Forensics Bonanza in Facebook Case

Discussion in 'privacy general' started by LockBox, Apr 3, 2012.

  LockBox

    LockBox

  Securit

    Securit

    Thanks! Very interesting reading!
  BrandiCandi

    BrandiCandi

    Interesting indeed.
  syncmaster913n

    syncmaster913n

    What I found most interesting in the paper is the fact that the forensics experts were able to extract metadata from files that were erased and overwritten by new data. I thought that doing that without employing very expensive means is not possible?
  Dogbiscuit

    Dogbiscuit

    Some metadata is stored in the Windows file system and not in the file itself.
  syncmaster913n

    syncmaster913n

    Ah, I see!

    Do you know of any free (or trial) software that can be used to analyze metadata from specific files? They mentioned one in the paper, but it is paid and has no trial. I'd like to see just how much information you can extract this way.
  Dogbiscuit

    Dogbiscuit

    I can't recommend one, but a search on 'metadata removal tool' showed many.
  syncmaster913n

    syncmaster913n

    Last edited: Apr 15, 2012
  chronomatic

    chronomatic

    It looks like this guy tried to hide his tracks by reinstalling Windows. He obviously doesn't understand that does nothing to hide most of the data that was on the drive.
  CloneRanger

    CloneRanger

    Eye-opening, Indeed !

    Thanks for posting :thumb:

    It appears he only reinstalled, Without deleting the partions first = Big No No :D
