Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 3rd, 2012, 04:04 PM
LockBox LockBox is offline
Very Frequent Poster
 
Join Date: Nov 2004
Posts: 2,081
Default Forensics Bonanza in Facebook Case

http://m.wired.com/threatlevel/2012/...hip-forensics/

Be sure to grab the .pdf and read the forensic examiners full report. Eye-opening.
  #2  
Old April 3rd, 2012, 10:21 PM
Securit Securit is offline
Infrequent Poster
 
Join Date: Feb 2012
Posts: 19
Default Re: Forensics Bonanza in Facebook Case

Thanks! Very interesting reading!
  #3  
Old April 4th, 2012, 11:13 AM
BrandiCandi
 
Posts: n/a
Default Re: Forensics Bonanza in Facebook Case

Interesting indeed.
  #4  
Old April 14th, 2012, 07:21 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Forensics Bonanza in Facebook Case

What I found most interesting in the paper is the fact that the forensics experts were able to extract metadata from files that were erased and overwritten by new data. I thought that doing that without employing very expensive means is not possible?
__________________
My setup
  #5  
Old April 14th, 2012, 09:38 PM
Dogbiscuit Dogbiscuit is offline
Frequent Poster
 
Join Date: Jul 2007
Posts: 640
Default Re: Forensics Bonanza in Facebook Case

Some metadata is stored in the Windows file system and not in the file itself.
  #6  
Old April 15th, 2012, 12:46 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Forensics Bonanza in Facebook Case

Ah, I see!

Do you know of any free (or trial) software that can be used to analyze metadata from specific files? They mentioned one in the paper, but it is paid and has no trial. I'd like to see just how much information you can extract this way.
__________________
My setup
  #7  
Old April 15th, 2012, 01:47 AM
Dogbiscuit Dogbiscuit is offline
Frequent Poster
 
Join Date: Jul 2007
Posts: 640
Default Re: Forensics Bonanza in Facebook Case

I can't recommend one, but a search on 'metadata removal tool' showed many.
  #8  
Old April 15th, 2012, 10:13 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Forensics Bonanza in Facebook Case

Yeah I already found this yesterday: http://www.forensicswiki.org/wiki/Do...ata_Extraction

a huge list. Exiftool seems really nice - it's under the "Images" category but it actually works with all file types.

And this is the one they referenced in the paper: http://www.payneconsulting.com/products/metadataretail/ - 80$ license. From what I can tell though it seems far less functional than the free Exiftool I mentioned above; except it has a friendly GUI.
__________________
My setup

Last edited by syncmaster913n : April 15th, 2012 at 10:18 AM.
  #9  
Old April 24th, 2012, 02:26 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Forensics Bonanza in Facebook Case

It looks like this guy tried to hide his tracks by reinstalling Windows. He obviously doesn't understand that does nothing to hide most of the data that was on the drive.
  #10  
Old April 25th, 2012, 12:15 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,858
Default Re: Forensics Bonanza in Facebook Case

Quote:
LockBox

Be sure to grab the .pdf and read the forensic examiners full report. Eye-opening.

Eye-opening, Indeed !

Thanks for posting

Quote:
chronomatic

It looks like this guy tried to hide his tracks by reinstalling Windows. He obviously doesn't understand that does nothing to hide most of the data that was on the drive.

It appears he only reinstalled, Without deleting the partions first = Big No No
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:11 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums