SlideShare a Scribd company logo
1 of 88
Download to read offline
FORENSIC INSIGHT SEMINAR
Web Browser Forensics : Part2
blueangel
blueangel1275@gmail.com
http://blueangel-forensic-note.tistory.com
forensicinsight.org Page 2 / 88
๊ฐœ์š”
1. Firefox ๋กœ๊ทธ ๋ถ„์„
2. Chrome ๋กœ๊ทธ ๋ถ„์„
3. Safari ๋กœ๊ทธ ๋ถ„์„
4. Opera ๋กœ๊ทธ ๋ถ„์„
5. ๋ถ„์„ ๋„๊ตฌ
forensicinsight.org Page 3 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 4 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ
โ€ข Cache Map File : _CACHE_MAP_
โ€ข Cache Block Files : _CACHE_00X_
โ€ข Separate Cache Data files
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 5 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache Map File ๊ตฌ์กฐ
โ€ข 32๊ฐœ์˜ Bucket๋กœ ์ด๋ฃจ์–ด์ง
โ€ข ํ•œ ๊ฐœ์˜ Bucket์€ 256๊ฐœ์˜ Record๋ฅผ ํฌํ•จ ๏ƒจ ์ด 8,192๊ฐœ์˜ Record ์ €์žฅ ๊ฐ€๋Šฅ
โ€ข ํ•˜๋‚˜์˜ Record(16byte)๋Š” Cache ๋ฐ์ดํ„ฐ์˜ ๋งตํ•‘ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ์Œ
Cache ์ •๋ณด ๋ถ„์„
Hash Number(4byte)
Eviction Rank(4byte)
Data location(4byte)
Metadata Location(4byte)
forensicinsight.org Page 6 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache Map File Record ๊ตฌ์กฐ
โ€ข Hash Number
๏ƒผ Cache ํŒŒ์ผ์˜ ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉ
โ€ข Data location, Metadata Location
๏ƒผ ์ตœ์ƒ์œ„ ๋ฐ”์ดํŠธ์˜ ํ•˜์œ„ 3๋น„ํŠธ ๊ฐ’์ด 0์ด๋ฉด Separate Cache ํŒŒ์ผ์— ์ €์žฅ 1,2,3์ด๋ฉด Cache Block ํŒŒ
์ผ์— ์ €์žฅ
โ€ข Eviction Rank
๏ƒผ Unkwon
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 7 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Separate Cache Data Files
โ€ข Cache Content๊ณผ Matadata์˜ ํฌ๊ธฐ๊ฐ€ ํฐ ๊ฒฝ์šฐ ์‚ฌ์šฉ
โ€ข Cache Data Files์˜ ์ด๋ฆ„
๏ƒผ <HASH NUMBER><TYPE><GENERATION NUMBER>
๏ƒผ HASH NUMBER
โ€ข Cache Map file์˜ Hash Number
๏ƒผ TYPE
โ€ข d: Cache Content
โ€ข m: Cache metadata
๏ƒผ GENERATION NUMBER
โ€ข Data location, Metadata Location ์ตœํ•˜์œ„ 1๋ฐ”์ดํŠธ ๊ฐ’
โ€ข Ex) F1FD0B04d01
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 8 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Three Cache Block Files
๏ƒผ ๋ฐ์ดํ„ฐ์˜ ์‹œ์ž‘
๏ƒผ Data location, Metadata Location์˜ ํ•˜์œ„ 3๋ฐ”์ดํŠธ ๊ฐ’
๏ƒผ ๋ฐ์ดํ„ฐ ํ• ๋‹น ํฌ๊ธฐ(๋ธ”๋ก ๋‹จ์œ„)
๏ƒผ ((Data location, Metadata Location) & 0x03000000) >> 24 ) + 1
๏ƒผ ๋ธ”๋ก ์‚ฌ์ด์ฆˆ
๏ƒผ Cache Block Files์˜ ํŒŒ์ผ ์ด๋ฆ„์— ๋”ฐ๋ผ ๋‹ค๋ฆ„
๏ƒผ โ€œ_CACHE_001_โ€->256 byte (0x100)
๏ƒผ โ€œ_CACHE_002_โ€->512 byte (0x400)
๏ƒผ โ€œ_CACHE_003โ€_->1024 byte (0x1000)
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 9 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Separate Cache Data Files ๋‚ด์šฉ ํ™•์ธ
โ€ข Data Location
๏ƒผ 8(1000): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 0์ด๋ฏ€๋กœ Separate Cache Data File์— ์ €์žฅ
๏ƒผ ํŒŒ์ผ ์ด๋ฆ„: 3A390709d01
โ€ข MetaData Location
๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1 ์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ
๏ƒผ offset: 0x000B94*0x100+0x1000 = 0x000BA400
Cache ์ •๋ณด ๋ถ„์„
Hash number Eviction Rank Data Location
MetaData Location
forensicinsight.org Page 10 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Separate Cache Data Files ๋‚ด์šฉ ํ™•์ธ
โ€ข _CACHE_001_ ํŒŒ์ผ์˜ offset 0x000BA400
โ€ข Cache ํด๋”์˜ 3A390709d01ํŒŒ์ผ์˜ ํ™•์žฅ์ž๋ฅผ gif ๋กœ ๋ณ€๊ฒฝํ•˜๋ฉด ๋‚ด์šฉ ํ™•์ธ ๊ฐ€๋Šฅ
Cache ์ •๋ณด ๋ถ„์„
URL
์ ‘์† ์‹œ๊ฐ„
๋ณ€๊ฒฝ ์‹œ๊ฐ„
ํŒŒ์ผ ํฌ๊ธฐ
Content Type
forensicinsight.org Page 11 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Three Cache Block File ๋‚ด์šฉ ํ™•์ธ
โ€ข Data Location
๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ
๏ƒผ offset: 0x000B33*0x100+0x1000 = 0x000B4300
โ€ข MetaData Location
๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1 ์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ
๏ƒผ offset: 0x000B36*0x100+0x1000 = 0x000B4600
Cache ์ •๋ณด ๋ถ„์„
Hash number Eviction Rank Data Location
MetaData Location
forensicinsight.org Page 12 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง Three Cache Block File ๋‚ด์šฉ ํ™•์ธ
โ€ข Content Data
โ€ข Content Metadata
Cache ์ •๋ณด ๋ถ„์„
URL
์ ‘์† ์‹œ๊ฐ„
๋ณ€๊ฒฝ ์‹œ๊ฐ„
ํŒŒ์ผ ํฌ๊ธฐ
Content Type
forensicinsight.org Page 13 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋ฐ์ดํ„ฐ ํฌ๊ธฐ
โ€ข Data์˜ ํฌ๊ธฐ๊ฐ€ 85 ๋ฐ”์ดํŠธ ๏ƒจ Content Data์˜ 85 ๋ฐ”์ดํŠธ๋ฅผ setup_myinfo.gif๋กœ ์ €์žฅ
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 14 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 15 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : places.sqlite
๏‚ง ํŒŒ์ผ ํ˜•์‹
๏‚ง SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ”
๏‚ง moz_places : ๋ฐฉ๋ฌธํ•œ URL ์ •๋ณด ์ €์žฅ
๏‚ง moz_historyvisits : ์‹ค์ œ ๋ฐฉ๋ฌธ ๊ธฐ๋ก ์ €์žฅ, place_id ๊ฐ’์„ ํ†ตํ•ด moz_place์˜ url ์ฐธ์กฐ
๏‚ง ์ €์žฅ ์ •๋ณด
๏‚ง URL
๏‚ง Title
๏‚ง ๋ฐฉ๋ฌธ ํšŸ์ˆ˜
๏‚ง ๋ฐฉ๋ฌธ ํƒ€์ž…(1 : URL ํƒ€์ดํ•‘ ์ ‘์†, 0 : ๋งํฌ ์ ‘์†)
๏‚ง ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 16 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง moz_places, moz_historyvisits ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 17 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 18 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : cookies.sqlite
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ”
โ€ข moz_cookies : ์ฟ ํ‚ค ๋ฐ์ดํ„ฐ ์ €์žฅ
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ํ˜ธ์ŠคํŠธ, ๊ฒฝ๋กœ
โ€ข ๋ณ€์ˆ˜, ๊ฐ’
โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜
โ€ข ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
โ€ข ์ฟ ํ‚ค ๋งŒ๋ฃŒ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
โ€ข isSecure, isHttpOnly
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 19 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง moz_cookies ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 20 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 21 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : downloads.sqlite
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ”
โ€ข moz_downloads : ์ฟ ํ‚ค ๋ฐ์ดํ„ฐ ์ €์žฅ
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ์†Œ์Šค URL
โ€ข ๋‹ค์šด๋ฐ›์€ Local ๊ฒฝ๋กœ
โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) : ์‹œ์ž‘/ ์ข…๋ฃŒ์‹œ๊ฐ„
โ€ข ๋‹ค์šด๋กœ๋“œ ๋ฐ›์€ ํฌ๊ธฐ, ์ด ๋‹ค์šด๋กœ๋“œ ํฌ๊ธฐ
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 22 / 88
Firefox ๋กœ๊ทธ ๋ถ„์„
๏‚ง moz_downloads ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 23 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 24 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ์ „์ฒด ํŒŒ์ผ ๊ตฌ์„ฑ
โ€ข data_0, data_1, data_2, data_3, ๋ฐ์ดํ„ฐ ํŒŒ์ผ
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 25 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ
โ€ข data_0
๏ƒผ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ๋จ( URL ๋ ˆ์ฝ”๋“œ์˜ ์œ„์น˜ ์ •๋ณด ์ €์žฅ)
๏ƒผ ์˜คํ”„์…‹ 0x2000 ๋ถ€ํ„ฐ 0x24 ๋ฐ”์ดํŠธ ๋‹จ์œ„๋กœ ์ €์žฅ
โ€ข data_1, data_2, data_3
๏ƒผ URL(URL ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋จ), ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ, Cache ๋ฐ์ดํ„ฐ ์ €์žฅ
๏ƒผ ์˜คํ”„์…‹ 0x2000 ๋ถ€ํ„ฐ ๋ธ”๋ก ๋‹จ์œ„๋กœ ์ €์žฅ
๏ƒผ ๋ธ”๋ก ๋‹จ์œ„
โ€ข data_1: 0x100
โ€ข data_2: 0x400
โ€ข data_3: 0x1000
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 26 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง data_0 ์—์„œ์˜ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ
โ€ข ์ตœ์ดˆ 2 ๋ฐ”์ดํŠธ
๏ƒผ ๋ธ”๋ก์˜ ์ธ๋ฑ์Šค
๏ƒผ 0x0001์ด๋ฉด ๋‘ ๋ฒˆ์งธ ๋ธ”๋ก์— URL๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ ๋˜์–ด ์žˆ์Œ
โ€ข 3๋ฒˆ์งธ ๋ฐ”์ดํŠธ
๏ƒผ ํŒŒ์ผ์˜ ์ธ๋ฑ์Šค
๏ƒผ 0x01์ด๋ฉด data_1 ํŒŒ์ผ์— URL ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ ๋˜์–ด ์žˆ์Œ
โ€ข URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜
๏ƒผ ๋ธ”๋ก ์ธ๋ฑ์Šค * ๋ธ”๋ก์˜ ๋‹จ์œ„ + 0x2000
Cache ์ •๋ณด ๋ถ„์„
HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F
00
10 URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜ ์ •๋ณด
20
forensicinsight.org Page 27 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง data_n(n=1, 2, 3) ์—์„œ์˜ URL ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ
โ€ข (๋ฉ”ํƒ€)๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„
๏ƒผ 4๋ฒˆ์งธ ๋ฐ”์ดํŠธ์— ๋”ฐ๋ผ ์ €์žฅ ์œ„์น˜ ๊ฒฐ์ •
โ€ข 0x80์ด๋ฉด ๋ณ„๋„์˜ ํŒŒ์ผ๋กœ ์ €์žฅ ๋‚˜๋จธ์ง€ 3๋ฐ”์ดํŠธ๊ฐ€ ํŒŒ์ผ์˜ ์ด๋ฆ„
โ€ข 0x80์ด ์•„๋‹ˆ๋ฉด โ€œURL ๋ ˆ์ฝ”๋“œ ์œ„์น˜โ€์™€ ๊ฐ™์€ ๋ฐฉ์‹์œผ๋กœ ๊ณ„์‚ฐ
Cache ์ •๋ณด ๋ถ„์„
HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F
00 URL์˜ ํฌ๊ธฐ
10 ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„
20 ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„
URL์˜
์‹œ์ž‘
์œ„์น˜
forensicinsight.org Page 28 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 1 : data_0์˜ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ์—์„œ URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜๋ฅผ ์ฐธ์กฐ
Cache ์ •๋ณด ๋ถ„์„
0x0002 * 0x100 + 0x2000 = 0x2200
data_1
data_0
URL์˜ ํฌ๊ธฐ
forensicinsight.org Page 29 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 2 : data_1์˜ URL ๋ ˆ์ฝ”๋“œ์—์„œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜๋ฅผ ์ฐธ์กฐ
Cache ์ •๋ณด ๋ถ„์„
data_1
๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ
๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜:data_1
0x0003 * 0x 100 + 0x2000 = 0x2300
data_1
forensicinsight.org Page 30 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 3 : data_1์˜ URL ๋ ˆ์ฝ”๋“œ์—์„œ ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜๋ฅผ ์ฐธ์กฐ
Cache ์ •๋ณด ๋ถ„์„
data_1
๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ
๋ฐ์ดํ„ฐํŒŒ์ผ ์ด๋ฆ„:f_000001
ํ™•์žฅ์ž ๋ณ€๊ฒฝ
forensicinsight.org Page 31 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cache ๋ฐ์ดํ„ฐ๊ฐ€ Cache ํŒŒ์ผ(data_n) ์•ˆ์— ์žˆ๋Š” ๊ฒฝ์šฐ
Cache ์ •๋ณด ๋ถ„์„
data_1
๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ
๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜:data_3
์˜คํ”„์…‹: 0x0000*0x1000+0x2000 = 0x2000
Data_3
forensicinsight.org Page 32 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ์ตœ์‹  ๋ฒ„์ „์˜ URL ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ
โ€ข (๋ฉ”ํƒ€)๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ ๊ณ„์‚ฐ ๋ฐฉ์‹์€ ๊ธฐ์กด๊ณผ ๋™์ผ
Cache ์ •๋ณด ๋ถ„์„
HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F
