<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Forensics</title>
	<atom:link href="http://www.darknet.org.uk/category/forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Mobius Forensic Toolkit 0.5.10 &#8211; Forensics Framework To Manage Cases &amp; Case Items</title>
		<link>http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/</link>
		<comments>http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 17:03:54 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[forensic framework]]></category>
		<category><![CDATA[forensic toolkit]]></category>
		<category><![CDATA[forensics framework]]></category>
		<category><![CDATA[free computer forensics tools]]></category>
		<category><![CDATA[mobius]]></category>
		<category><![CDATA[mobius forensic toolkit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3241</guid>
		<description><![CDATA[Mobius Forensic Toolkit is a forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions. Cases and item categories are defined using XML files for easy integration with other tools. Installation As root, type: python setup.py install Usage Run mobius_bin.py. You can download Mobius 0.5.10 here: mobiusft-0.5.10.tar.gz [...]]]></description>
			<content:encoded><![CDATA[<p>Mobius Forensic Toolkit is a forensic framework written in Python/GTK that manages cases and case items, providing an abstract interface for developing extensions. Cases and item categories are defined using XML files for easy integration with other tools.</p>
<p align="center"><img src="http://farm8.staticflickr.com/7164/6726345983_2816144f15.jpg" alt="Mobius Forensic Toolkit" /></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>Installation</strong></p>
<p>As root, type:</p>
<pre><code>python setup.py install</code></pre>
<p><strong>Usage</strong></p>
<p>Run mobius_bin.py.</p>
<p>You can download Mobius 0.5.10 here:</p>
<p><a href="http://download.savannah.gnu.org/releases/mobiusft/mobiusft-0.5.10.tar.gz">mobiusft-0.5.10.tar.gz</a><br />
<a href="http://download.savannah.gnu.org/releases/mobiusft/mobiusft-0.5.10.zip">mobiusft-0.5.10.zip</a></p>
<p>Or read more <a href="http://freecode.com/projects/mobiusft">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3241+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;t=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;title=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;title=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;title=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/&amp;title=Mobius+Forensic+Toolkit+0.5.10+%E2%80%93+Forensics+Framework+To+Manage+Cases+%26+Case+Items" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F01%2Fmobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/01/mobius-forensic-toolkit-0-5-10-forensics-framework-to-manage-cases-case-items/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Rec Studio 4 &#8211; Reverse Engineering Compiler &amp; Decompiler</title>
		<link>http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/</link>
		<comments>http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 18:37:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[decompiler]]></category>
		<category><![CDATA[decompiling]]></category>
		<category><![CDATA[interactive decompiler]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[REC decompiler]]></category>
		<category><![CDATA[rec studio]]></category>
		<category><![CDATA[Rec Studio 2]]></category>
		<category><![CDATA[rec studio 4]]></category>
		<category><![CDATA[reverse engineering tool]]></category>
		<category><![CDATA[reverse-engineering]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3082</guid>
		<description><![CDATA[REC Studio is an interactive decompiler. It reads a Windows, Linux, Mac OS X or raw executable file, and attempts to produce a C-like representation of the code and data used to build the executable file. It has been designed to read files produced for many different targets, and it has been compiled on several [...]]]></description>
			<content:encoded><![CDATA[<p>REC Studio is an interactive decompiler. It reads a Windows, Linux, Mac OS X or raw executable file, and attempts to produce a C-like representation of the code and data used to build the executable file. It has been designed to read files produced for many different targets, and it has been compiled on several host systems.</p>
<p>REC Studio 4 is a complete rewrite of the original REC decompiler. It uses more powerful analysis techniques such as partial Single Static Assignment (SSA), allows loading Mac OS X files and supports 32 and 64 bit binaries.</p>
<p>Although still under development, it has reached a stage that makes it more useful than the old Rec Studio 2.</p>
<p><strong>Features</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>    Multihost: Rec Studio runs on Windows XP/Vista/7, Ubuntu Linux, Mac OS X.</li>
<li>    Symbolic information support using Dwarf 2 and partial recognition of Microsoft&#8217;s PDB format.</li>
