FOCA 2.5.5Chema Alonso
What’s a FOCA?
FOCA on Linux?
FOCA + Wine
Previously on FOCA….
FOCA 0.X
A documentisWhatyousee…And whatyoudon´tTemplatepathsUsersworked in it.Departments.File & Printing ServersVersionHistoryEmbedded files…
What kind of data can be found?Metadata:Information stored to give information about the document.For example: Creator, Organization, etc..Hidden information:Information internally stored by programs and not editable.For example: Template paths, Printers, db structure, etc…Lost data:Information which is in documents due to human mistakes or negligence, because it was not intended to be there.For example: Links to internal servers, data hidden by format, etc…
MetadataMetadata LifecycleWrongmanagementBadformatconversionUnsecureoptionsWrongmanagementBadformatconversionUnsecureoptionsNew appsorprogramversionsSearchenginesSpidersDatabasesEmbeddedfilesHiddeninfoLost DataEmbeddedfiles
MetadataRisks“Secret” relationshipsGovernment & companiesCompanies & providersPiracy discoveryReputationSocial engineering attacksTargeting Malware
2003 – MS Word bytes Tony Blair
Targeting Malware
Targeting Malware
Electing the entry point
Why you should be using FS
Linux installation guide
Social Engineering Attack
Metadatacreatedby Google
Lost Data
Lost data everywhere
Metadata in SearchEngines
Pictureswith GPS info..EXIFREADERhttp://www.takenet.or.jp/~ryuuji/
Even Videos withusers…http://video.techrepublic.com.com/2422-14075_11-207247.html
And of course, printedtxt
OLE StreamsIn MS Office binaryformat filesStoreinformationaboutthe OSAre notcleanedwiththese ToolsFOCA findsthisinfo
FOCA: File types supportedOffice documents:
Open Office documents.
MS Office documents.
PDF Documents.
XMP.
EPS Documents.
Graphic documents.
EXIFF.
XMP.
Adobe Indesign, SVG, SVGZ (NEW)What can be found? Users:
Creators.
Modifiers .
Users in paths.
C:\Documents and settings\jfoo\myfile
/home/johnnyf
Operating systems.
Printers.
Local and remote.
Paths.
Local and remote.
Network info.
Shared Printers.
Shared Folders.
ACLS.
Internal Servers.
NetBIOS Name.
Domain Name.
IP Address.
Database structures.
Table names.
Colum names.
Devices info.
Mobiles.
Photo cameras.
Private Info.
Personal data.
History of use.
Software versions.Demo:Single files
Sample: FBI.govTotal:  4841 files
Are theycleaned?
FOCA 1 v. RC3Fingerprinting  Organizations with Collected Archives
Search for documents in Google and Bing
Automatic file downloading
Capable of extracting Metadata, hidden info and lost data
Cluster information
Analyzes the info to fingerprint the network.Metadata tracing
AlternativeDomains
AlternativeDomains
Sample: Printer info found in odf files returned by Google
Types of Engineers
DNS Prediction
Google Sets Prediction
IP Scanning
Manually-added Data
Demo:Mda.mil
What’s new in FOCA 2.5?Network Discovery
Recursivealgorithm

FOCA 2.5.5 Training