Introductie

Het komt steeds vaker voor dat de hulp wordt ingeroepen van digitaal forensisch onderzoekers. Onderzoek van pc's, netwerken, mobiele telefoons en aanverwante media vragen diepgaande kennis. Naast deze kennis zijn de tools voor het achterhalen van bepaalde gegevens en de interpretatie van gegevens zeer belangrijk. Deze blog zal proberen oplossingen aan te dragen voor hulp bij digitaal onderzoek. Verschillende tools passeren de revue, interessante artikelen worden verder uitgediept, links naar andere forensische sites en handleidingen ter ondersteuning komen aan bod.
ip information

zaterdag 12 april 2008

New Software lets Law Enforcement Patrol Peer-to-Peer Networks

OAK HILL, West Virginia. - March 28, 2008 – Zemerick Software, Inc. has announced
the availability of free computer software that lets law enforcement patrol peer-to-peer file sharing networks. This software, called Forensic P2P, joins other free software for law enforcement collectively known as SPEAR Forensics.
Forensic P2P lets officers search the Gnutella peer-to-peer network for files, such as music, image, and video files. Forensic P2P has all the features of popular file-sharing programs such as Bearshare and Limewire but with extra features designed specifically for use by law enforcement. Forensic P2P can integrate with the officers’ database of known illegal files to quickly highlight known illegal files in search results. Also, Forensic P2P can show the IP address and internet service provider information of users that are sharing files on the network.
Forensic P2P requires Windows XP or newer and is available for free to members of law enforcement at www.spearforensics.com.

zaterdag 5 april 2008

Wardriving

Afgelopen week heeft het consumentenprogramma "Kassa" maar weer eens gewaarschuwd om uw draadloze netwerk goed te beveiligen. In deze aflevering van 29 maart wordt getoond hoe gemakkelijk het is om draadloze netwerken te vinden die helemaal niet beveiligd zijn, of nog gebruik maken van de niet zo veilige WEP encryptie. Deze is, zoals te zien is, binnen enkele minuten te kraken.

In de studio gaat een juriste vervolgens in op de wet die sinds 2006 in Nederland geldt voor het misbruik van uw verbinding. Is het nu eigenlijk verboden om gebruik te maken van het onbeveiligde netwerk van de buren of niet?

dinsdag 1 april 2008

CaseNotes

The last months I was looking for a manner to write things down. I've tried different programs for writing a forensic report. Surprisingly somebody, John Douglas, released a program in juli 2007 which does all the things I was searching for: CaseNotes from QCC Information Security


The purpose of CaseNotes is to provide a single lightweight application program to run on the Microsoft Windows platform to allow forensic analysts and examiners of any discipline to securely record their contemporaneous notes electronically.




The main features are:

- Flexible configuration of case meta-data (case details, like the reference number, etc.)
- Secure “write-once, read-many” style of case note data capture
- Full audit trail of case note data entry and meta data edits in a self contained log
- Tamper evident storage of data using internal MD5 hashes for all data entered
- No use of heavy database technologies – all you need is the program and your case file
- Use of AES 512bit encryption (optional) to further secure data in sensitive cases
- Storage of configuration information in a user editable text based .ini file
- Support for running multiple copies of CaseNotes at the same time
- Tested and works in languages other than English (Japanese, Russian, Greek, Italian, ...)
- Supports changing time zones and any standard Windows date or time format
- Tested on Windows XP, Server 2003 and Windows Vista. (sorry if you use a Mac)
It’s free! That means no dongles and no restrictions on how many copies you use!

vrijdag 28 maart 2008

Farid founds ‘digital forensics’

Paper article By Michael Coburn from The Dartmouth Staff

With $100 Photoshop software and a little training, computer users can drastically alter digital photos, shedding a few pounds from a high school prom picture or removing a tumor from a medical image. While manipulated photos can be very difficult to detect, Hany Farid, associate chair of the computer science department at Dartmouth, is one of the first people to develop a method to find alterations in digital photographs.

woensdag 26 maart 2008

CTRL+C

Although an old problem, its still alive and can be (mis)used! Ctrl+C may be the most important work we do everyday. But it's not a very safe thing to do. Read on to know why. What happens when you press Ctrl+C while you are online. We do copy various data by Ctrl + C for pasting elsewhere. This copied data is stored in clipboard and is accessible from the net by a combination of Javascripts and ASP. This is called clipboard hack problem.

