<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post1876782392475655422..comments</id><updated>2010-08-12T07:41:23.276-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Forensic Practical</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/1876782392475655422/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-43393367643736123</id><published>2010-08-12T07:41:23.276-07:00</published><updated>2010-08-12T07:41:23.276-07:00</updated><title type='text'>Oh and BTW, for anyone who is still interested, yo...</title><content type='html'>Oh and BTW, for anyone who is still interested, you CANNOT just drag and drop this .E01 file into EnCase. &lt;br /&gt;&lt;br /&gt;In order to add this evidence, you have to select Add Device -&amp;gt; then on the left column Under Sources, right-click on Evidence file, and select New. A menu will come up, and from here drill down to the folder where the .E01 file resides. Continue to click next and EnCase will finally add this evidence and populate the directory structures.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/43393367643736123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/43393367643736123'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1281624083276#c43393367643736123' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-587299041'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5811151962206918928</id><published>2008-01-21T06:19:00.000-08:00</published><updated>2008-01-21T06:19:00.000-08:00</updated><title type='text'>the network dump shows that compromised host open ...</title><content type='html'>the network dump shows that compromised host open three way handshake to other host, then after the ACK from other hsot answers with a new SYN asumese that not receive the ACK package, so pther host send another ACK, but compromised host leaves hanshake get down: it seems be a port scanning.&lt;BR/&gt;I don't understand why in second steep of three way handshake other host response with ACK=1+SYN=0 and not with ACK=1+SYN=0, as expected.&lt;BR/&gt;&lt;BR/&gt;I convert encase image in dd image with FTK Imager, then use some anti-virus:&lt;BR/&gt;avast identify Win32:Rizo-E ( a trojan) in WINDOWS/system32/inetsrv/rpcall.exe&lt;BR/&gt;f-prot identify:&lt;BR/&gt;[Found possible security risk]  RESET5SETUP.EXE-&gt;(PEBundle)-&gt;(PEBundle)-&gt;(PEBundle)-&gt;(PEBundle)-&gt;(PEBundle)-&gt;(PECompact)&lt;BR/&gt;[Found downloader] WINDOWS/system32/reset5.dll&lt;BR/&gt;ClamAV on Helix v.1.9 (updated) identify anythings.&lt;BR/&gt;In event log I did't see anythings of strange.&lt;BR/&gt;I'think strange conduct of compromised host my be caused from those malware.&lt;BR/&gt;It may be usefull check internet navigation, to see if user visit some dangerous site, and virtualize compromised host to check if malware may be provenence of that.&lt;BR/&gt;I treat this test on my blog (http://www.denisfrati.it/?p=286) and you can read about it in english here&lt;BR/&gt;http://translate.google.com/translate?u=http%3A%2F%2Fwww.denisfrati.it%2F%3Fp%3D286&amp;langpair=it%7Cen&amp;hl=it&amp;ie=UTF-8&lt;BR/&gt;I apologize for my bad english.&lt;BR/&gt;see you</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5811151962206918928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5811151962206918928'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200925140000#c5811151962206918928' title=''/><author><name>denis</name><uri>http://www.denisfrati.it</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1163244105'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2514254877247602758</id><published>2008-01-20T21:24:00.000-08:00</published><updated>2008-01-20T21:24:00.000-08:00</updated><title type='text'>Cheers Lance, I've been looking for such an image ...</title><content type='html'>Cheers Lance, I've been looking for such an image for a while.  Hope you're feeling better after your Hong Kong trip.&lt;BR/&gt;&lt;BR/&gt;Darren</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/2514254877247602758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/2514254877247602758'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200893040000#c2514254877247602758' title=''/><author><name>darrencerasi</name><uri>www.i-analysis.com.sg</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1473130803'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-881907250969917257</id><published>2008-01-19T21:04:00.000-08:00</published><updated>2008-01-19T21:04:00.000-08:00</updated><title type='text'>Hogfly - sorry I replied earlier via mobile, but i...</title><content type='html'>Hogfly - sorry I replied earlier via mobile, but it didn't go through for some reason. I am not really trying to get around any licensing/distro restrictions. It is an EnCase evidence file of an operating system for forensic analysis, not for any other reason.