<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; harddrive-recovery</title>
	<atom:link href="http://www.darknet.org.uk/tag/harddrive-recovery/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Forensic Analysis of the Lost Veteran&#8217;s Administration Laptop</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/</link>
		<comments>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/#comments</comments>
		<pubDate>Thu, 06 Jul 2006 10:24:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[harddrive-recovery]]></category>
		<category><![CDATA[stolen-laptop]]></category>
		<category><![CDATA[veterans-administration]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/</guid>
		<description><![CDATA[An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop. Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.) As a former Computer [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop.</p>
<p>Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.)</p>
<blockquote><p>As a former Computer Forensic Specialist, I wanted to explain what&#8217;s probably going on with this laptop now that the FBI has the system and is forensically examining it. This explanation assumes the data was present on the hard drive (not a CD-Rom or other storage medium).</p></blockquote>
<p>The two main areas cover physical examination and digital examination, physical would be looking for fingerprints and looking for evidence of tampering (screw heads, case scratches etc.).</p>
<p>A little discussion on MAC times and so on, if anyone is interested in this area, I might elaborate later.</p>
<p>As I said in the previous article, there isn&#8217;t much they can do if someone knew what they were doing.</p>
<blockquote><p>The laptop thieves really know what they are doing. They remove the hard drive from the laptop, and mount it read-only (no modifications to the file system) on another computer, access the sensitive data and re-insert the hard drive into the stolen laptop. This is the same process the forensic examiner would use to prevent the examination from modifying the data contained on the laptop &#8212; and this is why I mentioned what the FBI might look for during the physical examination &#8212; marks on the screws or finger prints on the internal hard drive casing.</p></blockquote>
<p>Indeed.</p>
<p></p>
<p>Source: <a href="http://blog.zonelabs.com/blog/2006/06/forensics_looki.html">Zonelabs</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D278+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;t=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fa-forensic-analysis-of-the-los-veterans-administration-laptop%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

