<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post3274445515536289944..comments</id><updated>2011-05-29T04:59:20.472-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Forensic Practical #2</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/3274445515536289944/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2010036096347494656</id><published>2011-05-29T04:59:20.472-07:00</published><updated>2011-05-29T04:59:20.472-07:00</updated><title type='text'>Hello,

three years later, there&amp;#39;s no writeup?...</title><content type='html'>Hello,&lt;br /&gt;&lt;br /&gt;three years later, there&amp;#39;s no writeup? like practical 1?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2010036096347494656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2010036096347494656'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1306670360472#c2010036096347494656' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1071504581'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4311502377029482969</id><published>2010-07-28T22:30:19.821-07:00</published><updated>2010-07-28T22:30:19.821-07:00</updated><title type='text'>It appears that either VMWARE was used or Castor c...</title><content type='html'>It appears that either VMWARE was used or Castor changed the name of his workstation to connect to a network share which is where the secret files were located. Also it also looks like Castor changed the system time of the workstation perhaps to throw off any IT staff who might be reviewing his computer after his departure. He also deleted the NLTDR file so that his workstation would not boot to try and cover his tracks. &lt;br /&gt;&lt;br /&gt;How am I doing so far?? Am I on the right path?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4311502377029482969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4311502377029482969'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1280381419821#c4311502377029482969' title=''/><author><name>SB</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-403669650'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1411941317204833544</id><published>2008-02-20T19:15:00.000-08:00</published><updated>2008-02-20T19:15:00.000-08:00</updated><title type='text'>The server outage caused an issue with the image, ...</title><content type='html'>The server outage caused an issue with the image, but it is now fixed and you should be able to download it fine now.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1411941317204833544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1411941317204833544'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203563700000#c1411941317204833544' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9101736311972783981</id><published>2008-02-20T14:14:00.000-08:00</published><updated>2008-02-20T14:14:00.000-08:00</updated><title type='text'>I cannot download the image file...</title><content type='html'>I cannot download the image file...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/9101736311972783981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/9101736311972783981'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203545640000#c9101736311972783981' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1340441594'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3364824156192357697</id><published>2008-02-19T14:41:00.000-08:00</published><updated>2008-02-19T14:41:00.000-08:00</updated><title type='text'>Yeah EnCase V6.10 has deleted reg stuff. This is t...</title><content type='html'>Yeah EnCase V6.10 has deleted reg stuff. This is the first pass and there are deleted folders that point to existing items.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/3364824156192357697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/3364824156192357697'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203460860000#c3364824156192357697' title=''/><author><name>nik</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1879559973'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-444819604668279137</id><published>2008-02-18T09:16:00.000-08:00</published><updated>2008-02-18T09:16:00.000-08:00</updated><title type='text'>Now that I'm back at work.&lt;br&gt;&lt;br&gt;http://home.eune...</title><content type='html'>Now that I'm back at work.&lt;BR/&gt;&lt;BR/&gt;http://home.eunet.no/pnordahl/ntpasswd/&lt;BR/&gt;&lt;BR/&gt;He admits to finding details of the registry in a file attributed to an individual with the initials B.D.&lt;BR/&gt;&lt;BR/&gt;There's a link provided, as well as some cleaned up information in the source code for this utility.&lt;BR/&gt;&lt;BR/&gt;Great stuff.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/444819604668279137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/444819604668279137'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203354960000#c444819604668279137' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1934762090'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4193380127032676536</id><published>2008-02-16T12:45:00.000-08:00</published><updated>2008-02-16T12:45:00.000-08:00</updated><title type='text'>I don't have Harlan's book handy, but he mentioned...</title><content type='html'>I don't have Harlan's book handy, but he mentioned an individual who created a utility to boot/blow away a password in the SAM. He also happens to have done the most research on the registry, at least from a code and structure breakdown.&lt;BR/&gt;&lt;BR/&gt;Fascinating stuff, but it looks like the registry contains multiple HK blocks each one a multiple of 4096bytes in size. When items are deleted from the registry, these blocks become available.&lt;BR/&gt;&lt;BR/&gt;Looks like the mounting a registry file in Encase with the 'calculate unallocated space' option checked looks for all these available areas and concatenates them together.&lt;BR/&gt;&lt;BR/&gt;I fortunately get to beta test Encase, and right now there's a new option, kinda like a create folders type thing, that seeks to put some structure in to the deleted registry entries. Great stuff.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4193380127032676536'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4193380127032676536'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203194700000#c4193380127032676536' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1345964058'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4198609528049332948</id><published>2008-02-14T17:08:00.000-08:00</published><updated>2008-02-14T17:08:00.000-08:00</updated><title type='text'>Nik, &lt;br&gt;&lt;br&gt;SID "...682003330-1003" is OWNER whil...</title><content type='html'>Nik, &lt;BR/&gt;&lt;BR/&gt;SID "...682003330-1003" is OWNER while SID "...682003330-1004" is CASTER TROY.&lt;BR/&gt;&lt;BR/&gt;(Security.evt)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4198609528049332948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/4198609528049332948'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203037680000#c4198609528049332948' title=''/><author><name>du212</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1193123875'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5177256036775800893</id><published>2008-02-14T17:01:00.000-08:00</published><updated>2008-02-14T17:01:00.000-08:00</updated><title type='text'>Paul Bobby or Lance,&lt;br&gt;&lt;br&gt;What DOES mounting the...</title><content type='html'>Paul Bobby or Lance,&lt;BR/&gt;&lt;BR/&gt;What DOES mounting the ntuser.dat with the option "Calculate UA Space" (In Encase) do ?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/5177256036775800893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/5177256036775800893'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203037260000#c5177256036775800893' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1296095649'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-9207417995157201757</id><published>2008-02-14T14:54:00.000-08:00</published><updated>2008-02-14T14:54:00.000-08:00</updated><title type='text'>Just some locations I immediately started looking ...</title><content type='html'>Just some locations I immediately started looking in:&lt;BR/&gt;&lt;BR/&gt;a)(Castor)\Ntuser.dat-&gt;Software-&gt;&lt;BR/&gt;Microsoft-&gt;Windows-&gt;CurrentVersion-&gt;&lt;BR/&gt;Explorer-&gt;Comdlg32-&gt;OpenSaveMRU&lt;BR/&gt;&lt;BR/&gt;b)(Castor)\Ntuser.dat-&gt;Software-&gt;&lt;BR/&gt;Microsoft-&gt;Windows-&gt;CurrentVersion-&gt;&lt;BR/&gt;Explorer-&gt;RecentDocs-&gt;zip&lt;BR/&gt;&lt;BR/&gt;c)(Castor)\Ntuser.dat-&gt;Software-&gt;&lt;BR/&gt;Microsoft-&gt;Windows-&gt;CurrentVersion-&gt;&lt;BR/&gt;Explorer-&gt;CDburning-&gt;Drives-&gt;&lt;BR/&gt;&lt;BR/&gt;d)(Castor)\Ntuser.dat-&gt;Software-&gt;&lt;BR/&gt;NicoMakComputing-&gt;Winzip-&gt;filemenu&lt;BR/&gt;&lt;BR/&gt;e)System-&gt;ControlSet-&gt;Enum-&gt;USBStor&lt;BR/&gt;&lt;BR/&gt;f)SystemRestore-&gt;RP0,1,2,3-&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/9207417995157201757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/9207417995157201757'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1203029640000#c9207417995157201757' title=''/><author><name>du212</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1476848598'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3918406493758851142</id><published>2008-02-11T17:42:00.000-08:00</published><updated>2008-02-11T17:42:00.000-08:00</updated><title type='text'>Furthermore, Secret2 and secret 5 have ben copied ...</title><content type='html'>Furthermore, Secret2 and secret 5 have ben copied off the computer and then caster DID double-click on them.&lt;BR/&gt;(see the times in the INDX slack of recent)&lt;BR/&gt;The fact that there are no OBJID's on the local secret2/5.zip means they were offsite.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/3918406493758851142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/3918406493758851142'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202780520000#c3918406493758851142' title=''/><author><name>nik</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-79536732'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2374824608040550472</id><published>2008-02-11T17:32:00.000-08:00</published><updated>2008-02-11T17:32:00.000-08:00</updated><title type='text'>ObjId:&lt;br&gt;(GMT times)&lt;br&gt;Winzip installed between ...</title><content type='html'>ObjId:&lt;BR/&gt;(GMT times)&lt;BR/&gt;Winzip installed between 6:10 am and 8:32 pm on 1/30&lt;BR/&gt;&lt;BR/&gt;clicked on secret.zip in same time span (accessed time matches puts it to 6:27 AM)&lt;BR/&gt;&lt;BR/&gt;Caster's password set to BLANK on 1/30 8:32PM&lt;BR/&gt;&lt;BR/&gt;There's a deleted explorer.exe in the recycling bin deletd at 7:13;&lt;BR/&gt;it was mapped to &lt;BR/&gt;(oddly the sid is unknown!)