Steganography Revealed
Over the past couple of years, steganography has been the source of a lot of discussion, particularly as it was suspected that terrorists connected with the September 11 attacks might have used it for covert communications. While no such connection has been proven, the concern points out the effectiveness of steganography as a means of obscuring data. Indeed, along with encryption, steganography is one of the fundamental ways by which data can be kept confidential. This article will offer a brief introductory discussion of steganography: what it is, how it can be used, and the true implications it can have on information security.
Monday, April 14, 2003
Webinvestigator
The Internet consists of over two billion pages of information yet many investigators make only superficial use of this amazing resource. This site is dedicated to those who have to dig deeper and use information more carefully than the general public.
The Internet consists of over two billion pages of information yet many investigators make only superficial use of this amazing resource. This site is dedicated to those who have to dig deeper and use information more carefully than the general public.
Wednesday, April 02, 2003
CyberData
CyberData, LLC (formerly 20/20 Investigations, Inc.) has established itself as a leader in providing computer forensic analysis and computer crime investigation services. Our mission is to provide the highest quality of services with unequaled integrity. We serve our clients with complete honesty, outstanding customer service, and personal attention. We provide exceptional value to our clients by combining our investigative skills with our knowledge in computer forensics and computer crime investigations.
Services we provide are:
Computer Forensic Analysis
Analysis of previously analyzed reports
Analysis of computer media (hard drives, disks, CD's, flash cards, Palm Pilots, etc.)
Computer Crime Investigations
E-Mail Tracing and Internet Profiling
Intellectual Property Theft
Cyber-Stalking and Suspected Child Pornography
Online Fraud
Abuse of Computer Use Policies
Consulting
Minimizing data theft
Providing solutions to businesses
Analysis of Computer Use Policies
Password Cracking
Lost password?
Employee sabotage?
Hard Drive Wiping
Wipe the drive before you donate that old computer
New employee or re-allocating the computer to another person?
Unconditional guarantee – drives are wiped to Department of Defense standards
Data Recovery
Recover lost or missing files
Recover accidentally deleted files
CyberData, LLC (formerly 20/20 Investigations, Inc.) has established itself as a leader in providing computer forensic analysis and computer crime investigation services. Our mission is to provide the highest quality of services with unequaled integrity. We serve our clients with complete honesty, outstanding customer service, and personal attention. We provide exceptional value to our clients by combining our investigative skills with our knowledge in computer forensics and computer crime investigations.
Services we provide are:
Computer Forensic Analysis
Analysis of previously analyzed reports
Analysis of computer media (hard drives, disks, CD's, flash cards, Palm Pilots, etc.)
Computer Crime Investigations
E-Mail Tracing and Internet Profiling
Intellectual Property Theft
Cyber-Stalking and Suspected Child Pornography
Online Fraud
Abuse of Computer Use Policies
Consulting
Minimizing data theft
Providing solutions to businesses
Analysis of Computer Use Policies
Password Cracking
Lost password?
Employee sabotage?
Hard Drive Wiping
Wipe the drive before you donate that old computer
New employee or re-allocating the computer to another person?
Unconditional guarantee – drives are wiped to Department of Defense standards
Data Recovery
Recover lost or missing files
Recover accidentally deleted files
Compusleuth
CompuSleuth, Inc. is comprised of a team of highly skilled forensic computer specialists. Located in Westerville, Ohio, our goal is to provide expert services to the corporate, legal and accounting communities on both a local and national level.
CompuSleuth, Inc. is comprised of a team of highly skilled forensic computer specialists. Located in Westerville, Ohio, our goal is to provide expert services to the corporate, legal and accounting communities on both a local and national level.
WarTyping.com
The first (and currently only) site on the net dedicated specifically to the art of "War Typing". WarTyping is basically the act of location, and interception of radio signals transmitted by wireless keyboards onto the public airwaves by driving / walking around with the appropriate equipment.
The first (and currently only) site on the net dedicated specifically to the art of "War Typing". WarTyping is basically the act of location, and interception of radio signals transmitted by wireless keyboards onto the public airwaves by driving / walking around with the appropriate equipment.
