensic Focus, please use the form at &lt;a class="postlink" href="http://articles.forensicfocus.com/contact/" rel="nofollow" target="_blank" title="http://articles.forensicfocus.com/contact/"&gt;http://articles.forensicfocus.com/contact/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-9134504120950719296?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JzrLJhSimHU:k82HbMJtsDk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=JzrLJhSimHU:k82HbMJtsDk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=JzrLJhSimHU:k82HbMJtsDk:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/publishing-articles-at-forensic-focus.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2554488566135674937</guid><pubDate>Mon, 19 Sep 2011 13:03:00 +0000</pubDate><atom:updated>2011-09-19T06:03:38.897-07:00</atom:updated><title>What is “good enough” information security?</title><description>&lt;i&gt;by Simon Biles&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;

I have, occasionally in the past, mentored people in (on?) 
Information Security – once for money (this is not a revenue stream that
 I’ve mastered by any stretch of the imagination!), but more often than 
not, informally and infrequently. What there is in common with most 
people who are keen, but still a bit wet behind the ears, is an 
idealistic world view where Information Security, as a totality, can be 
obtained. It sometimes seems a bit like kicking a puppy to have to break
 it to people that, irregardless of how long, how much money and how 
much technology you throw at something, it will still have 
vulnerabilities and risks. Even the proverbial “unplug it, stick it in a
 safe and throw away the key” is still vulnerable. I’ve seen “Oceans 11″
 – I know what can happen to a safe.&lt;br /&gt;
&lt;br /&gt;

The reality is what we do for a living is to make security “good 
enough” – we are risk managers, risk mitigators, risk avoidance and risk
 acceptance professionals. We know what can happen, and then we decide 
if spending £x on it is worth it. Where we go wrong, inevitably, is that
 we sometimes have absolutely &lt;em&gt;no idea&lt;/em&gt; about the value of the 
asset that we are protecting. How can you determine if a countermeasure 
or control is appropriate if you don’t know this figure? The real 
problem is that very often the business has no real idea either...&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://articles.forensicfocus.com/2011/09/19/what-is-good-enough-information-security/"&gt;Read more &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2554488566135674937?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hJxyH0V0Tz8:MqJY4mjcvZQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hJxyH0V0Tz8:MqJY4mjcvZQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hJxyH0V0Tz8:MqJY4mjcvZQ:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/09/what-is-good-enough-information.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1836510284438143775</guid><pubDate>Wed, 24 Aug 2011 13:20:00 +0000</pubDate><atom:updated>2011-08-24T06:22:09.877-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">mobile forensics</category><title>Obtaining Information from Mobile Devices in Criminal Investigations</title><description>&lt;p style="font-style: italic;"&gt;by David W. Bennett&lt;/p&gt;&lt;p&gt;Mobile device forensics is the process of recovering digital evidence  from a mobile device under forensically sound conditions and utilizing  acceptable methods. Forensically sound is a term used in the digital  forensics community to justify the use of a particular technology or  methodology. Many practitioners use the term to describe the  capabilities of a piece of software or forensic analysis approach  (McKemmish, 3). Mobile devices vary in design and manufacturer. They are  continually evolving as existing technologies progress and new  technologies are introduced. It is important for forensics investigators  to develop an understanding of the working components of a mobile  device and the appropriate tasks to perform when they deal with them on a  forensic basis. Knowledge of the various types of mobile devices and  the features they possess is an important aspect of gathering  information for a case since usage logs and other important data can  potentially be acquired using forensics toolkits. &lt;/p&gt; &lt;p&gt;Mobile device forensics has expanded significantly over the past few  years. Older model mobile phones could store a limited amount of data  that could be easily obtained by the forensics investigator. With the  development of the smartphone, a significant amount of information can  still be retrieved from the device by a forensics expert; however the  techniques to gather this information have become increasingly  complicated...&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://articles.forensicfocus.com/2011/08/22/the-challenges-facing-computer-forensics-investigators-in-obtaining-information-from-mobile-devices-for-use-in-criminal-investigations/"&gt;http://articles.forensicfocus.com/2011/08/22/the-challenges-facing-computer-forensics-investigators-in-obtaining-information-from-mobile-devices-for-use-in-criminal-investigations/&lt;/a&gt;
&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1836510284438143775?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nqupH5E00G4:eRDzN8f3PlU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=nqupH5E00G4:eRDzN8f3PlU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=nqupH5E00G4:eRDzN8f3PlU:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/08/obtaining-information-from-mobile.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6133128957017378121</guid><pubDate>Tue, 23 Aug 2011 17:13:00 +0000</pubDate><atom:updated>2011-08-23T10:15:30.901-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">cold boot attack</category><category domain="http://www.blogger.com/atom/ns#">memory acquisition</category><title>An in-depth analysis of the cold boot attack: Can it be used for sound forensic memory acquisition?</title><description>by Richard Carbone
&lt;br /&gt;
&lt;br /&gt;The purpose of this technical memorandum is to examine the technical  characteristics behind the cold boot attack technique and to understand  when and how this technique should be applied to the field of computer  forensic investigations. Upon thorough examination of the technique, the  authors highlight its advantages, drawbacks, applicability and  appropriateness for use in the acquisition of computer memory contents.  The original cold boot attack paper, as conducted by a team of students  and researchers in 2008, demonstrated the usefulness of computer memory  remanence and how this phenomenon could be used to defeat popular disk  encryptions tools and other data hiding techniques necessary for the  safe storage of secret data and information. However, the technique is  not a panacea and has many drawbacks dictated by the laws of physics,  which cannot be overcome by the technique...
&lt;br /&gt;
&lt;br /&gt;Read more at &lt;a href="http://articles.forensicfocus.com/2011/08/21/an-in-depth-analysis-of-the-cold-boot-attack-can-it-be-used-for-sound-forensic-memory-acquisition/"&gt;http://articles.forensicfocus.com/2011/08/21/an-in-depth-analysis-of-the-cold-boot-attack-can-it-be-used-for-sound-forensic-memory-acquisition/&lt;/a&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-6133128957017378121?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hn-CGunEHjc:dLouK_ks77Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hn-CGunEHjc:dLouK_ks77Q:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hn-CGunEHjc:dLouK_ks77Q:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/08/in-depth-analysis-of-cold-boot-attack.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1008032827230525826</guid><pubDate>Mon, 22 Aug 2011 10:41:00 +0000</pubDate><atom:updated>2011-08-22T03:43:25.573-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Google history</category><category domain="http://www.blogger.com/atom/ns#">Google forensics</category><title>Google History Forensics</title><description>&lt;div style="font-style: italic;"&gt;by Craig Ball&lt;/div&gt;
&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;table align="right" bgcolor="white" border="0" width="100"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td&gt; &lt;img src="http://www.forensicfocus.com/images/other/craig-ball.jpg" alt="Craig Ball" align="right" border="0" /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt; About the Author&lt;p&gt; &lt;i&gt;Craig Ball is a Texas lawyer who limits his practice to service as a  court-appointed special master and consultant in computer forensics and  electronic discovery.&lt;/i&gt; &lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;In my last Forensic Focus column, I touched on migration to handhelds  and the cloud, mushrooming drive capacities and encryption-by-default  as just some of the factors auguring the eventual extinction of  conventional digital forensics. But an end to old school digital  forensics is no threat to examiners who evolve. There will be plenty to  do for those adapting their skills and tools to new sources and forms of  information. We will learn to read new tea leaves.&lt;/p&gt;  &lt;p&gt;Happily, for every source of forensically-rich information that fades  away, others emerge. For every MacBook configured to wipe deleted data,  there’s an iPhone storing screenshots and typed text. When webmail  shooed away some of our ability to locate messaging artifacts, social  networking and geolocation wandered in with stories to tell.&lt;/p&gt;  &lt;p&gt;Now and then, the emergent sources just seem too good to be true.&lt;/p&gt;  &lt;p&gt;Case in point: &lt;b&gt;Google History&lt;/b&gt;. &lt;/p&gt;  &lt;p&gt;Certainly, forensic analysts routinely look at Google searches &lt;i&gt;locally&lt;/i&gt;;  parsing Internet activity to assess what the user searched and surfed:  “Nude children.” “How to make chloroform.” “Wipe a hard drive.” It’s  compelling evidence. &lt;/p&gt;  &lt;p&gt;But, as users grow savvy about covering their tracks, we see more  cache deletion and deployment of antiforensic “privacy” tools designed  to deprive us of the low-lying fruit. It’s potentially “spoliation” on  the civil side and “obstruction of justice” on the criminal side. On  both sides, proving it helps justice be done. &lt;/p&gt;  &lt;p&gt;Then again, data can disappear innocently, too. Oliver Wendell  Holmes, Jr., observed that, “Even a dog distinguishes between being  stumbled over and being kicked." Discerning evil intent—&lt;i&gt;mens rea &lt;/i&gt;in  the law—is crucial to deciding whether and how much to punish actions  that result in lost evidence. One way we demonstrate intent is by  showing the planning that preceded an act. We reasonably infer intent to  destroy evidence from web searches seeking ways to make evidence  disappear.&lt;/p&gt;  &lt;p&gt;But what do you do when the data destroyed is the evidence of intent in its destruction?&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://www.forensicfocus.com/craig-ball"&gt;http://www.forensicfocus.com/craig-ball&lt;/a&gt;
&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1008032827230525826?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=PO5jR6DQKWI:2tZ4q4zr-DI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=PO5jR6DQKWI:2tZ4q4zr-DI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=PO5jR6DQKWI:2tZ4q4zr-DI:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/08/google-history-forensics.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7547842109568687746</guid><pubDate>Fri, 29 Jul 2011 13:38:00 +0000</pubDate><atom:updated>2011-07-29T06:39:36.890-07:00</atom:updated><title>Important Changes to "Articles &amp; Papers" Section</title><description>From today, the section where we display user submitted articles and  research papers is changing significantly. Users will now be able to  upload, edit and publish their own articles.