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/881907250969917257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/881907250969917257'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200805440000#c881907250969917257' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3146211529868875360</id><published>2008-01-19T18:23:00.000-08:00</published><updated>2008-01-19T18:23:00.000-08:00</updated><title type='text'>BTW, upload reset5setup.exe to www.virustotal.com ...</title><content type='html'>BTW, upload reset5setup.exe to www.virustotal.com and let it analyze it.&lt;BR/&gt;&lt;BR/&gt;Or check out this permalink: http://www.virustotal.com/analisis/21f95dfa1f10afe4ea2a581e2e34f599&lt;BR/&gt;&lt;BR/&gt;"Server_2003_Activation_Crack.EXE"</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3146211529868875360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3146211529868875360'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200795780000#c3146211529868875360' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-275250164'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3887279793569507219</id><published>2008-01-19T18:21:00.000-08:00</published><updated>2008-01-19T18:21:00.000-08:00</updated><title type='text'>"Microsoft Streaming Service Proxy"</title><content type='html'>"Microsoft Streaming Service Proxy"</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3887279793569507219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3887279793569507219'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200795660000#c3887279793569507219' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-969153159'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9081254410190154607</id><published>2008-01-19T14:54:00.000-08:00</published><updated>2008-01-19T14:54:00.000-08:00</updated><title type='text'>Can you elaborate or provide any theories you may ...</title><content type='html'>Can you elaborate or provide any theories you may have? Anything else of interest?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/9081254410190154607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/9081254410190154607'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200783240000#c9081254410190154607' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5677185997574009780</id><published>2008-01-19T14:29:00.000-08:00</published><updated>2008-01-19T14:29:00.000-08:00</updated><title type='text'>Check out reset4setup.exe in the image.</title><content type='html'>Check out reset4setup.exe in the image.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5677185997574009780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5677185997574009780'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200781740000#c5677185997574009780' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1708035518'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5863542921028965747</id><published>2008-01-19T13:16:00.000-08:00</published><updated>2008-01-19T13:16:00.000-08:00</updated><title type='text'>Not to be a pain..but how did you get around licen...</title><content type='html'>Not to be a pain..but how did you get around licensing/distribution of a complete operating system?  I've been trying to get together ideas for making my honeynet available for live analysis practicals but licensing is always a blocking issue.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5863542921028965747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/5863542921028965747'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200777360000#c5863542921028965747' title=''/><author><name>hogfly</name><uri>http://www.blogger.com/profile/00741773109962883616</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-212062349'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3132447929638419731</id><published>2008-01-19T13:13:00.000-08:00</published><updated>2008-01-19T13:13:00.000-08:00</updated><title type='text'>Hogfly - yes, its a complete WinXP Home system</title><content type='html'>Hogfly - yes, its a complete WinXP Home system</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3132447929638419731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3132447929638419731'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200777180000#c3132447929638419731' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3326368235997391384</id><published>2008-01-19T13:02:00.000-08:00</published><updated>2008-01-19T13:02:00.000-08:00</updated><title type='text'>Lance,&lt;br&gt;I'm curious...I haven't downloaded the i...</title><content type='html'>Lance,&lt;BR/&gt;I'm curious...I haven't downloaded the image yet but is the Encase image a complete XP image?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3326368235997391384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/1876782392475655422/comments/default/3326368235997391384'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical.html?showComment=1200776520000#c3326368235997391384' title=''/><author><name>hogfly</name><uri>http://www.blogger.com/profile/00741773109962883616</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-1876782392475655422' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/1876782392475655422' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-212062349'/></entry></feed>