Tuesday, April 01, 2003
ForensicsWeb
Welcome to Forensics Web! A site dedicated to technology related investigations and forensics. This site caters to law enforcment and corpsec interests with a special focus on computer related forensics and investigations. New sections, forums, and content will come online over time.
Welcome to Forensics Web! A site dedicated to technology related investigations and forensics. This site caters to law enforcment and corpsec interests with a special focus on computer related forensics and investigations. New sections, forums, and content will come online over time.
Thursday, March 20, 2003
tscrack
TScrack is a dictionary based (rather than bruteforce) password cracker for Microsoft Windows Terminal Services (RDP).
TScrack is a dictionary based (rather than bruteforce) password cracker for Microsoft Windows Terminal Services (RDP).
File Signature Database
This database is designed to assist examiners primarily for the process of searching unallocated space. With the ever-growing number of forensic tools being produced I have attempted to create a portable database, allowing examiners to export the data within, for the use on the majority of the leading forensic computing tools.
This database is designed to assist examiners primarily for the process of searching unallocated space. With the ever-growing number of forensic tools being produced I have attempted to create a portable database, allowing examiners to export the data within, for the use on the majority of the leading forensic computing tools.
Wednesday, March 19, 2003
Wireless Security & Hacking
This is the last article in the Wireless series. Just to remind you, the first article introduced the reader to the Wireless world and discussed Wireless devices and protocols. The second article went deeper into Wireless networks, provided general info on WLAN and discussed IEEE standards for them. This article deals with WLAN security, explains the most common attack techniques and introduces some useful tools.
This is the last article in the Wireless series. Just to remind you, the first article introduced the reader to the Wireless world and discussed Wireless devices and protocols. The second article went deeper into Wireless networks, provided general info on WLAN and discussed IEEE standards for them. This article deals with WLAN security, explains the most common attack techniques and introduces some useful tools.
Monday, March 17, 2003
Four basic steps can get hackers into most computers
Every breach of computer security is different, depending on the skills of the attacker and the defenses in your system. But most hackers follow the same four basic steps to perpetrate an attack — profiling, scanning, enumerating and exploiting.
Here's how each step works.
Every breach of computer security is different, depending on the skills of the attacker and the defenses in your system. But most hackers follow the same four basic steps to perpetrate an attack — profiling, scanning, enumerating and exploiting.
Here's how each step works.
Remote timing attacks are practical
Timing attacks are usually used to attack weak computing devices such as smartcards. We show that timing attacks apply to general software systems. Specifically, we devise a timing attack against OpenSSL. Our experiments show that we can extract private keys from an OpenSSL-based web server running on a machine in the local network. Our results demonstrate that timing attacks against network servers are practical and therefore all security systems should defend against them.
Timing attacks are usually used to attack weak computing devices such as smartcards. We show that timing attacks apply to general software systems. Specifically, we devise a timing attack against OpenSSL. Our experiments show that we can extract private keys from an OpenSSL-based web server running on a machine in the local network. Our results demonstrate that timing attacks against network servers are practical and therefore all security systems should defend against them.
Tuesday, March 11, 2003
Cryptographic Filesystems: Design and Implementation
As security becomes a greater focus in networks, every aspect of online information needs a level of protection from the network-level use of firewalls and IDS to the host-level use of IDS. However, an additional level of security has recently come to the forefront of security - cryptographic filesystems. While the technology for cryptographic filesystems has been available for quite a while, the deployment of cryptographic filesystems in production environments has not taken hold. This article will discuss some of the background and technology of cryptographic filesystems and will then cover some example implementations of these filesystems including Microsoft's Encrypting File System for Windows 2000, the Linux CryptoAPI, and the Secure File System.
As security becomes a greater focus in networks, every aspect of online information needs a level of protection from the network-level use of firewalls and IDS to the host-level use of IDS. However, an additional level of security has recently come to the forefront of security - cryptographic filesystems. While the technology for cryptographic filesystems has been available for quite a while, the deployment of cryptographic filesystems in production environments has not taken hold. This article will discuss some of the background and technology of cryptographic filesystems and will then cover some example implementations of these filesystems including Microsoft's Encrypting File System for Windows 2000, the Linux CryptoAPI, and the Secure File System.
