Source
Katana 2.0
Katana is a portable multi-boot security suite which brings together many of today's best security distributions and portable applications to run off a single Flash Drive. It includes distributions which focus on Pen-Testing, Auditing, Forensics, System Recovery, Network Analysis, and Malware Removal. Katana also comes with over 100 portable Windows applications; such as Wireshark, Metasploit, NMAP, Cain & Abel, and many more.
Katana Bootable:
- Backtrack
- the Ultimate Boot CD
- CAINE
- Ultimate Boot CD for Windows
- Ophcrack Live
- Puppy Linux
- Trinity Rescue Kit
- Clonezilla
- Derik's Boot and Nuke
- Kon-Boot (See boot fix here)
And instructions on installing additional Distributions can be found here.
Katana Tool Kit:
- Metasploit
- Wireshark
- NMAP
- John the Ripper
- Cain & Abel
- Firefox
- PuTTY
- the Unstoppable Copier
- OllyDBG
- Cygwin
- ClamAV
- IECookiesView
- MozillaCacheView
- FreeOTFE
- FindSSN
- The Sleuth Kit
- OpenOffice
and many more
Download
Name: Katana v2.0
File: katana-v2.0.rar
Size: ~ 4 GB
MD5: d77f1fec607657b6d82264e8b5ca47a4
DOWNLOAD:
TORRENT: katana-v2.0.torrent (preferred method)
Showing posts with label forensics. Show all posts
Showing posts with label forensics. Show all posts
Monday, January 24, 2011
Evaluating Mobile Telephone Connection Behaviour
Source
In general, all modern mobile telephones contain call information and SMS message storage which may be used as evidence. There may also be a wealth of other evidence available including browser history, sat nav usage etc. However, for the purposes of this article I am interested in discussing the accuracy and evaluation of telephone connection behaviour and hence I shall concentrate only on these two important sources of evidence.
There are various types of examinations conducted on mobile telephones to extract the call information and SMS messages (collectively I shall refer to these as connection information). The examination of a SIM card is a fairly ‘trivial’ process with a well-defined extraction procedure. However, handset examinations may be much trickier. For standard handset examinations (those that generally only extract the information live on the handset) there is no one product that can extract all of the connection information available for all handsets. Hence, when examining handsets, it is important as a first step to ensure the accuracy of the evidence you are presenting.
When presenting your evidence it may be worthwhile considering the measures you implement to be able to ascertain both the accuracy and meaning of information you present to ascertain that:
1. The extracted information is accurate and correctly attributed. For example, that a reported SMS message has the correct content and is appropriately stated as a sent, draft or a received SMS message.
2. The information is complete and where it is not, the omissions are known (and clearly declared in the report) or manually obtained.
3. The information is unambiguously reported.
More....
In general, all modern mobile telephones contain call information and SMS message storage which may be used as evidence. There may also be a wealth of other evidence available including browser history, sat nav usage etc. However, for the purposes of this article I am interested in discussing the accuracy and evaluation of telephone connection behaviour and hence I shall concentrate only on these two important sources of evidence.
There are various types of examinations conducted on mobile telephones to extract the call information and SMS messages (collectively I shall refer to these as connection information). The examination of a SIM card is a fairly ‘trivial’ process with a well-defined extraction procedure. However, handset examinations may be much trickier. For standard handset examinations (those that generally only extract the information live on the handset) there is no one product that can extract all of the connection information available for all handsets. Hence, when examining handsets, it is important as a first step to ensure the accuracy of the evidence you are presenting.
When presenting your evidence it may be worthwhile considering the measures you implement to be able to ascertain both the accuracy and meaning of information you present to ascertain that:
1. The extracted information is accurate and correctly attributed. For example, that a reported SMS message has the correct content and is appropriately stated as a sent, draft or a received SMS message.
2. The information is complete and where it is not, the omissions are known (and clearly declared in the report) or manually obtained.
3. The information is unambiguously reported.
More....
Helix 3 Pro
e-fense Inc. announces new management team
Helix3 vs Helix3 Pro
Helix2008R1.iso http://mirrors.cmich.edu/helix/
Source
Helix 2009 R1 ISO locally hosted here.
Source
Windows mode
In this mode, Helix is used just as any other CD inside Windows. Double-click to launch the application. You'll be warned about your actions.
The Windows mode differs from the Linux side in being a floating application rather than a complete operating system. Therefore, the navigation is a little different.
First, you have the Quick Launch.
Then, there is the Page menu, which allows you to browse different categories of tools.
The Windows side contains a broad range of highly useful utilities.
The Incident Response page is particularly rich, with lots of excellent programs. Did I say you should be knowledgeable and extremely careful when running these tools, as you can very easily obliterate your system and even cause significant damage to the LAN? There, I said it.
An entire section is dedicated to viewing (and retrieving) passwords, cookies and logs.
You also have tools for auditing of the system, remote connection (including VNC, SSH), file recovery, and rootkit scanning.
Like in Linux, it is possible to acquire entire disk drives (and even the physical memory).
You can also browse contents of files and folders, calculate hashes, check time stamps, and more. This allows you to look for suspicious, clandestine activities in your data archives.
As mentioned earlier, you can run full audits of your system.
Conclusion Helix is a highly useful toolbox. The dual mode is especially valuable, since quite a few system administrators are not that proficient in Linux. Furthermore, it allows Helix users to approach Windows-related problems with several methods, first trying to cope with problems while still logged in Windows and then escalating to the Linux live CD mode.
Helix is a stable, complete package, with a broad range of great utilities that will significantly increase your ability to respond to problems, threats and incidents in your environment.
For more details about forensics in general, please see the Introduction.
Helix3 vs Helix3 Pro
Helix2008R1.iso http://mirrors.cmich.edu/helix/
Source
Helix 2009 R1 ISO locally hosted here.
Source
Windows mode
In this mode, Helix is used just as any other CD inside Windows. Double-click to launch the application. You'll be warned about your actions.
The Windows mode differs from the Linux side in being a floating application rather than a complete operating system. Therefore, the navigation is a little different.
First, you have the Quick Launch.
Then, there is the Page menu, which allows you to browse different categories of tools.
The Windows side contains a broad range of highly useful utilities.