<li>    C++ is partially recognized: mangled names generated by gcc are demangled, as well as inheritance described in dwarf2 is honored. However, C++ is a very broad and difficult language, so some features like templates won&#8217;t likely be ever supported.</li>
<li>    Types and function prototype definitions can be specified in text files. Some standard Posix and Windows APIs are already provided in the Rec Studio package.</li>
<li>    Interactivity is supported, limited to definition of sections, labels and function entry points. Will need to improve it to support in-program definition of types and function parameters. </li>
</ul>
<p>Although REC can read Win32 executable (aka PE) files produced by Visual C++ or Visual Basic 5, there are limitations on the output produced. REC will try to use whatever information is present in the .EXE symbol table. If the .EXE file was compiled without debugging information, if a program data base file (.PDB) or Codeview (C7) format was used, or if the optimization option of the compiler was enabled, the output produced will not be very good. Moreover, Visual Basic 5 executable files are a mix of Subroutine code and Form data. It is almost impossible for REC to determine which is which. The only option is to use a .cmd file and manually specify which area is code and which area is data. </p>
<p>You can download Rec Studio 4 here:</p>
<p>Windows &#8211; <a href="http://www.backerstreet.com/rec/RecStudioWin.zip">RecStudioWin.zip</a><br />
Ubuntu &#8211; <a href="http://www.backerstreet.com/rec/RecStudioLinux.tgz">RecStudioLinux.tgz</a><br />
Mac &#8211; <a href="http://www.backerstreet.com/rec/RecStudioMac.tgz">RecStudioMac.tgz</a></p>
<p>Or read more <a href="http://www.backerstreet.com/rec/recdload.htm">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3082+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;t=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;title=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;title=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;title=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/&amp;title=Rec+Studio+4+%E2%80%93+Reverse+Engineering+Compiler+%26+Decompiler" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Frec-studio-4-reverse-engineering-compiler-decompiler%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/rec-studio-4-reverse-engineering-compiler-decompiler/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CAINE (Computer Aided INvestigative Environment) &#8211; Digital Forensics LiveCD</title>
		<link>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/</link>
		<comments>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 13:15:23 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Linux Hacking]]></category>
		<category><![CDATA[caine]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[digital forensics livecd]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[forensics livecd]]></category>
		<category><![CDATA[hacking-livecd]]></category>
		<category><![CDATA[linux forensics]]></category>
		<category><![CDATA[linux forensics livecd]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[mounter]]></category>
		<category><![CDATA[rbfstab]]></category>
		<category><![CDATA[security-livecd]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3188</guid>
		<description><![CDATA[CAINE (Computer Aided INvestigative Environment) is an Italian GNU/Linux live distribution created as a project of Digital Forensics. CAINE offers a complete forensic environment that is organized to integrate existing software tools as software modules and to provide a friendly graphical interface. The main design objectives that CAINE aims to guarantee are the following: an [...]]]></description>
			<content:encoded><![CDATA[<p>CAINE (Computer Aided INvestigative Environment) is an Italian GNU/Linux live distribution created as a project of Digital Forensics. CAINE offers a complete forensic environment that is organized to integrate existing software tools as software modules and to provide a friendly graphical interface.</p>
<p>The main design objectives that CAINE aims to guarantee are the following:</p>
<ul>
<li>        an interoperable environment that supports the digital investigator during the four phases of the digital investigation</li>
<li>        a user friendly graphical interface</li>
<li>        a semi-automated compilation of the final report</li>
</ul>
<p><strong>New Features/Tools</strong></p>
<ul>
<li>    New NAUTILUS SCripts</li>
<li>    ataraw</li>
<li>    bloom</li>
<li>    fiwalk</li>
<li>    xnview</li>
<li>    NOMODESET in starting menu</li>
<li>    xmount</li>
<li>    sshfs</li>
<li>    Reporting by Caine Interface fixed</li>
<li>    xmount-gui</li>
<li>    nbtempo</li>
<li>    fileinfo</li>
<li>    TSK_Gui</li>
<li>    Raid utils e bridge utils</li>
<li>    SMBFS</li>
<li>    BBT.py</li>
<li>    Widows Side:</li>
<li>    Wintaylor updated &#038; upgraded</li>
</ul>