00
10
20 URL์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ
30 ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„
40
50 URL์˜ ์‹œ์ž‘ ์œ„์น˜
forensicinsight.org Page 33 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 34 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History
๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ”
โ€ข urls ํ…Œ์ด๋ธ”
๏ƒผ ๋ฐฉ๋ฌธํ•œ url ์ •๋ณด ์ €์žฅ, ๊ฐ™์€ url์€ ์ค‘๋ณต ์ €์žฅ ์•ˆ ๋จ, ์ค‘๋ณต ๋ฐฉ๋ฌธ ์‹œ ๋งˆ์ง€๋ง‰ ์ ‘์† ์‹œ๊ฐ„ ์ €์žฅ
โ€ข visits ํ…Œ์ด๋ธ”
๏ƒผ ์‹ค์ œ ๋ฐฉ๋ฌธ ์ •๋ณด ์ €์žฅ, ์‹ค์ œ ๋ฐฉ๋ฌธ ์‹œ ์ €์žฅ๋˜๋Š” url์ •๋ณด๋Š” urls ํ…Œ์ด๋ธ”์—์„œ ์ฐธ์กฐ
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข URL
โ€ข Title
โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜
โ€ข ๋ฐฉ๋ฌธ ํƒ€์ž…(1 : URL ํƒ€์ดํ•‘ ์ ‘์†, 0 : ๋งํฌ ์ ‘์†)
โ€ข ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 35 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง urls, visits ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 36 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 37 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cookies
๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” : cookies ํ…Œ์ด๋ธ”
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ํ˜ธ์ŠคํŠธ, ๊ฒฝ๋กœ
โ€ข ๋ณ€์ˆ˜, ๊ฐ’
โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜
โ€ข ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
โ€ข ์ฟ ํ‚ค ๋งŒ๋ฃŒ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ)
โ€ข isSecure, isHttpOnly
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 38 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง cookies ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 39 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 40 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History
๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” : downloads ํ…Œ์ด๋ธ”
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ์†Œ์Šค URL
โ€ข ๋‹ค์šด๋ฐ›์€ Local ๊ฒฝ๋กœ
โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) : ์‹œ์ž‘/ ์ข…๋ฃŒ์‹œ๊ฐ„
โ€ข ์ด ๋‹ค์šด๋กœ๋“œ ํฌ๊ธฐ
โ€ข ๋‹ค์šด๋กœ๋“œ ์ƒํƒœ : ์„ฑ๊ณต(1), ์‹คํŒจ(0)
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 41 / 88
Chrome ๋กœ๊ทธ ๋ถ„์„
๏‚ง downloads ํ…Œ์ด๋ธ”
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 42 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 43 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cache.db
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹
๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ”
โ€ข cfurl_cache_response : ์บ์‹œ ์ธ๋ฑ์Šค ์ •๋ณด ์ €์žฅ
โ€ข cfurl_cache_blob_data : ์บ์‹œ ๋ฐ์ดํ„ฐ ์ €์žฅ
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข URL
โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ )
โ€ข ์บ์‹œ ๋ฐ์ดํ„ฐ
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 44 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํ…Œ์ด๋ธ” ๊ตฌ์กฐ
โ€ข cfurl_cache_response ํ…Œ์ด๋ธ”
โ€ข cfurl_cache_blob_data ํ…Œ์ด๋ธ”
Cache ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 45 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 46 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History.plist
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข Binary Plist
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข URL
โ€ข Title
โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜
โ€ข ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 47 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง History.plist ๊ตฌ์กฐ ( plistEditor Pro 2.0 ์‚ฌ์šฉ )
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 48 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 49 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cookies.plist
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข Text Plist
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ๋„๋ฉ”์ธ, ๊ฒฝ๋กœ
โ€ข ์ด๋ฆ„, ๊ฐ’
โ€ข ์ƒ์„ฑ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ)
โ€ข ๋งŒ๋ฃŒ ์‹œ๊ฐ„ ํ…์ŠคํŠธ ํ˜•์‹
โ€ข HttpOnly ์˜ต์…˜
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 50 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cookies.plist ๊ตฌ์กฐ
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 51 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cookie.binarycookie ํŒŒ์ผ ์ „์ฒด ๊ตฌ์กฐ
โ€ข Signature : โ€œCOOKโ€
โ€ข Page ๋‹จ์œ„๋กœ ๊ตฌ์„ฑ๋จ
๏ƒผ Page ๋Š” ๊ฐ€๋ณ€ ๊ธธ์ด
๏ƒผ Page ์‚ฌ์ด์ฆˆ๋ฅผ ๋ฐฐ์—ด ํ˜•์‹์œผ๋กœ ๋”ฐ๋กœ ์ €์žฅ
๏ƒผ Page ์‚ฌ์ด์ฆˆ ๋ฐฐ์—ด์ด ๋๋‚˜๋ฉด ์‹ค์ œ Page ๋“ค์ด ์œ„์น˜
Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
forensicinsight.org Page 52 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง Page ๊ตฌ์กฐ
โ€ข ๊ฐ ์ฟ ํ‚ค ์ •๋ณด๋Š” ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋จ
โ€ข ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ ํฌ๊ธฐ๋Š” ๊ฐ€๋ณ€
โ€ข ๊ฐ ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ์˜ ์œ„์น˜๋Š” ๋ฐฐ์—ด ํ˜•์‹์œผ๋กœ ์ €์žฅ๋จ
Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
forensicinsight.org Page 53 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง Cookie ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ
โ€ข URL, Path, Name, Value ๊ฐ’์€ ์•„์Šคํ‚ค ๊ฐ’ ํ˜•ํƒœ๋กœ ์ €์žฅ๋จ
โ€ข Create Date, Expiration Date
๏ƒผ 64 bit Double Mac Absolute Time(GMT) ???
๏ƒจ ์ด ํฌ๋ฉง์— ๋Œ€ํ•ด ์•„์‹œ๋Š” ๋ถ„์€ ๋ฉ”์ผ๋กœ ์•Œ๋ ค์ฃผ์‹œ๋ฉด ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ใ… ใ… 
Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
forensicinsight.org Page 54 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
- Cache ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 55 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Downloads.plist
๏‚ง ํŒŒ์ผ ํ˜•์‹
โ€ข Binary Plist
๏‚ง ์ €์žฅ ์ •๋ณด
โ€ข ์†Œ์Šค URL
โ€ข ๋‹ค์šด๋กœ๋“œ ๊ฒฝ๋กœ
โ€ข ๋‹ค์šด๋กœ๋“œ ํŒŒ์ผ ํฌ๊ธฐ
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 56 / 88
Safari ๋กœ๊ทธ ๋ถ„์„
๏‚ง Downloads.plist ๊ตฌ์กฐ
Download ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 57 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
- Generic Binary Format
- Cache ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 58 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Opera ๋ฒ„์ „ 5.0 ๋ถ€ํ„ฐ ์‚ฌ์šฉ
๏‚ง ๋ฒ„์ „ 3.x ์™€๋Š” ํ˜ธํ™˜ ์•ˆ ๋จ, ๋ฒ„์ „ 4.x ์™€๋Š” ํ˜ธํ™˜ ๊ฐ€๋Šฅ
๏‚ง ์ผ๋ จ์˜ ๊ธธ์ด ์ •๋ณด๋ฅผ ๊ฐ€์ง„ ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์ง‘ํ•ฉ
๏‚ง ๋Œ€์ƒ ํŒŒ์ผ
โ€ข dcache4.url : ์บ์‹œ ํŒŒ์ผ
โ€ข cookies4.dat : ์ฟ ํ‚ค ํŒŒ์ผ
โ€ข download.dat : ๋‹ค์šด๋กœ๋“œ ๋ชฉ๋ก ํŒŒ์ผ
Generic Binary Format(์กฐ๊ธˆ ๋ณต์žกํ•˜๋‹ˆ๊นŒ ์กธ์ง€ ๋งˆ์„ธ์š”โ€ฆใ… ใ…  )
forensicinsight.org Page 59 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๋ฐ์ดํ„ฐ ํƒ€์ž…
โ€ข ์ •์ˆ˜ ์ •๋ณด
๏ƒผ ๋น… ์—”๋””์•ˆ ํƒ€์ž…์œผ๋กœ ์ €์žฅ ๏ƒจ ํŒŒ์‹ฑ ์‹œ, ๋ฆฌํ‹€ ์—”๋””์•ˆ์œผ๋กœ ๋ณ€ํ™˜ ํ•„์š”
๏ƒผ EX) ๋ ˆ์ฝ”๋“œ ๊ธธ์ด ์ •๋ณด, ์‹œ๊ฐ„ ์ •๋ณด, ์‚ฌ์ด์ฆˆ ์ •๋ณด โ€ฆ
โ€ข ์‹œ๊ฐ„ ์ •๋ณด
๏ƒผ time_t ํƒ€์ž… ์‚ฌ์šฉ
๏ƒผ 1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€์œผ๋กœ ํ˜„์žฌ๊นŒ์ง€ ๊ฒฝ๊ณผ๋œ ์ดˆ
๏ƒผ ๋น… ์—”๋””์•ˆ ํƒ€์ž…์œผ๋กœ ์ €์žฅ
โ€ข ๋ฌธ์ž ์ •๋ณด
๏ƒผ ๊ธฐ๋ณธ์ ์œผ๋กœ ์˜์–ด๋Š” ์•„์Šคํ‚ค ํƒ€์ž…์œผ๋กœ ์ €์žฅ
๏ƒผ ๊ทธ ์™ธ ๋‹ค๊ตญ์–ด ์ผ ๊ฒฝ์šฐ UTF-8 ๋กœ ์ธ์ฝ”๋”ฉ
Generic Binary Format
forensicinsight.org Page 60 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ
โ€ข ํ—ค๋” + ๋ ˆ์ฝ”๋“œ ์ง‘ํ•ฉ
โ€ข ํ—ค๋” ๊ตฌ์„ฑ
๏ƒผ ํŒŒ์ผ ๋ฒ„์ „(4byte) : ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด๋‹ค ํŒŒ์ผ ๋ฒ„์ „์ด ๋†’์œผ๋ฉด ๋ชป ์ฝ์Œ
โ€ข ํ•˜์œ„ 12bit : minor ๋ฒ„์ „
โ€ข ์ƒ์œ„ 30bit : major ๋ฒ„์ „
๏ƒผ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฒ„์ „(4byte)
โ€ข 0x00002000 : ์ฟ ํ‚ค ํŒŒ์ผ
โ€ข 0x00020000 : ์บ์‹œ, ๋‹ค์šด๋กœ๋“œ ๋ชฉ๋ก ํŒŒ์ผ
๏ƒผ ๋ ˆ์ฝ”๋“œ์˜ Tag_ID ํฌ๊ธฐ (2byte)
๏ƒผ ๋ ˆ์ฝ”๋“œ์˜ ๋ฐ์ดํ„ฐ ํฌ๊ธฐ ํ•„๋“œ์˜ ํฌ๊ธฐ (2byte)
Generic Binary Format
forensicinsight.org Page 61 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ (๊ณ„์†)
โ€ข ๋ ˆ์ฝ”๋“œ ๊ตฌ์„ฑ
๏ƒผ Tag_ID(Default : 1byte)
โ€ข ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋˜๋Š” ๋ฐ์ดํ„ฐ์˜ ํƒ€์ž… ์ •๋ณด ์ €์žฅ
โ€ข Tag_ID ์ข…๋ฅ˜
ยป ์ผ๋ฐ˜ ๋ ˆ์ฝ”๋“œ Tag_ID
โ€ข Tag_ID+๊ธธ์ด์ •๋ณด+๋ฐ์ดํ„ฐ ๊ตฌ์„ฑ
ยป Boolean ํ”Œ๋ž˜๊ทธ Tag_ID
โ€ข ์ตœ์ƒ์œ„ ๋น„ํŠธ๊ฐ€(MSB)์˜ 1๊ณผ 0์œผ๋กœ ์ฐธ, ๊ฑฐ์ง“ ๊ตฌ๋ถ„
โ€ข Tag_ID๋งŒ ์กด์žฌ
๏ƒผ Data ๊ธธ์ด(Default : 2byte)
๏ƒผ Data
Generic Binary Format
Tag_ID(1byte)
Data ๊ธธ์ด
(2byte)
Data
forensicinsight.org Page 62 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ (๊ณ„์†)
โ€ข ๋ ˆ์ฝ”๋“œ ์ข…๋ฅ˜
๏ƒผ Entry ๋ ˆ์ฝ”๋“œ
โ€ข ํ•ด๋‹น ํŒŒ์ผ์˜ ์ •๋ณด ๋‹จ์œ„
โ€ข ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ๋“ค์„ ํฌํ•จ
โ€ข Tag_ID+๊ธธ์ด์ •๋ณด+๋ฐ์ดํ„ฐ๋ ˆ์ฝ”๋“œ ์ง‘ํ•ฉ
๏ƒผ Data ๋ ˆ์ฝ”๋“œ
โ€ข ์ผ๋ฐ˜์ ์œผ๋กœ Entry ๋ ˆ์ฝ”๋“œ์˜ ํ•˜์œ„ ๋ ˆ์ฝ”๋“œ, ๋‹จ๋…์œผ๋กœ๋„ ์กด์žฌ ํ•  ์ˆ˜ ์žˆ์Œ
โ€ข ์‹ค์ œ ๋ฐ์ดํ„ฐ ์ €์žฅ
โ€ข ์„œ๋ธŒ ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ๋ฅผ ํฌํ•จํ•˜๋Š” ๋ ˆ์ฝ”๋“œ๋„ ์žˆ์Œ( ex: HTTP ๋ ˆ์ฝ”๋“œ)
๏ƒผ Sub_Data ๋ ˆ์ฝ”๋“œ
โ€ข ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ์˜ ํ•˜์œ„ ๋ ˆ์ฝ”๋“œ
Generic Binary Format
forensicinsight.org Page 63 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Tag_ID ์ •๋ณด
โ€ข Entry Tag_ID
โ€ข ์ผ๋ฐ˜ ๋ฐ์ดํ„ฐ Tag_ID
Generic Binary Format
File Tag id
Cache 0x01
Cookies 0x01
Download List 0x41
Tag ID Contents Meaning
0x03 string URL
0x04 time_t ๋งˆ์ง€๋ง‰ ๋ฐฉ๋ฌธ์‹œ๊ฐ„
(0x0b | MSB_VALUE) flag The URL is a result of a form query
0x22 record Contains the name and last visited time of relative link in the document. May repeat
forensicinsight.org Page 64 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†)
โ€ข ์บ์‹œ, ๋‹ค์šด๋กœ๋“œ ํ˜ผ์šฉ ๋ฐ์ดํ„ฐ Tag_ID
โ€ข ๋‹ค์šด๋กœ๋“œ ๋ฐ์ดํ„ฐ Tag_ID
Generic Binary Format
Tag ID Contents Meaning
0x05 time_t Localtime, when the file was last loaded, not GMT
0x07 uint8 Status of load: 2 Loaded 4 Loading aborted 5 Loading failed
0x08 uint32 Content size
0x09 string MIME type of content
0x0A string Character set of content
(0x0C | MSB_VALUE) flag
File is downloaded and stored locally on user's disk, and is not part of the disk cache d
irectory
0x0D string Name of file (cache files: only local to cache directory)
(0x0F| MSB_VALUE) flag Always check if modified
0x10 record Contains the HTTP protocol specific information
Tag ID Contents Meaning
0x28 time_t Identifies the time when the loading of the last/previous segment of the downloaded file started.
0x29 time_t Identifies the time when the loading of the last/previous segment of the downloaded file was stopped.
0x2A uint32
How many bytes were in the previous segement of the file being downloaded. If the time the loading ended
is not known, this value will be assumed to be zero (0) and the download speed set to zero(unknown).
forensicinsight.org Page 65 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†)
โ€ข HTTP ๋ ˆ์ฝ”๋“œ ์„œ๋ธŒ Tag_ID
Generic Binary Format
Tag ID Contents Meaning
0x15 string HTTP date header
0x16 time_t Expiry date
0x17 string Last modified date
0x18 string MIME type of document
0x19 string Entity tag
0x1A string Moved to URL (Location header)
0x1B string Response line text
0x1C uint32 Response code
0x1D string Refresh URL
0x1E uint32 Refresh delta time
0x1F string Suggested file name
0x20 string Content Encodings
0x21 string Content Location
0x25 uint32
Together with tag 0x0026 (both must be present) this identifies the User Agent string last used to load
the resource. This value identifies the User Agent string. This value is used internally, and should not be
modified.
0x26 uint32
Together with tag 0x0025 (both must be present) this identifies the User Agent string last used to load
the resource. This value identifies the User Agent sub version. This value is used internally, and should
not be modified.
(0x30 | MSB_VALUE) flag Reserved for future use
(0x31 | MSB_VALUE) Flag Reserved for future use
forensicinsight.org Page 66 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ
โ€ข Entry ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์—ฐ์†์ ์ธ ์ง‘ํ•ฉ
โ€ข Entry ๋ ˆ์ฝ”๋“œ ์•ˆ์— Data ๋ ˆ์ฝ”๋“œ๋“ค์ด ์—ฐ์†์ ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Œ
โ€ข ํŠน์ • Data ๋ ˆ์ฝ”๋“œ(EX: HTTP Data ๋ ˆ์ฝ”๋“œ) ๋“ค์€ Sub Data ๋ ˆ์ฝ”๋“œ๋“ค์„ ํฌํ•จํ•จ
Generic Binary Format
forensicinsight.org Page 67 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
- Generic Binary Format
- Cache ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 68 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
Cache ์ •๋ณด ๋ถ„์„(์™ธ๋ถ€ ์ €์žฅ)
ํ—ค๋”
Entry ๋ ˆ์ฝ”๋“œ
Data ๋ ˆ์ฝ”๋“œ
Entry Tag_ID
Entry ๊ธธ์ด
Data Tag_ID
Data ๊ธธ์ด
Sub_Data Tag_ID
Sub_Data ๊ธธ์ด
Boolean Flag
Sub_Data ๋ ˆ์ฝ”๋“œ
Data
forensicinsight.org Page 69 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
โ€ข ๋ฐ์ดํ„ฐ Tag_ID๊ฐ€ 0x50์ธ ๋ ˆ์ฝ”๋“œ๋Š” ๋ฐ์ดํ„ฐ๋กœ ์‹ค์ œ ์บ์‹œ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•จ
โ€ข ๋ฐ์ดํ„ฐ Tag_ID๊ฐ€ 0X0D์ธ ๋ ˆ์ฝ”๋“œ๋Š” ๋ฐ์ดํ„ฐ๋กœ โ€˜์บ์‹œ ๋ฐ์ดํ„ฐ๊ฐ€ ์ €์žฅ ๋œ ํŒŒ์ผ ๊ฒฝ๋กœ๋ช…โ€™ ์„ ์ €์žฅํ•จ
โ€ข ๋‘ ๋ ˆ์ฝ”๋“œ ์ค‘ ํ•˜๋‚˜๋งŒ Entry ๋ ˆ์ฝ”๋“œ์— ์กด์žฌ
Cache ์ •๋ณด ๋ถ„์„ (๋‚ด๋ถ€ ์ €์žฅ)
forensicinsight.org Page 70 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
- Generic Binary Format
- Cache ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 71 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
Download ์ •๋ณด ๋ถ„์„(
ํ—ค๋”
Entry ๋ ˆ์ฝ”๋“œ
Data ๋ ˆ์ฝ”๋“œ
Entry Tag_ID
Entry ๊ธธ์ด
Data Tag_ID
Data ๊ธธ์ด
Sub_Data Tag_ID
Sub_Data ๊ธธ์ด
Boolean Flag
Sub_Data ๋ ˆ์ฝ”๋“œ
Data
forensicinsight.org Page 72 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
- Generic Binary Format
- Cache ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 73 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ
โ€ข Entry ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์—ฐ์†์ ์ธ ์ง‘ํ•ฉ
๏ƒผ Entry ๋ ˆ์ฝ”๋“œ ๋ถ„๋ฅ˜
โ€ข Domain Component : Tag ID 0x01
ยป 1/2/3๋‹จ๊ณ„๋กœ ๋ถ„๋ฅ˜๋จ(ex: www.opera.com ๏ƒจ com:1๋‹จ๊ณ„, opera:2๋‹จ๊ณ„, www:1๋‹จ๊ณ„)
ยป IP๋กœ๋งŒ ์ด๋ฃจ์–ด์ง„ Domian์ผ ๊ฒฝ์šฐ 1๋‹จ๊ณ„ Domain์œผ๋กœ๋งŒ ๊ตฌ์„ฑ๋จ(ex: 211.239.167.20)
ยป ๊ทธ ์™ธ ๋„๋ฉ”์ธ๋“ค์€ 1~2๋‹จ๊ณ„ ํ˜น์€ 1~3๋‹จ๊ณ„๋กœ ๊ตฌ์„ฑ๋จ
โ€ข Path Component : Tag ID 0x02, ์กด์žฌ ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๋„ ์žˆ์Œ
โ€ข Cookie Component : Tag ID 0x03
๏ƒผ ๊ตฌ์„ฑ ์˜ˆ : www.opera.com/verify
["com" Domain component] // 1 ๋‹จ๊ณ„ Domain component
["opera" Domain component] // 2 ๋‹จ๊ณ„ Domain component
["www" Domain component] // 3 ๋‹จ๊ณ„ Domain component
[โ€œverifyโ€ Path component]
[Cookie component]
[Path component terminator]
[end of domain flag ("www")]
[end of domain flag ("opera")]
[end of domain flag ("com")]
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 74 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ(๊ณ„์†)
โ€ข Cookie Component ์•ˆ์— Data ๋ ˆ์ฝ”๋“œ๋“ค์ด ์—ฐ์†์ ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Œ
โ€ข 1๋‹จ๊ณ„ Domain Component ์•„๋ž˜ ์—ฌ๋Ÿฌ ๊ฐœ์˜ 2๋‹จ๊ณ„ Domain Component ๊ฐ€ ์˜ฌ ์ˆ˜ ์žˆ์Œ
โ€ข 2๋‹จ๊ณ„ Domain Component ์•„๋ž˜ ์—ฌ๋Ÿฌ ๊ฐœ์˜ 3๋‹จ๊ณ„ Domain Component ๊ฐ€ ์˜ฌ ์ˆ˜ ์žˆ์Œ
โ€ข Path Component ๋Š” 1/2/3๋‹จ๊ณ„ Domain Component ์ค‘ ์–ด๋Š Component ์•„๋ž˜์—๋„ ์˜ฌ ์ˆ˜ ์žˆ
์Œ
โ€ข 1/2/3๋‹จ๊ณ„ Domain Component ์™€ Path Component ๊ฐ€ ๊ฒฐํ•ฉ๋˜์–ด host ์ด๋ฆ„ ์ •๋ณด๋ฅผ ์ด๋ฃจ๋ฉฐ ๊ทธ
์•„๋ž˜์— ์žˆ๋Š” Cookie ์ •๋ณด๋“ค์€ ๋™์ผํ•œ host ์ด๋ฆ„์„ ๊ฐ€์ง
Cookie ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 75 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Tag_ID ์ •๋ณด
โ€ข Entry Tag_ID
โ€ข ๋ฐ์ดํ„ฐ Tag_ID
Cookie ์ •๋ณด ๋ถ„์„
Tag id Component
0x01 Domain Component
0x02 Path Component
0x03 Cookie Component
Tag ID Contents Meaning
0x1E string Domain ์ •๋ณด
0x1D string Path ์ •๋ณด
0x10 string ์ฟ ํ‚ค ์ด๋ฆ„
0x11 string ์ฟ ํ‚ค ๊ฐ’
0x12 time_t ๋งŒ๋ฃŒ ์‹œ๊ฐ„
0x13 time_t ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„
0x28 ? ?
forensicinsight.org Page 76 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†)
โ€ข Component Terminator
Cookie ์ •๋ณด ๋ถ„์„
Tag id Terminator
0x84 Domain Component Terminator
0x85 Path Component Terminator
forensicinsight.org Page 77 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
Cookie ์ •๋ณด ๋ถ„์„(cookies4.dat ํŒŒ์ผ ๋ถ„์„)
01 Domain Component
Component ๊ธธ์ด
85
Data Tag_ID
Data ๊ธธ์ด
Path Component Terminator
Boolean Flag
Data
84 Domain Component Terminator
02 Path Component
03 Cookie Component
forensicinsight.org Page 78 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
- Generic Binary Format
- Cache ์ •๋ณด ๋ถ„์„
- Download ์ •๋ณด ๋ถ„์„
- Cookie ์ •๋ณด ๋ถ„์„
- History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 79 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
๏‚ง ๊ธฐ๋ณธ๊ตฌ์„ฑ
โ€ข ํ—ค๋” ํŒŒ์ผ ์—†์Œ
โ€ข ๋ ˆ์ฝ”๋“œ๋กœ๋งŒ ๊ตฌ์„ฑ
โ€ข ๋ ˆ์ฝ”๋“œ ๊ตฌ์„ฑ
๏ƒผ Title : UTF-8 ์ธ์ฝ”๋”ฉ
๏ƒผ URL : ASCII
๏ƒผ ๋ฐฉ๋ฌธ์‹œ๊ฐ„ : 1970๋…„ 1์›” 1์ผ 00:00:00 ๋ถ€ํ„ฐ ์ง€๊ธˆ๊นŒ์ง€์˜ ๊ฒฝ๊ณผ๋œ ์ดˆ( time_t )
๏ƒผ ๋ ˆ์ฝ”๋“œ end signature : -1( 2D 31 )
๏ƒผ ๊ตฌ๋ถ„์ž : 0x0A
History ์ •๋ณด ๋ถ„์„
forensicinsight.org Page 80 / 88
Opera ๋กœ๊ทธ ๋ถ„์„
History ์ •๋ณด ๋ถ„์„(global_history.dat ํŒŒ์ผ ๋ถ„์„)
Title
URL
๋ฐฉ๋ฌธ์‹œ๊ฐ„
End Signature
๊ตฌ๋ถ„์ž
forensicinsight.org Page 81 / 88
๋ถ„์„ ๋„๊ตฌ
- Firefox ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
- Chrome ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
- Safari ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
- Opera ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
- WEFA
forensicinsight.org Page 82 / 88
๋ถ„์„ ๋„๊ตฌ
๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html
โ€ข MozillaCacheView : Cache ๋ถ„์„
โ€ข MozillaHistoryView : History ๋ถ„์„
โ€ข MozillaCookieView : Cookie ๋ถ„์„
โ€ข FirefoxDownloadsView : Download List ๋ถ„์„
Firefox ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
forensicinsight.org Page 83 / 88
๋ถ„์„ ๋„๊ตฌ
๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html
โ€ข ChromeCacheView : Cache ๋ถ„์„
โ€ข ChromeHistoryView : History ๋ถ„์„
๏‚ง ChromeForensics : http://www.woanware.co.uk/?page_id=70
โ€ข History, Cookie, Download List ๋ถ„์„ (์ถ”๊ฐ€์ ์œผ๋กœ ์ž๋™์™„์„ฑ, Favicons, Thumbnails)
Chrome ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
forensicinsight.org Page 84 / 88
๋ถ„์„ ๋„๊ตฌ
๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html
โ€ข SafariCacheView : Cache ๋ถ„์„
โ€ข SafariHistoryView : History ๋ถ„์„
Safari ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
forensicinsight.org Page 85 / 88
๋ถ„์„ ๋„๊ตฌ
๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html
โ€ข OperaCacheView : Cache ๋ถ„์„
Opera ๋ถ„์„ ๋„๊ตฌ
forensicinsight.org Page 86 / 88
๋ถ„์„๋„๊ตฌ
๏‚ง ์ง€์› ๋ธŒ๋ผ์šฐ์ € : Internet Explorer, Firefox, Chrome, Safari, Opera
๏‚ง ๋ถ„์„ ๋Œ€์ƒ ์ •๋ณด
โ€ข Cache
โ€ข History
โ€ข Cookie(Safari 5.1 Cookie ์ œ์™ธ)
โ€ข Download List
๏‚ง Freeware Download ๏ƒจ http://www.4n6tech.com/skin_kr/images/WEFA_v1.2_-_Freeware.zip
WEFA(Web Browser Forensic Analyzer
forensicinsight.org Page 87 / 88
๊ฒฐ ๋ก 
๏‚ง ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ํŒŒ์ผ ๊ตฌ์กฐ ๋ถ„์„์˜ ํ•„์š”์„ฑ?
โ€ข ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ์ •๋ณด ๋ถ„์„์˜ ๊ธฐ๋ณธ ๋ฐฐ๊ฒฝ ์ง€์‹ ๏ƒจ ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์ง์ ‘ ์ˆ˜๋™ ๋ถ„์„์ด ๊ฐ€๋Šฅ
โ€ข ๋‚จ์ด ๋งŒ๋“  ๋ถ„์„ ๋„๊ตฌ๋Š” ๋ชป ๋ฏฟ๊ฒ ๋‹ค!!! or ํ•ด๋‹น ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•ด ์ฃผ๋Š” ๋„๊ตฌ๊ฐ€ ์—†์„ ๋•Œ
๏ƒจ ๋กœ๊ทธ ํŒŒ์ผ ์ง€์‹์„ ํ†ตํ•ด ์ง์ ‘ ํŒŒ์‹ฑ ๋„๊ตฌ ๊ฐœ๋ฐœ
โ€ข ๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ์ž˜ ํŒŒ์‹ฑํ•˜์ง€ ๋ชปํ•œ๋‹ค๋ฉด?
๏ƒจ ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ํฌ๋ฉง์€ ๋ฒ„์ „์—…์„ ํ•˜๋ฉด์„œ ์กฐ๊ธˆ์”ฉ ๋ฐ”๋€Œ๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ
๏ƒจ ๊ตฌ๊ธ€๋ง์„ ํ†ตํ•ด ์ƒˆ๋กœ์šด ๋ฒ„์ „์˜ ํฌ๋ฉง ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ or ๊ธฐ์กด ํฌ๋ฉง์„ ํ† ๋Œ€๋กœ ์ง์ ‘ ๋ถ„์„ํ•ด ๋ณผ ํ•„
์š”์„ฑ์ด ์žˆ์Œ
๏‚ง ๋กœ๊ทธ ํŒŒ์ผ ๋ถ„์„ํ•  ๋•Œ, ์œ ์˜ ์‚ฌํ•ญ~!!
โ€ข ๊ฐ ๋ธŒ๋ผ์šฐ์ € ๋ณ„ ์„œ๋กœ ๋‹ค๋ฅธ ์‹œ๊ฐ„ ํฌ๋ฉง์„ ๊ฐ€์ง
๏ƒผ ๊ฐ ์‹œ๊ฐ„ ํฌ๋ฉง์— ๋งž์ถ”์–ด์„œ ๊ณ„์‚ฐํ•  ํ•„์š”์„ฑ์ด ์žˆ์Œ
๏ƒผ ํ•ด๋‹น ์‹œ๊ฐ„ ์ •๋ณด๊ฐ€ GMT ์ธ์ง€ ๋กœ์ปฌ ํƒ€์ž„์ธ์ง€ ๊ตฌ๋ถ„ ํ•„์š”
โ€ข ์ธ์ฝ”๋”ฉ๋œ ์ •๋ณด
๏ƒผ ๋‹ค๊ตญ์–ด์˜ ๊ฒฝ์šฐ, URL ์ธ์ฝ”๋”ฉ๋˜์–ด ๊ทธ๋Œ€๋กœ ์ €์žฅ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ ๏ƒจ ์ธ์ฝ”๋”ฉ ๋ฐฉ์‹์— ๋”ฐ๋ฅธ ๋””์ฝ”๋”ฉ
๏ƒผ ๋ณดํ†ต์€ ๊ฑฐ์˜ ๋Œ€๋ถ€๋ถ„ UTF-8 ์ธ์ฝ”๋”ฉ, ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์œ ๋‹ˆ์ฝ”๋“œ ์ธ์ฝ”๋”ฉ ํ˜น์€ ์ฝ”๋“œํŽ˜์ด์ง€ ์ธ์ฝ”๋”ฉ
forensicinsight.org Page 88 / 88
์งˆ๋ฌธ ๋ฐ ๋‹ต๋ณ€

