Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 27 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home
EH-Net
May 22, 2013, 11:33:48 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1]
1  Features / Dec 07 - Frosty the Snow Crash / Re: [Article]-Frosty the Snow Crash on: March 25, 2008, 09:18:52 AM
Were the winners of this challenge posted somewhere? I can't seem to find it. Just curious. Thanks!
2  Ethical Hacking Discussions and Related Certifications / Forensics / Private Investigator Licence Required for CF on: March 16, 2008, 08:36:53 PM
I was told that Illinois recently made some changes that requires computer forensics that will be used in court to be only done by individuals or companies with private investigator licenses. I can't seem to confirm this through a google search. Has anyone run into this? All I can find is an article from January talking about pending legislation in South Carolina.
3  Features / April 07 - Microsoft Office Space / Re: [Article]-Microsoft Office Space: A SQL With Flair - Answers and Winners on: July 05, 2007, 10:15:47 AM
I could just be blind or having a case of the Mondays, but I can't seem to find a link to the answers...
4  Ethical Hacking Discussions and Related Certifications / Forensics / Re: Forensic write blockers on: July 05, 2007, 12:28:52 AM
It really depends on what you're capturing. PATA? SATA? SCSI (I/II/III)? SCA? 1.8" IDE, 2.5" IDE? USB? Flash? SD? When you get down to it there's no cheap solution. You're likely to spend a lot just to cover the bases.

If you really need to budget then review what your most likely acquisitions are going to be. If you have a lot of legacy systems, it'll likely be IDE. Newer systems, SATA. High Availability servers? SCSI. Then price out one and figure something out for the others.

Some nice little devices that we use are the FireFly (SATA->Firewire) hardware write blocks. They're around US$200. You can find them here http://www.digitalintelligence.com/forensicwriteblockers.php along with other forensic write blockers.

If you want to go the cheapest route, use a linux system with auto mounting disabled and buy some USB or Firewire drive enclosures. If you go this route make sure you create a documented procedure for acquiring evidence and follow it every time. You might even go as far as to record the history of your shell commands as part of your digital case file.
5  Ethical Hacking Discussions and Related Certifications / Forensics / Re: MAC address as evidence on: July 05, 2007, 12:15:17 AM
If the mac address is your only evidence tying the activity to the host then it's likely to be attacked. If you can provide other evidence that can corroborate the system's mac address that would be helpful. For example, if you have history of mac->ip from your switches, network flow logs and time stamps from something like web cache history on the suspect computer that matches the flow log time stamps, it further reinforces that the mac address at the time was valid.

To be honest though, I don't know how that would work out in court as I've never had to testify yet, however it seems to make logical sense.
Pages: [1]
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.063 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.