Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 58 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow Cold boot
EH-Net
May 25, 2013, 04:30:23 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Cold boot  (Read 4939 times)
0 Members and 1 Guest are viewing this topic.
Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« on: June 14, 2011, 01:56:15 PM »

So at my recent SANS 408 Forensics class my instructor told me about a method that him and some others are looking into to see if they can actually pull it off and if they can work with some people to get some software up and running.

He said this is already being looked at by others in the community.

What the cold boot is, is getting the cache of the volitile memory.  The previous thinking was once the computer was shut down the data stored in the memory was wiped immediatly.  Well, that's not always the case as the memory is run on power and that it slowly leaks off and then is gone forever.

This would help with Forensics investigations and such...

What are your thoughts on this.  If there is enough colaboration do you think it would be done?
Logged

Security+, Network+, C|EH, CHFI, CPT
MaXe
Hero Member
*****
Offline Offline

Posts: 669


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #1 on: June 14, 2011, 03:18:14 PM »

What the cold boot is, is getting the cache of the volatile memory.  The previous thinking was once the computer was shut down the data stored in the memory was wiped immediately.  Well, that's not always the case as the memory runs on power and that it slowly leaks off and then is gone forever.

What are your thoughts on this.  If there is enough collaboration do you think it would be done?

There was an article, some time ago about dumping information from the RAM. (Quite some time ago.)
One of them that I found interesting, was freezing the computer down to -271C or something like that, immediately, and thereby somehow preserving the contents, of what was in the ram at the time. (Transportation issue.)

Stealing what's in the (hot) RAM at run-time is of course easier, if the contents aren't encrypted somehow. (I say somehow because everything can work in theory, but in theory a lot cannot work as well  Cheesy )

Anyway, I haven't really played with this, but of course I've heard about it  Smiley

The problem with stealing data from RAM, where the power slowly degrades, is a possible corruption of the data or total loss (of data), when there isn't a sufficient amount of power. This depends on the amount of time used of course.

If it's a transportation issue, steal the contents while the ram is HOT as I already mentioned or hibernate the system xD Either virtually or physically. These are just ideas, and some of it may not work in real life, but I have a great imagination  Smiley
Logged

I'm an InterN0T'er
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.565 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.