More Related Content

Viewers also liked

(130622) #fitalk trend of personal information protection
(130622) #fitalk   trend of personal information protection(130622) #fitalk   trend of personal information protection
(130622) #fitalk trend of personal information protectionINSIGHT FORENSIC
ย 
(120107) #fitalk anonymizing activities
(120107) #fitalk   anonymizing activities(120107) #fitalk   anonymizing activities
(120107) #fitalk anonymizing activitiesINSIGHT FORENSIC
ย 
(120211) #fitalk sq lite record recovery
(120211) #fitalk   sq lite record recovery(120211) #fitalk   sq lite record recovery
(120211) #fitalk sq lite record recoveryINSIGHT FORENSIC
ย 
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉINSIGHT FORENSIC
ย 
(130105) #fitalk criminal civil judicial procedure in korea
(130105) #fitalk   criminal civil judicial procedure in korea(130105) #fitalk   criminal civil judicial procedure in korea
(130105) #fitalk criminal civil judicial procedure in koreaINSIGHT FORENSIC
ย 
(120318) #fitalk introduction to kindle forensics
(120318) #fitalk   introduction to kindle forensics(120318) #fitalk   introduction to kindle forensics
(120318) #fitalk introduction to kindle forensicsINSIGHT FORENSIC
ย 
(120218) #fitalk forensic impact according to the firmware manipulation
(120218) #fitalk   forensic impact according to the firmware manipulation(120218) #fitalk   forensic impact according to the firmware manipulation
(120218) #fitalk forensic impact according to the firmware manipulationINSIGHT FORENSIC
ย 
(120616) #fitalk web browser forensics - part iii
(120616) #fitalk   web browser forensics - part iii(120616) #fitalk   web browser forensics - part iii
(120616) #fitalk web browser forensics - part iiiINSIGHT FORENSIC
ย 
(121215) #fitalk 3th holy shield forensics probs write-ups
(121215) #fitalk   3th holy shield forensics probs write-ups(121215) #fitalk   3th holy shield forensics probs write-ups
(121215) #fitalk 3th holy shield forensics probs write-upsINSIGHT FORENSIC
ย 
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐINSIGHT FORENSIC
ย 
(120513) #fitalk an introduction to linux memory forensics
(120513) #fitalk   an introduction to linux memory forensics(120513) #fitalk   an introduction to linux memory forensics
(120513) #fitalk an introduction to linux memory forensicsINSIGHT FORENSIC
ย 
(130216) #fitalk reverse connection tool analysis
(130216) #fitalk   reverse connection tool analysis(130216) #fitalk   reverse connection tool analysis
(130216) #fitalk reverse connection tool analysisINSIGHT FORENSIC
ย 
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„INSIGHT FORENSIC
ย 
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!INSIGHT FORENSIC
ย 
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผINSIGHT FORENSIC
ย 

Viewers also liked (15)

(130622) #fitalk trend of personal information protection
(130622) #fitalk   trend of personal information protection(130622) #fitalk   trend of personal information protection
(130622) #fitalk trend of personal information protection
ย 
(120107) #fitalk anonymizing activities
(120107) #fitalk   anonymizing activities(120107) #fitalk   anonymizing activities
(120107) #fitalk anonymizing activities
ย 
(120211) #fitalk sq lite record recovery
(120211) #fitalk   sq lite record recovery(120211) #fitalk   sq lite record recovery
(120211) #fitalk sq lite record recovery
ย 
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ
(Ficon2016) #4 ์‹ค ์‚ฌ๋ก€๋ฅผ ํ†ตํ•ด ๋ณธ ๋„คํŠธ์›Œํฌ ํฌ๋ Œ์‹์˜ ๋ฒ”์œ„์™€ ํšจ์šฉ
ย 
(130105) #fitalk criminal civil judicial procedure in korea
(130105) #fitalk   criminal civil judicial procedure in korea(130105) #fitalk   criminal civil judicial procedure in korea
(130105) #fitalk criminal civil judicial procedure in korea
ย 
(120318) #fitalk introduction to kindle forensics
(120318) #fitalk   introduction to kindle forensics(120318) #fitalk   introduction to kindle forensics
(120318) #fitalk introduction to kindle forensics
ย 
(120218) #fitalk forensic impact according to the firmware manipulation
(120218) #fitalk   forensic impact according to the firmware manipulation(120218) #fitalk   forensic impact according to the firmware manipulation
(120218) #fitalk forensic impact according to the firmware manipulation
ย 
(120616) #fitalk web browser forensics - part iii
(120616) #fitalk   web browser forensics - part iii(120616) #fitalk   web browser forensics - part iii
(120616) #fitalk web browser forensics - part iii
ย 
(121215) #fitalk 3th holy shield forensics probs write-ups
(121215) #fitalk   3th holy shield forensics probs write-ups(121215) #fitalk   3th holy shield forensics probs write-ups
(121215) #fitalk 3th holy shield forensics probs write-ups
ย 
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ
(Fios#02) 1. ๋žœ์„ฌ์›จ์–ด ์—ฐ๋Œ€๊ธฐ
ย 
(120513) #fitalk an introduction to linux memory forensics
(120513) #fitalk   an introduction to linux memory forensics(120513) #fitalk   an introduction to linux memory forensics
(120513) #fitalk an introduction to linux memory forensics
ย 
(130216) #fitalk reverse connection tool analysis
(130216) #fitalk   reverse connection tool analysis(130216) #fitalk   reverse connection tool analysis
(130216) #fitalk reverse connection tool analysis
ย 
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„
(Fios#02) 7. ์œˆ๋„์šฐ 10 ํฌ๋ Œ์‹ ๋ถ„์„
ย 
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!
(Ficon2016) #5 ํฌ๋ Œ์‹ ์‚ฌ๋ก€๋ฅผ ์•Œ์•„๋ณด์ง€ ๋ง์ž…๋‹ˆ๋‹ค!
ย 
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ
(Ficon2016) #2 ์นจํ•ด์‚ฌ๊ณ  ๋Œ€์‘, ์ด๋ ‡๋‹ค๊ณ  ์ „ํ•ด๋ผ
ย 

Similar to (120325) #fitalk web browser forensics - part ii

(120318) #fitalk web browser forensics - part i
(120318) #fitalk   web browser forensics - part i(120318) #fitalk   web browser forensics - part i
(120318) #fitalk web browser forensics - part iINSIGHT FORENSIC
ย 
(120318) #fitalk web browser forensics - part i
(120318) #fitalk   web browser forensics - part i(120318) #fitalk   web browser forensics - part i
(120318) #fitalk web browser forensics - part iINSIGHT FORENSIC
ย 
(121013) #fitalk ie 10 forensics
(121013) #fitalk   ie 10 forensics(121013) #fitalk   ie 10 forensics
(121013) #fitalk ie 10 forensicsINSIGHT FORENSIC
ย 
(120128) #fitalk sql server anti-forensics
(120128) #fitalk   sql server anti-forensics(120128) #fitalk   sql server anti-forensics
(120128) #fitalk sql server anti-forensicsINSIGHT FORENSIC
ย 
๊ธฐ์ˆ 6๊ธฐ 3์กฐ
๊ธฐ์ˆ 6๊ธฐ 3์กฐ๊ธฐ์ˆ 6๊ธฐ 3์กฐ
๊ธฐ์ˆ 6๊ธฐ 3์กฐKangwook Lee
ย 
(120616) #fitalk web browser forensics - part iii
(120616) #fitalk   web browser forensics - part iii(120616) #fitalk   web browser forensics - part iii
(120616) #fitalk web browser forensics - part iiiINSIGHT FORENSIC
ย 
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅeungjin cho
ย 
(130622) #fitalk the stealing windows password
(130622) #fitalk   the stealing windows password(130622) #fitalk   the stealing windows password
(130622) #fitalk the stealing windows passwordINSIGHT FORENSIC
ย 
(130928) #fitalk cloud storage forensics - dropbox
(130928) #fitalk   cloud storage forensics - dropbox(130928) #fitalk   cloud storage forensics - dropbox
(130928) #fitalk cloud storage forensics - dropboxINSIGHT FORENSIC
ย 
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉ
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉObject storage์˜ ์ดํ•ด์™€ ํ™œ์šฉ
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉSeoro Kim
ย 
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?Nts Nuli
ย 
DEVIEW 2013 Presentation
DEVIEW 2013 PresentationDEVIEW 2013 Presentation
DEVIEW 2013 PresentationWon Gil Kim
ย 
(130330) #fitalk codegate 2013 write-ups
(130330) #fitalk   codegate 2013 write-ups(130330) #fitalk   codegate 2013 write-ups
(130330) #fitalk codegate 2013 write-upsINSIGHT FORENSIC
ย 
(160820) #fitalk fileless malware forensics
(160820) #fitalk    fileless malware forensics(160820) #fitalk    fileless malware forensics
(160820) #fitalk fileless malware forensicsINSIGHT FORENSIC
ย 
Infiniflux introduction
Infiniflux introductionInfiniflux introduction
Infiniflux introductionInfiniFlux Korea
ย 
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰ํ˜œ์›… ๋ฐ•
ย 

Similar to (120325) #fitalk web browser forensics - part ii (20)

(120318) #fitalk web browser forensics - part i
(120318) #fitalk   web browser forensics - part i(120318) #fitalk   web browser forensics - part i
(120318) #fitalk web browser forensics - part i
ย 
(120318) #fitalk web browser forensics - part i
(120318) #fitalk   web browser forensics - part i(120318) #fitalk   web browser forensics - part i
(120318) #fitalk web browser forensics - part i
ย 
(121013) #fitalk ie 10 forensics
(121013) #fitalk   ie 10 forensics(121013) #fitalk   ie 10 forensics
(121013) #fitalk ie 10 forensics
ย 
(120128) #fitalk sql server anti-forensics
(120128) #fitalk   sql server anti-forensics(120128) #fitalk   sql server anti-forensics
(120128) #fitalk sql server anti-forensics
ย 
๊ธฐ์ˆ 6๊ธฐ 3์กฐ
๊ธฐ์ˆ 6๊ธฐ 3์กฐ๊ธฐ์ˆ 6๊ธฐ 3์กฐ
๊ธฐ์ˆ 6๊ธฐ 3์กฐ
ย 
Ssscon forensic pt
Ssscon forensic ptSsscon forensic pt
Ssscon forensic pt
ย 
(120616) #fitalk web browser forensics - part iii
(120616) #fitalk   web browser forensics - part iii(120616) #fitalk   web browser forensics - part iii
(120616) #fitalk web browser forensics - part iii
ย 
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ
์ธ๋ฉ”๋ชจ๋ฆฌ DBMS๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๋น…๋ฐ์ดํ„ฐ ๋ถ„์„ ์†”๋ฃจ์…˜ ๊ฐœ๋ฐœ ์‚ฌ๋ก€ - ๋ฆฌ์–ผํƒ€์ž„ํ…Œํฌ ํ•œํ˜ ์—ฐ๊ตฌ์†Œ์žฅ
ย 
(130622) #fitalk the stealing windows password
(130622) #fitalk   the stealing windows password(130622) #fitalk   the stealing windows password
(130622) #fitalk the stealing windows password
ย 
(130928) #fitalk cloud storage forensics - dropbox
(130928) #fitalk   cloud storage forensics - dropbox(130928) #fitalk   cloud storage forensics - dropbox
(130928) #fitalk cloud storage forensics - dropbox
ย 
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉ
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉObject storage์˜ ์ดํ•ด์™€ ํ™œ์šฉ
Object storage์˜ ์ดํ•ด์™€ ํ™œ์šฉ
ย 
์ €์žฅ์žฅ์น˜
์ €์žฅ์žฅ์น˜์ €์žฅ์žฅ์น˜
์ €์žฅ์žฅ์น˜
ย 
Html5
Html5 Html5
Html5
ย 
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?
[2012๋„๋ฆฌ์„ธ๋ฏธ๋‚˜] ์˜ค๋น ~ ๋„ค์ด๋ฒ„ ์™œ ์ด๋ ‡๊ฒŒ ๋Šฆ๊ฒŒ ๋– ?
ย 
Openstack Swift overview
Openstack Swift overviewOpenstack Swift overview
Openstack Swift overview
ย 
DEVIEW 2013 Presentation
DEVIEW 2013 PresentationDEVIEW 2013 Presentation
DEVIEW 2013 Presentation
ย 
(130330) #fitalk codegate 2013 write-ups
(130330) #fitalk   codegate 2013 write-ups(130330) #fitalk   codegate 2013 write-ups
(130330) #fitalk codegate 2013 write-ups
ย 
(160820) #fitalk fileless malware forensics
(160820) #fitalk    fileless malware forensics(160820) #fitalk    fileless malware forensics
(160820) #fitalk fileless malware forensics
ย 
Infiniflux introduction
Infiniflux introductionInfiniflux introduction
Infiniflux introduction
ย 
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰
๊ตฌ๊ธ€์„ ์ง€ํƒฑํ•˜๋Š” ๊ธฐ์ˆ  ์š”์•ฝ - Google ๊ฒ€์ƒ‰
ย 