<p>    <strong>“rbfstab”</strong> is a utility that is activated during boot or when a device is plugged.  It writes read-only entries to /etc/fstab so devices are safely mounted for forensic imaging/examination.  It is self installing with ‘rbfstab -i’ and can be disabled with ‘rbfstab -r’.  It contains many improvements over past rebuildfstab incarnations.  Rebuildfstab is a traditional means for read-only mounting in forensics-orient distributions.</p>
<p>    <strong>“mounter”</strong> is a GUI mounting tool that sits in the system tray.  Left clicking the system tray drive icon activates a window where the user can select devices to mount or un-mount.  With rbfstab activated, all devices, except those with volume label “RBFSTAB”, are mounted read-only.  Mounting of block devices in Nautilus (file browser) is not possible for a normal user with rbfstab activated making mounter a consistent interface for users.</p>
<p>You can download CAINE 2.5/Supernova here:</p>
<p><a href="http://www.caine-live.net/Downloads/caine2.5.iso">caine2.5.iso</a></p>
<p>Or read more <a href="http://www.caine-live.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3188+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;t=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/&amp;title=CAINE+%28Computer+Aided+INvestigative+Environment%29+%E2%80%93+Digital+Forensics+LiveCD" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fcaine-computer-aided-investigative-environment-digital-forensics-livecd%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/caine-computer-aided-investigative-environment-digital-forensics-livecd/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>File Disclosure Browser &#8211; Tool To Explore .DS_Store Files</title>
		<link>http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/</link>
		<comments>http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 16:04:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[ds_store]]></category>
		<category><![CDATA[ds_store files]]></category>
		<category><![CDATA[file disclosure browser]]></category>
		<category><![CDATA[hacking the web]]></category>
		<category><![CDATA[information collection]]></category>
		<category><![CDATA[information disclosure]]></category>
		<category><![CDATA[information-leak]]></category>
		<category><![CDATA[parsing ds_store files]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3197</guid>
		<description><![CDATA[The File Disclosure Browser takes .DS_Store files found on websites and parses through them to find a list of all potential files in the directory. It can then either just display the URLs for the files or if you give it a proxy it can browse to the files itself. The author wrote it after [...]]]></description>
			<content:encoded><![CDATA[<p>The File Disclosure Browser takes .DS_Store files found on websites and parses through them to find a list of all potential files in the directory. It can then either just display the URLs for the files or if you give it a proxy it can browse to the files itself.</p>
<p>The author wrote it after reading the <a href="http://pauldotcom.com/2011/08/dirbuster-to-burp-the-missing.html">PDC blog post on passing <a href="http://www.darknet.org.uk/2011/11/dirbuster-brute-force-directories-files-names/">DirBuster</a> through Burp</a> and figured doing the same thing for the contents of DS_Store files would be useful. He also plans to extend this to work with other disclosure files, including dwsync.xml files created by Dreamweaver and possibly some of the code repository files, cvs, svn, git etc.</p>
<p><strong>Requirements</strong></p>
<p>To run the app you need to install the CPAN module, you can do this by becoming root, entering the CPAN shell then asking it to do the install:</p>
<pre><code># perl -MCPAN -e shell
cpan[1]> install Mac::Finder::DSStore</code></pre>
<p>You can download File Disclosure Browser v1.0 here:</p>
<p><a href="http://www.digininja.org/files/fdb_1.0.tar.bz2">fdb_1.0.tar.bz2</a></p>
<p>Or read more <a href="http://www.digininja.org/projects/fdb.php">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3197+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;t=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;title=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;title=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;title=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/&amp;title=File+Disclosure+Browser+%E2%80%93+Tool+To+Explore+.DS_Store+Files" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Ffile-disclosure-browser-tool-to-explore-ds_store-files%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/file-disclosure-browser-tool-to-explore-ds_store-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIAT &#8211; The Cryptographic Implementations Analysis Toolkit</title>
		<link>http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/</link>
		<comments>http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 15:42:23 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[analysing cryptography]]></category>