The Incident Response page is particularly rich, with lots of excellent programs. Did I say you should be knowledgeable and extremely careful when running these tools, as you can very easily obliterate your system and even cause significant damage to the LAN? There, I said it.
An entire section is dedicated to viewing (and retrieving) passwords, cookies and logs.
You also have tools for auditing of the system, remote connection (including VNC, SSH), file recovery, and rootkit scanning.
Like in Linux, it is possible to acquire entire disk drives (and even the physical memory).
You can also browse contents of files and folders, calculate hashes, check time stamps, and more. This allows you to look for suspicious, clandestine activities in your data archives.
As mentioned earlier, you can run full audits of your system.
Conclusion Helix is a highly useful toolbox. The dual mode is especially valuable, since quite a few system administrators are not that proficient in Linux. Furthermore, it allows Helix users to approach Windows-related problems with several methods, first trying to cope with problems while still logged in Windows and then escalating to the Linux live CD mode.
Helix is a stable, complete package, with a broad range of great utilities that will significantly increase your ability to respond to problems, threats and incidents in your environment.
For more details about forensics in general, please see the Introduction.
Forensic Tools and Live CDs
Most of the time, we do not really care about our computers. They are a means to an end, or many ends. Games, Internet, work, you name it. When everything works, the PC is a somewhat noisy beast that lets us do what we want - most of the time. But what happens when something goes wrong?
Suddenly, your machine won't boot. Suddenly, you have managed to contract malware. Your hard disk is misbehaving, your partitions are gone, your files are gone. These kinds of disasters are all too common. Unfortunately, very few people think about them, let alone prepare for them.
Don't be one of them You can avoid - or at the very least, minimize - risks and damages by exercising a continuous, pro-active approach to integrity and security. It begins with very basic concepts of data backup and simple desktop maintenance and extends beyond disasters into evidence collection and analysis, incidence reporting, vulnerability discovery and patching, and damage control.
In this series of articles, we will talk about specialized Linux distributions that are particularly suited for these kinds of tasks: incidence response, data recovery, security audits, and investigation of system failures. In one word, we will talk about forensics-oriented distributions. Today, we will just introduce the topic. In the follow-up articles, we will review several highly useful, dedicated forensics Linux distributions.
So, before you start ... There are some things you need to know.
First, you can custom-build your own set for utilities for the task - for example, run Ubuntu, load it with goodies and then create a bootable image with Remastersys - however, you might as well rely on security professional to do the job for you. Let them create the tools; you use them.
Second, analyzing and fixing system failures and security breaches takes a bit of knowledge. Therefore, if you're not really familiar with system internals, either Linux, Windows or both, you might not be able to fully utilize the power of tools presented here. Still, it does not hurt to be aware of them and have them handy, in case of a disaster.
Third, forensics of the kind we are talking about here is the 2nd or even a 3rd level of response. There's much you can do before turning to heavy-duty hacking. Thus, enter the must-have toolbox for any security conscious (Linux) user:
Must-have toolbox The tools listed below should always be within your reach. Most of them come as individual live CDs, so you should carry a pouch with you. If you're extra-geeky, you might even use them from bootable USB drives. Whatever the case, you should have them ready for instant use, whether you're at home, work, a friend's place, or traveling abroad.
In no particular order:
This is a live CD specifically geared toward rescue and recovery. The tools package includes some of the most important tools available for Linux user, like GParted, PartImage, Grub, Lilo, sfdisk, TestDisk, and more.
PartImage is a powerful, friendly disk/partition imaging software, allowing you to quickly and easily backup and recover your entire disks or individual partitions, including the Windows NTFS filesystem.You can learn more about how to use Partimage in my tutorial: Free imaging software - CloneZilla & PartImage - Tutorial. PartImage is included with the SystemRescueCD.
Speaking of imaging software, CloneZilla is another powerful candidate for disk / partition backup and recovery; see the tutorial above.
Another extremely important tool is TestDisk. This tool allows to recover lost partitions, make not-bootable disks boot again and restore delete files. It is one of the more effective and powerful utilities on the market. When everything else fails, TestDisk won't. TestDisk is included with the SystemRescueCD.
Super Grub Disk is intended to run from a floppy disk or CD and is used for system rescue. Most importantly, it can be used to restore boot loaders, including GRUB, LILO and even Windows boot loader.
Other toolsEven though this article is geared toward Linux users, there's a fair chance they will be asked upon to act on behalf of a Windows friend in need, in which case they should be familiar with Windows tools as well. The best choice for Windows is:
This is one of the most important tools a Windows user can have. It is a complete bootable Windows kernel, packaged with tens of useful utilities in a range of categories.
Among offered tools are 7-Zip, a43, Ad-Aware SE, Agent Ransack, AVPersonal, BGInfo, CPU Bench, CWShredder, DeepBurner, Dirms, Disk Copy, Disk Image, Disk Wipe, Eraser, ERUNT, Explore2fs, ExplorerXP, File Recovery, FileZilla, Firefox, Floppy Repair, Foxit Reader, freeCommander, Free Undelete, HD Cleaner, HDTune, HijackThis, IPScan, IZArc, MaxBlast, MemTest, MbrFix, MBRWiz, Notepad++, Opera, P95, PasswordPro, PDF Reader, Popcorn, PPPOEXP, Putty, R-Linux, RecoveryManager, RegCleaner, Scribe, SmallCD, Stinger, SuperAntiSpyware, Sysclean, UltraVNC, xplorer2, WinDLG, and many more. You should also read the UBCD4WIN articles: How to create a bootable live Windows CD
Ultimate Boot CD for Windows (UBCD4WIN) just gets better and better
Furthermore, for more details about a wide range of programs of all kinds, please see:
A (sweet) collection of Windows programs
A (cool) list of Linux tools
----------------------------------------
ecophobia said February 2, 2009
- FCCU Gnu/Linux Boot CD
- http://www.lnx4n6.be/Downloads/download.php?dir=isos&type=iso&target=fccu-linux-cd-12.1
- CAINE (Computer Aided Investigative Environment) http://www.caine-live.net/en/index.html
- DEFT
- http://www.deftlinux.net/ Penguin Sleuth Kit
- http://penguinsleuth.org
- http://brainstretching.blogspot.com/ None of them are as good as Helix yet, but this fact just shows how much time and effort was put into Helix.
s-t-d.org
caine-live.net
CAINE - Computer Aided Investigative Environment
Of the two distros, CAINE seems to be closest in look, feel, and functionality to the Helix3 environment. It is based on Ubuntu Linux 8.04, and contains a Windows autorun GUI. CAINE is available as a 643MB ISO download from http://www.caine-live.net/, and it is version 0.5 that is used in this review.
CAINE started as the graduation thesis of the lead developer, Giancarlo Giustini, at the Information Engineering Department of the University of Modena e Reggio Emilia, Italy. CAINE was designed to wrap the common forensic tools in a user-friendly GUI to help streamline the investigative process.
On the Windows side, CAINE provides WinTaylor, a point-and-click interface to many incident response and collection tools. The autorun utility pops up first, presenting the standard disclaimers, and gives the user the option to install the VB6 Runtime library, or the ability to register the .ocx files if running under Vista, if needed (see Figure 1).
Figure 1 - CAINE startup screen under Windows
An alterative to using the WinTaylor GUI is to run the forensic utilities from inside Windows Internet Explorer. As always, it is important to remember that everything done on a live system modifies the system being examined, and all efforts should be made to minimize any changes to the system (see Figure 2).
Figure 2 - WinTaylor, a GUI for a large number of Windows based forensic tools
Once WinTaylor is started, the Analysis 1 tab provides access to a number of NIRSoft and other tools used for extracting system and personal information. It is recommended that you disable any Anti-virus programs, as many of these tools are often flagged as hacking tools, trojans, or backdoors. Analysis 2 Tab contains RAM and Network tools such as MDD< Win32dd, Winen, fport, TCPView and Advanced LAN Scanner. Analysis 3 contains FTK Imager, Windows Forensic Toolchest, and Nigilant 32. The remaining two tabs provide access to the Sysinternals Suite of tools in either a GUI or command line environment. In addition, the GUI provides access screen snapshot utility and a file hash calculator.
DEFT - Digital Evidence & Forensic Toolkit
DEFT v4 is based on Xubuntu Linux, and is available as a 700MB ISO download for either CD or USB, and even a special version for the EEE PC, from http://www.deftlinux.net/, and like CAINE, is based in Italy. Unlike CAINE and Helix3, DEFT presents a more compact look and feel. By default, DEFT doesnt use a GUI in either Windows or Linux. DEFT makes it very clear on it's website that DEFT it isn't for newbie[s]
When inserted into Windows system, not much will happen, but in many ways that is a good thing. As I have mentioned numerous times, anything you run on a live system modifies that system.
The GUI interfaces of Helix3 and CAINE both consume and overwrite RAM, potentially destroying evidence.
Since DEFT doesnt autorun a GUI, the user must be comfortable with command-line executables and parameters (a skill I see quickly disappearing in many college students).
The GUI interfaces of Helix3 and CAINE both consume and overwrite RAM, potentially destroying evidence.
Since DEFT doesnt autorun a GUI, the user must be comfortable with command-line executables and parameters (a skill I see quickly disappearing in many college students).
The Windows based utilities are located in the deft_extra directory, and there are a lot of them. Aside from all the standard collection utilities, there are a number of other open source utilities such as Abiword, various editor, pdf viewer, antivirus utilities, and many, many more. These additional tools allow investigator to perform additional tasks while having minimal impact on the suspect system. These tools can also be transferred to a forensic workstation and installed. There is also an index.html file in this directory that will give you a better idea of all the tools that are available.
And Just One More
Another interesting distribution is SUMO (Security Utilizing Multiple Options) Linux from Sun Tzu Data and Marcus J. Carey which is a multi-boot DVD image, which allows the user to select from and boot the following CDs:
Backtrack 3
Helix 2.0
Samurai Linux
Darik's Boot and Nuke (dban)
Damn Vulnerable Linux
Helix 2.0
Samurai Linux
Darik's Boot and Nuke (dban)
Damn Vulnerable Linux
Sumo Linux's boot selector
This ISO image is 3.6GB, is available from http://sumolinux.suntzudata.com/, and is distributed via bittorrent. Aside from the forensics capabilities provided by Helix and Backtrack, as well as the additional security tools provided by Backtrack and dban, this makes for a well-rounded security utility DVD that should be in all computer guru's toolbox. And there is just enough room that you could probably squeeze CAINE and/or DEFT into it. Now that would really be something.
============================Security and Forensics Watch-List: GSD Linkfest Style
Source by Claus Valca
Here’s a well-rounded selection of security and forensics tools and resources that are almost certainly will have you scrabbling around for a system or two to throw them at.
- More Links - Windows Incident Response – Harlan has a most excellent and jam-packed post full of forensics goodies such as a reference to a new Windows memory imaging tool update for the free Win32dd. Also in that post was introduction (to me) of a new system info-gathering tool called MIR-ROR. Like similar “collective” tools such as his own RegRipper, Security Database’s Evidence Collector, and Mandiant’s First Response these multi-function info collection tools aren’t solutions in themselves, but they can make the collection of first-pass level logs and information simpler. Armed with these after careful analysis by the responder, more surgical system analysis can take place with task-specific tools. I’ll let Harlan’s own words on MIR-ROR speak for themselves…
I recently heard about a tool called MIR-ROR, put together originally by Troy Larson and then expanded by Russ McRee, both of Microsoft. Russ blogged about it here, and there's a toolsmith article available on it, as well. MIR-ROR is a batch file that is useful for running tools on a system as part of incident response; what I like about this is that Russ isn't sitting back hoping that someone does something like this, he's taking advantage of his knowledge and capabilities to put this together. And he's made it available to the public, along with instructions on how to run it. I like tools like this because they're self-documenting...properly constructed and commented, they serve as their own documentation. As always, the standard caveat applies...use/deploy tools like this as part of an incident response plan. If your plan says you need to acquire a pristine image of the drive first, you will want to consider holding off on using a tool like this...
You will have to collect many of the executables that are needed and assemble them into the package. The documentation is great. As I recall I found a few references that were off but some patient Googling turned up the correct locations and I soon had it all put together.