More from INSIGHT FORENSIC

(150124) #fitalk advanced $usn jrnl forensics (english)
(150124) #fitalk   advanced $usn jrnl forensics (english)(150124) #fitalk   advanced $usn jrnl forensics (english)
(150124) #fitalk advanced $usn jrnl forensics (english)INSIGHT FORENSIC
ย 
(140118) #fitalk detection of anti-forensics artifacts using ioa fs
(140118) #fitalk   detection of anti-forensics artifacts using ioa fs(140118) #fitalk   detection of anti-forensics artifacts using ioa fs
(140118) #fitalk detection of anti-forensics artifacts using ioa fsINSIGHT FORENSIC
ย 
(140118) #fitalk 2013 e-discovery trend
(140118) #fitalk   2013 e-discovery trend(140118) #fitalk   2013 e-discovery trend
(140118) #fitalk 2013 e-discovery trendINSIGHT FORENSIC
ย 
(141031) #fitalk os x yosemite artifacts
(141031) #fitalk   os x yosemite artifacts(141031) #fitalk   os x yosemite artifacts
(141031) #fitalk os x yosemite artifactsINSIGHT FORENSIC
ย 
(140716) #fitalk ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹
(140716) #fitalk   ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹(140716) #fitalk   ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹
(140716) #fitalk ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹INSIGHT FORENSIC
ย 
(140716) #fitalk digital evidence from android-based smartwatch
(140716) #fitalk   digital evidence from android-based smartwatch(140716) #fitalk   digital evidence from android-based smartwatch
(140716) #fitalk digital evidence from android-based smartwatchINSIGHT FORENSIC
ย 
(140625) #fitalk sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„
(140625) #fitalk   sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„(140625) #fitalk   sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„
(140625) #fitalk sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„INSIGHT FORENSIC
ย 
(140407) #fitalk d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„
(140407) #fitalk   d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„(140407) #fitalk   d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„
(140407) #fitalk d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„INSIGHT FORENSIC
ย 
(130216) #fitalk potentially malicious ur ls
(130216) #fitalk   potentially malicious ur ls(130216) #fitalk   potentially malicious ur ls
(130216) #fitalk potentially malicious ur lsINSIGHT FORENSIC
ย 
(130202) #fitalk trends in d forensics (jan, 2013)
(130202) #fitalk   trends in d forensics (jan, 2013)(130202) #fitalk   trends in d forensics (jan, 2013)
(130202) #fitalk trends in d forensics (jan, 2013)INSIGHT FORENSIC
ย 
(130202) #fitalk china threat
(130202) #fitalk   china threat(130202) #fitalk   china threat
(130202) #fitalk china threatINSIGHT FORENSIC
ย 
(130119) #fitalk apt, cyber espionage threat
(130119) #fitalk   apt, cyber espionage threat(130119) #fitalk   apt, cyber espionage threat
(130119) #fitalk apt, cyber espionage threatINSIGHT FORENSIC
ย 
(130119) #fitalk all about physical data recovery
(130119) #fitalk   all about physical data recovery(130119) #fitalk   all about physical data recovery
(130119) #fitalk all about physical data recoveryINSIGHT FORENSIC
ย 
(130105) #fitalk trends in d forensics (dec, 2012)
(130105) #fitalk   trends in d forensics (dec, 2012)(130105) #fitalk   trends in d forensics (dec, 2012)
(130105) #fitalk trends in d forensics (dec, 2012)INSIGHT FORENSIC
ย 
(130907) #fitalk generating volatility linux profile
(130907) #fitalk   generating volatility linux profile(130907) #fitalk   generating volatility linux profile
(130907) #fitalk generating volatility linux profileINSIGHT FORENSIC
ย 
(130727) #fitalk rp log tracker
(130727) #fitalk   rp log tracker(130727) #fitalk   rp log tracker
(130727) #fitalk rp log trackerINSIGHT FORENSIC
ย 
(130727) #fitalk pfp (portable forensic platform), #2 story
(130727) #fitalk   pfp (portable forensic platform), #2 story(130727) #fitalk   pfp (portable forensic platform), #2 story
(130727) #fitalk pfp (portable forensic platform), #2 storyINSIGHT FORENSIC
ย 
(130727) #fitalk anonymous network concepts and implementation
(130727) #fitalk   anonymous network concepts and implementation(130727) #fitalk   anonymous network concepts and implementation
(130727) #fitalk anonymous network concepts and implementationINSIGHT FORENSIC
ย 
(130720) #fitalk trends in d forensics
(130720) #fitalk   trends in d forensics(130720) #fitalk   trends in d forensics
(130720) #fitalk trends in d forensicsINSIGHT FORENSIC
ย 

More from INSIGHT FORENSIC (19)

(150124) #fitalk advanced $usn jrnl forensics (english)
(150124) #fitalk   advanced $usn jrnl forensics (english)(150124) #fitalk   advanced $usn jrnl forensics (english)
(150124) #fitalk advanced $usn jrnl forensics (english)
ย 
(140118) #fitalk detection of anti-forensics artifacts using ioa fs
(140118) #fitalk   detection of anti-forensics artifacts using ioa fs(140118) #fitalk   detection of anti-forensics artifacts using ioa fs
(140118) #fitalk detection of anti-forensics artifacts using ioa fs
ย 
(140118) #fitalk 2013 e-discovery trend
(140118) #fitalk   2013 e-discovery trend(140118) #fitalk   2013 e-discovery trend
(140118) #fitalk 2013 e-discovery trend
ย 
(141031) #fitalk os x yosemite artifacts
(141031) #fitalk   os x yosemite artifacts(141031) #fitalk   os x yosemite artifacts
(141031) #fitalk os x yosemite artifacts
ย 
(140716) #fitalk ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹
(140716) #fitalk   ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹(140716) #fitalk   ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹
(140716) #fitalk ์ „์ž๊ธˆ์œต์‚ฌ๊ณ ์—์„œ์˜ ๋””์ง€ํ„ธ ํฌ๋ Œ์‹
ย 
(140716) #fitalk digital evidence from android-based smartwatch
(140716) #fitalk   digital evidence from android-based smartwatch(140716) #fitalk   digital evidence from android-based smartwatch
(140716) #fitalk digital evidence from android-based smartwatch
ย 
(140625) #fitalk sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„
(140625) #fitalk   sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„(140625) #fitalk   sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„
(140625) #fitalk sq lite ์†Œ๊ฐœ์™€ ๊ตฌ์กฐ ๋ถ„์„
ย 
(140407) #fitalk d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„
(140407) #fitalk   d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„(140407) #fitalk   d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„
(140407) #fitalk d trace๋ฅผ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ๋™์  ๋ถ„์„
ย 
(130216) #fitalk potentially malicious ur ls
(130216) #fitalk   potentially malicious ur ls(130216) #fitalk   potentially malicious ur ls
(130216) #fitalk potentially malicious ur ls
ย 
(130202) #fitalk trends in d forensics (jan, 2013)
(130202) #fitalk   trends in d forensics (jan, 2013)(130202) #fitalk   trends in d forensics (jan, 2013)
(130202) #fitalk trends in d forensics (jan, 2013)
ย 
(130202) #fitalk china threat
(130202) #fitalk   china threat(130202) #fitalk   china threat
(130202) #fitalk china threat
ย 
(130119) #fitalk apt, cyber espionage threat
(130119) #fitalk   apt, cyber espionage threat(130119) #fitalk   apt, cyber espionage threat
(130119) #fitalk apt, cyber espionage threat
ย 
(130119) #fitalk all about physical data recovery
(130119) #fitalk   all about physical data recovery(130119) #fitalk   all about physical data recovery
(130119) #fitalk all about physical data recovery
ย 
(130105) #fitalk trends in d forensics (dec, 2012)
(130105) #fitalk   trends in d forensics (dec, 2012)(130105) #fitalk   trends in d forensics (dec, 2012)
(130105) #fitalk trends in d forensics (dec, 2012)
ย 
(130907) #fitalk generating volatility linux profile
(130907) #fitalk   generating volatility linux profile(130907) #fitalk   generating volatility linux profile
(130907) #fitalk generating volatility linux profile
ย 
(130727) #fitalk rp log tracker
(130727) #fitalk   rp log tracker(130727) #fitalk   rp log tracker
(130727) #fitalk rp log tracker
ย 
(130727) #fitalk pfp (portable forensic platform), #2 story
(130727) #fitalk   pfp (portable forensic platform), #2 story(130727) #fitalk   pfp (portable forensic platform), #2 story
(130727) #fitalk pfp (portable forensic platform), #2 story
ย 
(130727) #fitalk anonymous network concepts and implementation
(130727) #fitalk   anonymous network concepts and implementation(130727) #fitalk   anonymous network concepts and implementation
(130727) #fitalk anonymous network concepts and implementation
ย 
(130720) #fitalk trends in d forensics
(130720) #fitalk   trends in d forensics(130720) #fitalk   trends in d forensics
(130720) #fitalk trends in d forensics
ย 

Recently uploaded

์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ
์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ
์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค
ย 
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)Wonjun Hwang
ย 
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)Wonjun Hwang
ย 
A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)Tae Young Lee
ย 
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionMOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionKim Daeun
ย 
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Kim Daeun
ย 

Recently uploaded (6)

์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ
์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ
์บ๋“œ์•ค๊ทธ๋ž˜ํ”ฝ์Šค 2024๋…„ 5์›”ํ˜ธ ๋ชฉ์ฐจ
ย 
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)
Console API (Kitworks Team Study ๋ฐฑํ˜œ์ธ ๋ฐœํ‘œ์ž๋ฃŒ)
ย 
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)
Merge (Kitworks Team Study ์ด์„ฑ์ˆ˜ ๋ฐœํ‘œ์ž๋ฃŒ 240426)
ย 
A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)A future that integrates LLMs and LAMs (Symposium)
A future that integrates LLMs and LAMs (Symposium)
ย 
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution DetectionMOODv2 : Masked Image Modeling for Out-of-Distribution Detection
MOODv2 : Masked Image Modeling for Out-of-Distribution Detection
ย 
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
Continual Active Learning for Efficient Adaptation of Machine LearningModels ...
ย 

