Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 34 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
January 08, 2009, 04:05:22 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
  Home Help Calendar Login Register  
  Show Posts
Pages: 1 [2]
16  Ethical Hacking Discussions and Related Certifications / Other / Re: ophcrack on: May 15, 2008, 02:24:39 PM
Does the Ophcrack CD work in other PC's still?  Can you boot the PC you are having trouble with from another CD, say Ubuntu or Knoppix?
17  EH-Net / ChicagoCon 2008s / Re: Podcast - Follow the Bouncing Malware LIVE on: May 01, 2008, 09:13:51 AM
I listened to the podcast and followed through with the presentation.  I can see why people rave about Toms courses now.  Very Enjoyable.

I did a blog post on malware hunting ( http://synjunkie.blogspot.com/2007/11/hunting-malware-in-windows.html ) a few months back but compared to Tom's stuff it looks like I need to go back to the drawing board.


18  Ethical Hacking Discussions and Related Certifications / Forensics / Re: "New" tool on: April 30, 2008, 06:12:05 PM
Right. Missed those.

I need to read more carefully before posting I guess.
19  Ethical Hacking Discussions and Related Certifications / Forensics / Re: "New" tool on: April 30, 2008, 05:30:26 AM
From the description of the tool it doesn't sound very different from what it's possible to acheive with the U3 switchblade or hacksaw (see hak.5 forums).  obviously the tools within those kits are aimed at the attackers and are already available and in use.  The forensic tools can easily be ported over from a incident response toolkit that is also available.

I would suggest that this tool is nothing new and once again the defenders are playing catchup.
20  Ethical Hacking Discussions and Related Certifications / Forensics / Re: "New" tool on: April 29, 2008, 05:51:53 PM
wouldn't it depend on how the USB drive was set up. Surely if the partition with the tools on was set up like the CD partition (read only) on the Hacksaw (U3) for example , and the other partition was to log the results of running the tools. It wouldn't be that dissimilar to running tools from a CD.

I know a registry key would be created for the USB device but the first responder  or LEO would be documenting the process and tools in use anyway so that would explain that.
21  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Google History on: April 18, 2008, 04:49:30 PM

are there any proxy server logs or web filter logs that you can cross reference the sites through. that may help you place the individual at the PC at the time.

Whats also useful if you do have logs is looking at what else the  IP did at about the same time.  did the IP visit a myspace page or a gmail account at the same time? if so can you tie some activity to an individual.

One tool I would like to suggest is RegRipper by Harlan Carvey. Its a brand new tool and I'm yet to give it a good run-through yet, but it might help with the visited Urls. Look on sourceforge for it.  And please give Harlan feedback on bugs etc...

Regards

SynJunkie
22  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Data Recovery.... on: April 18, 2008, 04:36:09 PM
Thanks.

It's a weird coincidence that data recovery was something I was focusing on in that recent blog post.
23  Ethical Hacking Discussions and Related Certifications / Network Pen Testing / Re: DNS Allocation Problem on: April 17, 2008, 03:35:45 PM
Hi,

This post is a bit old so 'm not sure if it still relevant to you, but a nice tool to confirm your details of shared hosting is the "hostnames on IP" under Nameserver on www.serversniff.net

Regards

SynJunkie
24  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Data Recovery.... on: April 17, 2008, 03:05:42 PM
Hi Loic

i was just browsing the forums and i saw your post so I thought I would register as i might be able to help.

If I had the same problem as you i would do the following.

1. I would boot into a distro such as backtrack or any other that has DD.  using DD I would create a image of the disk onto the external drive. 

dd if=/dev/hda of=/mnt/usb/hdd.img  (or whatever the external disk is mounted as).


2. once I have that image i would use a tool such as foremost to run through the image and pull alot of the files out.

foremost -v -o /home/loic/dump /mnt/usb/hdd.img

This should pull many filetypes out and place them in folders within a folder called dump (create this folder before you start) in your home drive.


Or you could boot into backtrack, mount the external drive as say /mnt/usb and then run foremost direct to that without creating the image.

foremost -v -o /mnt/usb/dump /dev/hda

This would be quicker than ceating the image first obviously.

I have just put a post up on my blog about simple data recovery at http://synjunkie.blogspot.com

I hope this might have been of use to you.
Pages: 1 [2]
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.052 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.