Friday, March 07, 2003
Crypto For Newbies
Alright, I know you have read some crypto tutorial on the web before and you probably got confused at the first site of "cipher". In this tutorial I will not discribe very indepth of how the crypto works, but I will go over the very basics and introduce you to the different types of common encryptions and encoding schemes used on the net. I will go over how to encrypt and decrypt each of them so this tutorial should be a walk in the park. I've added a section on JTR, it is not very detailed.. but nether is the rest of this tutorial. It should be enough to get you going with JTR and crack a few password files. There are a few basic encoding methods used. I say encoding because they are just other ways of presenting data, unlike encryption they do not try to keep the message secret. Anyone can decode them without knowing the key, all they need to know is which program to use to decode it, or how to arrange the letters. Three very basic forms of encoding are uuencode (.uue) base64 (.b64) and rot13 (doesn't have a file extention as far as I know) All of these encoding methods are really simple to understand and decode. I'll also go over XOR and DES, which are true forms of encryption.
Alright, I know you have read some crypto tutorial on the web before and you probably got confused at the first site of "cipher". In this tutorial I will not discribe very indepth of how the crypto works, but I will go over the very basics and introduce you to the different types of common encryptions and encoding schemes used on the net. I will go over how to encrypt and decrypt each of them so this tutorial should be a walk in the park. I've added a section on JTR, it is not very detailed.. but nether is the rest of this tutorial. It should be enough to get you going with JTR and crack a few password files. There are a few basic encoding methods used. I say encoding because they are just other ways of presenting data, unlike encryption they do not try to keep the message secret. Anyone can decode them without knowing the key, all they need to know is which program to use to decode it, or how to arrange the letters. Three very basic forms of encoding are uuencode (.uue) base64 (.b64) and rot13 (doesn't have a file extention as far as I know) All of these encoding methods are really simple to understand and decode. I'll also go over XOR and DES, which are true forms of encryption.
Thursday, March 06, 2003
TAKEDOWN: Transcripts
In the course of tracking the attacker, a great deal of network traffic was captured by a specially modified version of tcpdump (here's information on the legality of the acquisition of this evidence), and then a program written by Tsutomu was used to produce playable logs. Another program will play them back (forwards or backwards) for you, in real-time (or faster, if you choose).
In the course of tracking the attacker, a great deal of network traffic was captured by a specially modified version of tcpdump (here's information on the legality of the acquisition of this evidence), and then a program written by Tsutomu was used to produce playable logs. Another program will play them back (forwards or backwards) for you, in real-time (or faster, if you choose).
Attack Lab Design & Security Mini How-Two
This document provides guidance for building and securing an attack lab. An attack lab is a networking environment designed for evaluating exploits, viruses, and similar security related software, and sometimes provides a facility for pen-test training, practice, and exercises. There are security measures that should be put in place to minimize the risk associated with the aforementioned activities. This document describes the necessary hardware, software, and network setup for an efficient and effective attack lab, as well as procedures and mechanisms to minimize the risks associated with running an attack lab.
This document provides guidance for building and securing an attack lab. An attack lab is a networking environment designed for evaluating exploits, viruses, and similar security related software, and sometimes provides a facility for pen-test training, practice, and exercises. There are security measures that should be put in place to minimize the risk associated with the aforementioned activities. This document describes the necessary hardware, software, and network setup for an efficient and effective attack lab, as well as procedures and mechanisms to minimize the risks associated with running an attack lab.
raptor's room
I'm a computer security researcher and consultant, a UNIX software developer and a system administrator. My particular interests are networking (specifically old-style X.25 packet switched networks and IEEE 802.11 wlan), telephony (fixed and mobile phones), communication protocols, and cryptography.
