Re: P2V - Live Forensics
Chris Barber <[email protected]> Wed, 2 Mar 2011 20:14:48 -0700
| Newsgroups | gmane.comp.security.forensics |
|---|---|
| Message-ID | <[email protected]> |
I am not an expert in this field by any means, and I have never been to court over a forensics case, I primarily perform Personnel level work. I have to agree with Paul on this one and that it could lead to issues in a courtroom especially if the defense wants a copy of the image that you used. It would be very possible that they would find out that the reason the PC did not come back up was cause by you, as a means to frame the user. One ruse I use on occasion is to shutdown the network port the user is attached to and the PC will not connect to the network. You get the same call to the help desk, they tell the user to shut down the PC and a tech will be there shortly to look at the issue. You make sure the PC is offline then enable the port, show up with a second PC to let the user work with fo= r a day or so while you try to figure out why the original PC is not working. Make the image and return the PC to the user the next day. I have no chance of leaving any finger prints on the PC for anyone to find. On Wed, Mar 2, 2011 at 2:36 AM, David Howe <[email protected]> wrot= e: > > Ah, but I didn't. That's the good bit - you alter the drive before the us= er ever brings it in, and the chain of evidence only needs to start once it= is on your desk. You need never admit or even mention that you broke it in= the first place. Your "investigation" starts when the user brings in a non= -booting device, and whatever happened before that isn't your problem :) > > You only correct the copy to boot again, the original stays intact (and i= f you want one to play with, you make a second copy for that). > > -----Original Message----- > From: Paul Schmehl [mailto:[email protected]] > Sent: 28 February 2011 16:59 > To: Dave Howe; [email protected] > Subject: Re: P2V - Live Forensics > > --On February 22, 2011 10:18:52 AM +0000 Dave Howe > <[email protected]> wrote: > > > On 15/02/2011 15:13, [email protected] wrote: > >> Ladies, Gentlemen, and otherwise: > >> > >> I have a situation whereby I need to obtain an image of an individual'= s > >> laptop suitable for potential prosecution in a US court; however, I on= ly > >> have a limited window in which to grab the image, and was looking for > >> alternatives in order to not "spook" the poor guy or his co-workers wh= o > >> would no doubt tell him about me, as I go into his office and randomly > >> image his drive! > > > > Here's one I have done in the past. > > Use psexec, mapped drives, whatever to gain access to the machine while > > running. rename ntldr to something else - next time the machine shuts > > down, it won't come up again. > > > > User screams, brings in machine for maint > > > > Very clever, but it will cause you problems in court. =C2=A0You altered t= he > drive before you removed it. =C2=A0Can you prove you didn't alter anythin= g else? > If not, your image isn't forensically sound and won't hold up in court. > > To obtain a forensically sound image, you need to capture the drive, eith= er > physically or over the network, without making any changes to it. =C2=A0Y= ou also > need to be able to prove that the image is identical to the drive you > captured, which means the md5 sum checks out and the image needs to be > read-only > > -- > Paul Schmehl, Senior Infosec Analyst > As if it wasn't already obvious, my opinions > are my own and not those of my employer. > ******************************************* > "It is as useless to argue with those who have > renounced the use of reason as to administer > medication to the dead." Thomas Jefferson > "There are some ideas so wrong that only a very > intelligent person could believe in them." George Orwell > > > David Howe Technical Analyst > > T:0161 227 1010 F:0161 227 1020 =C2=A0E: [email protected] > > Disclaimer > The information contained in this communication from david.howe@ansgroup.= co.uk sent at 2011-03-0209:36:33 is confidential and may be legally privile= ged. It is intended solely for use by [email protected] and other= s authorised to receive it. If you are not [email protected] you = are hereby notified that any disclosure, copying,distribution or taking act= ion in reliance of the contents of this information is strictly prohibited = and may be unlawful. ANS Group Plc Terms & Conditions apply, all prices are= subject to VAT, expenses excluded,E&O,E. > > ANS Group Plc 2010, Registered Office is Synergy House, Manchester Scienc= e Park, Manchester, M15 6SY. Reg No. 3176761. (Registered in England & Wale= s) > > > ----------------------------------------------------------------- > Certify Software Integrity - thawte Code Signing Certificates > This guide will show you how Code Signing Certificates are used to secure= code that can be downloaded from the Internet. You will also learn how the= se certificates operate with different software platforms. > http://www.dinclinx.com/Redirect.aspx?36;5000;25;1371;0;2;946;005be7f5c87= 2ea1f > > -- Chris Barber [email protected] =CB=99=C9=94=C4=B1=C6=83=C9=90=C9=AF =C9=AFo=C9=B9=C9=9F =C7=9Dlq=C9=90=C9= =A5s=C4=B1n=C6=83u=C4=B1=CA=87s=C4=B1pu=C4=B1 s=C4=B1 =CA=8E=C6=83olou=C9= =A5=C9=94=C7=9D=CA=87 p=C7=9D=C9=94u=C9=90=CA=8Cp=C9=90 =CA=8El=CA=87u=C7= =9D=C4=B1=C9=94=C4=B1=C9=9F=C9=9Fns =CA=8Eu=C9=90, - Arthur C. Clarke ----------------------------------------------------------------- Certify Software Integrity - thawte Code Signing Certificates This guide will show you how Code Signing Certificates are used to secure code that can be downloaded from the Internet. You will also learn how these certificates operate with different software platforms. http://www.dinclinx.com/Redirect.aspx?36;5000;25;1371;0;2;946;005be7f5c872ea1f