&lt;BR/&gt;(Mapped drive and other user deletes it by fileshare)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2374824608040550472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2374824608040550472'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202779920000#c2374824608040550472' title=''/><author><name>nik</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-117003364'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-906953918205524909</id><published>2008-02-10T20:13:00.000-08:00</published><updated>2008-02-10T20:13:00.000-08:00</updated><title type='text'>Good, you made the point I was trying to illustrat...</title><content type='html'>Good, you made the point I was trying to illustrate that just because the directory appears empty in the forensic tool you may be using, does not mean there isn't any good information there. Looking at the contents of the folder in hex or using an EnScript to parse the buffer (cheater ;) may provide excellent information, like in this case.&lt;BR/&gt;&lt;BR/&gt;Might I suggest a search of the filenames you have found, using Unicode across unallocated and specifically the $LogFile.&lt;BR/&gt;&lt;BR/&gt;Additionally, since you have discovered several zip files of interest, what application(s) might be used by the user to view/create those zips?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/906953918205524909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/906953918205524909'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202703180000#c906953918205524909' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7718831922467842484</id><published>2008-02-10T19:41:00.000-08:00</published><updated>2008-02-10T19:41:00.000-08:00</updated><title type='text'>Yep it's empty.&lt;br&gt;&lt;br&gt;&lt;br&gt;;)&lt;br&gt;&lt;br&gt;Parsed out th...</title><content type='html'>Yep it's empty.&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;;)&lt;BR/&gt;&lt;BR/&gt;Parsed out the INDX buffer using the enscript, pulled secret2.lnk complete with timestamps.&lt;BR/&gt;&lt;BR/&gt;Also within the buffer is a directory entry for secret5.lnk.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/7718831922467842484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/7718831922467842484'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202701260000#c7718831922467842484' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1436674114'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8738398004862652219</id><published>2008-02-10T16:15:00.000-08:00</published><updated>2008-02-10T16:15:00.000-08:00</updated><title type='text'>Anybody look in Castor Troy's Recent folder?</title><content type='html'>Anybody look in Castor Troy's Recent folder?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/8738398004862652219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/8738398004862652219'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202688900000#c8738398004862652219' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-2838037564438076929</id><published>2008-02-10T12:37:00.000-08:00</published><updated>2008-02-10T12:37:00.000-08:00</updated><title type='text'>Ack, some stuff was truncated in the previous comm...</title><content type='html'>Ack, some stuff was truncated in the previous comment.&lt;BR/&gt;&lt;BR/&gt;I continued my search, taking advantage of mounting the ntuser.dat with the "calculate unallocated space" option.&lt;BR/&gt;&lt;BR/&gt;supersecret2.zip&lt;BR/&gt;supersecret3.zip&lt;BR/&gt;supersecret4.zip&lt;BR/&gt;supersecret5.zip&lt;BR/&gt;supersecret6.zip&lt;BR/&gt;&lt;BR/&gt;were found there.&lt;BR/&gt;&lt;BR/&gt;The hex surrounding these filenames and the 8.3 MSDOS filenames also there are similar to the structure in the Stream previously discovered in the clear in the registry.&lt;BR/&gt;&lt;BR/&gt;High probability that these files are also present on the thumb drive.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2838037564438076929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/2838037564438076929'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202675820000#c2838037564438076929' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1110121216'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1629775320422110818</id><published>2008-02-10T12:27:00.000-08:00</published><updated>2008-02-10T12:27:00.000-08:00</updated><title type='text'>In the NTUser.dat file of Caster Troy, specificall...</title><content type='html'>In the NTUser.dat file of Caster Troy, specifically Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\0\ViewView2, I got a keyword hit on 'supersecret'.&lt;BR/&gt;&lt;BR/&gt;The Streams key records window size/location information when a particular window is closed.&lt;BR/&gt;&lt;BR/&gt;The corresponding StreamsMRU key records the application used.&lt;BR/&gt;&lt;BR/&gt;In this case, there is a reference to E:\, meaning Explorer was used to view the contents of the E:\ root drive - which as already determined, was an inserted USB thumb drive.&lt;BR/&gt;&lt;BR/&gt;The coolness about this particular ViewView2 value inthe key is that it lists all files visible in the explorer window.