- Memory Acquisition for First Responders – Forensic Incidence Response blog – Since I just mentioned win32dd this post by hogfly came at an opportune time. I believe that while memory acquisition and imaging is still primarily of use to forensic examiners, system admins can use the same lessons and apply them when doing incident response to a malware-infected system. As I say over and over again, too many IT Techs when getting a report of a virus/trojan/malware infection just run roughshod over the system with anti-virus/anti-malware cleaning tools and remove critical information to help understand WHAT is going on and WHY. There are LOTS of great Windows-based tools to capture memory images and data…many of them free (another post) so there’s little excuse not to capture an image of the memory of an infected system before going to town on the cleaning. Getting a sector-based image of the physical drive could also be valuable as well. This gets the end-user up and producing again and lets the analysts have more time in the lab dissecting the cadaver without everyone breathing down their neck with impatience.
- Live Analysis Part I - Changing of the Guard - The Digital Standard – Thoughtful post by cepogue on just that prior theme. Sometimes some incidents (or organizational attitudes/processes just don’t support the “by-the-book” Incident Response handling methodologies. Managers want the system cleaned and up and running, users complain about loss productivity, you can’t convince anyone who matters about the need to determine what if any data may have leaked. So many techs (and “my-blood-runs-IR” analysts) have to do a crash-n-dash response. That said, with skill and pre-planning, you can still make the best of a bad IR situation and hopefully walk away with valuable info despite the organizational “head-in-the-sand” culture. I’m looking forward to Part II.
- Forensics 101: Acquiring an Image with FTK Imager – SANS Forensics blog – Great how-to post on using FTK Imager to perform a GUI-based image pull from a system or storage device.
- Directory Link Counts and Hidden Directories – SANS Forensics blog – This post was a neat review of Unix file-structure handling and how to leverage it for searching for hidden directories. I was wondering if there was a Windows-supported solution. I saw in the comments note that OSSEC has this ability and in poking around found an agent tool compatible with Windows in the Downloads section. Though not exactly the same there is Joanna’s tool FLISTER from her invisiblethings.org tools page which might be worth looking into as well for Windows folks.
- Getting your fill of Reverse Engineering and Malware Analysis - Room362.com. An outstanding collection of links to sites/sources for reverse engineering and malware analysis tools, techniques and news. Quite bookmark-worthy.
- New BackTrack 4 “Forensics Mode” - CyberSec.eu. News that the next version of BackTrack (security and pen-testing LiveCD) will offer a “forensics-mode” boot-option from the Grub loader. Nice to have this option available to a venerable security minded LiveCD. If you just can’t wait, Remote-Exploit has made the BackTrack 4 Pre Release download ISO (fyi-DVD sized) available at that link. For even more info check out the release pdf and Introduction Video.
- Helix3 2009R1 FREE is once again available for download from the developers. Please see this GSD post Helix3: Thanks for the memories… to come up to speed on the issue. A recent comment by Lauren on that post got me looking around (and I did have to look hard to find it!) for the download link on the e-fense site. It can be found here. Registration is required to get to the download page, but if you hadn’t already tucked away a ISO file of the last free version, you do now have a safe option to get it fresh. Of course, to e-fense’s credit, they would rather you pony up some $ to get the newest (non-free) version of HelixPro and depending on your needs, that might be a better thing to do. Either way, it’s nice having the choice again.
- Download HelixCE200401brc1.iso RC1!!! Updated – Meanwhile, out of the previous “Helix going commercial” drama mentioned above, Charles Tendell struck on a new Helix “Community Edition” version. Due to licensing and other issues (RE: IAMAL) , he had to strip out some e-fense specifically-developed apps from his build that were present in the original Helix project builds. However he continues to plug away at filling the voids with new tools from other sources. Check it out including these screenshots and application list.
- Explorer Suite (PE analyzer) III – NTCore – A jam-packed tool to allow analysis and review of executable PE files. From the developer:
Created by Daniel Pistelli, a freeware suite of tools including a PE editor called CFF Explorer and a process viewer. The PE editor has full support for PE32/64. Special fields description and modification (.NET supported), utilities, rebuilder, hex editor, import adder, signature scanner, signature manager, extension support, scripting, disassembler, dependency walker etc. First PE editor with support for .NET internal structures. Resource Editor (Windows Vista icons supported) capable of handling .NET manifest resources. The suite is available for x86, x64 and Itanium.
- Ophcrack 3.3.0 and Ophcrack LiveCD 2.3.0. – New versions of these password auditing/cracking tools are now available. Don’t let the unsync’ed versioning fool you. The main program is version 3.3.0 and the LiveCD version 2.3.0 contains the program version 3.3.0. Go figure. Changes in the new version are described on their News page as follows:
Ophcrack version 3.3.0 includes support for our new tables vista_seven. These tables crack 99% of passwords of length 7 composed of almost any character including special characters. This table set will be included in our professional tables bundle.
New features have been added like the table size verification in order to warn the user if the tables have not been fully downloaded for example. It is also possible to tune how the preloading should be done.
An important effort was made to release a brand new LiveCD. A very interesting and refreshing distribution called Slitaz was customized to make a lighter than ever ophcrack LiveCD. It should enable us to update the LiveCD more often and to make your experience much better too. We would like to thank Slitaz team for their support in making this LiveCD. Do not hesitate to give a look at their stable distribution!
- NetworkMiner v0.88 – New release on this awesome packet-capture management tool. What I really like about it is the ability to parse PCAP files for offline study as well as the ability to extract and save media files (such as audio or video files) which are streamed across a network. Supported protocols for file extraction are FTP, HTTP and SMB. I don’t have to packet-sniff often, but when I do and I need to analyze a lot of the content being moved, this is the first tool I reach for…hands down!
- Wireshark version 1.2 – Speaking of network packet capturing..Wireshark got a bump to version 1.2. According to the Release notice:
This is the new stable release branch of Wireshark and many new and exciting features have been added since 1.0 was released.
In this release
For a complete list of changes, please refer to the 1.2.0 release notes.
- Wireshark has a spiffy new start page.
- Display filters now autocomplete.
- A 64-bit Windows (x64) installer is now provided.
- Support for the c-ares resolver library has been added. It has many advantages over ADNS.
- Many new protocol dissectors and capture file formats have been added.
- Macintosh OS X support has been improved.
- GeoIP database lookups.