&lt;br /&gt;&lt;br /&gt;The URL for the new section is &lt;a href="http://articles.forensicfocus.com/" target="_blank" title="http://articles.forensicfocus.com/" class="postlink" rel="nofollow"&gt;http://articles.forensicfocus.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you would like to submit an article or paper please email &lt;a href="mailto:admin@forensicfocus.com"&gt;admin@forensicfocus.com&lt;/a&gt; so that we can start the process of setting you up with an account (separate from your normal Forensic Focus account).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7547842109568687746?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=311jPRY4Ffs:AKqnZ9D9jqs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=311jPRY4Ffs:AKqnZ9D9jqs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=311jPRY4Ffs:AKqnZ9D9jqs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/07/important-changes-to-articles-papers.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4798019148380323328</guid><pubDate>Wed, 29 Jun 2011 11:43:00 +0000</pubDate><atom:updated>2011-06-29T04:45:27.068-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics recruitment</category><category domain="http://www.blogger.com/atom/ns#">Scott Burkeman</category><title>Interview with Scott Burkeman, Warner Scott Recruitment</title><description>&lt;div&gt;&lt;i&gt;Scott is a Director at &lt;a href="http://www.warnerscott.com/"&gt;Warner Scott Recruitment&lt;/a&gt; in London, specialising in computer forensics recruitment throughout the UK and abroad.&lt;/i&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Forensic Focus: Can you tell us something about your background? How did Warner Scott Recruitment come into being?&lt;/b&gt; &lt;p&gt; Scott Burkeman: I have been involved in Forensic Technology and Fraud  recruitment for over a decade, working for an international recruitment  firm and more recently with Warner Scott. I initially began placing  Senior Forensic Accounting professionals prior to the boom in Computer  Forensics. Many of my clients were looking to develop Computer Forensic  teams from scratch and asked me to get involved in the recruitment of  Forensic Technology candidates to assist in their growth plans. Since  then, the rest is history!  &lt;/p&gt;&lt;p&gt; Warner Scott Recruitment was set up in 2006 as a specialist recruitment  consultancy with the vision of developing long-standing, meaningful  relationships with both our candidates and clients. We have a strong  focus on the Computer Forensic and eDiscovery market and are one of only  a handful of specialist consultancies that have a dedicated team  focusing in this area.  &lt;/p&gt;&lt;p&gt; Many of the candidates we have placed over the years are now our clients  and vice versa. We pride ourselves in our market knowledge, deep  relationships and a strong understanding of the markets we operate in.  We are fortunate enough to work on many roles on an exclusive basis as  our clients trust us enough to find the best people in the market. &lt;/p&gt;&lt;p&gt; The Computer Forensic area is an extremely unique market to operate  within and has some wonderful characters and personalities that make  this area a pleasure to work in. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Forensic Focus: What services do you offer to digital forensics jobseekers?&lt;/b&gt; &lt;/p&gt;&lt;p&gt; Scott Burkeman: We are more than just a recruitment firm. As well as  placing candidates into roles, we offer career advice and counselling,  coaching, CV advice, interview tips and much more. As mentioned above,  we are keen to develop long term relationships with our candidates, so  if anyone fancies a chat about the state of the market, is looking to  benchmark their salary or just wants some career advice, please do not  hesitate to call us, or pop in to see us for a coffee and chat. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;b&gt;Forensic Focus: What is the current state of the digital forensics job market? Which sectors are hiring?&lt;/b&gt; &lt;/p&gt;&lt;p&gt; Scott Burkeman: The market has been up and down in recent years, which  has been characterised by the state of the wider economy. With the  government cuts in public spending, there has been much uncertainty  within the public sector, which has resulted in some redundancies. Many  private sector companies which previously had large government contracts  have had to adapt and change to accommodate the loss of work. &lt;/p&gt;&lt;p&gt; However, the eDiscovery &amp;amp; Litigation Support market continues to  remains buoyant as well as the Data Analytics arena. The large  consultancy firms and international boutiques are still hiring the best  candidates and increasingly Banks and Corporates are approaching us to  help fill in-house Investigations roles.  &lt;/p&gt;&lt;p&gt; With the increase of Anti Money Laundering (AML) projects and the  introduction of the Anti Bribery &amp;amp; Corruption Act this year, the  demand for Forensic Technology experts with strong corporate  investigations experience remains high...