		<category><![CDATA[analysing malware]]></category>
		<category><![CDATA[ciat]]></category>
		<category><![CDATA[cryptoanalysis]]></category>
		<category><![CDATA[Cryptographic Implementations Analysis Toolkit]]></category>
		<category><![CDATA[Cryptology]]></category>
		<category><![CDATA[crytographic analysis]]></category>
		<category><![CDATA[malware analysis]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3203</guid>
		<description><![CDATA[The Cryptographic Implementations Analysis Toolkit (CIAT) is a compendium of command line and graphical tools whose aim is to help in the detection and analysis of encrypted byte sequences within files (executable and non-executable). It is particularly helpful in the forensic analysis and reverse engineering of malware using cryptographic code and encrypted payloads. This was [...]]]></description>
			<content:encoded><![CDATA[<p>The Cryptographic Implementations Analysis Toolkit (CIAT) is a compendium of command line and  graphical  tools  whose  aim  is  to  help  in  the  detection  and  analysis  of  encrypted  byte sequences within files (executable and non-executable). It is particularly helpful in the forensic analysis and reverse engineering of malware using cryptographic code and encrypted payloads.</p>
<p>This was an interesting find because it wasn&#8217;t too long ago I published a post about <a href="http://www.darknet.org.uk/2011/08/mediggo-tool-to-detect-weak-or-insecure-cryptosystems-using-generic-cryptanalysis-techniques/">Mediggo, a Tool To Detect Weak Or Insecure Cryptosystems Using Generic Cryptanalysis Techniques</a>.</p>
<p><strong>Requirements </strong></p>
<p>Windows  Binaries  included  in  this  distribution  as  well  as  supporting  libraries  were  compiled using gcc, Mingw and Msys. </p>
<p>Linux binaries were compiled using gcc 4.1.2. They were tested from command line in machine with Windows Vista Home Premium (32 bit + SP1) and on Linux Gentoo 2008.0 X86 operating systems.<br />
 <div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /><br />
They should run without problems in any computer with Windows 2000, XP or VISTA 32bit and any  Linux  x86  with  Mesa3-D,  but I  cannot guarantee  that. If  you  have  problems  with  these<br />
binaries or want to run the programs in other platform you’ll need to compile them yourself.</p>
<p><strong>Compiling </strong></p>
<p>Version  1.02  includes  standard  configuration  scripts for Unix  like  systems.  The  old  Makefile (Makefile.linux32) is still included; if you use Windows I suggest you use MINGW+MSYS.  </p>
<p>You can download CIAT v1.02 here:</p>
<p><a href="http://downloads.sourceforge.net/project/ciat/ciat/1.02/ciat-1.02.zip?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fciat%2F&#038;ts=1317914757&#038;use_mirror=ncu">ciat-1.02.zip</a></p>
<p>Or read more <a href="http://sourceforge.net/projects/ciat/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3203+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;t=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;title=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;title=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;title=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/&amp;title=CIAT+%E2%80%93+The+Cryptographic+Implementations+Analysis+Toolkit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fciat-the-cryptographic-implementations-analysis-toolkit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/ciat-the-cryptographic-implementations-analysis-toolkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetworkMiner v1.1 Released &#8211; Windows Packet Analyzer &amp; Sniffer</title>
		<link>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/</link>
		<comments>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/#comments</comments>
		<pubDate>Tue, 20 Sep 2011 15:09:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[network miner]]></category>
		<category><![CDATA[network-forensics]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[network-sniffing]]></category>
		<category><![CDATA[networkminer]]></category>
		<category><![CDATA[packet-sniffer]]></category>
		<category><![CDATA[passive network sniffer]]></category>
		<category><![CDATA[windows network sniffer]]></category>
		<category><![CDATA[windows packet capture tool]]></category>
		<category><![CDATA[windows packet sniffer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3190</guid>
		<description><![CDATA[NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates [...]]]></description>
			<content:encoded><![CDATA[<p>NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.</p>
<p>NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).</p>
<p>NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>It&#8217;s been a long time since we last mentioned NetworkMiner, it was back in 2008 &#8211; <a href="http://www.darknet.org.uk/2008/02/networkminer-passive-sniffer-packet-analysis-tool-for-windows/">NetworkMiner – Passive Sniffer &#038; Packet Analysis Tool for Windows</a>.</p>