(120325) #fitalk web browser forensics - part ii

  • 1. FORENSIC INSIGHT SEMINAR Web Browser Forensics : Part2 blueangel blueangel1275@gmail.com http://blueangel-forensic-note.tistory.com
  • 2. forensicinsight.org Page 2 / 88 ๊ฐœ์š” 1. Firefox ๋กœ๊ทธ ๋ถ„์„ 2. Chrome ๋กœ๊ทธ ๋ถ„์„ 3. Safari ๋กœ๊ทธ ๋ถ„์„ 4. Opera ๋กœ๊ทธ ๋ถ„์„ 5. ๋ถ„์„ ๋„๊ตฌ
  • 3. forensicinsight.org Page 3 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 4. forensicinsight.org Page 4 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ โ€ข Cache Map File : _CACHE_MAP_ โ€ข Cache Block Files : _CACHE_00X_ โ€ข Separate Cache Data files Cache ์ •๋ณด ๋ถ„์„
  • 5. forensicinsight.org Page 5 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache Map File ๊ตฌ์กฐ โ€ข 32๊ฐœ์˜ Bucket๋กœ ์ด๋ฃจ์–ด์ง โ€ข ํ•œ ๊ฐœ์˜ Bucket์€ 256๊ฐœ์˜ Record๋ฅผ ํฌํ•จ ๏ƒจ ์ด 8,192๊ฐœ์˜ Record ์ €์žฅ ๊ฐ€๋Šฅ โ€ข ํ•˜๋‚˜์˜ Record(16byte)๋Š” Cache ๋ฐ์ดํ„ฐ์˜ ๋งตํ•‘ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ์Œ Cache ์ •๋ณด ๋ถ„์„ Hash Number(4byte) Eviction Rank(4byte) Data location(4byte) Metadata Location(4byte)
  • 6. forensicinsight.org Page 6 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache Map File Record ๊ตฌ์กฐ โ€ข Hash Number ๏ƒผ Cache ํŒŒ์ผ์˜ ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉ โ€ข Data location, Metadata Location ๏ƒผ ์ตœ์ƒ์œ„ ๋ฐ”์ดํŠธ์˜ ํ•˜์œ„ 3๋น„ํŠธ ๊ฐ’์ด 0์ด๋ฉด Separate Cache ํŒŒ์ผ์— ์ €์žฅ 1,2,3์ด๋ฉด Cache Block ํŒŒ ์ผ์— ์ €์žฅ โ€ข Eviction Rank ๏ƒผ Unkwon Cache ์ •๋ณด ๋ถ„์„
  • 7. forensicinsight.org Page 7 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Separate Cache Data Files โ€ข Cache Content๊ณผ Matadata์˜ ํฌ๊ธฐ๊ฐ€ ํฐ ๊ฒฝ์šฐ ์‚ฌ์šฉ โ€ข Cache Data Files์˜ ์ด๋ฆ„ ๏ƒผ <HASH NUMBER><TYPE><GENERATION NUMBER> ๏ƒผ HASH NUMBER โ€ข Cache Map file์˜ Hash Number ๏ƒผ TYPE โ€ข d: Cache Content โ€ข m: Cache metadata ๏ƒผ GENERATION NUMBER โ€ข Data location, Metadata Location ์ตœํ•˜์œ„ 1๋ฐ”์ดํŠธ ๊ฐ’ โ€ข Ex) F1FD0B04d01 Cache ์ •๋ณด ๋ถ„์„
  • 8. forensicinsight.org Page 8 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Three Cache Block Files ๏ƒผ ๋ฐ์ดํ„ฐ์˜ ์‹œ์ž‘ ๏ƒผ Data location, Metadata Location์˜ ํ•˜์œ„ 3๋ฐ”์ดํŠธ ๊ฐ’ ๏ƒผ ๋ฐ์ดํ„ฐ ํ• ๋‹น ํฌ๊ธฐ(๋ธ”๋ก ๋‹จ์œ„) ๏ƒผ ((Data location, Metadata Location) & 0x03000000) >> 24 ) + 1 ๏ƒผ ๋ธ”๋ก ์‚ฌ์ด์ฆˆ ๏ƒผ Cache Block Files์˜ ํŒŒ์ผ ์ด๋ฆ„์— ๋”ฐ๋ผ ๋‹ค๋ฆ„ ๏ƒผ โ€œ_CACHE_001_โ€->256 byte (0x100) ๏ƒผ โ€œ_CACHE_002_โ€->512 byte (0x400) ๏ƒผ โ€œ_CACHE_003โ€_->1024 byte (0x1000) Cache ์ •๋ณด ๋ถ„์„
  • 9. forensicinsight.org Page 9 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Separate Cache Data Files ๋‚ด์šฉ ํ™•์ธ โ€ข Data Location ๏ƒผ 8(1000): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 0์ด๋ฏ€๋กœ Separate Cache Data File์— ์ €์žฅ ๏ƒผ ํŒŒ์ผ ์ด๋ฆ„: 3A390709d01 โ€ข MetaData Location ๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1 ์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ ๏ƒผ offset: 0x000B94*0x100+0x1000 = 0x000BA400 Cache ์ •๋ณด ๋ถ„์„ Hash number Eviction Rank Data Location MetaData Location
  • 10. forensicinsight.org Page 10 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Separate Cache Data Files ๋‚ด์šฉ ํ™•์ธ โ€ข _CACHE_001_ ํŒŒ์ผ์˜ offset 0x000BA400 โ€ข Cache ํด๋”์˜ 3A390709d01ํŒŒ์ผ์˜ ํ™•์žฅ์ž๋ฅผ gif ๋กœ ๋ณ€๊ฒฝํ•˜๋ฉด ๋‚ด์šฉ ํ™•์ธ ๊ฐ€๋Šฅ Cache ์ •๋ณด ๋ถ„์„ URL ์ ‘์† ์‹œ๊ฐ„ ๋ณ€๊ฒฝ ์‹œ๊ฐ„ ํŒŒ์ผ ํฌ๊ธฐ Content Type
  • 11. forensicinsight.org Page 11 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Three Cache Block File ๋‚ด์šฉ ํ™•์ธ โ€ข Data Location ๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ ๏ƒผ offset: 0x000B33*0x100+0x1000 = 0x000B4300 โ€ข MetaData Location ๏ƒผ 9(1001): ํ•˜์œ„ 2๋น„ํŠธ์˜ ๊ฐ’์ด 1 ์ด๋ฏ€๋กœ _CACHE_001_ ์— ์ €์žฅ ๏ƒผ offset: 0x000B36*0x100+0x1000 = 0x000B4600 Cache ์ •๋ณด ๋ถ„์„ Hash number Eviction Rank Data Location MetaData Location
  • 12. forensicinsight.org Page 12 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Three Cache Block File ๋‚ด์šฉ ํ™•์ธ โ€ข Content Data โ€ข Content Metadata Cache ์ •๋ณด ๋ถ„์„ URL ์ ‘์† ์‹œ๊ฐ„ ๋ณ€๊ฒฝ ์‹œ๊ฐ„ ํŒŒ์ผ ํฌ๊ธฐ Content Type
  • 13. forensicinsight.org Page 13 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋ฐ์ดํ„ฐ ํฌ๊ธฐ โ€ข Data์˜ ํฌ๊ธฐ๊ฐ€ 85 ๋ฐ”์ดํŠธ ๏ƒจ Content Data์˜ 85 ๋ฐ”์ดํŠธ๋ฅผ setup_myinfo.gif๋กœ ์ €์žฅ Cache ์ •๋ณด ๋ถ„์„
  • 14. forensicinsight.org Page 14 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 15. forensicinsight.org Page 15 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : places.sqlite ๏‚ง ํŒŒ์ผ ํ˜•์‹ ๏‚ง SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” ๏‚ง moz_places : ๋ฐฉ๋ฌธํ•œ URL ์ •๋ณด ์ €์žฅ ๏‚ง moz_historyvisits : ์‹ค์ œ ๋ฐฉ๋ฌธ ๊ธฐ๋ก ์ €์žฅ, place_id ๊ฐ’์„ ํ†ตํ•ด moz_place์˜ url ์ฐธ์กฐ ๏‚ง ์ €์žฅ ์ •๋ณด ๏‚ง URL ๏‚ง Title ๏‚ง ๋ฐฉ๋ฌธ ํšŸ์ˆ˜ ๏‚ง ๋ฐฉ๋ฌธ ํƒ€์ž…(1 : URL ํƒ€์ดํ•‘ ์ ‘์†, 0 : ๋งํฌ ์ ‘์†) ๏‚ง ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) History ์ •๋ณด ๋ถ„์„
  • 16. forensicinsight.org Page 16 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง moz_places, moz_historyvisits ํ…Œ์ด๋ธ” ๊ตฌ์กฐ History ์ •๋ณด ๋ถ„์„
  • 17. forensicinsight.org Page 17 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 18. forensicinsight.org Page 18 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : cookies.sqlite ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” โ€ข moz_cookies : ์ฟ ํ‚ค ๋ฐ์ดํ„ฐ ์ €์žฅ ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ํ˜ธ์ŠคํŠธ, ๊ฒฝ๋กœ โ€ข ๋ณ€์ˆ˜, ๊ฐ’ โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜ โ€ข ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) โ€ข ์ฟ ํ‚ค ๋งŒ๋ฃŒ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) โ€ข isSecure, isHttpOnly Cookie ์ •๋ณด ๋ถ„์„
  • 19. forensicinsight.org Page 19 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง moz_cookies ํ…Œ์ด๋ธ” ๊ตฌ์กฐ Cookie ์ •๋ณด ๋ถ„์„
  • 20. forensicinsight.org Page 20 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 21. forensicinsight.org Page 21 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : downloads.sqlite ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” โ€ข moz_downloads : ์ฟ ํ‚ค ๋ฐ์ดํ„ฐ ์ €์žฅ ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ์†Œ์Šค URL โ€ข ๋‹ค์šด๋ฐ›์€ Local ๊ฒฝ๋กœ โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) : ์‹œ์ž‘/ ์ข…๋ฃŒ์‹œ๊ฐ„ โ€ข ๋‹ค์šด๋กœ๋“œ ๋ฐ›์€ ํฌ๊ธฐ, ์ด ๋‹ค์šด๋กœ๋“œ ํฌ๊ธฐ Download ์ •๋ณด ๋ถ„์„
  • 22. forensicinsight.org Page 22 / 88 Firefox ๋กœ๊ทธ ๋ถ„์„ ๏‚ง moz_downloads ํ…Œ์ด๋ธ” ๊ตฌ์กฐ Download ์ •๋ณด ๋ถ„์„
  • 23. forensicinsight.org Page 23 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 24. forensicinsight.org Page 24 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ์ „์ฒด ํŒŒ์ผ ๊ตฌ์„ฑ โ€ข data_0, data_1, data_2, data_3, ๋ฐ์ดํ„ฐ ํŒŒ์ผ Cache ์ •๋ณด ๋ถ„์„
  • 25. forensicinsight.org Page 25 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ โ€ข data_0 ๏ƒผ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ๋จ( URL ๋ ˆ์ฝ”๋“œ์˜ ์œ„์น˜ ์ •๋ณด ์ €์žฅ) ๏ƒผ ์˜คํ”„์…‹ 0x2000 ๋ถ€ํ„ฐ 0x24 ๋ฐ”์ดํŠธ ๋‹จ์œ„๋กœ ์ €์žฅ โ€ข data_1, data_2, data_3 ๏ƒผ URL(URL ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋จ), ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ, Cache ๋ฐ์ดํ„ฐ ์ €์žฅ ๏ƒผ ์˜คํ”„์…‹ 0x2000 ๋ถ€ํ„ฐ ๋ธ”๋ก ๋‹จ์œ„๋กœ ์ €์žฅ ๏ƒผ ๋ธ”๋ก ๋‹จ์œ„ โ€ข data_1: 0x100 โ€ข data_2: 0x400 โ€ข data_3: 0x1000 Cache ์ •๋ณด ๋ถ„์„
  • 26. forensicinsight.org Page 26 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง data_0 ์—์„œ์˜ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ โ€ข ์ตœ์ดˆ 2 ๋ฐ”์ดํŠธ ๏ƒผ ๋ธ”๋ก์˜ ์ธ๋ฑ์Šค ๏ƒผ 0x0001์ด๋ฉด ๋‘ ๋ฒˆ์งธ ๋ธ”๋ก์— URL๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ ๋˜์–ด ์žˆ์Œ โ€ข 3๋ฒˆ์งธ ๋ฐ”์ดํŠธ ๏ƒผ ํŒŒ์ผ์˜ ์ธ๋ฑ์Šค ๏ƒผ 0x01์ด๋ฉด data_1 ํŒŒ์ผ์— URL ๋ ˆ์ฝ”๋“œ๊ฐ€ ์ €์žฅ ๋˜์–ด ์žˆ์Œ โ€ข URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜ ๏ƒผ ๋ธ”๋ก ์ธ๋ฑ์Šค * ๋ธ”๋ก์˜ ๋‹จ์œ„ + 0x2000 Cache ์ •๋ณด ๋ถ„์„ HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 00 10 URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜ ์ •๋ณด 20
  • 27. forensicinsight.org Page 27 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง data_n(n=1, 2, 3) ์—์„œ์˜ URL ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ โ€ข (๋ฉ”ํƒ€)๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ ๏ƒผ 4๋ฒˆ์งธ ๋ฐ”์ดํŠธ์— ๋”ฐ๋ผ ์ €์žฅ ์œ„์น˜ ๊ฒฐ์ • โ€ข 0x80์ด๋ฉด ๋ณ„๋„์˜ ํŒŒ์ผ๋กœ ์ €์žฅ ๋‚˜๋จธ์ง€ 3๋ฐ”์ดํŠธ๊ฐ€ ํŒŒ์ผ์˜ ์ด๋ฆ„ โ€ข 0x80์ด ์•„๋‹ˆ๋ฉด โ€œURL ๋ ˆ์ฝ”๋“œ ์œ„์น˜โ€์™€ ๊ฐ™์€ ๋ฐฉ์‹์œผ๋กœ ๊ณ„์‚ฐ Cache ์ •๋ณด ๋ถ„์„ HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 00 URL์˜ ํฌ๊ธฐ 10 ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ 20 ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ URL์˜ ์‹œ์ž‘ ์œ„์น˜
  • 28. forensicinsight.org Page 28 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 1 : data_0์˜ ์ธ๋ฑ์Šค ๋ ˆ์ฝ”๋“œ์—์„œ URL ๋ ˆ์ฝ”๋“œ ์œ„์น˜๋ฅผ ์ฐธ์กฐ Cache ์ •๋ณด ๋ถ„์„ 0x0002 * 0x100 + 0x2000 = 0x2200 data_1 data_0 URL์˜ ํฌ๊ธฐ
  • 29. forensicinsight.org Page 29 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 2 : data_1์˜ URL ๋ ˆ์ฝ”๋“œ์—์„œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜๋ฅผ ์ฐธ์กฐ Cache ์ •๋ณด ๋ถ„์„ data_1 ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜:data_1 0x0003 * 0x 100 + 0x2000 = 0x2300 data_1
  • 30. forensicinsight.org Page 30 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache ํ”ผ์ผ ๋‚ด์šฉ ํ™•์ธ 3 : data_1์˜ URL ๋ ˆ์ฝ”๋“œ์—์„œ ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜๋ฅผ ์ฐธ์กฐ Cache ์ •๋ณด ๋ถ„์„ data_1 ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฐ์ดํ„ฐํŒŒ์ผ ์ด๋ฆ„:f_000001 ํ™•์žฅ์ž ๋ณ€๊ฒฝ
  • 31. forensicinsight.org Page 31 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cache ๋ฐ์ดํ„ฐ๊ฐ€ Cache ํŒŒ์ผ(data_n) ์•ˆ์— ์žˆ๋Š” ๊ฒฝ์šฐ Cache ์ •๋ณด ๋ถ„์„ data_1 ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜:data_3 ์˜คํ”„์…‹: 0x0000*0x1000+0x2000 = 0x2000 Data_3
  • 32. forensicinsight.org Page 32 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ์ตœ์‹  ๋ฒ„์ „์˜ URL ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ โ€ข (๋ฉ”ํƒ€)๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ ๊ณ„์‚ฐ ๋ฐฉ์‹์€ ๊ธฐ์กด๊ณผ ๋™์ผ Cache ์ •๋ณด ๋ถ„์„ HEX 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 00 10 20 URL์˜ ํฌ๊ธฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ 30 ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ์ดํ„ฐ์˜ ์œ„์น˜ ๋ฐ ์ด๋ฆ„ 40 50 URL์˜ ์‹œ์ž‘ ์œ„์น˜
