RE: images for computer forensics?



Like people told me when I asked this-buy secondhand disks from ebay and go
crazeee! You will be amazed...
Also, here in Oz the council do a hard rubbish removal service once a year.
You leave your rubbish on the kerb and they collect it-or other people
scavenge. Scavenge and get your friends round to marvel at what info you can
rebuild from 'deleted' files. Or even wide open files. The process for
recovering files/logs etc is the same as if it were a 'crime scene'.

Like Ansgar said, nobody is going to want to open up their confidential case
data to the world.


-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx] On
Behalf Of Ansgar -59cobalt- Wiechers
Sent: Tuesday, February 27, 2007 2:31 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: images for computer forensics?

On 2007-02-26 Zhihao wrote:
Hi list, was wondering if anyone knows of any online resources I can
visit that has got real life case studies of cybercrime and actually
has got the disk image of the server that was hacked? or even a disk
image of a system that was used to compromise a server? Went over to
honeynet.org and they do have an image of a purposely hacked redhat
6.2 but I will prefer a resource that will have actual disk images
from a crime scene.

I sure hope that nothing like that exists and will ever exist, because
these images will most likely contain confidential, maybe even personal
data.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

---------------------------------------------------------------------------
This list is sponsored by: BigFix

If your IT fails, you're out of business - or worse. Arm your
enterprise with BigFix, the single converged IT security and operations
engine. BigFix enables continuous discovery, assessment, remediation,
and enforcement for complex and distributed IT environments in real-time
from a single console.
Think what's next. Think BigFix.

http://ad.doubleclick.net/clk;82309979;15562032;o?http://www.bigfix.com/ITNe
xt/
---------------------------------------------------------------------------


---------------------------------------------------------------------------
This list is sponsored by: BigFix

If your IT fails, you're out of business - or worse. Arm your
enterprise with BigFix, the single converged IT security and operations
engine. BigFix enables continuous discovery, assessment, remediation,
and enforcement for complex and distributed IT environments in real-time
from a single console.
Think what's next. Think BigFix.

http://ad.doubleclick.net/clk;82309979;15562032;o?http://www.bigfix.com/ITNext/
---------------------------------------------------------------------------



Relevant Pages

  • Daily #4116
    ... Resovled Images of LMC Microlensing Events Observed by a Telescope at ... caused by faint LMC stars. ... Testing the Stellar Coalescence and Accretion Disk Theories of Massive ...
    (sci.astro.hubble)
  • Sharpest Image Ever Obtained of a Circumstellar Disk Reveals Signs of Young Planets
    ... SHARPEST IMAGE EVER OBTAINED OF A CIRCUMSTELLAR DISK REVEALS SIGNS ... are signs of unseen planets. ... has acquired high resolution images of the nearby star AU ...
    (sci.astro)
  • NIB to Disk!
    ... portable) for the PC that splits the .nib image into tracks, marks sync bytes, makes sure the track start is at the start, removes garbage and shortens inter-sector gaps, all to fit the 53248 bits per track of a ..nib image into the merely 51024 bits per track of a well-adjusted Disk II drive. ... tracks as files from a DOS 3.3 disk and then writes them to a new disk. ... and transfers the track files to the disk images. ... the game: the demo program, the player disk copier, the start of the ...
    (comp.sys.apple2)
  • Re: Cromemco CP/M 5 1/4 disk
    ... My recollection is that the source code has conditional assembly in it for persci/stepper motor drives, and also for 8"/5.25", but the 5.25" was never tested. ... I don't think I supplied disk images, per se, but rather source and object code for the files. ...
    (comp.os.cpm)
  • Re: SVD 1s on eBay
    ... >>> am selling original SVD 1's on eBay with and without Apple dongles. ... I wanted an SVD for a long time but couldn't get ahold of Eric ... To sum it up the SVD let's you run disk images on your Apple computer ... You upload your disk images to the SVD and hook the SVD ...
    (comp.sys.apple2)