<p>Now there&#8217;s a new version!</p>
<p><strong>New in v1.1</strong></p>
<p>The new version supports features such as:</p>
<ul>
<li>Extraction of Google Analytics data</li>
<li>Better parsing of SMB data</li>
<li>Support for PPP frames</li>
<li>Even more stable than the 1.0 release</li>
</ul>
<p>You can download NetworkMiner v1.1 here:</p>
<p><a href="http://sourceforge.net/projects/networkminer/files/networkminer/NetworkMiner-1.1/NetworkMiner_1-1.zip/download">NetworkMiner_1-1.zip</a></p>
<p>Or read more <a href="http://www.netresec.com/?page=NetworkMiner">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3190+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;t=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fnetworkminer-v1-1-released-windows-packet-analyzer-sniffer%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Collar Bomber Gets Owned By Word Metadata &amp; USB Drive</title>
		<link>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/</link>
		<comments>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 17:34:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[collar bomb]]></category>
		<category><![CDATA[collar bomber]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[extortion]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[Paul "Doug" Peters]]></category>
		<category><![CDATA[paul peters]]></category>
		<category><![CDATA[recover usb drive data]]></category>
		<category><![CDATA[usb drive recovery]]></category>
		<category><![CDATA[usb forensics]]></category>
		<category><![CDATA[word metadata]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3174</guid>
		<description><![CDATA[There were other more technical and probably relevant stories to report on today, but for some reason I just found this story very odd and strangely fascinating. Now here a strange case, a man climbs into a young girls bedroom in the middle of the night, threatens her with a baseball bat and then chains [...]]]></description>
			<content:encoded><![CDATA[<p>There were other more technical and probably relevant stories to report on today, but for some reason I just found this story very odd and strangely fascinating.</p>
<p>Now here a strange case, a man climbs into a young girls bedroom in the middle of the night, threatens her with a baseball bat and then chains a bomb to her neck. His random instructions include e-mailing to a <a href="http://www.darknet.org.uk/tag/gmail/">Gmail</a> account and he leaves a &#8216;soft copy&#8217; version of the ransom note on a pen-drive with the girl.</p>
<p>You can find the court docs here &#8211; <a href="http://www.scribd.com/doc/62526127/Collar-Bomber-Complaint">Collar Bomber Complaint</a></p>
<blockquote><p>The man who claimed to have attached a bomb collar to an Australian high school student two weeks ago thought it would be a good idea to leave a ransom note on a USB stick looped around her neck. What he probably didn&#8217;t realize is that he also left his name, hidden deep in the device&#8217;s memory.</p>
<p>Court documents unsealed Tuesday describe the harrowing Aug. 3 incident, which began when a man broke into Madeline Pulver&#8217;s bedroom wearing a striped balaclava and wielding a black aluminum baseball bat. He told her to sit down and chained a black box around her neck.</p>
<p>He also draped a purple lanyard over the terrified girl with a note saying that the black box was a bomb. The note included ransom instructions for Pulver&#8217;s family, telling them to e-mail a Google address &#8212; dirkstraun1840@gmail.com &#8212; for further instructions. Also on the lanyard was a 4GB USB stick that contained a digital version of the note, saved as a pdf file.</p>
<p>The next 10 hours were a gruelling ordeal for the girl before a Sydney police bomb squad was able to determined that the threat was a hoax. But a closer look at the USB drive turned up a couple of files that the criminal thought he&#8217;d deleted. One of them, a version of the ransom note written in Microsoft Word, contained metadata about the document&#8217;s author, including his name: &#8220;Paul P.&#8221;</p>
<p>On Monday, U.S. authorities arrested Paul &#8220;Doug&#8221; Peters, 50, in La Grange, Kentucky, seeking to extradite him to Australia to face kidnapping and breaking-and-entering charges. It&#8217;s not clear why Peters attempted such a bizarre crime, but U.S. prosecutors say he once worked for a company linked to Pulver&#8217;s family. The girl&#8217;s father, Bill Pulver, is the CEO of voice recognition software company Appen Butler Hill. </p></blockquote>
<p>There are plenty of metadata extraction tools such as <a href="http://www.darknet.org.uk/2007/10/metagoofil-12-metadata-extractor-tool/">Metagoofil</a> and <a href="http://www.darknet.org.uk/2008/01/the-revisionist-metadata-retrieval-tool/" title="The Revisionist – Metadata Retrieval Tool">The Revisionist</a>. And well even without those, after recovering the file you can just open it in Word and view the metadata.</p>