I'm a computer security researcher and consultant, a UNIX software developer and a system administrator. My particular interests are networking (specifically old-style X.25 packet switched networks and IEEE 802.11 wlan), telephony (fixed and mobile phones), communication protocols, and cryptography.
Security Is in the Smart Cards
News that a hacker recently accessed as many as 8 million Visa and MasterCard accounts would have been shocking if we weren't becoming so disturbingly numb to such break-ins. We really can't go on this way if retail e-commerce is to become a permanent, trusted part of our lives.
How did we get here? Credit card companies and online retailers bent over backward to make consumers feel secure about their transactions. Seeing to it that credit card numbers can't be lifted via communications over the wire or over the air was an important step.
But what of the credit card data once it's in the hands of the online retailer or the transaction processing company? In the instance above, Data Processing International, which services mostly television and catalog sales by phone, was the target. At a minimum, that data should be stored in encrypted form, preferably encrypted with the credit card vendor's public key so that the data is inaccessible to anyone but the vendor. But even better, it should not be stored at all.
The credit card data needed to complete a transaction should be submitted once and not retained. American Express' Private Payments program is a leader here, as the vendor gets a temporary transaction number, not the actual credit card number. But retailers have, by and large, chosen to store credit card numbers in online databases to encourage easier purchasing. Here's where smart cards can help. Using a smart card and scanner in combination with online wallet software can alleviate the chore of entering card data manually.
News that a hacker recently accessed as many as 8 million Visa and MasterCard accounts would have been shocking if we weren't becoming so disturbingly numb to such break-ins. We really can't go on this way if retail e-commerce is to become a permanent, trusted part of our lives.
How did we get here? Credit card companies and online retailers bent over backward to make consumers feel secure about their transactions. Seeing to it that credit card numbers can't be lifted via communications over the wire or over the air was an important step.
But what of the credit card data once it's in the hands of the online retailer or the transaction processing company? In the instance above, Data Processing International, which services mostly television and catalog sales by phone, was the target. At a minimum, that data should be stored in encrypted form, preferably encrypted with the credit card vendor's public key so that the data is inaccessible to anyone but the vendor. But even better, it should not be stored at all.
The credit card data needed to complete a transaction should be submitted once and not retained. American Express' Private Payments program is a leader here, as the vendor gets a temporary transaction number, not the actual credit card number. But retailers have, by and large, chosen to store credit card numbers in online databases to encourage easier purchasing. Here's where smart cards can help. Using a smart card and scanner in combination with online wallet software can alleviate the chore of entering card data manually.
Monday, March 03, 2003
Hydan: Information Hiding in Program Binaries
Hydan steganographically conceals a message into an application. It exploits redundancy in the i386 instruction set by defining sets of functionally equivalent instructions. It then encodes information in machine code by using the appropriate instructions from each set.
Hydan steganographically conceals a message into an application. It exploits redundancy in the i386 instruction set by defining sets of functionally equivalent instructions. It then encodes information in machine code by using the appropriate instructions from each set.
SSH Tunneling part 1 - Local Forwarding
Want to encrypt an otherwise cleartext transmission? SSH Tunneling may be the tool for you.
Want to encrypt an otherwise cleartext transmission? SSH Tunneling may be the tool for you.
Computer Crime Investigator's Toolkit
What I've tried to do is devise a summary of basic, practical knowledge, "tricks," if you like, that should interest all computer crime investigators. While they may not be the final word in preparing for an examination, these techniques will provide some insight into the ways and means of computer criminals. I hope to get you into the spirit of the hunt. Learning to think how a criminal looks at twisting, altering, hiding, and diverting information will definitely make the game more interesting. This is a pathfinder, a starting point to discovering other resources.
What I've tried to do is devise a summary of basic, practical knowledge, "tricks," if you like, that should interest all computer crime investigators. While they may not be the final word in preparing for an examination, these techniques will provide some insight into the ways and means of computer criminals. I hope to get you into the spirit of the hunt. Learning to think how a criminal looks at twisting, altering, hiding, and diverting information will definitely make the game more interesting. This is a pathfinder, a starting point to discovering other resources.
Subscribe to:
Posts (Atom)