&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://www.forensicfocus.com/scott-burkeman-interview-290611"&gt;http://www.forensicfocus.com/scott-burkeman-interview-290611&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-4798019148380323328?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=rbi1S2l4YIY:PE07l2NpiU0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=rbi1S2l4YIY:PE07l2NpiU0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=rbi1S2l4YIY:PE07l2NpiU0:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/06/interview-with-scott-burkeman-warner.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-9087254965939646849</guid><pubDate>Tue, 24 May 2011 13:37:00 +0000</pubDate><atom:updated>2011-05-24T06:39:58.505-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">data recovery training</category><category domain="http://www.blogger.com/atom/ns#">Scott Moulton</category><category domain="http://www.blogger.com/atom/ns#">data recovery</category><title>Scott Moulton’s “5-Day Data Recovery Expert Certification” Course</title><description>&lt;div&gt;&lt;i&gt;reviewed by by Karlo Arozqueta&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.myharddrivedied.com/data-recovery-training"&gt;http://www.myharddrivedied.com/data-recovery-training&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Just about every individual who is immersed in the Information  Technology field has either personally experienced it, or knows someone  who has: The hard drive “click of death”. For most, this sound is the  start of a downward spiral of doom and depression and eventually a large  bill from a data recovery company. For some, however, this is the  beginning of a new field of interest in technology. There is only one  problem: The field of hard drive data recovery is one that is still  shrouded in secrecy and misinformation. How can someone break into an  industry where advice is doled out in hushed tones and newcomers are  shunned and told to seek professional (read:$$$) help?&lt;/p&gt;  &lt;p&gt;Scott Moulton has been trying to change that, and is one of the few  individuals teaching a vendor-neutral data recovery class to the public.  I attended one of Scott’s 5 day training classes in 2009, and have kept  up with him as the course has grown. In an effort to assist other  individuals in deciding if this course is worth taking, I opted to write  this review. Please note that while my personal attendance of the  course was in 2009, I routinely volunteer to assist in these courses  (for free) when they come to my geographic area of Washington DC, so  this information is current as of May of 2011. Also, while the term  “hard drive” has now become the catch-all term, the course material  covers recovery of both traditional mechanical hard drives and touches  on the latest recovery technologies for flash based devices like USB  thumb drives and Solid-State Drives (SSD).&lt;/p&gt;  &lt;p&gt;This class is appropriate for any individuals who have a solid  understanding of computer forensics and filesystems and want to take  their knowledge to the next level in terms of understanding exactly how  data is stored on the drive, how the device works, and how it can be  recovered when conventional imaging techniques fail. This was my primary  reason for attending the course. The class is also appropriate for any  individual who wants to approach data recovery as a means to expand  their computer-support business and wants to add DR (data recovery) as  an additional service...&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://www.forensicfocus.com/scott-moulton-data-recovery-review-200511"&gt;http://www.forensicfocus.com/scott-moulton-data-recovery-review-200511&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-9087254965939646849?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ygJXNlCofJ0:tAGLnI6v5QM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=ygJXNlCofJ0:tAGLnI6v5QM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=ygJXNlCofJ0:tAGLnI6v5QM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/05/scott-moultons-5-day-data-recovery.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-437320762979479160</guid><pubDate>Tue, 24 May 2011 11:24:00 +0000</pubDate><atom:updated>2011-05-24T04:26:36.688-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">chris hargreaves</category><title>Standard Units in Digital Forensics</title><description>&lt;div style="font-style: italic;"&gt;by Chris Hargreaves&lt;/div&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;table align="right" bgcolor="white" border="0" width="100"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td&gt; &lt;img src="http://www.forensicfocus.com/images/other/chris-hargreaves.jpg" alt="Chris Hargreaves" align="right" border="0" /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt; About the Author&lt;p&gt; &lt;i&gt;Dr Chris Hargreaves is a lecturer at the Centre for Forensic Computing at Cranfield University in Shrivenham, UK.