  • 33. forensicinsight.org Page 33 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 34. forensicinsight.org Page 34 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History ๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” โ€ข urls ํ…Œ์ด๋ธ” ๏ƒผ ๋ฐฉ๋ฌธํ•œ url ์ •๋ณด ์ €์žฅ, ๊ฐ™์€ url์€ ์ค‘๋ณต ์ €์žฅ ์•ˆ ๋จ, ์ค‘๋ณต ๋ฐฉ๋ฌธ ์‹œ ๋งˆ์ง€๋ง‰ ์ ‘์† ์‹œ๊ฐ„ ์ €์žฅ โ€ข visits ํ…Œ์ด๋ธ” ๏ƒผ ์‹ค์ œ ๋ฐฉ๋ฌธ ์ •๋ณด ์ €์žฅ, ์‹ค์ œ ๋ฐฉ๋ฌธ ์‹œ ์ €์žฅ๋˜๋Š” url์ •๋ณด๋Š” urls ํ…Œ์ด๋ธ”์—์„œ ์ฐธ์กฐ ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข URL โ€ข Title โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜ โ€ข ๋ฐฉ๋ฌธ ํƒ€์ž…(1 : URL ํƒ€์ดํ•‘ ์ ‘์†, 0 : ๋งํฌ ์ ‘์†) โ€ข ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) History ์ •๋ณด ๋ถ„์„
  • 35. forensicinsight.org Page 35 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง urls, visits ํ…Œ์ด๋ธ” ๊ตฌ์กฐ History ์ •๋ณด ๋ถ„์„
  • 36. forensicinsight.org Page 36 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 37. forensicinsight.org Page 37 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cookies ๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” : cookies ํ…Œ์ด๋ธ” ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ํ˜ธ์ŠคํŠธ, ๊ฒฝ๋กœ โ€ข ๋ณ€์ˆ˜, ๊ฐ’ โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜ โ€ข ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) โ€ข ์ฟ ํ‚ค ๋งŒ๋ฃŒ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) โ€ข isSecure, isHttpOnly Cookie ์ •๋ณด ๋ถ„์„
  • 38. forensicinsight.org Page 38 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง cookies ํ…Œ์ด๋ธ” ๊ตฌ์กฐ Cookie ์ •๋ณด ๋ถ„์„
  • 39. forensicinsight.org Page 39 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 40. forensicinsight.org Page 40 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History ๏‚ง ํŒŒ์ผ ํ˜•์‹ : SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” : downloads ํ…Œ์ด๋ธ” ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ์†Œ์Šค URL โ€ข ๋‹ค์šด๋ฐ›์€ Local ๊ฒฝ๋กœ โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(1601๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ๋งˆ์ดํฌ๋กœ์ดˆ) : ์‹œ์ž‘/ ์ข…๋ฃŒ์‹œ๊ฐ„ โ€ข ์ด ๋‹ค์šด๋กœ๋“œ ํฌ๊ธฐ โ€ข ๋‹ค์šด๋กœ๋“œ ์ƒํƒœ : ์„ฑ๊ณต(1), ์‹คํŒจ(0) Download ์ •๋ณด ๋ถ„์„
  • 41. forensicinsight.org Page 41 / 88 Chrome ๋กœ๊ทธ ๋ถ„์„ ๏‚ง downloads ํ…Œ์ด๋ธ” Download ์ •๋ณด ๋ถ„์„
  • 42. forensicinsight.org Page 42 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 43. forensicinsight.org Page 43 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cache.db ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ ํ˜•์‹ ๏‚ง ์ฃผ์š” ํ…Œ์ด๋ธ” โ€ข cfurl_cache_response : ์บ์‹œ ์ธ๋ฑ์Šค ์ •๋ณด ์ €์žฅ โ€ข cfurl_cache_blob_data : ์บ์‹œ ๋ฐ์ดํ„ฐ ์ €์žฅ ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข URL โ€ข ๋‹ค์šด๋กœ๋“œ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ ) โ€ข ์บ์‹œ ๋ฐ์ดํ„ฐ Cache ์ •๋ณด ๋ถ„์„
  • 44. forensicinsight.org Page 44 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํ…Œ์ด๋ธ” ๊ตฌ์กฐ โ€ข cfurl_cache_response ํ…Œ์ด๋ธ” โ€ข cfurl_cache_blob_data ํ…Œ์ด๋ธ” Cache ์ •๋ณด ๋ถ„์„
  • 45. forensicinsight.org Page 45 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 46. forensicinsight.org Page 46 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : History.plist ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข Binary Plist ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข URL โ€ข Title โ€ข ๋ฐฉ๋ฌธ ํšŸ์ˆ˜ โ€ข ๋ฐฉ๋ฌธ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ History ์ •๋ณด ๋ถ„์„
  • 47. forensicinsight.org Page 47 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง History.plist ๊ตฌ์กฐ ( plistEditor Pro 2.0 ์‚ฌ์šฉ ) History ์ •๋ณด ๋ถ„์„
  • 48. forensicinsight.org Page 48 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 49. forensicinsight.org Page 49 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Cookies.plist ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข Text Plist ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ๋„๋ฉ”์ธ, ๊ฒฝ๋กœ โ€ข ์ด๋ฆ„, ๊ฐ’ โ€ข ์ƒ์„ฑ ์‹œ๊ฐ„(2001๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€ ๊ฒฝ๊ณผ๋œ ์ดˆ) โ€ข ๋งŒ๋ฃŒ ์‹œ๊ฐ„ ํ…์ŠคํŠธ ํ˜•์‹ โ€ข HttpOnly ์˜ต์…˜ Cookie ์ •๋ณด ๋ถ„์„
  • 50. forensicinsight.org Page 50 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cookies.plist ๊ตฌ์กฐ Cookie ์ •๋ณด ๋ถ„์„
  • 51. forensicinsight.org Page 51 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cookie.binarycookie ํŒŒ์ผ ์ „์ฒด ๊ตฌ์กฐ โ€ข Signature : โ€œCOOKโ€ โ€ข Page ๋‹จ์œ„๋กœ ๊ตฌ์„ฑ๋จ ๏ƒผ Page ๋Š” ๊ฐ€๋ณ€ ๊ธธ์ด ๏ƒผ Page ์‚ฌ์ด์ฆˆ๋ฅผ ๋ฐฐ์—ด ํ˜•์‹์œผ๋กœ ๋”ฐ๋กœ ์ €์žฅ ๏ƒผ Page ์‚ฌ์ด์ฆˆ ๋ฐฐ์—ด์ด ๋๋‚˜๋ฉด ์‹ค์ œ Page ๋“ค์ด ์œ„์น˜ Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
  • 52. forensicinsight.org Page 52 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Page ๊ตฌ์กฐ โ€ข ๊ฐ ์ฟ ํ‚ค ์ •๋ณด๋Š” ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋จ โ€ข ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ ํฌ๊ธฐ๋Š” ๊ฐ€๋ณ€ โ€ข ๊ฐ ์ฟ ํ‚ค ๋ ˆ์ฝ”๋“œ์˜ ์œ„์น˜๋Š” ๋ฐฐ์—ด ํ˜•์‹์œผ๋กœ ์ €์žฅ๋จ Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
  • 53. forensicinsight.org Page 53 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Cookie ๋ ˆ์ฝ”๋“œ ๊ตฌ์กฐ โ€ข URL, Path, Name, Value ๊ฐ’์€ ์•„์Šคํ‚ค ๊ฐ’ ํ˜•ํƒœ๋กœ ์ €์žฅ๋จ โ€ข Create Date, Expiration Date ๏ƒผ 64 bit Double Mac Absolute Time(GMT) ??? ๏ƒจ ์ด ํฌ๋ฉง์— ๋Œ€ํ•ด ์•„์‹œ๋Š” ๋ถ„์€ ๋ฉ”์ผ๋กœ ์•Œ๋ ค์ฃผ์‹œ๋ฉด ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ใ… ใ…  Cookie ์ •๋ณด ๋ถ„์„ : 5.1 ๋ฒ„์ „๋ถ€ํ„ฐ ์ƒˆ๋กœ์šด ํŒŒ์ผ ํฌ๋ฉง ์‚ฌ์šฉ (Cookie.binarycookie)
  • 54. forensicinsight.org Page 54 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ - Cache ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„
  • 55. forensicinsight.org Page 55 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ๋ช… : Downloads.plist ๏‚ง ํŒŒ์ผ ํ˜•์‹ โ€ข Binary Plist ๏‚ง ์ €์žฅ ์ •๋ณด โ€ข ์†Œ์Šค URL โ€ข ๋‹ค์šด๋กœ๋“œ ๊ฒฝ๋กœ โ€ข ๋‹ค์šด๋กœ๋“œ ํŒŒ์ผ ํฌ๊ธฐ Download ์ •๋ณด ๋ถ„์„
  • 56. forensicinsight.org Page 56 / 88 Safari ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Downloads.plist ๊ตฌ์กฐ Download ์ •๋ณด ๋ถ„์„
  • 57. forensicinsight.org Page 57 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ - Generic Binary Format - Cache ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด๋ถ„์„ - History ์ •๋ณด ๋ถ„์„
  • 58. forensicinsight.org Page 58 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Opera ๋ฒ„์ „ 5.0 ๋ถ€ํ„ฐ ์‚ฌ์šฉ ๏‚ง ๋ฒ„์ „ 3.x ์™€๋Š” ํ˜ธํ™˜ ์•ˆ ๋จ, ๋ฒ„์ „ 4.x ์™€๋Š” ํ˜ธํ™˜ ๊ฐ€๋Šฅ ๏‚ง ์ผ๋ จ์˜ ๊ธธ์ด ์ •๋ณด๋ฅผ ๊ฐ€์ง„ ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์ง‘ํ•ฉ ๏‚ง ๋Œ€์ƒ ํŒŒ์ผ โ€ข dcache4.url : ์บ์‹œ ํŒŒ์ผ โ€ข cookies4.dat : ์ฟ ํ‚ค ํŒŒ์ผ โ€ข download.dat : ๋‹ค์šด๋กœ๋“œ ๋ชฉ๋ก ํŒŒ์ผ Generic Binary Format(์กฐ๊ธˆ ๋ณต์žกํ•˜๋‹ˆ๊นŒ ์กธ์ง€ ๋งˆ์„ธ์š”โ€ฆใ… ใ…  )
  • 59. forensicinsight.org Page 59 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๋ฐ์ดํ„ฐ ํƒ€์ž… โ€ข ์ •์ˆ˜ ์ •๋ณด ๏ƒผ ๋น… ์—”๋””์•ˆ ํƒ€์ž…์œผ๋กœ ์ €์žฅ ๏ƒจ ํŒŒ์‹ฑ ์‹œ, ๋ฆฌํ‹€ ์—”๋””์•ˆ์œผ๋กœ ๋ณ€ํ™˜ ํ•„์š” ๏ƒผ EX) ๋ ˆ์ฝ”๋“œ ๊ธธ์ด ์ •๋ณด, ์‹œ๊ฐ„ ์ •๋ณด, ์‚ฌ์ด์ฆˆ ์ •๋ณด โ€ฆ โ€ข ์‹œ๊ฐ„ ์ •๋ณด ๏ƒผ time_t ํƒ€์ž… ์‚ฌ์šฉ ๏ƒผ 1970๋…„ 1์›” 1์ผ 00:00:00 ๊ธฐ์ค€์œผ๋กœ ํ˜„์žฌ๊นŒ์ง€ ๊ฒฝ๊ณผ๋œ ์ดˆ ๏ƒผ ๋น… ์—”๋””์•ˆ ํƒ€์ž…์œผ๋กœ ์ €์žฅ โ€ข ๋ฌธ์ž ์ •๋ณด ๏ƒผ ๊ธฐ๋ณธ์ ์œผ๋กœ ์˜์–ด๋Š” ์•„์Šคํ‚ค ํƒ€์ž…์œผ๋กœ ์ €์žฅ ๏ƒผ ๊ทธ ์™ธ ๋‹ค๊ตญ์–ด ์ผ ๊ฒฝ์šฐ UTF-8 ๋กœ ์ธ์ฝ”๋”ฉ Generic Binary Format
  • 60. forensicinsight.org Page 60 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ โ€ข ํ—ค๋” + ๋ ˆ์ฝ”๋“œ ์ง‘ํ•ฉ โ€ข ํ—ค๋” ๊ตฌ์„ฑ ๏ƒผ ํŒŒ์ผ ๋ฒ„์ „(4byte) : ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด๋‹ค ํŒŒ์ผ ๋ฒ„์ „์ด ๋†’์œผ๋ฉด ๋ชป ์ฝ์Œ โ€ข ํ•˜์œ„ 12bit : minor ๋ฒ„์ „ โ€ข ์ƒ์œ„ 30bit : major ๋ฒ„์ „ ๏ƒผ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฒ„์ „(4byte) โ€ข 0x00002000 : ์ฟ ํ‚ค ํŒŒ์ผ โ€ข 0x00020000 : ์บ์‹œ, ๋‹ค์šด๋กœ๋“œ ๋ชฉ๋ก ํŒŒ์ผ ๏ƒผ ๋ ˆ์ฝ”๋“œ์˜ Tag_ID ํฌ๊ธฐ (2byte) ๏ƒผ ๋ ˆ์ฝ”๋“œ์˜ ๋ฐ์ดํ„ฐ ํฌ๊ธฐ ํ•„๋“œ์˜ ํฌ๊ธฐ (2byte) Generic Binary Format
  • 61. forensicinsight.org Page 61 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ (๊ณ„์†) โ€ข ๋ ˆ์ฝ”๋“œ ๊ตฌ์„ฑ ๏ƒผ Tag_ID(Default : 1byte) โ€ข ๋ ˆ์ฝ”๋“œ์— ์ €์žฅ๋˜๋Š” ๋ฐ์ดํ„ฐ์˜ ํƒ€์ž… ์ •๋ณด ์ €์žฅ โ€ข Tag_ID ์ข…๋ฅ˜ ยป ์ผ๋ฐ˜ ๋ ˆ์ฝ”๋“œ Tag_ID โ€ข Tag_ID+๊ธธ์ด์ •๋ณด+๋ฐ์ดํ„ฐ ๊ตฌ์„ฑ ยป Boolean ํ”Œ๋ž˜๊ทธ Tag_ID โ€ข ์ตœ์ƒ์œ„ ๋น„ํŠธ๊ฐ€(MSB)์˜ 1๊ณผ 0์œผ๋กœ ์ฐธ, ๊ฑฐ์ง“ ๊ตฌ๋ถ„ โ€ข Tag_ID๋งŒ ์กด์žฌ ๏ƒผ Data ๊ธธ์ด(Default : 2byte) ๏ƒผ Data Generic Binary Format Tag_ID(1byte) Data ๊ธธ์ด (2byte) Data
  • 62. forensicinsight.org Page 62 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ํŒŒ์ผ ๊ตฌ์„ฑ (๊ณ„์†) โ€ข ๋ ˆ์ฝ”๋“œ ์ข…๋ฅ˜ ๏ƒผ Entry ๋ ˆ์ฝ”๋“œ โ€ข ํ•ด๋‹น ํŒŒ์ผ์˜ ์ •๋ณด ๋‹จ์œ„ โ€ข ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ๋“ค์„ ํฌํ•จ โ€ข Tag_ID+๊ธธ์ด์ •๋ณด+๋ฐ์ดํ„ฐ๋ ˆ์ฝ”๋“œ ์ง‘ํ•ฉ ๏ƒผ Data ๋ ˆ์ฝ”๋“œ โ€ข ์ผ๋ฐ˜์ ์œผ๋กœ Entry ๋ ˆ์ฝ”๋“œ์˜ ํ•˜์œ„ ๋ ˆ์ฝ”๋“œ, ๋‹จ๋…์œผ๋กœ๋„ ์กด์žฌ ํ•  ์ˆ˜ ์žˆ์Œ โ€ข ์‹ค์ œ ๋ฐ์ดํ„ฐ ์ €์žฅ โ€ข ์„œ๋ธŒ ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ๋ฅผ ํฌํ•จํ•˜๋Š” ๋ ˆ์ฝ”๋“œ๋„ ์žˆ์Œ( ex: HTTP ๋ ˆ์ฝ”๋“œ) ๏ƒผ Sub_Data ๋ ˆ์ฝ”๋“œ โ€ข ๋ฐ์ดํ„ฐ ๋ ˆ์ฝ”๋“œ์˜ ํ•˜์œ„ ๋ ˆ์ฝ”๋“œ Generic Binary Format
  • 63. forensicinsight.org Page 63 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Tag_ID ์ •๋ณด โ€ข Entry Tag_ID โ€ข ์ผ๋ฐ˜ ๋ฐ์ดํ„ฐ Tag_ID Generic Binary Format File Tag id Cache 0x01 Cookies 0x01 Download List 0x41 Tag ID Contents Meaning 0x03 string URL 0x04 time_t ๋งˆ์ง€๋ง‰ ๋ฐฉ๋ฌธ์‹œ๊ฐ„ (0x0b | MSB_VALUE) flag The URL is a result of a form query 0x22 record Contains the name and last visited time of relative link in the document. May repeat
  • 64. forensicinsight.org Page 64 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†) โ€ข ์บ์‹œ, ๋‹ค์šด๋กœ๋“œ ํ˜ผ์šฉ ๋ฐ์ดํ„ฐ Tag_ID โ€ข ๋‹ค์šด๋กœ๋“œ ๋ฐ์ดํ„ฐ Tag_ID Generic Binary Format Tag ID Contents Meaning 0x05 time_t Localtime, when the file was last loaded, not GMT 0x07 uint8 Status of load: 2 Loaded 4 Loading aborted 5 Loading failed 0x08 uint32 Content size 0x09 string MIME type of content 0x0A string Character set of content (0x0C | MSB_VALUE) flag File is downloaded and stored locally on user's disk, and is not part of the disk cache d irectory 0x0D string Name of file (cache files: only local to cache directory) (0x0F| MSB_VALUE) flag Always check if modified 0x10 record Contains the HTTP protocol specific information Tag ID Contents Meaning 0x28 time_t Identifies the time when the loading of the last/previous segment of the downloaded file started. 0x29 time_t Identifies the time when the loading of the last/previous segment of the downloaded file was stopped. 0x2A uint32 How many bytes were in the previous segement of the file being downloaded. If the time the loading ended is not known, this value will be assumed to be zero (0) and the download speed set to zero(unknown).