<p>I&#8217;m guessing this Paul Peters chap wasn&#8217;t so familiar with wear levelling and metadata. He should have known better, and well he was doing this for a ransom..so really he should have just bought a new pen-drive for the job. </p>
<p>But as we know well, these people don&#8217;t think like we do &#8211; that&#8217;s why they end up in the news.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Police collected footage from surveillance cameras in a library where a computer was used to access the Gmail account. The footage, along with the USB drive and circumstantial evidence, such as purchases made around the time of the incident, link Peters to the crime, prosecutors say.</p>
<p>Even if the collar bomber had known his name was on the USB drive, it would have been very hard to remove it, according to Frank McClain, an independent computer forensics expert.</p>
<p>As computer geeks and investigators know, when users delete a file from a computer the file isn&#8217;t deleted immediately from the hard drive. Instead, the computer takes note that the area of the disk where the file is stored is now available to be written over. So investigators can often recover at least snippets of data from files that are supposed to have been deleted.</p>
<p>With flash drives things are more complex, thanks to mechanisms built into the drives to prolong their lifespan. Because flash memory cells stop working after they&#8217;ve been overwritten too many times, flash devices use tricks called &#8220;wear leveling&#8221; to even out how the memory cells are used. A side effect of wear levelling is that it is &#8220;almost impossible&#8221; to completely erase data from a flash device, McClain said.</p>
<p>That can come in handy for people trying to recover photos or other files they&#8217;ve accidentally deleted, and there are many tools, some of them free, to help recover their data.</p>
<p>The collar bomber&#8217;s first mistake was thinking he could delete something completely from his USB stick. But he also erred by not altering the metadata in his Word document. When Word saves a document, it automatically saves data, such as the user&#8217;s login name, as part of the file. Office 2007 users can see this metadata by hitting the Office button, then &#8220;Prepare&#8221; and &#8220;Properties.&#8221; </p></blockquote>
<p>Well there you go, an interesting mid-week story &#8211; not entirely sure what is going to happen to this guy. Doesn&#8217;t seem like a really strong case for extradition &#8211; he just seems like a complete nutcase.</p>
<p>He had a decent enough idea for extortion I suppose, just a really poor execution. Perhaps he&#8217;s been watching to o many Hollywood movies where these things seem really easy and nothing even goes wrong.</p>
<p>BTW if any of you readers out there see any cool new tools/techniques or news tidbits that I may have missed, I always welcome a heads-up so just hit me up on the <a href="http://www.darknet.org.uk/contact-darknet/" title="Contact Darknet">Contact Page here</a>.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/081711-the-collar-bombers-explosive-tech-249844.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3174+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;t=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/&amp;title=Collar+Bomber+Gets+Owned+By+Word+Metadata+%26+USB+Drive" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F08%2Fcollar-bomber-gets-owned-by-word-metadata-usb-drive%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/08/collar-bomber-gets-owned-by-word-metadata-usb-drive/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>ksymhunter &#8211; Routines For Hunting Down Kernel Symbols</title>
		<link>http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/</link>
		<comments>http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 15:51:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[kernel symbol hunter]]></category>
		<category><![CDATA[kernel symbol tool]]></category>
		<category><![CDATA[kernel symbols]]></category>
		<category><![CDATA[ksymhunter]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3138</guid>
		<description><![CDATA[Routines for hunting down kernel symbols from from kallsyms, System.map, vmlinux, vmlinuz, and remote symbol servers. Examples: $ ./ksymhunter prepare_kernel_cred [+] trying to resolve prepare_kernel_cred... [+] resolved prepare_kernel_cred using /boot/System.map-2.6.38-gentoo [+] resolved prepare_kernel_cred to 0xffffffff81061060 And.. $ ./ksymhunter commit_creds [+] trying to resolve commit_creds... [+] resolved commit_creds using /boot/System.map-2.6.38-gentoo [+] resolved commit_creds to 0xffffffff81060dc0 You [...]]]></description>
			<content:encoded><![CDATA[<p>Routines for hunting down kernel symbols from from kallsyms, System.map, vmlinux, vmlinuz, and remote symbol servers.</p>
<p>Examples:</p>
<pre><code>$ ./ksymhunter prepare_kernel_cred
[+] trying to resolve prepare_kernel_cred...