&lt;/i&gt; &lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  One of the earliest lectures in the MIT Openware programme in Physics  begins with the lecture “Units and Dimensional Analysis”. Units of  measurement are critical to science, so much so that there is a standard  that defines science’s system of units, for example the precise  definition of a kilogram -- the SI (&lt;i&gt;Système International d’Unités&lt;/i&gt; or &lt;i&gt;International System of Units&lt;/i&gt;).  The notion of units of measurement in science is extremely important  and it therefore seems sensible to consider how this applies to digital  forensics.   &lt;p&gt; As we will see, this does not necessarily suggest that there should be  standard units of measurement in digital forensics, to report, for  example, the position of the start of a file. As will be discussed later  in the article, this is not always appropriate, since it is useful to  describe such positions in different ways depending on the context.  However, this article will discuss that reporting &lt;i&gt;&lt;b&gt;some&lt;/b&gt;&lt;/i&gt; unit of measurement is essential.  &lt;/p&gt;&lt;p&gt; Perhaps it is best to begin with a simple example: &lt;/p&gt;&lt;p&gt; &lt;i&gt;“the text string ‘this is evidence’ was located at position 34556”&lt;/i&gt; &lt;/p&gt;&lt;p&gt; Since this important evidential artefact has been located, it seems  sensible to check that the artefact is actually there. So, we should  examine position 34556... but 34556 what? Bytes, sectors, blocks? Let us  assume just for a second that the position is expressed in bytes, but  what about the number base? If the position in which the string was  identified was 86FC, it would be reasonable to assume that this is a  hexadecimal offset. However, in this example we have 34556. This could  be decimal or hexadecimal. So in order to precisely identify the  position of this string, not only does the unit of measurement need to  be expressed, but so too does the number base in which it is expressed. &lt;/p&gt; Furthermore, consider the organisation of a disk...&lt;br /&gt;&lt;br /&gt;Read more at &lt;a href="http://www.forensicfocus.com/chris-hargreaves"&gt;http://www.forensicfocus.com/chris-hargreaves&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-437320762979479160?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hAbgFkU9dys:CCKcyE5kJbY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=hAbgFkU9dys:CCKcyE5kJbY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=hAbgFkU9dys:CCKcyE5kJbY:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/05/standard-units-in-digital-forensics.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6721249419370381629</guid><pubDate>Tue, 24 May 2011 10:15:00 +0000</pubDate><atom:updated>2011-05-24T03:18:14.078-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Nessus</category><category domain="http://www.blogger.com/atom/ns#">vulnerability scanners</category><category domain="http://www.blogger.com/atom/ns#">Si Biles</category><title>PitchLake - a tar pit for scanners</title><description>&lt;div&gt;&lt;span style="font-style: italic;"&gt;by Simon Biles&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;table align="right" bgcolor="white" border="0" width="100"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td&gt; &lt;img src="http://www.forensicfocus.com/images/other/simon-biles.gif" alt="Simon Biles" align="right" border="0" /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt; About the Author&lt;p&gt; &lt;i&gt;Simon Biles is a founder of &lt;a href="http://www.thinking-security.com/"&gt;Thinking Security Ltd.&lt;/a&gt;, an Information Security and Risk Management consultancy firm based near Oxford in the UK.&lt;/i&gt; &lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;   &lt;p&gt;We’ve had two bank holidays in a row here in the UK – first off for  Easter, then for the Royal Wedding – time off work coupled with very  pleasant weather and plenty of “refreshments” has caused my brain to  atrophy! So, rather than pulling one of my usual type of topics from the  hat for this article, I thought that I’d do a mini-project for the  month.&lt;/p&gt;  &lt;p&gt;[ I’ll apologise up front though – I can only just program in both  Perl and C, and C isn’t exactly column friendly, so it’ll be Perl. I  know that many readers here can program in Perl, and most of you  probably better than me – I’d be interested to hear corrections, tips  and tricks in the comments so as to improve, as no doubt there are  better ways of doing this ! ]&lt;/p&gt;  &lt;p&gt;One of my first tasks in the office this morning, after a cup of  coffee of course, was to review my server logs [1]. As of yet I’ve not  got enough staff to have a minion to do this for me, but to be honest  I’d miss the connection to the real world of computing if I did [2]. I  run a Linux server in a datacentre in Birmingham as my company’s main  web-server and my high bandwidth, static IP’d pen-test machine. For the  last few months I’ve been meaning to do something about the 404 errors (&lt;a href="http://en.wikipedia.org/wiki/HTTP_404"&gt;http://en.wikipedia.org/wiki/HTTP_404&lt;/a&gt;)  that are being reported by Apache – some are my fault for taking pages  away that people clearly still cross reference – the others though are  clearly the work of automated web vulnerability scanning tools.&lt;/p&gt;  Vulnerability scanners (&lt;a href="http://en.wikipedia.org/wiki/Vulnerability_scanner"&gt;http://en.wikipedia.org/wiki/Vulnerability_scanner&lt;/a&gt;)  are the bottom end of the pen-test toolkit – they are to penetration  testing what the Windows “find” command is to digital forensics; e.g.  superficial and basic. There are various types – but of interest today  are those that operate on the application layer over HTTP (&lt;a href="http://en.wikipedia.org/wiki/ISO_model#Layer_7:_Application_Layer"&gt;http://en.wikipedia.org/wiki/ISO_model#Layer_7:_Application_Layer&lt;/a&gt;). In the open source market both Nikto (&lt;a href="http://www.cirt.net/nikto2"&gt;http://www.cirt.net/nikto2&lt;/a&gt;) and Nessus (&lt;a href="http://www.tenable.com/products/nessus"&gt;http://www.tenable.com/products/nessus&lt;/a&gt;)  [ Nessus isn’t open source per se, but is free for home use … ] are  examples of products that perform tests against webservers for  potentially insecure CGIs and files – the trouble with this is that in  order to determine if an insecure CGI script or file is present, the  scanner asks Apache for it, and receives a 404 if it isn’t there, each  404 is written to the log, and when Nikto, for example, tests for over  6400 possible vulnerabilities you can imagine what the logs look like !  Sadly, tools like these, as they are available to everyone, are not only  used by the kind of people that get written authorisation before  testing your web server...&lt;br /&gt;&lt;br /&gt;Read more at &lt;a href="http://www.forensicfocus.com/simon-biles"&gt;http://www.forensicfocus.com/simon-biles&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-6721249419370381629?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4ZUzDolmKzs:RXZt6OjTr5s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=4ZUzDolmKzs:RXZt6OjTr5s:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=4ZUzDolmKzs:RXZt6OjTr5s:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/05/pitchlake-tar-pit-for-scanners.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2267360934283266696</guid><pubDate>Tue, 29 Mar 2011 08:23:00 +0000</pubDate><atom:updated>2011-03-29T01:23:51.411-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">craig ball</category><title>The End of Digital Forensics?</title><description>&lt;div&gt;by Craig Ball&lt;/div&gt;&lt;br /&gt;&lt;p&gt; &lt;/p&gt;&lt;table align="right" bgcolor="white" border="0" width="100"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td&gt; &lt;img src="http://www.forensicfocus.com/images/other/craig-ball.jpg" alt="Craig Ball" align="right" border="0" /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt; About the Author&lt;p&gt; &lt;i&gt;Craig Ball is a Texas lawyer who limits his practice to service as a  court-appointed special master and consultant in computer forensics and  electronic discovery.&lt;/i&gt; &lt;/p&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  When Microsoft introduced its Encrypting File System (EFS) in Windows  2000, the Cassandras of computer forensics peppered the listserves with  predictions that the days of digital forensics were numbered.   Ten  years on and hundreds of systems acquired, I’ve yet to handle a case  stymied by encryption—and 90% of my acquisitions were corporate  machines, many with TPMs and fingerprint readers.  &lt;i&gt;Voluntary&lt;/i&gt; encryption turned out to be &lt;i&gt;no&lt;/i&gt; encryption at all. &lt;p&gt; The next sky falling threats to forensics were privacy tools and  features.  “Surely,” our Chicken Littles clucked, “everyone will run  free tools that routinely wipe unallocated clusters and securely delete  data!”   Turns out, they only run the antiforensic tools right before  the examiner arrives, and most such tools do a lousy job covering their  tracks.  Instead, we’ve come to see much &lt;i&gt;more&lt;/i&gt; revealing data and  metadata created and retained by operating systems.  The Windows  Registry and all those logs and .dat files are like birthday presents  from Bill Gates. &lt;/p&gt;&lt;p&gt; Finally, there are the stormy forecasts about the Cloud.  Absent  dominion over physical storage media, digital forensics is indeed  different.  We need credentials to acquire data in the Cloud, and  deletion tends to mean really gone.  But the silver lining is that the  portable devices used to access Cloud data tend to store so much  information that they’re proving a cornucopia of case-making  information.  Are handhelds trickier to acquire?  Sure.  Are they less  revealing?  