<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; data-recovery</title>
	<atom:link href="http://www.darknet.org.uk/tag/data-recovery/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Foremost &#8211; Recover Files From Drive or Drive Image AKA Carving</title>
		<link>http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/</link>
		<comments>http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/#comments</comments>
		<pubDate>Mon, 17 Sep 2007 19:57:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[dd]]></category>
		<category><![CDATA[encase]]></category>
		<category><![CDATA[file-forensics]]></category>
		<category><![CDATA[foremost]]></category>
		<category><![CDATA[forensics-tools]]></category>
		<category><![CDATA[free-forensics]]></category>
		<category><![CDATA[open-source-forensics]]></category>
		<category><![CDATA[recover-files]]></category>
		<category><![CDATA[safeback]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/</guid>
		<description><![CDATA[Foremost is a console program to recover files based on their headers, footers, and internal data structures. This process is commonly referred to as data carving. Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers can be specified by a [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Foremost is a console program to recover files based on their headers, footers, and internal data structures. This process is commonly referred to as data carving. Foremost can work on image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive.</p>
<p>The headers and footers can be specified by a configuration file or you can use command line switches to specify built-in file types. These built-in types look at the data structures of a given file format allowing for a more reliable and faster recovery.</p>
<p>Originally developed by the United States Air Force Office of Special Investigations and The Center for Information Systems Security Studies and Research , foremost has been opened to the general public.</p>
<p>You can download the latest version here:</p>
<p><a href="http://foremost.sourceforge.net/pkg/foremost-1.5.tar.gz">foremost-1.5.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://foremost.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D690+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;t=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;title=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;title=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;title=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/&amp;title=Foremost+%E2%80%93+Recover+Files+From+Drive+or+Drive+Image+AKA+Carving" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F09%2Fforemost-recover-files-from-drive-or-drive-image-aka-carving%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/09/foremost-recover-files-from-drive-or-drive-image-aka-carving/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Handy Recovery for Recovering Deleted Data on Windows</title>
		<link>http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/</link>
		<comments>http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/#comments</comments>
		<pubDate>Fri, 02 Mar 2007 11:20:05 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[computer-data]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[data-recovery-information]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[handy-recovery]]></category>
		<category><![CDATA[recover-deleted-files]]></category>
		<category><![CDATA[undelete]]></category>
		<category><![CDATA[undelete-software]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/</guid>
		<description><![CDATA[Handy Recovery is pretty neat software, there is occasions when I&#8217;m using Windows and I need to recover something or I&#8217;ve deleted something by mistake (I have a habit of using SHIFT+DEL so it&#8217;s not even in the recycle bin. I usually use Active Undelete and was pretty happy with it, I got a chance [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.handyrecovery.com/">Handy Recovery</a> is pretty neat software, there is occasions when I&#8217;m using Windows and I need to recover something or I&#8217;ve deleted something by mistake (I have a habit of using SHIFT+DEL so it&#8217;s not even in the recycle bin.</p>
<p>I usually use Active Undelete and was pretty happy with it, I got a chance to try out this software though and looked pretty cool.</p>
<p><img src="http://farm1.static.flickr.com/185/407670959_f0a7ad7fc6.jpg?v=0" alt="Handy Recovery" /></p>
<p>I have to say I do prefer <a href="http://www.handyrecovery.com/">Handy Recovery</a> to Active Undelete, it&#8217;s faster, small (Only 876kb including installer) and the best part is it gives an actual probability of data recovery for each file.</p>
<p>Plus it has a pretty neat filter/search system for finding specific files if you don&#8217;t know their location. The program supports FAT 12/16/32, NTFS and NTFS 5 + EFS file systems. This tool can recover files from deleted and formatted partitions or create disk images for deferred recovery. It shows probability of successful recovery for each file and features in-depth disk scanning for certain file types. According to Microsoft, Handy Recovery turned out to be among the first 100 applications that have earned the &#8220;Certified for Windows Vista&#8221; logo.</p>
<p>The Interface is nice and simple and it runs through the analysis stage pretty quickly, it&#8217;s very easy to recover files (recommended to recover to a different partition to reduce chances of permanent data loss) and just takes a couple of clicks.</p>
<p><img src="http://farm1.static.flickr.com/153/407670962_5fde59c8b7.jpg?v=0" alt="File Recovery" /></p>
<p>The trial version is limited to recover 1 file per day and can be download here:</p>
<p><a href="http://www.handyrecovery.com/handyrecovery.exe">Handy Recovery</a></p>
<p>There is also a freeware &#8216;lite&#8217; version here:<br />
<a href="http://www.handyrecovery.com/handyrecovery-fw.exe"><br />
Handy Recovery Lite</a></p>
<p><strong>System Requirements</strong></p>
<p>Windows 95/98/NT/2000/ME/XP/Vista<br />
File systems: FAT12/16/32 or NTFS/NTFS 5.</p>
<p>You can purchase <a href="http://www.handyrecovery.com/">Handy Recovery</a> here:</p>
<p><a href="http://www.handyrecovery.com/order.shtml">Order Handy Recovery</a></p>
<p></p>
<p>It&#8217;s pretty reasonably priced at <strong>$39US</strong> for 1-4 copies with discounts if you buy 5 or more.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D491+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;t=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;title=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;title=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;title=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/&amp;title=Handy+Recovery+for+Recovering+Deleted+Data+on+Windows" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F03%2Fhandy-recovery-for-recovering-deleted-data-on-windows%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/03/handy-recovery-for-recovering-deleted-data-on-windows/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Data Recovery &#8211; A Decent Article</title>
		<link>http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/</link>
		<comments>http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/#comments</comments>
		<pubDate>Wed, 17 Jan 2007 09:39:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[computer-data]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[data-recovery-information]]></category>
		<category><![CDATA[digital-forensics]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/</guid>
		<description><![CDATA[Data recovery is an important subject and it&#8217;s definitely a good thing to have a positive understanding of data recovery and how it could effort you personally or your business. So someone told me about this Data recovery article which is a decent original reference to data recovery which contains some good original information, links [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Data recovery is an important subject and it&#8217;s definitely a good thing to have a positive understanding of data recovery and how it could effort you personally or your business.</p>
<p>So someone told me about this <a href="http://www.bestpricecomputers.co.uk/glossary/data-recovery.htm">Data recovery article</a> which is a decent original reference to data recovery which contains some good original information, links to other similar resources, free data recovery downloads and an explanation of the main parts involved.</p>
<blockquote><p>Definition: Data recovery is the salvaging of data originally stored on media such as magnetic disks and tapes and which has become corrupt or inaccessible.</p></blockquote>
<p>The sidebar is pretty useful on the <a href="http://www.bestpricecomputers.co.uk/glossary/data-recovery.htm">Data recovery article</a> so do check it out, it has software, services and links to more information on industry standard sites like Wikipedia.</p>
<p>It also has related articles and related companies like OnTrack.</p>
<p>The article also covers some basic parts of forensics, like how when an item is deleted it&#8217;s not actually gone, just the marker in the file allocation table is removed.</p>
<blockquote><p><strong>Can erased data be recovered?</strong></p>
<p>Yes, usually. When you delete a file the file is not actually deleted. It&#8217;s just the entry in the index pointing to the file&#8217;s actual location that is deleted. The file itself is left untouched but subsequent work you do on the PC could overwrite the location where the file was so it&#8217;s important to minimise any amateur attempts at data recovery. </p></blockquote>
<p>This is something we&#8217;ve stressed many times at Darknet as any old $29.95 undelete tool can recover these files easily.</p>
<p>The important part of the article is the part about what mistakes you can make, this is crucial if you wish to save your data integrity in case of a failure.</p>
<p>I do find the design of the page a little plain (it looks like something designed in 1997) and the pink and light blue colour scheme jars my eyes a little.</p>
<p>The info is laid out clearly though and the site is easy to navigate, which is a good thing.</p>
<p></p>
<p>You can read more about <a href="http://en.wikipedia.org/wiki/Data_recovery">Data Recovery at Wiki here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Data+Recovery+%E2%80%93+A+Decent+Article+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D459+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;t=Data+Recovery+%E2%80%93+A+Decent+Article" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;title=Data+Recovery+%E2%80%93+A+Decent+Article" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;title=Data+Recovery+%E2%80%93+A+Decent+Article" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;title=Data+Recovery+%E2%80%93+A+Decent+Article" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/&amp;title=Data+Recovery+%E2%80%93+A+Decent+Article" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fdata-recovery-a-decent-article%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/data-recovery-a-decent-article/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A Forensic Analysis of the Lost Veteran&#8217;s Administration Laptop</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/</link>
		<comments>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/#comments</comments>
		<pubDate>Thu, 06 Jul 2006 10:24:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[harddrive-recovery]]></category>
		<category><![CDATA[stolen-laptop]]></category>
		<category><![CDATA[veterans-administration]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/</guid>
		<description><![CDATA[An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop. Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.) As a former Computer [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop.</p>
<p>Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.)</p>
<blockquote><p>As a former Computer Forensic Specialist, I wanted to explain what&#8217;s probably going on with this laptop now that the FBI has the system and is forensically examining it. This explanation assumes the data was present on the hard drive (not a CD-Rom or other storage medium).</p></blockquote>
<p>The two main areas cover physical examination and digital examination, physical would be looking for fingerprints and looking for evidence of tampering (screw heads, case scratches etc.).</p>
<p>A little discussion on MAC times and so on, if anyone is interested in this area, I might elaborate later.</p>
<p>As I said in the previous article, there isn&#8217;t much they can do if someone knew what they were doing.</p>
<blockquote><p>The laptop thieves really know what they are doing. They remove the hard drive from the laptop, and mount it read-only (no modifications to the file system) on another computer, access the sensitive data and re-insert the hard drive into the stolen laptop. This is the same process the forensic examiner would use to prevent the examination from modifying the data contained on the laptop &#8212; and this is why I mentioned what the FBI might look for during the physical examination &#8212; marks on the screws or finger prints on the internal hard drive casing.</p></blockquote>
<p>Indeed.</p>
<p></p>
<p>Source: <a href="http://blog.zonelabs.com/blog/2006/06/forensics_looki.html">Zonelabs</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D278+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;t=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fa-forensic-analysis-of-the-los-veterans-administration-laptop%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Veterans Administration Chief Says Laptop Recovered</title>
		<link>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/</link>
		<comments>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/#comments</comments>
		<pubDate>Wed, 05 Jul 2006 07:28:19 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[data-forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[hardware-security]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[laptop-security]]></category>
		<category><![CDATA[physical-security]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[veterans-administration]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/</guid>
		<description><![CDATA[Ah, so finally they got it back, from a street corner of all places. Let&#8217;s hope they shall be a little more careful in the future yah? The missing laptop and hard drive that contained veterans&#8217; personal information has been found, Veterans Administration Chief Jim Nicholson announced Thursday. The announcement came at the beginning of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah, so finally they got it back, from a street corner of all places.</p>
<p>Let&#8217;s hope they shall be a little more careful in the future yah?</p>
<blockquote><p>The missing laptop and hard drive that contained veterans&#8217; personal information has been found, Veterans Administration Chief Jim Nicholson announced Thursday. </p>
<p>The announcement came at the beginning of a hearing before the House Veterans&#8217; Affairs Committee hearing.</p>
<p>&#8220;It was confirmed to me by the deputy attorney general that law enforcement has in their possession the &#8230; laptop and hard drive,&#8221; Nicholson said in a statement at the hearing.  &#8220;The serial numbers match.&#8221;</p></blockquote>
<p>Of course the FBI will roll out it&#8217;s forensics experts to testify the data has not been accessed, but let&#8217;s face it, how hard is it to mount the drive read only and clone it?</p>
<p>Not very right..</p>
<blockquote><p>Experts were conducting forensic tests on the laptop and hard drive, Nicholson said. It was not immediately clear if the data on the equipment had been copied or compromised, but Nicholson said &#8220;there is reason to be optimistic.&#8221;</p>
<p>He did not say how the equipment was recovered, on where it&#8217;s been during the past two months.  The equipment was found Wednesday; Nicholson said he wasn&#8217;t aware of any arrests made in connection with the incident.</p>
<p>An FBI spokesman said the laptop computer was recovered &#8220;in the area,&#8221; but could not provide more specific information.  Forensics tests showed &#8220;the sensitive files were not accessed,&#8221; according to special agent in charge Bill Chase. </p></blockquote>
<p>We&#8217;ll look at the forensics techniques in more depth later.</p>
<p></p>
<p>Source: <a href="http://www.msnbc.msn.com/id/13613727/">MSNBC</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Veterans+Administration+Chief+Says+Laptop+Recovered+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D279+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;t=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fveterans-administration-chief-says-laptop-recovered%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