- OpenStreetMap + GeoIP integration.
- Improved Postscript(R) print output.
- The preference handling code is now much smarter about changes.
- Support for Pcap-ng, the next-generation capture file format.
- Support for process information correlation via IPFIX.
- Column widths are now saved.
- The last used configuration profile is now saved.
- Protocol preferences are changeable from the packet details context menu.
- Support for IP packet comparison.
- Capinfos now shows the average packet rate.
Version 3.0 will be a major update. The following major new features were added:
- Guest SMP with up to 32 virtual CPUs (VT-x and AMD-V only)
- Windows guests: ability to use Direct3D 8/9 applications / games (experimental)
- Support for OpenGL 2.0 for Windows, Linux and Solaris guests
Forensics at journaling filesystems
Computer Forensics - The Basics
Original device
------------
Backtrack 4 pre release is ready, get it here here.
More about offensive-security, creators of backtrack:
http://www.offensive-security.com/
Off course Protech and BackTrack (the Rolls of pentesting distro) are not considered as forensic live CD but as pentesting live CD.
Pentesting distro are intended for network and system auditing, and they can be used bycybercriminals to gain access on a host, or by the sysadmin. or the pentester consultant in order to audit the line defense.
Unlike forensic live cds which are devoted mostly for static analysis, and data acquisition; pentesting live cd are mostly intended for offensive taks like port scan, os finguerprint, sniffing, exploit attempts etc.
But some live cd can also be used simply as a read only OS for connecting in hot spot as i use to do with Protech (now i use another one).
------------
What is computer forensics?
Principles of computer forensics
Hard disk drives - the basics
Linux 'dd' basics
Computer Forensics work placement
Source Principles of computer forensics
Hard disk drives - the basics
Linux 'dd' basics
Computer Forensics work placement
Original device
- adquire an image from it
- duplicate the aquired image to get a copy to work with
- and store the original device and the initial image
------------
Backtrack 4 pre release is ready, get it here here.
More about offensive-security, creators of backtrack:
http://www.offensive-security.com/
Off course Protech and BackTrack (the Rolls of pentesting distro) are not considered as forensic live CD but as pentesting live CD.
Pentesting distro are intended for network and system auditing, and they can be used bycybercriminals to gain access on a host, or by the sysadmin. or the pentester consultant in order to audit the line defense.
Unlike forensic live cds which are devoted mostly for static analysis, and data acquisition; pentesting live cd are mostly intended for offensive taks like port scan, os finguerprint, sniffing, exploit attempts etc.
But some live cd can also be used simply as a read only OS for connecting in hot spot as i use to do with Protech (now i use another one).
------------
To work with an already taken image in Autopsy/Sleuthkit you have to mount the image, that's right. But in that case there is no problem, it's sufficient to set the image file read only to prevent any change.
But to get the image - and that's what I was talking about - there is no need to mount the original drive (the source) so the source is under no circumstances altered by the process of taking the image.
Thats two completely different things, prevent the source from being altered by the imaging process and on the other hand taking care that the image which has already been taken will not be altered by the analysis.
An in Encase you do not mount the image, you just add it to a case. Encase takes care that the image is not altered by the analysis, so that way it is even not necessary to set the image file read only (though it does not hurt).
But to get the image - and that's what I was talking about - there is no need to mount the original drive (the source) so the source is under no circumstances altered by the process of taking the image.
Thats two completely different things, prevent the source from being altered by the imaging process and on the other hand taking care that the image which has already been taken will not be altered by the analysis.
An in Encase you do not mount the image, you just add it to a case. Encase takes care that the image is not altered by the analysis, so that way it is even not necessary to set the image file read only (though it does not hurt).
----------
At a guess some journalled filesystems drivers may be replay the journal regardless of whether it's been mounted read-only. I would imagine that this would be considered a bug since it is so counter intuitive to the whole idea of mounting read-only.
On the other hand you may support the idea that for the sake on integrity the journal should be replayed regardless of how it is mounted. I'd consider this course of action faulty and I'd suprised if it happens. If it does, open source kernels such Linux as used by Helix could be 'fixed' for the purposes of forensic use.
Mounting any primary evidence media, even in read only mode, is really bad form in my book unless there is no other option available. In UNIX/Linux you should read an image from the raw device...
$ dd if=/dev/sda of=evidence_image
If windows can't do this without mounting the device then image the it on a *nix system and import the image file into EnCase, FTK etc. for analysis.
On the other hand you may support the idea that for the sake on integrity the journal should be replayed regardless of how it is mounted. I'd consider this course of action faulty and I'd suprised if it happens. If it does, open source kernels such Linux as used by Helix could be 'fixed' for the purposes of forensic use.
Mounting any primary evidence media, even in read only mode, is really bad form in my book unless there is no other option available. In UNIX/Linux you should read an image from the raw device...
$ dd if=/dev/sda of=evidence_image
If windows can't do this without mounting the device then image the it on a *nix system and import the image file into EnCase, FTK etc. for analysis.
----------------
Again I'm making another guess but consider commands that act upon filesystems that are not mounted, the obvious one being fsck. You don't mount the filesystem but it potentially changes the raw data. Perhaps technologies such as LVM and software RAID are incapable of mounting a filesystem without modifiying the data on disk if not the files on the filesystem.
----------------
It's the journal that can change the hash. Read this
But I wouldn't call that a bug, it's intended behaviour. If it wouldn't be implemented like that the journal could not guarantee the integrity of the filesystem after a crash.
But I wouldn't call that a bug, it's intended behaviour. If it wouldn't be implemented like that the journal could not guarantee the integrity of the filesystem after a crash.