[+] resolved prepare_kernel_cred using /boot/System.map-2.6.38-gentoo
[+] resolved prepare_kernel_cred to 0xffffffff81061060</code></pre>
<p>And..</p>
<pre><code>$ ./ksymhunter commit_creds
[+] trying to resolve commit_creds...
[+] resolved commit_creds using /boot/System.map-2.6.38-gentoo
[+] resolved commit_creds to 0xffffffff81060dc0</code></pre>
<p>You can download ksymhunter v1.0 here:</p>
<p><a href="https://github.com/jonoberheide/ksymhunter/tarball/master">ksymhunter.tar.gz</a></p>
<p>Or read more <a href="https://github.com/jonoberheide/ksymhunter">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3138+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;t=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;title=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;title=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;title=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/&amp;title=ksymhunter+%E2%80%93+Routines+For+Hunting+Down+Kernel+Symbols" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fksymhunter-routines-for-hunting-down-kernel-symbols%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/ksymhunter-routines-for-hunting-down-kernel-symbols/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sniffjoke 0.4.1 Released &#8211; Anti-sniffing Framework &amp; Tool For Session Scrambling</title>
		<link>http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/</link>
		<comments>http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/#comments</comments>
		<pubDate>Mon, 30 May 2011 09:13:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[anti sniffing technology]]></category>
		<category><![CDATA[anti-sniffing]]></category>
		<category><![CDATA[anti-sniffing framework]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[prevent packet sniffing]]></category>
		<category><![CDATA[session scrambler]]></category>
		<category><![CDATA[session scrambler tool]]></category>
		<category><![CDATA[session scrambling tool]]></category>
		<category><![CDATA[sniffjoke]]></category>
		<category><![CDATA[tool for session scrambling]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3110</guid>
		<description><![CDATA[SniffJoke is an application for Linux that handle transparently your TCP connection, delaying, modifying and injecting fake packets inside your transmission, make them almost impossible to be correctly read by a passive wiretapping technology (IDS or sniffer). An Internet client running SniffJoke injects in the transmission flow some packets able to seriously disturb passive analysis [...]]]></description>
			<content:encoded><![CDATA[<p>SniffJoke is an application for Linux that handle transparently your TCP connection, delaying, modifying and injecting fake packets inside your transmission, make them almost impossible to be correctly read by a passive wiretapping technology (IDS or sniffer).</p>
<p>An Internet client running SniffJoke injects in the transmission flow some packets able to seriously disturb passive analysis like sniffing, interception and low level information theft. No server support is needed!</p>
<p>The internet protocols have been developed to allow two elements to communicate, not some third-parts to intercept their communication. This will happen, but the communication system has been not developed with this objective. SniffJoke uses the network protocol in a permitted way, exploiting the implicit difference of network stack present in an operating system respect the sniffers dissector.</p>
<p><strong>How Does It Work?</strong></p>
<p>It works only under Linux (at the moment), creates a fake default gateway in your OS (the client or a default gateway) using a TUN interface check every traffic passing thru it, tracks every session and<br />
applyies two concepts: the scramble and the hack.</p>
<p>The scramble is the technology to bring:</p>
<ol>
<li>A sniffer to accept as true a packet who will be discarded by the server, or</li>
<li>A sniffer to drop a packet who will be accepted by the server.</li>
</ol>
<p>The scramble technology brings in desynchronisation between the sniffer flow and the real flow.</p>
<p>The bogus packet accepted by the sniffer is generated by the &#8220;plugin&#8221; is a C++ simple class, which in a pseudo statefull tracking will forge the packet to be injected inside the flow. is pretty easy to develop<br />
anew one, and if someone wants to make research on sniffers attack (or fuzzing the flow searching for bugs) need to make the hand inside its.</p>
<p>The configuration permits to define blacklist/whitelist ip address to scramble, a degree of aggressivity for each port, which plugin will be used.</p>
<p>You can download SniffJoke here:</p>
<p><a href="http://www.delirandom.net/sniffjoke/sniffjoke-0.4.1.tar.bz2">sniffjoke-0.4.1.tar.bz2</a></p>
<p>Or read more <a href="http://www.delirandom.net/sniffjoke/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3110+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;t=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;title=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;title=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;title=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/&amp;title=Sniffjoke+0.4.1+Released+%E2%80%93+Anti-sniffing+Framework+%26+Tool+For+Session+Scrambling" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F05%2Fsniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/05/sniffjoke-0-4-1-released-anti-sniffing-framework-tool-for-session-scrambling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Analyser v3.0 &#8211; A Static &amp; Dynamic Malware Analysis Tool</title>
		<link>http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/</link>
		<comments>http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/#comments</comments>
		<pubDate>Mon, 23 May 2011 11:27:19 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[analyse malware]]></category>
		<category><![CDATA[analyze malware]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[dynamic malware analysis]]></category>
		<category><![CDATA[malware analyser]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[malware analyzer]]></category>
		<category><![CDATA[malware forensics]]></category>
		<category><![CDATA[static analysic]]></category>
		<category><![CDATA[static malware analysis]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3116</guid>
		<description><![CDATA[Malware Analyser is freeware tool to perform static and dynamic analysis on malware executables, it can be used to identify potential traces of anti-debug, keyboard hooks, system hooks and DEP setting change calls in the malware. This is a stepping release since for the first time the Dynamic Analysis has been included for file creations [...]]]></description>
			<content:encoded><![CDATA[<p>Malware Analyser is freeware tool to perform static and dynamic analysis on malware executables, it can be used to identify potential traces of anti-debug, keyboard hooks, system hooks and DEP setting change calls in the malware.</p>
<p>This is a stepping release since for the first time the Dynamic Analysis has been included for file creations (will be improved for other network/registry indicators sooner) along with process dumping feature.</p>
<p><strong>Features</strong></p>
<ul>
<li>
String based analysis for registry, API calls, IRC Commands, DLL&#8217;s called and VM Aware.</li>
<li>Display detailed headers of PE with all its section details, import and export symbols etc.</li>
<li>On Distro, can perform an ascii dump of the PE along with other options (check &#8211;help argument).</li>
<li>
For Windows, it can generate various section of a PE : DOS Header, DOS Stub, PE File Header, Image Optional Header, Section Table, Data Directories, Sections</li>
<li>ASCII dump on windows machine</li>
<li>Code Analysis (disassembling)</li>
<li>Online malware checking (<a href="http://www.virustotal.com">http://www.virustotal.com</a>)</li>
<li>Check for Packer from the Database.</li>
<li>Tracer functionality</li>
<li>Signature Creation: Allows to create signature of malware</li>
<li>CRC and Timestamp verification.</li>
<li>Entropy based scan to identify malicious sections.</li>
<li>Dump a process memory</li>
<li>Dynamic Analysis (Still in beginning stage) for file creations.</li>
</ul>
<p>You can download Malware Analyser v3.0 here:</p>
<p><a href="http://www.malwareanalyser.com/home/malware_analyser%203.0.zip">malware_analyser 3.0.zip</a></p>
<p>Or read more <a href="http://www.malwareanalyser.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3116+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;t=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;title=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;title=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;title=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/&amp;title=Malware+Analyser+v3.0+%E2%80%93+A+Static+%26+Dynamic+Malware+Analysis+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F05%2Fmalware-analyser-v3-0-a-static-dynamic-malware-analysis-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/05/malware-analyser-v3-0-a-static-dynamic-malware-analysis-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