&lt;BR/&gt;&lt;BR/&gt;Parsing it out:&lt;BR/&gt;&lt;BR/&gt;Supersecret&lt;BR/&gt;secret1.zip&lt;BR/&gt;secret2.zip&lt;BR/&gt;secret3.zip&lt;BR/&gt;secret4.zip&lt;BR/&gt;secret5.zip&lt;BR/&gt;&lt;BR/&gt;Unfortunately I've had to rely on Paraben registry analyzer to pull out timestamp information from the StreamMRU keys as I haven't been able to find the format of the StreamMRUs anywhere yet. Have to wait until tomorrow.&lt;BR/&gt;&lt;BR/&gt;So he is suspected as having access to Supersecret stoof - it's already on his thumbdrive. Naughty boy.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1629775320422110818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1629775320422110818'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202675220000#c1629775320422110818' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1987468675'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1650328399515676283</id><published>2008-02-09T18:38:00.000-08:00</published><updated>2008-02-09T18:38:00.000-08:00</updated><title type='text'>Paul Bobby -&lt;br&gt;&lt;br&gt;Very good start, although ther...</title><content type='html'>Paul Bobby -&lt;BR/&gt;&lt;BR/&gt;Very good start, although there is much more there waiting to be found!! ;)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1650328399515676283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1650328399515676283'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202611080000#c1650328399515676283' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-7163490086597422955</id><published>2008-02-07T19:31:00.000-08:00</published><updated>2008-02-07T19:31:00.000-08:00</updated><title type='text'>1/30/08 9:08:50am he installed Winzip. System rest...</title><content type='html'>1/30/08 9:08:50am he installed Winzip. System restore point&lt;BR/&gt;created&lt;BR/&gt;&lt;BR/&gt;1/30/08 9:09:09am Maybe Google Toolbar installed&lt;BR/&gt;&lt;BR/&gt;1/30/08 9:18:03am several ZIP files created.&lt;BR/&gt;&lt;BR/&gt;1/30/08 9:26:30am USBSTOR.SYS is created in System32\drivers&lt;BR/&gt;&lt;BR/&gt;1/30/08 9:27:29am LNK file created in a system restore directory&lt;BR/&gt;LNK file points to e:\secret2.zip, serial # of device 98eb-802a which does not match the serial number of the single partition in the evidence file. &lt;BR/&gt;&lt;BR/&gt;The USBStor key in the SYSTEM registry contains a single entry&lt;BR/&gt;About a device called "USB NAND FLASH DISK USB Device"&lt;BR/&gt;&lt;BR/&gt;1/30/08 9:41:22am sdelete.exe was created in the LST folder. No prefetch for this executable, cannot say if it was executed or not (Last Access was 1 second later, so maybe it was). Userassist does not show it executing. MUICache does not show it as having been executed. Shows up as having a window size of 800x600 in the ShellNoRoam BAGs key - application once ran with that window size, but cannot show it ran then.&lt;BR/&gt;&lt;BR/&gt;So the theory is that the user created ZIP files from documents on his machine.&lt;BR/&gt;&lt;BR/&gt;Copied them to a thumb drive.&lt;BR/&gt;&lt;BR/&gt;Sdelete.exe may have been used by Mr. Mueller to clean up the evidence file, or by Caster Troy to remove ZIP and documents from his My Documents folder. &lt;BR/&gt;&lt;BR/&gt;I'll keep looking.&lt;BR/&gt;&lt;BR/&gt;BTW keep doing challenges, they are  great exercises.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/7163490086597422955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/7163490086597422955'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1202441460000#c7163490086597422955' title=''/><author><name>Paul Bobby</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1309784303'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-814869599796664000</id><published>2008-02-01T09:18:00.000-08:00</published><updated>2008-02-01T09:18:00.000-08:00</updated><title type='text'>It's better than Dirk Diggler..</title><content type='html'>It's better than Dirk Diggler..</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/814869599796664000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/814869599796664000'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1201886280000#c814869599796664000' title=''/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1592171251'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1616044635466684992</id><published>2008-02-01T03:18:00.000-08:00</published><updated>2008-02-01T03:18:00.000-08:00</updated><title type='text'>"Castor Troy"?  You're a profiler's best friend!  ...</title><content type='html'>"Castor Troy"?  You're a profiler's best friend!  ;-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1616044635466684992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/3274445515536289944/comments/default/1616044635466684992'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2008/01/forensic-practical-2.html?showComment=1201864680000#c1616044635466684992' title=''/><author><name>Keydet89</name><uri>http://www.blogger.com/profile/08966595734678290320</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://a652.ac-images.myspacecdn.com/images01/55/m_ab5e482b5e1cd7c3fe90874adf42cf2b.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2008/01/forensic-practical-2.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-3274445515536289944' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/3274445515536289944' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-570367412'/></entry></feed>