----------------
Did some research on this, slide 53 suggest that the Journaled File system tracks the number of times the file system is mounted and that accounts for the changes in hashes.
http://www.blackhat.com/presentations/bh-usa-03/bh-us-03-willis-c/bh-us-03-willis.pdf#search=%22forensics%20ext3%20journaling%20hashes%22
I would say that this is a bug with the linux loopback driver, which is why that sleuthkit article suggest modding it. Of course, the patch is only for the 2.4 kernel. Its funny because I discussed this possibility with two other forensics guys and they both agreed that this was impossible and none of us had ever seen it. So would you agree then, it would be best practices if using a host linux system and mounting either reiserfs or ext3 image to either use a hardware write blocker or burn the image to DVD to be on the safe side? Also, does this apply only to the mounting of the original device(because then it wouldn't really apply) or the image copy(which is what I'm concerned with).
http://www.blackhat.com/presentations/bh-usa-03/bh-us-03-willis-c/bh-us-03-willis.pdf#search=%22forensics%20ext3%20journaling%20hashes%22
I would say that this is a bug with the linux loopback driver, which is why that sleuthkit article suggest modding it. Of course, the patch is only for the 2.4 kernel. Its funny because I discussed this possibility with two other forensics guys and they both agreed that this was impossible and none of us had ever seen it. So would you agree then, it would be best practices if using a host linux system and mounting either reiserfs or ext3 image to either use a hardware write blocker or burn the image to DVD to be on the safe side? Also, does this apply only to the mounting of the original device(because then it wouldn't really apply) or the image copy(which is what I'm concerned with).
-----------------
It applies only to the handling of the original device.
Sure it could happen to the image too, but to prevent that in addition to loopback-mount the image read-only set the image-file read-only (r--r--r--) before mounting it so you can be sure that nothing will be altered.
Furthermore the best you can do is to never do any analysis on the original image, use a copy of it and you're safe anyway...
Sure it could happen to the image too, but to prevent that in addition to loopback-mount the image read-only set the image-file read-only (r--r--r--) before mounting it so you can be sure that nothing will be altered.
Furthermore the best you can do is to never do any analysis on the original image, use a copy of it and you're safe anyway...
------------------
Most of the confusion seems to be around the term 'mount'. Tools like Encase do not mount forensic images as you would a loopback file system for example. Forensic tools analyse a file system in the same way as you would analyse any other binary file i.e. it reads it and understands the structure but does not access it in the way it you natively would.
Another example of the difference between mounting and analysing could be drawn between file systems and MS Office documents. If you open a document in Word, the way you would normally, you risk altering the file. Tools exist to access the content of the document in a safe manner, or you can simply work on a copy (of a copy) of the evidence.
Good practice is to work on a copy of any image you have taken. This reduces the risk that you will need to re-image a device which can only act to increase the risk of compromising your evidence.
Another example of the difference between mounting and analysing could be drawn between file systems and MS Office documents. If you open a document in Word, the way you would normally, you risk altering the file. Tools exist to access the content of the document in a safe manner, or you can simply work on a copy (of a copy) of the evidence.
Good practice is to work on a copy of any image you have taken. This reduces the risk that you will need to re-image a device which can only act to increase the risk of compromising your evidence.
Monday, October 18, 2010
Windows File Analyzer
Fuente por Asfasfos
Cuando se realizan pruebas forenses sobre equipos Windows hay ciertos ficheros que tienen una especial importancia. Por ejemplo el fichero thumbs.db consiste en una pequeña base de datos en donde se guardan las últimas imagenes que se han visto en Windows por el usuario, es una forma mas de acelerar las futuras consultas de las imágenes. Otro fichero importante puede ser el index.dat que contiene todo el registro por donde el usuario ha navegado.
A continuación podemos ver un ejemplo de la herramienta aplicada sobre el ficheroindex.dat:
Windows File Analyzer nos permite analizar los siguientes tipos de ficheros:
- Thumbs.db: permite analizar las imagenes que ha registrado este fichero
- Papelera de reciclaje: nos permite analizar los ficheros que hay en la papelera de reciclaje
- Accesos directos: WFA nos permite analizar los accesos directos en busca de fechas de última modificación y fechas de creación
- Index.dat: nos permite analizar la información de la navegación (páginas visitadas, cookies, etc)
- Carpeta Prefetch: el prefetch es el sistema que utiliza Windows para mejorar el rendimiento del SO y lo utiliza sobre las aplicaciones mas empleadas. Con esta información podemos saber cuales son las aplicaciones mas utilizadas y sus ultimas fechas de utilización por el usuario.
Como veis Windows File Analyzer es una herramienta muy completa que nos ayudará en nuestras auditorías forenses a sistemas Windows. Esta aplicación funciona bajo las versiones mas populares de Windows como XP y Vista además de funcionar sobre Windows 98 y 2003 Server.
La última versión la podeis descargar de aqui
Tuesday, August 31, 2010
Introduction to Forensics
Source Apr 22, 2008 By Kyle Rankin
in Security 
Figure 1. Default Autopsy Page 
Figure 2. Host Manager Page
Start the Investigation 
Figure 3. File Analysis 
Figure 4. Sample timeline.txt File
A break-in can happen to any system administrator. Find out how to use Autopsy and Sleuthkit to hit the ground running on your first forensics project.
Computer forensics (among other things the ability to piece together clues from a system to determine how an intruder broke in) can take years or even decades to master.
If you have never conducted a forensics analysis on a computer, you might not even know exactly where to start. In this guide, I cover how to use the set of forensics tools in Sleuthkit with its Web front end, Autopsy, to organize your first forensics case.
Before You Start
Before You Start
One of the most common scenarios in which you might want to use forensics tools on a system is the case of a break-in. If your system has been compromised, you must figure out how the attacker broke in so you can patch that security hole. Before you do anything, you need to make an important decision—do you plan to involve law enforcement and prosecute the attacker?
If the answer is yes, you should leave the compromised system alone and make no changes to it.
Any changes you make post-attack could complicate and taint the evidence, and because of that, many people have a policy of unplugging a system once they detect an attack and leaving it off until law enforcement arrives.
Investigators likely will want the complete system, or at least the drives, so they can store it safely; thus, your forensics analysis might end here until your system is returned.
If you do not plan to prosecute the attacker, you still need to set up some policies beforehand on how to respond to an attack.
The first policy you should create concerns whether to pull the power from a compromised server immediately. Two main schools of thought exist on this.
- One school of thought says that because a live server contains valuable data in RAM, such as running processes, logged in users and so forth, that you should try to collect all of that live data first and then power off the server.
- The opposing school says that once a system is compromised, all parts of the system are potentially compromised and cannot be trusted, including any tools you might use to grab live system data, so you should pull the power from the server immediately. Otherwise, attackers also could have compromised shutdown scripts to remove their tracks.