Not on your life! &lt;/p&gt;&lt;p&gt; But lately, one acorn that &lt;i&gt;has&lt;/i&gt; fallen on my head and caused me to  look warily aloft is the quantum leap in hard drive capacity.  I  suspect I’ve acquired more aggregate data in the last year than in all  of the previous nine years &lt;i&gt;put together&lt;/i&gt;.  Not more &lt;i&gt;media&lt;/i&gt;, mind you, &lt;i&gt;more data&lt;/i&gt;.  At least more &lt;i&gt;nulls&lt;/i&gt;, but we’ve got to read those too, right?&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://www.forensicfocus.com/craig-ball"&gt;http://www.forensicfocus.com/craig-ball&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-2267360934283266696?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=qn5tT0TvYJY:OTFkeNFdsL8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=qn5tT0TvYJY:OTFkeNFdsL8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=qn5tT0TvYJY:OTFkeNFdsL8:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/03/end-of-digital-forensics.html</link><author>noreply@blogger.com (admin)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1770088810131997058</guid><pubDate>Mon, 28 Mar 2011 04:42:00 +0000</pubDate><atom:updated>2011-03-27T21:44:39.904-07:00</atom:updated><title>Fragmentation of the digital forensics community</title><description>From the forums:&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;I started in the digital forensics community about five years ago, and I  already feel old, and I am a Johnny-come-lately. This post may come off  as a “Hey, you kids, get offa my lawn!” rant. Rather than a rant, I  really hope that people start talking about a way to find a small number  of safe lawns for all the kids to play on.&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; In those five years I’ve noticed that the computer forensics community  has become *less* supportive, not more supportive. This runs contrary to  trends to other communities such as software engineering tools, web  frameworks, and startups. I have some feelings and thoughts on why this  is. I wish I had some good ideas on how to turn this trend around.&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; I think there are four major problems:&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; 1) Fragmentation of the sites supporting the community.&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; When I showed up, there was Forensic Focus, the CCE list, and HTCIA.  (And other people probably had their three or four sources that don’t  overlap with mine.) Now, I’ve got Forensic Focus, CCE, HTCIA, HTCC,  DFCB, wn4n6s, and a host of OS and tool specific sites. Then there is  LinkedIn, with an almost one to one mapping of all the external groups,  plus subgroups, plus additional new groups not represented elsewhere.It  seems that everyone wants their own lawn to play on rather than  contributing to the health of an existing lawn. How often have you seen a  post along the lines of “Hey, I set up a new forensics wiki! Come check  it out and help it grow!” Or found yet another computer forensics  LinkedIn group?&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; This leads to two related problems: Where do you post, and where do you  go looking for information? I belong to a lot of the mailing lists and  use my personal mail archive as a research tool when I have questions,  but that doesn’t reach into the various web based forums. And if I want  to post a question, where does it go? Some people blast every mailing  list they’re on, hoping for an answer. And the more we balkanize, the  more likely those questions are to go unanswered.&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="font-style: italic;"&gt; I still use FF and the CCE list mostly, but then there are items #2 an #3...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Read more at &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=7442"&gt;http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=7442&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-1770088810131997058?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=xPDl_lE01vs:WbvL1XKsdcM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=xPDl_lE01vs:WbvL1XKsdcM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=xPDl_lE01vs:WbvL1XKsdcM:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/03/fragmentation-of-digital-forensics.html</link><author>noreply@blogger.com (admin)</author><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7038062173608608490</guid><pubDate>Thu, 24 Mar 2011 12:53:00 +0000</pubDate><atom:updated>2011-03-27T21:45:40.050-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">mobile telephone connection records</category><category domain="http://www.blogger.com/atom/ns#">Sam Raincock</category><title>Evaluating Mobile Telephone Connection Behaviour - Part 2</title><description>by Sam Raincock&lt;br /&gt;&lt;br /&gt;&lt;table align="right" bgcolor="white" border="0" width="100"&gt; &lt;tbody&gt;&lt;tr&gt; &lt;td&gt; &lt;img src="http://www.forensicfocus.com/images/other/sam-raincock.jpg" alt="" align="right" border="0" /&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td align="center"&gt; &lt;i&gt;Sam Raincock from &lt;a href="http://www.raincock.co.uk/"&gt;SRC&lt;/a&gt; is an  IT and telecommunications expert witness specialising in the evaluation  of digital evidence. She also provides training and IT security  consultancy.