|
EH-Net
|
|
May 19, 2013, 07:26:47 PM
|
Show Posts
|
|
Pages: [1] 2
|
|
4
|
EH-Net / Calendar Of Events / Re: Notacon 6
|
on: March 17, 2009, 12:21:51 AM
|
Just reserved my hotel room for Notacon, myself (@punkrokk) and @antitree are both going to wardrive there Anyone from EH.net gonna be there? 
|
|
|
|
|
6
|
Features / Book Reviews / Re: Packet Analysis book suggestions
|
on: March 17, 2009, 12:09:15 AM
|
I have been looking for a good book about packet analysis. I am really not looking for a book about a specific packet sniffing tool. I want one that really digs into analyzing packet contents. I have been considering getting "Practical Packet Analysis: Using Wireshark to Solve Real-World Network Problems" but I am not sure it is what I want. Has anyone read it? Is it any good?
I have not read the above book, but I have read and used Network Intrusion Detection, by Northcutt and Novak. It has a lot of great sections on Packet Analysis, some excellent tcpdump examples, as well as a very well rounded analysis of TCP and it's weaknesses. It goes into some stuff in more detail than Hacking Exposed in some cases (although the book is really on a different topic) and has dozens of example packet captures with detail analysis and explanations. I use it to teach a Network Forensics and Security class.
|
|
|
|
|
10
|
Ethical Hacking Discussions and Related Certifications / Forensics / Archiving files without changing the MAC timestamps
|
on: February 18, 2009, 10:56:08 AM
|
|
Hi,
So when I was at shmoocon, I was talking with some people about my thesis: Role Based File Archiving. The main problem I ran into with my research was that I couldn't find a good way to -- when archiving files -- to provide integrity or non-repudiation to the MAC timestamps (Modified, last Accessed, Created).
The above being said, my programmatic work around was to read the time stamps before copy, but then rewrite them after copy. The problem is that I don't want to have to do this, and this opens up a potential "weak link" in an archiving system especially in court if I can prove you can change the MAC stamps when archiving.
My question is: Does anyone know of a programatic way to archive files and folders in NTFS and ext3/4 that will truly archive the file (provide transparent archiving, for legal purposes... or just to know that it hasn't/can't be modified without an audit trail) for non-repudiation purposed and/or integrity purposes?
Thanks!
-=punkrokk=-
|
|
|
|
|
13
|
EH-Net / Calendar Of Events / Re: ShmooCon 2009
|
on: February 17, 2009, 07:31:04 PM
|
|
Hey.... I got to hang with some friends (Brian and Ryan) as well as meet CG, oneeyedcarmen, and many other interesting peeps.... quite a few from the Chicago Hacker scene, and the chicago 2600... I enjoyed the FastTrack preview, and the shmoo release of Backtrack 4 beta. I wish it was longer!!! I also was able to pick up a few good books from NoStarch, as well as meet Paul and Larry from pauldotcom security weekly... all in all a great time!
Anyways, can't wait for Chicagocon in May!!!
-punkrokk
|
|
|
|
|
Loading...
|