I personally lean more toward the second school of thought and believe that no commands should be run and no changes made to a system once a break-in is discovered.
The second policy you should create beforehand concerns how and whether to image the hard drives on the system and how and when to bring the system back into service. If you cannot tolerate much downtime on the system, you probably will want to create an exact image of the drives to examine elsewhere, and then re-install your operating system on the original drives.
Remember, once a system has been compromised, you can no longer trust the system. There could very well be a back door that you missed. It's worth saying again that if you plan to prosecute, you will not be able to bring the system back into service, at least not with the original drives as investigators will need them.
If you have the extra space, I recommend creating images of your drives to work from and leaving the originals alone. If you accidentally write to the images, you always can create a fresh image from the original drives. Autopsy can manage raw disk or partition images, so any imaging tool, from dd to Ghost, will work.
Install Sleuthkit and Autopsy
Install Sleuthkit and Autopsy
For the purposes of this guide, I assume you have created an image of any drives on the system and have stored them on a separate machine that you will use for the forensics analysis.
This new machine needs to have both Sleuthkit and Autopsy installed. Some distributions have both Sleuthkit and Autopsy available as precompiled packages, so you can use your distribution's package manager to install them. Otherwise, you can download and compile the tools from the tarballs available on the main project site, sleuthkit.org.
Autopsy works as a Web-based front end to all of the Sleuthkit tools and makes it easy to examine a filesystem without learning each of the different command-line tools. Autopsy also makes it easy to organize multiple forensics analyses into different cases, so you can reference them later. Once Autopsy is installed, get root privileges, and type autopsy into a terminal to start the program. Instructions on Autopsy's settings appear in the terminal, including the default location for evidence (/var/lib/autopsy) and the default port on which it listens (9999). Open a Web browser and type in http://localhost:9999/autopsy to view the default Autopsy page and start your investigation.
Figure 1. Default Autopsy Page
From the main Autopsy page, click Open Case to open a case you already have created, or for this example, click New Case. In the New Case page, you can name and describe your case, and you also can provide a list of investigators who will work on the case. Once your case is named and created, you will see the case gallery—a page that simply lists all the cases you have created. If this is your first case, simply click OK to proceed to the Host Gallery. The Host Gallery lists all the servers you are investigating for this case. In our example, only one host was compromised, but often an attacker will move from one compromised host to another, so include as many hosts as you need to investigate in this gallery. As with the Case Gallery, click Add Host to fill out information about the host you are adding.
You will see some interesting fields on the Add Host page relating to time. If the host was set to a time zone different from your local time zone, be sure to put its time zone in the Time Zone field. When you piece together a chain of events, especially across multiple hosts, having correctly synced time is valuable. The Timeskew Adjustment field lets you account for a server with out-of-sync time, and Autopsy automatically adjusts the times to reflect any skew you put in this field.
When you add the host and go back to the Host Gallery, select the host to analyze and click OK to go to the Host Manager page. If this is a new host, the first thing you should do is click Add Image File to add the image you created previously. The image page has only three fields: Location, Type and Import Method. Autopsy expects that the image is available somewhere on the local computer—either actually on the local disk or via an NFS or SMB mount. Type the full file path to the image file in the Location field. The Type field lets you inform Autopsy of the type of image you created. If you imaged the entire drive, select Disk; otherwise, select Partition. If you select Disk, Autopsy scans the partition table for you and lists all the image's partitions.
Autopsy needs the image file to be in its evidence locker in some form, and the Import Method field lets you choose how to put the image file there. If you store all your Autopsy evidence on a separate USB drive, you may want to select Copy, so that a copy of the image stays with the rest of the evidence. If your evidence locker is on your local disk along with the image (which is likely under the default settings), select Symlink or Move, depending on whether you want the image to stay in its original location. Repeat these steps to add any additional images for your host.
Figure 2. Host Manager Page
Start the Investigation
Now that you have created the case, added a host and selected any disk images, you are ready to start the analysis. On the Host Manager page, you will see all the partitions available to analyze. The root (/) partition is a good place to start, so select it, and click Analyze. The Analyze page lists a number of different ways to investigate the filesystem, but click the File Analysis button along the top of the screen to enter one of the main pages you will use for this analysis.
Figure 3. File Analysis
The File Analysis page gives you a complete view of the filesystem, starting at its root. The top-right frame lists all the files in the current directory, along with additional information each in its own field, including MAC times, permissions and file size. MAC (Modified, Accessed and Changed times), refers to three different changes the filesystem keeps track of for each file. The modified time is the last time the file or directory actually was written to. For instance, if you open a text file, edit it and save the changes, this updates the modified time. The access time is the last time the file or directory was accessed at all. Reading a file updates its access time, and listing the contents of a directory also updates its access time. The changed time keeps track of the last time the file's metadata (such as file permissions and owner) were changed. It's possible, in some cases, for some or all of these times to match.
Each of the files or directories in the File Analysis page are hyperlinked. If you click a directory, the page changes to list the contents of that directory. If you click a file, the bottom-right frame changes to list the contents of the file (even if it's binary) along with a number of functions you can perform on that file. You can display the ASCII or Hex versions of a file or have Autopsy scan the file and display only the ASCII strings inside. This feature is particularly handy to try on suspected trojan files. Often the ASCII strings inside a trojan binary list strange IRC channels or other remote servers or passwords the attacker is using. You also can export a copy of the file to your local disk for further examination.
Attackers often like to delete files to cover their tracks, but Autopsy can attempt to recover them from the free space on the filesystem. Go to the File Analysis page, click the All Deleted Files button on the bottom of the left-hand frame, and Autopsy lists all the deleted files it finds on the system. If Autopsy can recover that much information, you also can see the MAC times and may even be able to click on the file and recover its original contents!
All of these features are handy, but one of the most useful is the Add Note feature. If, for instance, you notice a system binary in your /bin directory that has a strange recent modified date and you notice some suspicious ASCII strings inside, you could click Add Note and list your findings. On the Add Note page, you also can add a sequencer event based on MAC time. If you thought the modified time was suspicious, you might select M-Time on the Add Note page. When you add notes like this for a number of files or directories, you end up with a large series of notes on what you have found along with interesting times. From the Host Manager window (the window that lists the host's partitions), click View Notes to see the list. This is an invaluable feature when you are trying to piece together the sequence of events from an attacker—particularly when you want to share your findings with others.
