![]() |
|
#1
|
|||
|
|||
|
http://m.wired.com/threatlevel/2012/...hip-forensics/
Be sure to grab the .pdf and read the forensic examiners full report. Eye-opening. |
|
#2
|
|||
|
|||
|
Thanks! Very interesting reading!
|
|
#3
|
|||
|
|||
|
Interesting indeed.
|
|
#4
|
|||
|
|||
|
What I found most interesting in the paper is the fact that the forensics experts were able to extract metadata from files that were erased and overwritten by new data. I thought that doing that without employing very expensive means is not possible?
__________________
My setup |
|
#5
|
|||
|
|||
|
Some metadata is stored in the Windows file system and not in the file itself.
|
|
#6
|
|||
|
|||
|
Ah, I see!
Do you know of any free (or trial) software that can be used to analyze metadata from specific files? They mentioned one in the paper, but it is paid and has no trial. I'd like to see just how much information you can extract this way.
__________________
My setup |
|
#7
|
|||
|
|||
|
I can't recommend one, but a search on 'metadata removal tool' showed many.
|
|
#8
|
|||
|
|||
|
Yeah I already found this yesterday: http://www.forensicswiki.org/wiki/Do...ata_Extraction
a huge list. Exiftool seems really nice - it's under the "Images" category but it actually works with all file types. And this is the one they referenced in the paper: http://www.payneconsulting.com/products/metadataretail/ - 80$ license. From what I can tell though it seems far less functional than the free Exiftool I mentioned above; except it has a friendly GUI.
__________________
My setup Last edited by syncmaster913n : April 15th, 2012 at 10:18 AM. |
|
#9
|
|||
|
|||
|
It looks like this guy tried to hide his tracks by reinstalling Windows. He obviously doesn't understand that does nothing to hide most of the data that was on the drive.
|
|
#10
|
||||
|
||||
|
Quote:
Eye-opening, Indeed ! Thanks for posting Quote:
It appears he only reinstalled, Without deleting the partions first = Big No No ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|