<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; veterans-administration</title>
	<atom:link href="http://www.darknet.org.uk/tag/veterans-administration/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Forensic Analysis of the Lost Veteran&#8217;s Administration Laptop</title>
		<link>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/</link>
		<comments>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/#comments</comments>
		<pubDate>Thu, 06 Jul 2006 10:24:53 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[computer-forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[digital-forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[harddrive-recovery]]></category>
		<category><![CDATA[stolen-laptop]]></category>
		<category><![CDATA[veterans-administration]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-stolen-veterans-administration-laptop/</guid>
		<description><![CDATA[An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop. Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.) As a former Computer [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting speculative post on the forensics techniques that would most likely be used by the FBI during the investigation of the recovered Veteran&#8217;s Administration laptop.</p>
<p>Most of them are pretty straight forwards if you have any kind of experience with digital forensics and data recovery (disaster recovery, incident response etc.)</p>
<blockquote><p>As a former Computer Forensic Specialist, I wanted to explain what&#8217;s probably going on with this laptop now that the FBI has the system and is forensically examining it. This explanation assumes the data was present on the hard drive (not a CD-Rom or other storage medium).</p></blockquote>
<p>The two main areas cover physical examination and digital examination, physical would be looking for fingerprints and looking for evidence of tampering (screw heads, case scratches etc.).</p>
<p>A little discussion on MAC times and so on, if anyone is interested in this area, I might elaborate later.</p>
<p>As I said in the previous article, there isn&#8217;t much they can do if someone knew what they were doing.</p>
<blockquote><p>The laptop thieves really know what they are doing. They remove the hard drive from the laptop, and mount it read-only (no modifications to the file system) on another computer, access the sensitive data and re-insert the hard drive into the stolen laptop. This is the same process the forensic examiner would use to prevent the examination from modifying the data contained on the laptop &#8212; and this is why I mentioned what the FBI might look for during the physical examination &#8212; marks on the screws or finger prints on the internal hard drive casing.</p></blockquote>
<p>Indeed.</p>
<p></p>
<p>Source: <a href="http://blog.zonelabs.com/blog/2006/06/forensics_looki.html">Zonelabs</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D278+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;t=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/&amp;title=A+Forensic+Analysis+of+the+Lost+Veteran%E2%80%99s+Administration+Laptop" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fa-forensic-analysis-of-the-los-veterans-administration-laptop%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/a-forensic-analysis-of-the-los-veterans-administration-laptop/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Veterans Administration Chief Says Laptop Recovered</title>
		<link>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/</link>
		<comments>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/#comments</comments>
		<pubDate>Wed, 05 Jul 2006 07:28:19 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[data-forensics]]></category>
		<category><![CDATA[data-recovery]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[hardware-security]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[laptop-security]]></category>
		<category><![CDATA[physical-security]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[veterans-administration]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/</guid>
		<description><![CDATA[Ah, so finally they got it back, from a street corner of all places. Let&#8217;s hope they shall be a little more careful in the future yah? The missing laptop and hard drive that contained veterans&#8217; personal information has been found, Veterans Administration Chief Jim Nicholson announced Thursday. The announcement came at the beginning of [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah, so finally they got it back, from a street corner of all places.</p>
<p>Let&#8217;s hope they shall be a little more careful in the future yah?</p>
<blockquote><p>The missing laptop and hard drive that contained veterans&#8217; personal information has been found, Veterans Administration Chief Jim Nicholson announced Thursday. </p>
<p>The announcement came at the beginning of a hearing before the House Veterans&#8217; Affairs Committee hearing.</p>
<p>&#8220;It was confirmed to me by the deputy attorney general that law enforcement has in their possession the &#8230; laptop and hard drive,&#8221; Nicholson said in a statement at the hearing.  &#8220;The serial numbers match.&#8221;</p></blockquote>
<p>Of course the FBI will roll out it&#8217;s forensics experts to testify the data has not been accessed, but let&#8217;s face it, how hard is it to mount the drive read only and clone it?</p>
<p>Not very right..</p>
<blockquote><p>Experts were conducting forensic tests on the laptop and hard drive, Nicholson said. It was not immediately clear if the data on the equipment had been copied or compromised, but Nicholson said &#8220;there is reason to be optimistic.&#8221;</p>
<p>He did not say how the equipment was recovered, on where it&#8217;s been during the past two months.  The equipment was found Wednesday; Nicholson said he wasn&#8217;t aware of any arrests made in connection with the incident.</p>
<p>An FBI spokesman said the laptop computer was recovered &#8220;in the area,&#8221; but could not provide more specific information.  Forensics tests showed &#8220;the sensitive files were not accessed,&#8221; according to special agent in charge Bill Chase. </p></blockquote>
<p>We&#8217;ll look at the forensics techniques in more depth later.</p>
<p></p>
<p>Source: <a href="http://www.msnbc.msn.com/id/13613727/">MSNBC</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Veterans+Administration+Chief+Says+Laptop+Recovered+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D279+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;t=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/&amp;title=Veterans+Administration+Chief+Says+Laptop+Recovered" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fveterans-administration-chief-says-laptop-recovered%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/veterans-administration-chief-says-laptop-recovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