If you find a piece of information, such as an IP address or a particular server name as you scan files, you also can click Keyword Search at the top of the Analysis page to scan the entire filesystem for that keyword. You might find log entries or additional files the attacker uploaded that reference that keyword in unlikely places with this tool.
One thing you will discover is that the sequence of events is very important when figuring out an attacker's steps. The File Analysis window lets you sort by any of the headers, including the MAC times. An attacker often will replace a system binary under /bin or /sbin with a trojan, and because that will update the modified time for a file, if you sort the /bin and /sbin directories by modified time in the File Analysis window, you quickly can see suspicious file changes, such as a series of core programs, like ls, vi and echo, all modified a few days ago at a time when you know you didn't update any programs.
Where to Search
Where to Search
If you are new to forensics, you might not be sure of exactly where to start looking in your filesystem. A few directories often contain evidence of an attack that will at least give you a starting point. I've already mentioned the /bin and /sbin directories, as attackers often replace core system binaries in these directories with trojans. The /tmp and /var/tmp directories also are favorite locations, as any user on the system can write to them, so attackers often start their attacks in these directories and download rootkits and other tools here. Pay particular attention for hidden directories (directories that start with a .) in /var/tmp, as that's one way for attackers to cover their tracks from a casual observer. Finally, scan under /home and /root for suspicious files or strange commands in each users' .bash_history file.
What you hope to find is some idea of when attackers were active on your system. Once you have an idea of when the attackers were there, you can check file access and modify times during that period to track down where the attackers were on your system and which files they touched. Although you certainly could browse through the File Analysis window directory by directory, Autopsy provides an easier way via its File Activity Time Line. If you are currently in the File Analysis window, click Close to return to the main Host Manager window that lists the images you have added for your host. From there, click the File Activity Time Line button. Next, click Create Data File, click the check box next to all of the images it lists, and then click OK. This job will take some time, depending on the size and speed of your disk and your CPU.
Once the data file is created, click OK to proceed to the Create Timeline window. In this window, you can narrow down your timeline so that it lists only a particular time period; however, just leave all the options as they are for now and click OK. As you never exactly know where an investigation will lead, you don't want to rule out periods of time that might have valuable clues. When the timeline has been created, click OK to view the Web-based timeline viewer, but a note on that page gives a valuable tip—the timeline is easier to view via a text editor than from the Web interface. Find the raw timeline text file under /var/lib/autopsy/case/host/output/timeline.txt. If you named your case Investigation1 and your host Gonzo, you can find the file under /var/lib/autopsy/Investigation1/Gonzo/output/timeline.txt.
Figure 4. Sample timeline.txt File
The timeline.txt file lists every file on your image sorted by MAC time. This file contains a lot of information, but once you figure out what each field stands for, it's easier to decipher. The first column lists the time in question for a file followed by the file size. The next field denotes whether this time was a time the file was modified, accessed, changed or any combination of the three. If a file was both modified and accessed at this time, but its metadata was not changed, you would see “ma.” in this field. The next field lists the file permissions, followed by the user and group that owned the file. The final two fields list the filesystem inode and the full path to the file or directory. Note that if a group of files has the same time, only the first time field is filled.
If you have found one of the attackers' files, try to locate it in the timeline and see what other files were accessed and especially modified during that time period. With this method, you often can see a list of accessed files that show someone compiling or executing a program. If you notice that the attackers used a particular account on the system, use the File Analysis window to check the /home/username/.bash_history for that user and see any other commands the attackers might have run.
In addition, look at the login history, which often is found under /var/log/messages, for other times that user has logged in and try to correlate those times with any other file activity on the system inside the timeline.txt file. Remember to add notes for each clue you find—as you dig further and further into the filesystem, it can be difficult to keep track of all the different files and how they correlate, but the notes page makes it easy to see. The ultimate goal is to try to locate the earliest time attackers left tracks on the system and use that information to figure out how they got in.
As you might gather, thorough forensics analysis can be a time-consuming process. Even with a tool like Autopsy, it still takes time and experience to make sense of all of the data it presents so you can piece together an attack. One easy way to gain experience is to image your personal system and view it through Autopsy. Create a timeline and see whether you can track down some of the commands you last ran or files you last edited. You might possibly even want to attack your own machine and see if you can use Autopsy to retrace your steps. Although nothing can replace real data, this sort of practice goes a long way toward understanding forensics so you're prepared when a real attack occurs.
Tuesday, June 15, 2010
Helix3 (Pro)
Source
As expected, e-fense is moving to a commercial business model with their Helix3 Pro and no free support or user's forum will be available to Helix users from 2 February 2009.
To get access to Helix support and forum e-fense is introducing the membership for $19.95 a month or $239 a year. It is not very clear at this stage; whether Helix3 Pro will be available for free download to non-members.
30 January 2009To get access to Helix support and forum e-fense is introducing the membership for $19.95 a month or $239 a year. It is not very clear at this stage; whether Helix3 Pro will be available for free download to non-members.
Helix3 Pro will not be free!
Helix3 Enterprise
e-fense Inc. announces new management team
Helix3 vs Helix3 Pro
2 May 2009
E-fense decided to keep a free version of Helix3 alive
It can be downloaded here.
Helix is a ubuntu based linux distro that aims to help your work on Computer Forensic , Incident Response and Electronic Discovery. It almost has everything you need for your live forensic! By using Helix live cd , you can still boot into customized linux environment , that includes customized linux kernels, excellent hardware detection and many applications dedicated to Incident Response and Forensics !
Here’s the excerpt from their official site :
Helix has been modified very carefully to NOT touch the host computer in any way and it is forensically sound. Helix wil not auto mount swap space, or auto mount any attached devices. Helix also has a special live side for Incident Response and Forensics.Download Helix3 : http://www.e-fense.com/helix/Download.html
Helix focuses on Incident Response & Forensics tools. It is meant to be used by individuals who have a sound understanding of Incident Response and Forensic techniques.
http://mirrors.cmich.edu/helix/Helix2008R1.iso
http://nebula.indocisc.co.id/~za/iso/
Sunday, August 2, 2009
Subscribe to:
Posts (Atom)