Do not keep sensitive data (like passwords, credit card numbers, PIN etc.) in the clipboard while surfing the web. It is extremely easy to extract the text stored in the clipboard to steal your sensitive information. Forward this information to as many friends as you can, to save them from online frauds!

It is true, text you last copied for pasting (copy & paste) can be stolen when you visit web sites using a combination of JavaScript and ASP (or PHP, or CGI) to write your possible sensitive data to a database on another server.

The Clipboard hack is done by the following Source Code:



How to safeguard yourself from Clipboard Hack Problem?

To avoid clipboard hack problem, do the following:

1.Go to internet options->security.
2.Press custom level.
3.In the security settings, select disable under Allow paste operations via script.

Now the contents of your clipboard are safe.

Interestingly, this hack works only on internet explorer, and not on Mozilla Firefox browser. Please forward this article to as many friends as you can to make them aware of this issue with CTRL+C.

NOTE : HERE THE HACK APPLIES TO ALL METHOD OF COPY OR CUT
LIKE CTRL + INSERT / SHIFT + DEL / BY RIGHT CLICK COPY OR CUT

donderdag 27 december 2007

Adverteren naar het onderwerp...

Dagelijks heb ik een aantal vaste sites die ik langsloop. Tegenwoordig kan je daarbij geholpen worden door je "eigen" startpagina, iGoogle. Vandaag zag ik bij de nieuwsitems op FOK!frontpage die ik vanuit mijn iGoogle aanklikte een artikel over een vrouw die door een onbekende man voor de trein is geduwd. Diep triest dat dit soort dingen gebeuren. Echter worden de pagina's van FOK ook gevuld met advertenties. Van de Google advertenties weten we dat deze gerelateerd zijn aan de website waarop ze staan, maar dat het soms ook averechts kan werken toont de onderstaande afbeelding aan.



In dit geval geen "gerelateerde" advertentie van Google, maar wel een advertentie van Ditzo, een verzekeringsmaatschappij. In het flashfilmpje wordt een nietsvermoedende man platgewalst door een sloopkogel. De advertenties worden weliswaar random onder de artikelen gezet, maar het lijkt mij dat deze niet helemaal gepast is...

Daarnaast kan je je afvragen in hoeverre op deze manier adverteren effectief is. Op het moment dat je de advertentie aanklikt,zal bij een aantal mensen de informatiebalk tevoorschijn komen met de melding dat er een pop-up geblokkeerd is.



De mensen die dan toch nog de advertentie willen zien kunnen vervolgens de informatiebalk aanklikken, waarna ze kunnen kiezen voor pop-ups tijdelijk toestaan...



Helaas zal de pagina zich dan verversen. Grote kans dat de random gekozen advertentie pas weer verschijnt nadat de pagina meerdere malen is ververst. In mijn test duurde het in 1 geval wel 20x voordat de betreffende advertentie weer verscheen. Helaas... na het aanklikken van de advertentie verscheen weer de informatiebalk waarin ik de pop-up tijdelijk toe kan staan. Natuurlijk kan ik kiezen voor de andere optie "pop-ups van deze website altijd toestaan", maar wil ik dat wel? Hiermee zadel ik mijzelf op met ongewenste popups van deze "toegestane" website. Daarnaast loop ik het risico dat de beveiliging van mijn pc aangetast wordt. Het ging mij tenslotte alleen maar om die ene advertentie en niet die honderden anderen...

