<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1746946614390371171.post9005956245523335949..comments</id><updated>2011-10-05T10:02:55.712-07:00</updated><category term='Cell Phones'/><category term='CRLF'/><category term='Wireless'/><category term='Vista'/><category term='Kindle'/><category term='CP'/><category term='File Signatures'/><category term='Hash'/><category term='SQL'/><category term='File System'/><category term='Email'/><category term='Patch'/><category term='Exclusion List'/><category term='dd'/><category term='SHA1'/><category term='MFT'/><category term='Photos'/><category term='Service Pack'/><category term='Keywords'/><category term='Import'/><category term='Encryption'/><category term='Firewall'/><category term='export'/><category term='EnScript Requests'/><category term='Install Date'/><category term='Timestamps'/><category term='Office Metadata'/><category term='NIST'/><category term='Password Bypass'/><category term='EnScript Tutorial'/><category term='MAC Address'/><category term='Domains'/><category term='GREP'/><category term='Thumbnails'/><category term='FTP'/><category term='USB History'/><category term='Virus'/><category term='Search Hits'/><category term='Bookmark'/><category term='MD5'/><category term='Winen'/><category term='LogFile'/><category term='EMLX'/><category term='Video'/><category term='Operating System'/><category term='Yahoo'/><category term='Duplicates'/><category term='Icons'/><category term='USNJRNL'/><category term='Restore Points'/><category term='Windows 7'/><category term='Base64'/><category term='Unallocated'/><category term='eBlaster'/><category term='Ghost'/><category term='XOR'/><category term='VSS'/><category term='Selected Text'/><category term='Network Information'/><category term='Forensic Practical'/><category term='Decode'/><category term='SANS'/><category term='Extensions'/><category term='Limewire'/><category term='Search'/><category term='Registry'/><category term='OSX'/><category term='IIS'/><category term='Unused Disk Space'/><category term='Event Logs'/><category term='Norton AV'/><category term='Foreign Language'/><category term='Lanman'/><category term='Redaction'/><category term='UserAssist'/><category term='ICAC'/><category term='LUHN'/><category term='Count'/><category term='Filename'/><category term='thumbcache'/><category term='ROT13'/><category term='HTML'/><category term='Incident Response'/><category term='Anti-Forensics'/><category term='Memory'/><category term='Internet History'/><category term='LEF'/><category term='File Types'/><category term='Triage'/><category term='SearchPak'/><category term='F-Response'/><category term='BitLocker'/><title type='text'>Comments on Computer Forensics, Malware Analysis &amp;amp; Digital Investigations: Forensic Practical Exercise #3 - SOLVED</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.forensickb.com/feeds/9005956245523335949/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html'/><author><name>Lance Mueller</name><uri>http://www.blogger.com/profile/15789264000499223230</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1329128585782794434</id><published>2011-10-05T10:02:55.712-07:00</published><updated>2011-10-05T10:02:55.712-07:00</updated><title type='text'>Nice Challenge!
