Tuesday, May 11, 2010

BackTrack R1 Dev Public Release is out!

I notice that the creators of BackTrack have released "BackTrack R1" version.  I didn't read much fanfare about the "unofficial build", but the improved drivers, updated kernel and other programs updated make the D/L worth a try.  It appears that many changes are geared towards addressing hardware issues.

Friday, April 30, 2010

Symantec Internet Security Threat Report (April, 2010)

Symantec has published their Internet Security Threat Report - both the Internet Security Threat Report: Volume XV: April 2010 and their Executive Summary.  Their annual reports confirms many of the threat vectors we've heard about over the previous months including PDF documents, Active X, web-based attack, etc.  Included is browser comparison, and more definitive information related to hacking, phishing, spam and botnets.

I have been looking for information which can be added to a presentation that I can present to various C-Level Executives.  Realizing that the focal points of said presentation is inevitably different than that directed at mid-level managers, I found such information within this report.  For example, on Pg. 48 of the full document, there is a bar graph detailing New malicious code signatures from 2002 - 2009.  The significance is obvious when you look at the graph.  The question is however, can we translate this trend into additional resources to enhance IT/Information Security within an organization?

Thursday, April 22, 2010

Mac OSX Forensics becomes "The Apple Examiner"

For the last few years, MacOSXForensics.com has been a continuing reference source for my Mac-based forensic investigations.  The website has now changed names, and moved to The Apple Examiner Website.  The site is very nicely laid out, easy to understand and contains information on the newest of Apple technology.  I see a new area on iPhone/IPad/IPod.


I've been analyzing some iPhones lately, and instead of focusing on the (logical) information parsed out by Cellebrite and XRY, I've been throwing the images into FTK and EnCase.   FTK does a very good job parsing out the PLISTS for examination.  If you're more partial to EnCase, there is a PLIST parser on the Guidance Website (created 03/2010 by Simon Key) which can be downloaded from here  (you'll likely need an account to log into the Support Portal.)  Once these PLISTS have been parsed out, you cannot imagine the information forensically available within an iPhone.  I'm doing up some screenshots of how to bring the Physical Image into FTK and EnCase to preview it (you have to change a byte).  Of course, I maintain the original, and flip the byte on a copy.

Check out Ryan and Dave's website.  If you're interested in Mac Forensics, you HAVE to bookmark this one.

Monday, April 5, 2010

MoonSols Windows Memory Toolkit

Matthieu Suiche has "made the move in a new direction" and created a new website and toolkit. His new site/company is MoonSols.

Matthieu states:

MoonSols is releasing his first product called "MoonSols Windows Memory Toolkit". MoonSols Windows Memory Toolkit is the most advanced toolkit for Windows physical memory snapshot management.

MoonSols Windows Memory Toolkit had been designed to deal with Microsoft Windows hibernation file (from Microsoft Windows XP to Microsoft Windows 7 in both 32-bits and 64-bits (x64) Editions), Microsoft full memory crashdump (in both 32-bits and 64-bits (x64) Editions), and raw memory dump files (from memory acquisition tools like win32dd or win64dd, or Virtualization application like VMWare). Moreover, MoonSols Windows Memory Toolkit also contains new version of win32dd and win64dd.
Two versions are available - Community (free) and Professional (cost).

Matthieu's WinDD tool has been part of our lab's Incident Response toolset for almost 2 years now. I expect that testing of his toolset will be equally as effective as WinDD.

The continued R&D and commitment of persons like Matthieu (and several others) continue to move our profession forward - almost at a rate that is difficult to keep up with :)

Saturday, March 27, 2010

Windows Memory Analysis - EnScript

I recently tried an EnCase EnScript called "Memory Forensic Toolkit". The tool is used as any EnScript is used, and uses the processes run in Volatility however, within the Windows EnCase environment. The download has three distinct directories for the various Windows OS versions it supports (XP, Win7 and Server2003). From some basic testing, so far the EnScripts (13 or so for each OS Version) have worked as anticipated. My tests using the EnScripts with Vista - not so good (although it does not claim to support Vista). Newest version 1.69 was just released today.

The site is in primarily Japanese CCI: Computer Crime Investigation and appears to be run by Takahiro Haruyama.

Next up...comparing the EnScript results with those produced by running Volatility.

Friday, March 26, 2010

SIFT v2.0

I have been taking SIFT 2.0 for a test drive over the week and notice that the official release has been posted to the SANS Computer Forensics website. The amount of information on this release is incredible. It is quite apparent that Rob Lee has spent considerable time and thought in this update. You will need an account with SANS to be able to download.

There is also a detailed SIFT Tool Listing (download link). The document is very detailed and for those who may be new to SIFT VM appliance, the first few pages may help you get started. An example of the robustness - Volatility has over 50 plug-ins, many programs for Timeline Analysis, artifact and Registry analysis, Data Carving...and the list goes on.

What are you telling your investigators/officers?

We had some discussion over the last few weeks about the ability (or inability) of non-forensically trained investigators to assist in the collection of digital evidence at crime scenes.

As we see the field of forensics adopting a stronger move towards live acquisitions (including RAM, certain (un)scripted processes and eventually the hard drive), we are wondering what we should be tasking our investigators to do. Our unir simply cannot assist at every scene. Too many cases and far too wide a geographical area. Is pulling the plug in these circumstances still acceptable? Should we be moving to a "Cofee-type" procedure where little training is required. One significant challenge is the numerous different areas in which our officers must acquire and maintain skills (in traditional policing areas). Can we really expect them to rise to a new level??

Any comments or suggestions would be welcome.

Wednesday, March 17, 2010

Knew it was going to happen....

It finally happened. Those "old school" forensic practices caught some colleagues while seizing a Dell laptop. The old practice of pulling the plug led to the drive being inaccessible when they returned to the lab due to a bios password being present. The actual hard drive was removed but various imaging techniques did not work. That being said, RAM had been imaged and a password was located in RAM (for an email account). Luckily the password was the same and we were able to access the drive.

One more reason to hasten our move to 100% live imaging at the scene; grabbing both the RAM and the drive. One more reason to get F-Response for everyone in the office!

FYI...once we had the password, we booted the laptop (with hard drive enclosed) using Helix Pro. Using Helix, we imaged the drive to a RW-mounted wiped external USB drive. Worked like a charm.

Good guys 1 - Bad guys 0 (but just barely).

Wednesday, November 25, 2009

You just gotta think outside the box...the logical box that is!

I recently ran across an article published by well-knowned security researcher Joanna Rutkowska. She prepared a very detailed article on a new attacked she calls the "Evil Maid Attack" - named after a possible "vector of attack." An attack can be launched by an infected USB thumbdrive (full .img image available on the site), which is inserted into a powered-down laptop. The laptop is booted to the USB drive, and after 1-2 minutes, the hard drive is infected with the "Evil Maid Attack." The next time the owner boots his laptop and enters his encryption password, it is captured for retrieval. The attacker simply boots the laptop a second time, again with the infected USB thumbdrive, and the password is displayed.

A full explanation for how this attack works is on her website. (hint...first 63sectors of Physical drive, locates TrueCrypt loader, launches attack to hook the TrueCrypt function that asks for the password.....)

When the image is run against anti-malware programs, the following results were obtained:
VirusTotal 1/41 (Sophos)
Jotti's 1/21 (Sophos)

Like I said.....you have to think outside of the "logical box".

Friday, November 13, 2009

Internet Evidence Finder - new release and more

Jad from JadSoftware has released v3.0 of Internet Evidence Finder. While the program has now made the move to commercial, I doubt you'll find another tools that is as effective at parsing out artifacts as does this program. The pricing ranges from $29.99 for a single licence, to $129.99 for an unlimited site licence. In the field of forensics, we pay more for add-ons.


I'm not sure where Jad finds the time, but he has added several more features. Included in the 10 new features are Limewire® ver 5.3.6 Search History, Limewire.props files, IE8 InPrivate/Recovery URLs, Yahoo!® Messenger Group Chat, Yahoo!® Webmail email, Hotmail® Webmail email, AOL® Instant Messenger chat logs, Messenger Plus!® chat logs, MySpace® chat, Bebo® chat. He includes an index.htm page to index the some the searches and made several tweaks to the existing searches. The program is FREE for Law Enforcement use (thanks Jad!).

On top of that, he has created another program called Facebook JPG finder (v1.0.0). The program will search for images, and provide details about the date/times of the file, MD5, location, and possible ID/Profile name. He qualifies the program by indicating that the user must realize that the program locates the photo and cannot guarantee the photos are from Facebook.

Oh yeah...those in Law Enforcement and may be looking for an "Incident Response/Live Analysis" scripted tool, head on over to NRDFI.net . They have been kind enough to post the law enforcement version of DriveProphet for free use. I realize that those who consider themselves "masters" of all, this program (an in fact Cofee) can be defined as scripted tools that simply automate the use of other freely available tools. You know WHAT...we aren't all as gifted as others....we occasionally need formatted and trusted tools which we are confident will do the job, in a prompt and efficient time, and punch out a nicely formatted report for our investigations. Maybe it's just me, but I simply cannot recall the commands and switches for 20-50 commands, which I like to run during incident response. FWIW....