&lt;/i&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;&lt;u&gt;Connection Records&lt;/u&gt;&lt;p&gt; Within the UK, details of past telephone connections are stored by the  network providers.  The minimum storage is advised by the Data Retention  (EC Directive) Regulations [1][2].  However, each network provider is  able to disclose different types of information about past connection  activity and this availability also changes over time.  As a result, it  is important to be familiar with what connection record information may  be available to your case so you can make appropriate requests to obtain  access to it.  Perhaps a useful strategy for companies undertaking  connection record evaluation work would be to compile a procedure where  your organisation will contact the network providers every 6 months to  determine if anything has changed.   &lt;/p&gt;&lt;p&gt; It is also important to note that the network providers will provide a  ‘standard’ format of connection records if they are not directed  regarding the information you require.  My philosophy with network  records is that if you don’t ask, you won’t get it! &lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;u&gt;Examining Connection Records&lt;/u&gt; &lt;/p&gt;&lt;p&gt; Most often the instructions received in connection charting matters are  to compile charts of connection patterns of the telephones of interest  in a case.  This is generally over a certain time period and may also  include a frequency analysis to determine how many connections have  occurred with particularly numbers of interest.  It may (especially in  defence cases) also include questions about the meaning of connections  and the possible circumstances of the calls/SMS messages. &lt;/p&gt;&lt;p&gt; Where connection records specialists are lucky, they are provided with  the records in electronic format.  Where they are ill-fated they obtain a  file of 500+ pages in paper format and the electronic records are  unavailable (very common in older cases). &lt;/p&gt;&lt;p&gt; With paper records, you have two options: transfer the records into  electronic format (however, you are going to have to thoroughly validate  that this has occurred correctly) or you will need to examine them by  eye.  Actually, dealing with paper connection records is a lot easier  than it sounds as you become used to looking for patterns over time. &lt;/p&gt;&lt;p&gt; With electronic records, if you are using pivot tables to assist you in  performing a frequency analysis of the connection behaviour to establish  how many connections have been made with certain telephone number of  interest, remember that a telephone number may be provided in the  records in various formats.  For example, 07777 111111 may also be  provided as 447777 111111.   &lt;/p&gt;&lt;p&gt; Also with electronic records – make sure you don’t suffer from sorting  issues.  Firstly, if you haven’t set your data to be the correct type  (which can be an annoying activity in itself), sorting can produce  unexpected results.  And of course, there is also the old Excel sorting  problem where you sort by column and don’t expand the selection to the  other data values too, resulting in shuffling your original connection  records table. &lt;/p&gt;&lt;p&gt; Although all these points may seem very basic, in my experience mistakes  do occur in this type of processing.  Another area for error is  overlooking the obvious – the date being in the wrong format or the  wrong number is searched for etc.    Hence, the key when performing  connection charting/analysis is to validate, validate, validate and  assume nothing...&lt;/p&gt;&lt;p&gt;Read more at &lt;a href="http://www.forensicfocus.com/sam-raincock"&gt;http://www.forensicfocus.com/sam-raincock&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36666403-7038062173608608490?l=forensicfocus.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=mxEpd3eeOD4:h_cUMAZ74Cs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?i=mxEpd3eeOD4:h_cUMAZ74Cs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:cGdyc7Q-1BI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=cGdyc7Q-1BI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:XAVGb8Xj5zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=XAVGb8Xj5zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ForensicFocusBlog?a=mxEpd3eeOD4:h_cUMAZ74Cs:u0Zhe-nyOHo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ForensicFocusBlog?d=u0Zhe-nyOHo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2011/03/evaluating-mobile-telephone-connection.html</link><author>noreply@blogger.com (admin)</author><thr:total>0</thr:total></item></channel></rss>