Is it possible for you to post som...</title><content type='html'>Nice Challenge!&lt;br /&gt;Is it possible for you to post some more similar to this one? I would like to practice more as I failed my class last semester and I better pass it next time!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/1329128585782794434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/1329128585782794434'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1317834175712#c1329128585782794434' title=''/><author><name>photochromic lenses</name><uri>http://vistalowcost.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1284181789'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-1519730067888026668</id><published>2011-03-09T13:25:09.720-08:00</published><updated>2011-03-09T13:25:09.720-08:00</updated><title type='text'>This exercise is kind difficult because is long, I...</title><content type='html'>This exercise is kind difficult because is long, I got it wrong the first time actually! But then I solved it the second time, so you may need to try more than one time no big deal !</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/1519730067888026668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/1519730067888026668'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1299705909720#c1519730067888026668' title=''/><author><name>accountant in italy</name><uri>http://www.costanzoeassociati.it/en/index.html</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1152278704'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-3803452924828683506</id><published>2011-03-09T13:23:21.515-08:00</published><updated>2011-03-09T13:23:21.515-08:00</updated><title type='text'>This practical exercise is very much like Humpty D...</title><content type='html'>This practical exercise is very much like Humpty Dumpty. It&amp;#39;s a simple scenario, a simple JPG file fragmented in unallocated space. The complex part is that its in 35 pieces</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/3803452924828683506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/3803452924828683506'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1299705801515#c3803452924828683506' title=''/><author><name>digital microscope</name><uri>http://digimicroscope.info</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1152278704'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-8101291311007842265</id><published>2010-12-10T09:44:26.590-08:00</published><updated>2010-12-10T09:44:26.590-08:00</updated><title type='text'>As you explain it, it looks really simple and easy...</title><content type='html'>As you explain it, it looks really simple and easy to understand, I had an exercise similar to this in my book, but really hard to understand. I appreciate your post, thanks</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/8101291311007842265'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/8101291311007842265'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1292003066590#c8101291311007842265' title=''/><author><name>Turks and Caicos Villas</name><uri>http://www.amanyaravillas.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1494941113'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-5894817019920015317</id><published>2010-09-21T15:02:57.410-07:00</published><updated>2010-09-21T15:02:57.410-07:00</updated><title type='text'>I used JPEGsnoop as a guide to find the JPG marker...</title><content type='html'>I used JPEGsnoop as a guide to find the JPG markers and headers... too late after the post but really enjoy the puzzle!!! Thanks Lance</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/5894817019920015317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/5894817019920015317'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1285106577410#c5894817019920015317' title=''/><author><name>pakeshi</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1087293960'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4534682118597065188</id><published>2010-05-31T21:15:59.688-07:00</published><updated>2010-05-31T21:15:59.688-07:00</updated><title type='text'>Great read thanks for the post!</title><content type='html'>Great read thanks for the post!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/4534682118597065188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/4534682118597065188'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1275365759688#c4534682118597065188' title=''/><author><name>weeds season 5</name><uri>http://www.weedsseason5.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-549700617'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6411334173768514653</id><published>2010-02-21T15:11:34.907-08:00</published><updated>2010-02-21T15:11:34.907-08:00</updated><title type='text'>Well, I have been reading your blog posts daily an...</title><content type='html'>Well, I have been reading your blog posts daily and the reason I come on your blog frequently is its compelling content… Thanks for sharing..Regards… http://www.pctechoutlet.com</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/6411334173768514653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/6411334173768514653'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1266793894907#c6411334173768514653' title=''/><author><name>Cheap Computers</name><uri>http://www.pctechoutlet.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1335075974'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-6838534188810047340</id><published>2010-01-21T12:33:50.412-08:00</published><updated>2010-01-21T12:33:50.412-08:00</updated><title type='text'>I had carved out a whole bunch of sectors of jpg d...</title><content type='html'>I had carved out a whole bunch of sectors of jpg data, then work intervened before I could piece them together... well I was in the right track there but couldn&amp;#39;t figure out what on earth happened to the partitions! Thanks for the challenge Lance.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/6838534188810047340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/6838534188810047340'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1264106030412#c6838534188810047340' title=''/><author><name>Hex Editrix</name><uri>http://www.blogger.com/profile/03357618485595582767</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-890776353'/></entry><entry><id>tag:blogger.com,1999:blog-1746946614390371171.post-4615800808940889538</id><published>2010-01-15T04:31:31.668-08:00</published><updated>2010-01-15T04:31:31.668-08:00</updated><title type='text'>amazing</title><content type='html'>amazing</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/4615800808940889538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1746946614390371171/9005956245523335949/comments/default/4615800808940889538'/><link rel='alternate' type='text/html' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html?showComment=1263558691668#c4615800808940889538' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.forensickb.com/2010/01/forensic-practical-exercise-3-solved.html' ref='tag:blogger.com,1999:blog-1746946614390371171.post-9005956245523335949' source='http://www.blogger.com/feeds/1746946614390371171/posts/default/9005956245523335949' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-954896412'/></entry></feed>