  • 65. forensicinsight.org Page 65 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†) โ€ข HTTP ๋ ˆ์ฝ”๋“œ ์„œ๋ธŒ Tag_ID Generic Binary Format Tag ID Contents Meaning 0x15 string HTTP date header 0x16 time_t Expiry date 0x17 string Last modified date 0x18 string MIME type of document 0x19 string Entity tag 0x1A string Moved to URL (Location header) 0x1B string Response line text 0x1C uint32 Response code 0x1D string Refresh URL 0x1E uint32 Refresh delta time 0x1F string Suggested file name 0x20 string Content Encodings 0x21 string Content Location 0x25 uint32 Together with tag 0x0026 (both must be present) this identifies the User Agent string last used to load the resource. This value identifies the User Agent string. This value is used internally, and should not be modified. 0x26 uint32 Together with tag 0x0025 (both must be present) this identifies the User Agent string last used to load the resource. This value identifies the User Agent sub version. This value is used internally, and should not be modified. (0x30 | MSB_VALUE) flag Reserved for future use (0x31 | MSB_VALUE) Flag Reserved for future use
  • 66. forensicinsight.org Page 66 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ โ€ข Entry ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์—ฐ์†์ ์ธ ์ง‘ํ•ฉ โ€ข Entry ๋ ˆ์ฝ”๋“œ ์•ˆ์— Data ๋ ˆ์ฝ”๋“œ๋“ค์ด ์—ฐ์†์ ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Œ โ€ข ํŠน์ • Data ๋ ˆ์ฝ”๋“œ(EX: HTTP Data ๋ ˆ์ฝ”๋“œ) ๋“ค์€ Sub Data ๋ ˆ์ฝ”๋“œ๋“ค์„ ํฌํ•จํ•จ Generic Binary Format
  • 67. forensicinsight.org Page 67 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ - Generic Binary Format - Cache ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„
  • 68. forensicinsight.org Page 68 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ Cache ์ •๋ณด ๋ถ„์„(์™ธ๋ถ€ ์ €์žฅ) ํ—ค๋” Entry ๋ ˆ์ฝ”๋“œ Data ๋ ˆ์ฝ”๋“œ Entry Tag_ID Entry ๊ธธ์ด Data Tag_ID Data ๊ธธ์ด Sub_Data Tag_ID Sub_Data ๊ธธ์ด Boolean Flag Sub_Data ๋ ˆ์ฝ”๋“œ Data
  • 69. forensicinsight.org Page 69 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ โ€ข ๋ฐ์ดํ„ฐ Tag_ID๊ฐ€ 0x50์ธ ๋ ˆ์ฝ”๋“œ๋Š” ๋ฐ์ดํ„ฐ๋กœ ์‹ค์ œ ์บ์‹œ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•จ โ€ข ๋ฐ์ดํ„ฐ Tag_ID๊ฐ€ 0X0D์ธ ๋ ˆ์ฝ”๋“œ๋Š” ๋ฐ์ดํ„ฐ๋กœ โ€˜์บ์‹œ ๋ฐ์ดํ„ฐ๊ฐ€ ์ €์žฅ ๋œ ํŒŒ์ผ ๊ฒฝ๋กœ๋ช…โ€™ ์„ ์ €์žฅํ•จ โ€ข ๋‘ ๋ ˆ์ฝ”๋“œ ์ค‘ ํ•˜๋‚˜๋งŒ Entry ๋ ˆ์ฝ”๋“œ์— ์กด์žฌ Cache ์ •๋ณด ๋ถ„์„ (๋‚ด๋ถ€ ์ €์žฅ)
  • 70. forensicinsight.org Page 70 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ - Generic Binary Format - Cache ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„
  • 71. forensicinsight.org Page 71 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ Download ์ •๋ณด ๋ถ„์„( ํ—ค๋” Entry ๋ ˆ์ฝ”๋“œ Data ๋ ˆ์ฝ”๋“œ Entry Tag_ID Entry ๊ธธ์ด Data Tag_ID Data ๊ธธ์ด Sub_Data Tag_ID Sub_Data ๊ธธ์ด Boolean Flag Sub_Data ๋ ˆ์ฝ”๋“œ Data
  • 72. forensicinsight.org Page 72 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ - Generic Binary Format - Cache ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„
  • 73. forensicinsight.org Page 73 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ โ€ข Entry ๋ ˆ์ฝ”๋“œ๋“ค์˜ ์—ฐ์†์ ์ธ ์ง‘ํ•ฉ ๏ƒผ Entry ๋ ˆ์ฝ”๋“œ ๋ถ„๋ฅ˜ โ€ข Domain Component : Tag ID 0x01 ยป 1/2/3๋‹จ๊ณ„๋กœ ๋ถ„๋ฅ˜๋จ(ex: www.opera.com ๏ƒจ com:1๋‹จ๊ณ„, opera:2๋‹จ๊ณ„, www:1๋‹จ๊ณ„) ยป IP๋กœ๋งŒ ์ด๋ฃจ์–ด์ง„ Domian์ผ ๊ฒฝ์šฐ 1๋‹จ๊ณ„ Domain์œผ๋กœ๋งŒ ๊ตฌ์„ฑ๋จ(ex: 211.239.167.20) ยป ๊ทธ ์™ธ ๋„๋ฉ”์ธ๋“ค์€ 1~2๋‹จ๊ณ„ ํ˜น์€ 1~3๋‹จ๊ณ„๋กœ ๊ตฌ์„ฑ๋จ โ€ข Path Component : Tag ID 0x02, ์กด์žฌ ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๋„ ์žˆ์Œ โ€ข Cookie Component : Tag ID 0x03 ๏ƒผ ๊ตฌ์„ฑ ์˜ˆ : www.opera.com/verify ["com" Domain component] // 1 ๋‹จ๊ณ„ Domain component ["opera" Domain component] // 2 ๋‹จ๊ณ„ Domain component ["www" Domain component] // 3 ๋‹จ๊ณ„ Domain component [โ€œverifyโ€ Path component] [Cookie component] [Path component terminator] [end of domain flag ("www")] [end of domain flag ("opera")] [end of domain flag ("com")] Cookie ์ •๋ณด ๋ถ„์„
  • 74. forensicinsight.org Page 74 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๊ธฐ๋ณธ ๊ตฌ์„ฑ(๊ณ„์†) โ€ข Cookie Component ์•ˆ์— Data ๋ ˆ์ฝ”๋“œ๋“ค์ด ์—ฐ์†์ ์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ์Œ โ€ข 1๋‹จ๊ณ„ Domain Component ์•„๋ž˜ ์—ฌ๋Ÿฌ ๊ฐœ์˜ 2๋‹จ๊ณ„ Domain Component ๊ฐ€ ์˜ฌ ์ˆ˜ ์žˆ์Œ โ€ข 2๋‹จ๊ณ„ Domain Component ์•„๋ž˜ ์—ฌ๋Ÿฌ ๊ฐœ์˜ 3๋‹จ๊ณ„ Domain Component ๊ฐ€ ์˜ฌ ์ˆ˜ ์žˆ์Œ โ€ข Path Component ๋Š” 1/2/3๋‹จ๊ณ„ Domain Component ์ค‘ ์–ด๋Š Component ์•„๋ž˜์—๋„ ์˜ฌ ์ˆ˜ ์žˆ ์Œ โ€ข 1/2/3๋‹จ๊ณ„ Domain Component ์™€ Path Component ๊ฐ€ ๊ฒฐํ•ฉ๋˜์–ด host ์ด๋ฆ„ ์ •๋ณด๋ฅผ ์ด๋ฃจ๋ฉฐ ๊ทธ ์•„๋ž˜์— ์žˆ๋Š” Cookie ์ •๋ณด๋“ค์€ ๋™์ผํ•œ host ์ด๋ฆ„์„ ๊ฐ€์ง Cookie ์ •๋ณด ๋ถ„์„
  • 75. forensicinsight.org Page 75 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Tag_ID ์ •๋ณด โ€ข Entry Tag_ID โ€ข ๋ฐ์ดํ„ฐ Tag_ID Cookie ์ •๋ณด ๋ถ„์„ Tag id Component 0x01 Domain Component 0x02 Path Component 0x03 Cookie Component Tag ID Contents Meaning 0x1E string Domain ์ •๋ณด 0x1D string Path ์ •๋ณด 0x10 string ์ฟ ํ‚ค ์ด๋ฆ„ 0x11 string ์ฟ ํ‚ค ๊ฐ’ 0x12 time_t ๋งŒ๋ฃŒ ์‹œ๊ฐ„ 0x13 time_t ๋งˆ์ง€๋ง‰ ์ ‘๊ทผ ์‹œ๊ฐ„ 0x28 ? ?
  • 76. forensicinsight.org Page 76 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง Tag_ID ์ •๋ณด(๊ณ„์†) โ€ข Component Terminator Cookie ์ •๋ณด ๋ถ„์„ Tag id Terminator 0x84 Domain Component Terminator 0x85 Path Component Terminator
  • 77. forensicinsight.org Page 77 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ Cookie ์ •๋ณด ๋ถ„์„(cookies4.dat ํŒŒ์ผ ๋ถ„์„) 01 Domain Component Component ๊ธธ์ด 85 Data Tag_ID Data ๊ธธ์ด Path Component Terminator Boolean Flag Data 84 Domain Component Terminator 02 Path Component 03 Cookie Component
  • 78. forensicinsight.org Page 78 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ - Generic Binary Format - Cache ์ •๋ณด ๋ถ„์„ - Download ์ •๋ณด ๋ถ„์„ - Cookie ์ •๋ณด ๋ถ„์„ - History ์ •๋ณด ๋ถ„์„
  • 79. forensicinsight.org Page 79 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ ๏‚ง ๊ธฐ๋ณธ๊ตฌ์„ฑ โ€ข ํ—ค๋” ํŒŒ์ผ ์—†์Œ โ€ข ๋ ˆ์ฝ”๋“œ๋กœ๋งŒ ๊ตฌ์„ฑ โ€ข ๋ ˆ์ฝ”๋“œ ๊ตฌ์„ฑ ๏ƒผ Title : UTF-8 ์ธ์ฝ”๋”ฉ ๏ƒผ URL : ASCII ๏ƒผ ๋ฐฉ๋ฌธ์‹œ๊ฐ„ : 1970๋…„ 1์›” 1์ผ 00:00:00 ๋ถ€ํ„ฐ ์ง€๊ธˆ๊นŒ์ง€์˜ ๊ฒฝ๊ณผ๋œ ์ดˆ( time_t ) ๏ƒผ ๋ ˆ์ฝ”๋“œ end signature : -1( 2D 31 ) ๏ƒผ ๊ตฌ๋ถ„์ž : 0x0A History ์ •๋ณด ๋ถ„์„
  • 80. forensicinsight.org Page 80 / 88 Opera ๋กœ๊ทธ ๋ถ„์„ History ์ •๋ณด ๋ถ„์„(global_history.dat ํŒŒ์ผ ๋ถ„์„) Title URL ๋ฐฉ๋ฌธ์‹œ๊ฐ„ End Signature ๊ตฌ๋ถ„์ž
  • 81. forensicinsight.org Page 81 / 88 ๋ถ„์„ ๋„๊ตฌ - Firefox ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ - Chrome ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ - Safari ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ - Opera ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ - WEFA
  • 82. forensicinsight.org Page 82 / 88 ๋ถ„์„ ๋„๊ตฌ ๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html โ€ข MozillaCacheView : Cache ๋ถ„์„ โ€ข MozillaHistoryView : History ๋ถ„์„ โ€ข MozillaCookieView : Cookie ๋ถ„์„ โ€ข FirefoxDownloadsView : Download List ๋ถ„์„ Firefox ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
  • 83. forensicinsight.org Page 83 / 88 ๋ถ„์„ ๋„๊ตฌ ๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html โ€ข ChromeCacheView : Cache ๋ถ„์„ โ€ข ChromeHistoryView : History ๋ถ„์„ ๏‚ง ChromeForensics : http://www.woanware.co.uk/?page_id=70 โ€ข History, Cookie, Download List ๋ถ„์„ (์ถ”๊ฐ€์ ์œผ๋กœ ์ž๋™์™„์„ฑ, Favicons, Thumbnails) Chrome ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
  • 84. forensicinsight.org Page 84 / 88 ๋ถ„์„ ๋„๊ตฌ ๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html โ€ข SafariCacheView : Cache ๋ถ„์„ โ€ข SafariHistoryView : History ๋ถ„์„ Safari ๋กœ๊ทธ ๋ถ„์„ ๋„๊ตฌ
  • 85. forensicinsight.org Page 85 / 88 ๋ถ„์„ ๋„๊ตฌ ๏‚ง Nirsoft : http://www.nirsoft.net/web_browser_tools.html โ€ข OperaCacheView : Cache ๋ถ„์„ Opera ๋ถ„์„ ๋„๊ตฌ
  • 86. forensicinsight.org Page 86 / 88 ๋ถ„์„๋„๊ตฌ ๏‚ง ์ง€์› ๋ธŒ๋ผ์šฐ์ € : Internet Explorer, Firefox, Chrome, Safari, Opera ๏‚ง ๋ถ„์„ ๋Œ€์ƒ ์ •๋ณด โ€ข Cache โ€ข History โ€ข Cookie(Safari 5.1 Cookie ์ œ์™ธ) โ€ข Download List ๏‚ง Freeware Download ๏ƒจ http://www.4n6tech.com/skin_kr/images/WEFA_v1.2_-_Freeware.zip WEFA(Web Browser Forensic Analyzer
  • 87. forensicinsight.org Page 87 / 88 ๊ฒฐ ๋ก  ๏‚ง ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ํŒŒ์ผ ๊ตฌ์กฐ ๋ถ„์„์˜ ํ•„์š”์„ฑ? โ€ข ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ์ •๋ณด ๋ถ„์„์˜ ๊ธฐ๋ณธ ๋ฐฐ๊ฒฝ ์ง€์‹ ๏ƒจ ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์ง์ ‘ ์ˆ˜๋™ ๋ถ„์„์ด ๊ฐ€๋Šฅ โ€ข ๋‚จ์ด ๋งŒ๋“  ๋ถ„์„ ๋„๊ตฌ๋Š” ๋ชป ๋ฏฟ๊ฒ ๋‹ค!!! or ํ•ด๋‹น ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•ด ์ฃผ๋Š” ๋„๊ตฌ๊ฐ€ ์—†์„ ๋•Œ ๏ƒจ ๋กœ๊ทธ ํŒŒ์ผ ์ง€์‹์„ ํ†ตํ•ด ์ง์ ‘ ํŒŒ์‹ฑ ๋„๊ตฌ ๊ฐœ๋ฐœ โ€ข ๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ์ž˜ ํŒŒ์‹ฑํ•˜์ง€ ๋ชปํ•œ๋‹ค๋ฉด? ๏ƒจ ์›น ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ ํฌ๋ฉง์€ ๋ฒ„์ „์—…์„ ํ•˜๋ฉด์„œ ์กฐ๊ธˆ์”ฉ ๋ฐ”๋€Œ๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ ๏ƒจ ๊ตฌ๊ธ€๋ง์„ ํ†ตํ•ด ์ƒˆ๋กœ์šด ๋ฒ„์ „์˜ ํฌ๋ฉง ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ or ๊ธฐ์กด ํฌ๋ฉง์„ ํ† ๋Œ€๋กœ ์ง์ ‘ ๋ถ„์„ํ•ด ๋ณผ ํ•„ ์š”์„ฑ์ด ์žˆ์Œ ๏‚ง ๋กœ๊ทธ ํŒŒ์ผ ๋ถ„์„ํ•  ๋•Œ, ์œ ์˜ ์‚ฌํ•ญ~!! โ€ข ๊ฐ ๋ธŒ๋ผ์šฐ์ € ๋ณ„ ์„œ๋กœ ๋‹ค๋ฅธ ์‹œ๊ฐ„ ํฌ๋ฉง์„ ๊ฐ€์ง ๏ƒผ ๊ฐ ์‹œ๊ฐ„ ํฌ๋ฉง์— ๋งž์ถ”์–ด์„œ ๊ณ„์‚ฐํ•  ํ•„์š”์„ฑ์ด ์žˆ์Œ ๏ƒผ ํ•ด๋‹น ์‹œ๊ฐ„ ์ •๋ณด๊ฐ€ GMT ์ธ์ง€ ๋กœ์ปฌ ํƒ€์ž„์ธ์ง€ ๊ตฌ๋ถ„ ํ•„์š” โ€ข ์ธ์ฝ”๋”ฉ๋œ ์ •๋ณด ๏ƒผ ๋‹ค๊ตญ์–ด์˜ ๊ฒฝ์šฐ, URL ์ธ์ฝ”๋”ฉ๋˜์–ด ๊ทธ๋Œ€๋กœ ์ €์žฅ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ ๏ƒจ ์ธ์ฝ”๋”ฉ ๋ฐฉ์‹์— ๋”ฐ๋ฅธ ๋””์ฝ”๋”ฉ ๏ƒผ ๋ณดํ†ต์€ ๊ฑฐ์˜ ๋Œ€๋ถ€๋ถ„ UTF-8 ์ธ์ฝ”๋”ฉ, ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์œ ๋‹ˆ์ฝ”๋“œ ์ธ์ฝ”๋”ฉ ํ˜น์€ ์ฝ”๋“œํŽ˜์ด์ง€ ์ธ์ฝ”๋”ฉ
  • 88. forensicinsight.org Page 88 / 88 ์งˆ๋ฌธ ๋ฐ ๋‹ต๋ณ€