Challenge yourself...

everybody goes on about reading, yes reading articles is important, but it is much better if you try and find it out yourself through experiments, you may find something nobody has discovered yet, because you didn't just follow what somebody wrote and you approached it with an open mind.

"take the stairs instead of the elevator"

its a metaphorical statement for finding something out. if you enter a building and need to go up you look for the stairs or elevator. imagine as you learn you rise up.

you could take the elevator, this will take you up the quickest. all you have to do is find the right one and push a button. however you may miss something in your apparent rapid ascent and not understand how you got there.

the alternative is the stairs. it will take you longer to get there and will require more time and effort. however each step will build on the previous ones, giving you a solid foundation to higher levels. you may also notice some interesting things on the way.

there is another way. do not rise, let the rise descend to you. this can by done by changing your reality so that you believe you are further up. if you believe it strongly enough it will "appear" to be no different from actually being there. if you can also change nearby entities' realities then they will think you are on their level. however it is a pretence and could be adverse if sustained for time. there is no subsitute for true first person experience.

thus the "mini challanges" were formed. simple and not so simple tasks for you to try. there is no race or rank and you are not graded on how you do. it is up to you to do the best you can.the challanges

use a resource hacker to modify an image and text string of a program.

save a file to your hard drive - delete it (also in recycle bin) using windows (not secure 3rd party delete) and then recover it using an undelete program or hex editor.

setup a test webserver to be accessed either on your local network or the internet, include ftp/ssh for user account upload. setup .htaccess on a folder. run a server sided script like asp/php/pl.

install a (smallish) program and record all of its file and registry entries and modifications.

tryout a different shell for your operating system.

setup a 2kpro box(no other bootable partitions or boot.ini edited) with ntfs - bios(pwd protected) set to boot from harddrive. set a (short) admin password and shutdown. get local admin access without using your memory of the password. findout what the password was.

backup a dvd and cd you own to divx (audio/video synced) and mp3 respectfully.

make a usable crosslinked piece of network cable.

hide a file/some data (atleast 512kb) somewhere on your hard drive.

crack a (shortish) des/md5 password with john the ripper.

check your email (not webmail) and send a message using telnet.

use a packet capturing program to see what information is exchanged when you connect to a website, when you check your email.

install/use pgp and exchange signed/encrypted email with a friend.

findout the manufactures, model numbers and main specifications of the major components in your computer.

signup for a shell account and try/use some of the services.

send a spoofed arp reply to a remote computer

do a trace on a domain name, find the ip, find out all the connections to get there, who is it hosted by, who was it registered by and under which accredited registrar.

compile some code into an exe, either written by you or somebody else, if the latter modify the code slightly, to add/remove/optimize a feature.

connect to an irc server and use/learn at least 10 /commands.

write a couple of html or wap web pages including images using a text editor. if html, include the style and script tags.

browse the internet using a/multiple proxy(s).

use nmap(nt) to do a scan on a remote computer.

install a rule based firewall - delete all default rules and write your own. test your security with an online scanner and/or local network scans.

install a linux distro either on a clean disk or dual boot.

woensdag 21 november 2007

Let op wat u print...

De GHDB, oftewel de Google Hacking Database (http://johnny.ihackstuff.com/ghdb.php), is een aardige bron om eens een avondje aan te besteden. Er staan zoekopdrachten voor Google in die wat andere resultaten geven dan die je normaal gesproken kan verwachten. Alhoewel er al een aardig aantal queries in de database zijn terug te vinden, is deze natuurlijk nooit volledig. Hieronder mijn bevindingen met betrekking tot een querie die nog niet in de GHDB staat, maar er ongetwijfeld vroeg of laat in zal komen.

De opdracht “web/user/nl/websys” levert 2 resultaten op. Eventueel kan nl veranderd worden in een andere landcode om meer resultaten te krijgen.



De twee links in dit geval wijzen beide naar hetzelfde IP adres. Het aanklikken van deze link brengt je naar een pagina die afkomstig is van een printer of multifunctional. Door het adres aan te passen, en alleen het ip adres te laten staan kom je op de frontpage terecht.



Zonder in te hoeven loggen kunnen diverse opties van de IS 2127 bekeken worden. De opties onder de tab “> Opdr. -> Printer -> Historie” Laten zien dat er actief gebruik wordt gemaakt van deze machine.



Toch wel nieuwsgierig geworden welke instantie zijn machines op deze wijze aan het internet heeft gekoppeld, heb ik een scan uitgevoerd op de iprange. Dit levert het volgende op:



Klaarblijkelijk betreft het hier de UvA, oftewel de Universiteit van Amsterdam. Sommige ip adressen leveren interessante gegevens op. Gegevens die je niet open en bloot op het internet wil zetten. Via de optie Document Server kunnen opgeslagen gegevens worden opgevraagd zonder op het apparaat in te hoeven loggen. Faxen, kopieen en prints blijven soms langer bestaan dan wenselijk is. Een aantal van deze apparaten beschikt namelijk over een harddisk. Organisaties schaffen deze machines aan vanwege het efficiente gebruik, echter wordt vaak vergeten dat ze afgeconfigureerd moeten worden nadat ze ook zijn neergezet...

De CERT van de Universiteit van Amsterdam is inmiddels geinformeerd. Uit de reactie van Jeroen Roodhart, lid van het CERT team, blijkt wel dat het inderdaad niet de bedoeling is geweest: "Dank voor uw melding, hiervoor is een call aangemaakt met call-id CERT-UvA#001255. Dit kan inderdaad niet de bedoeling zijn en wij zullen zo snel mogelijk deze misconfiguratie verhelpen."

woensdag 31 oktober 2007

The Recycle Bin

The Recycle Bin
Functionality is straightforward. It was developed as a way to throw things away without really losing them because they didn't really mean to throw it away.

Similar to regular file deletion, the OS makes the file invisible to the original directory but it won't zero out the cluster chain. It adds a directory entry to the Recycle Bin directory and renames the file. If you delete John.jpg, you'll now have a df000010.jpg in the trash can that is associated with the name John.jpg and the path f:/My Pictures/Yadda/Yadda/John.jpg.

From a forensics perspective, it is obvious that stuff gets into the trash can because the user put it there. On Windows Me/9x machines, the trash can is a community dump. All accounts on a machine share a single trash can. This is a big security problem because you can have something you don't want someone else to see and in the community trash can anybody with an account on the machine can get to it.

On later Windows boxes, you can tell which trash can is whose by looking in the SAM file.

INFO2 Structure
"Deleted" file path
"Deleted" file index number
"Deleted" file drive location
"Deleted" file date and time
"Deleted" file physical size

The recycle bin tracks only user deleted files. It does not track stuff that the OS deletes, such as temporary Internet files and deleting things with a shift-click.

The trash can doesn't hold stuff deleted from removable media or networks. The time stamps will be "machine active time bias" relative.

FAT vs. NTFS Recycle Bins

FAT: 280 byte INFO2 records and all users on the machine can access filesNTFS: 800 byte INFO2 records and the bin is user-specific based on SID.

The recycle bin has its own Master File Table record for deleted files. FTK is able to show that a file has been removed from the bin and all of the INFO2 data for removed files.

When an item is removed from the file, it's not possible to tell whether it was deleted from the bin or moved back out of the bin. Both actions have the same result as far as the Recycle Bin is concerned.

The date an item is moved into the recycle bin is a potentially powerful piece of evidence, and that informaiton is stored in the INFO2 data in the trash can.

maandag 15 oktober 2007

Quote

If Sherlock Holmes were alive today, he would surely be a master of computer forensics...

Real Time Visitors !