Tactical Fingerprinting using metadata, hidden info and lost data

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Tactical Fingerprinting using metadata, hidden info and lost data - Presentation Transcript

    1. Chema Alonso, Enrique Rando
    2.  
      • Metadata:
        • Information stored to give information about the document.
          • For example: Creator, Organization, etc..
      • Hidden information:
        • Information internally stored by programs and not editable.
          • For example: Template paths, Printers, db structure, etc…
      • Lost data:
        • Information which is in documents due to human mistakes or negligence, because it was not intended to be there.
          • For example: Links to internal servers, data hidden by format, etc…
    3. Wrong management Bad format conversion Unsecure options New apps or program versions Embedded files Search engines Spiders Databases Embedded files Wrong management Bad format conversion Unsecure options
      • The answer is NOT.
      • Almost nobody is cleaning documents.
      • Companies publish thousand of documents without cleaning them before:
        • Metadata.
        • Hidden Info.
        • Lost data.
    4. Total: 4841 files
    5.  
    6. Real Name Username Internal Domain .. And more…
    7. Total: 896 files
    8.  
    9.  
    10. Total: 1075 files
    11. User Software Version Internal Server NetBIOS name Remote Printer Name Local Printer
    12.  
    13.  
    14.  
    15.  
    16.  
      • Office documents:
        • Open Office documents.
        • MS Office documents.
        • PDF Documents.
          • XMP.
        • EPS Documents.
        • Graphic documents.
          • EXIFF.
          • XMP.
        • And almost everything….
    17. EXIFREADER http://www.takenet.or.jp/~ryuuji/
    18.  
    19. http://video.techrepublic.com.com/2422-14075_11-207247.html
    20.  
    21.  
    22.  
      • Users:
        • Creators.
        • Modifiers .
        • Users in paths.
          • C:Documents and settingsjfoomyfile
          • /home/johnnyf
      • History of use.
      • Operating systems.
      • Software versions.
      • Paths.
        • Local and remote.
      • Network info.
        • Shared Printers.
        • Shared Folders.
        • ACLS.
      • Printers.
        • Local and remote.
      • Internal Servers.
        • NetBIOS Name.
        • Domain Name.
        • IP Address.
      • Database structures.
        • Table names.
        • Colum names.
      • Devices info.
        • Mobiles.
        • Photo cameras.
      • Private Info.
        • Personal data.
      • Info is in the file in raw format:
        • Binary.
        • ASCII .
      • Therefore Hex or ASCII editors can be used:
        • HexEdit.
        • Notepad++.
        • Bintext
      • Special tools can be used:
        • Exif redaer
        • ExifTool
        • Libextractor.
        • Metagoofil.
      • … or just open the file!
    23.  
      • http://www.edge-security.com/metagoofil.php
    24.  
    25.  
    26.  
    27.  
    28.  
    29.  
    30.  
    31.  
      • These tools only extract metadata.
      • Not looking for Hidden Info.
      • Not looking for lost data.
      • Not post-analysis.
      • Fingerprinting Organizations with Collected Archives.
        • Search for documents
        • Automatic file downloading
        • Capable of extracting Metadata, hidden info and lost data.
        • Cluster information
        • Analyzes the info to fingerprint the network.
    32.  
    33.  
    34. http://www.informatica64.com/FOCA
    35.  
    36.  
    37.  
    38. http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=144e54ed-d43e-42ca-bc7b-5446d34e5360
    39.  
      • OOMetaExtractor
      http://www.codeplex.org/oometaextractor
    40.  
    41. http://www.metashieldprotector.com
    42.  
    43.  
    44.  
      • Authors
        • Chema Alonso
          • [email_address]
        • Enrique Rando
          • [email_address]
        • Alejandro Martín
          • [email_address]
        • Francisco Oca
          • [email_address]
        • Antonio Guzmán
          • [email_address]
    45.  

    + chemai64chemai64, 7 months ago

    custom

    1088 views, 0 favs, 2 embeds more stats

    Sesison about metadata security delivered in Blackh more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1088
      • 884 on SlideShare
      • 204 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 45
    Most viewed embeds
    • 203 views on http://elladodelmal.blogspot.com
    • 1 views on http://feeds2.feedburner.com

    more

    All embeds
    • 203 views on http://elladodelmal.blogspot.com
    • 1 views on http://feeds2.feedburner.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories