<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: A Forensic Analysis of the Stolen Veteran&#8217;s Administration Laptop</title>
	<atom:link href="http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Tue, 07 Oct 2008 20:24:42 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Joe</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-3539</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Wed, 26 Jul 2006 01:55:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-3539</guid>
		<description>usually they copy the hddd contents over and play with thise ones as the originals are evidnece in court. all processes are logged so that any results are re obtainalbe from another copy.</description>
		<content:encoded><![CDATA[<p>usually they copy the hddd contents over and play with thise ones as the originals are evidnece in court. all processes are logged so that any results are re obtainalbe from another copy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Pinheiro</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2824</link>
		<dc:creator>Pedro Pinheiro</dc:creator>
		<pubDate>Mon, 10 Jul 2006 13:57:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2824</guid>
		<description>And would it be possible to design a live CD that wouldn't leave ANY traces?  Such as reading first the IDE info and reflashing afterwards, and not writing anything on the disk?  It would be an interesting alternative to opening the laptop to remove the disk (impossible not to leave any traces, imagine doing it on an iBook!).</description>
		<content:encoded><![CDATA[<p>And would it be possible to design a live CD that wouldn&#8217;t leave ANY traces?  Such as reading first the IDE info and reflashing afterwards, and not writing anything on the disk?  It would be an interesting alternative to opening the laptop to remove the disk (impossible not to leave any traces, imagine doing it on an iBook!).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bj</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2812</link>
		<dc:creator>bj</dc:creator>
		<pubDate>Mon, 10 Jul 2006 04:40:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2812</guid>
		<description>well; the real thing to do (if you were the bad guy) is to do a raw copy of the entire drive (dd / logicube) of the hard drive, then to do all your analysis on that..... that way you dont leave traces on the original drive (and not on the hardware if u use logicube or something equivalent).</description>
		<content:encoded><![CDATA[<p>well; the real thing to do (if you were the bad guy) is to do a raw copy of the entire drive (dd / logicube) of the hard drive, then to do all your analysis on that&#8230;.. that way you dont leave traces on the original drive (and not on the hardware if u use logicube or something equivalent).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2747</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Fri, 07 Jul 2006 04:30:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2747</guid>
		<description>&lt;strong&gt;Pedro:&lt;/strong&gt; You are right to a degree, it depends on the level of detail you go to. The thing is many of the modern bootable CD's mount any FAT32/NTFS partitions they find read/write which would leave last accessed information for any files you copied off. Also there is informations stored on the IDE channels, last accessed, last booted etc.</description>
		<content:encoded><![CDATA[<p><strong>Pedro:</strong> You are right to a degree, it depends on the level of detail you go to. The thing is many of the modern bootable CD&#8217;s mount any FAT32/NTFS partitions they find read/write which would leave last accessed information for any files you copied off. Also there is informations stored on the IDE channels, last accessed, last booted etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pedro Pinheiro</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2746</link>
		<dc:creator>Pedro Pinheiro</dc:creator>
		<pubDate>Thu, 06 Jul 2006 23:20:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2746</guid>
		<description>What kind of traces would booting with a linux live CD leave...? As I understand (unless you delete/change files) when such live CDs mount an existing partition, they don't write anything on it.  Am I wrong?</description>
		<content:encoded><![CDATA[<p>What kind of traces would booting with a linux live CD leave&#8230;? As I understand (unless you delete/change files) when such live CDs mount an existing partition, they don&#8217;t write anything on it.  Am I wrong?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Data Recovery&#187; Blog Archive &#187; A Forensic Analysis of the Stolen Veterans Administration Laptop (search mac data recovery)</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2738</link>
		<dc:creator>Data Recovery&#187; Blog Archive &#187; A Forensic Analysis of the Stolen Veterans Administration Laptop (search mac data recovery)</dc:creator>
		<pubDate>Thu, 06 Jul 2006 11:05:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/#comment-2738</guid>
		<description>[...] A Forensic Analysis of the Stolen Veterans Administration LaptopAn interesting speculative post on the techniques that would most likely be used by the FBI during&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] A Forensic Analysis of the Stolen Veterans Administration LaptopAn interesting speculative post on the techniques that would most likely be used by the FBI during&#8230; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
