SlideShare a Scribd company logo
1 of 15
Download to read offline
Resurse Open Source în
  Computer Forensic
       18 Mai 2007
   Cezar Spatariu Neagu
Agendă
Cine sînt eu?
Ce este Computer Forensic?
De ce Computer Forensic cu ajutorul tool-
urilor Open Source?
Distribu ii, tool-uri şi resurse.
Implica ii legale.
Întrebări, răspunsuri, discu ii.
Ce este computer forensic?

Computer forensic is application of the scientific
  methods to digital media in order to establish
    factual information for juridical review.
Fapte penale:
– Îndreptate împotriva unui calculator.
– Unde calculatorul con ine probe.
– Unde calculatorul este instrument în comiterea
  infrac iunii.
De ce computer forensic?

Cine sînt tipii răi?
Ce s-a intîmplat şi cînd?
De ce s-a intîmplat?
Ce putem face să nu se mai întîmple?
De ce open source ?
One of the questions I hear most often is: “why should I use Linux when I
  already have [insert Windows GUI forensic tool here]?” There are
  many reasons why Linux is quickly gaining ground as a forensic
  platform. I’m hoping this document will illustrate some of those
  attributes.
       · Control – not just over your forensic software, but
   the whole OS and attached hardware.
       · Flexibility – boot from a CD (to a complete OS),
   file system support, platform support, etc.
       · Power – A Linux distribution is a forensic tool.
“The Law Enforcement and Forensic Examiner's Introduction to Linux A Beginner's Guide” NASA
Computer Forensic înseamnă:
Prelevarea datelor.
Analiza probelor.
Documentarea
întregului proces.
Probleme
  ‚To pull or not the cable?‘. This is the question.


  Offline Forensic
  Online Forensic
  – Root-kit-uri, criptoviruşi, malware (memory
    resident),
  – Medii criptate.
  – Sisteme ce nu pot fi oprite.
Starea sistemului este modificată.DOCUMENTEAZĂ!
Proprietă i
O distribu ie (LiveCD) poate fi folosită dacă:
– NU modifică sistemul de unde se
  prelevează.TESTEAZĂ!(vezi Knoppix)
– Suportă un spectru larg de controlere.
– Oferă programe (shell-uri şi binaries) pentru
  prelevare de probe online.
– Oferă sisteme de logging pentru documentarea
  procesului de forensic.
Tool pentru prelevare
nc, hdparm, fdisk, mmls, lshw, cat /proc/…
dd if=/dev/victimaHDD_MEM of=/media/caseNr.dd
dclfdd if=/dev/victimaHDD_MEM of=/media/caseNr
hash=sha1sum hashlog=/media/CaseNr/image.hash
sha1sum ori md5sum?
aimage (AFT Tools)
  linen ( EnCase Image Acquisition Tool )
Tool-uri pentru analiză
file, strings, scalpel,foremost (reconstituie
fisiere)
Autopsy (integrare cu NSRL), PyFLAG (case
management)
Sleuthkit ,Faust (analiza binary si shell script-uri)
Antivirus (ClamAV. F-Prot)
Rootkit detector (chkrootkit, rkhunter)
Stego (Outguess, Stegdetect )
libewf Expert Witness Library - Encase
Windows World
Regviewer – Registry Viewer
– (share-uri accesate, device-uri conectate, timeline,
  useri)
GroKEVT – analiza Windows Event View
Rifiuti – analiza Recycle BIN
fcrackzip
Internet Explorer
     pasco index.dat
     galleta cookie
Firefox
     mork.pl
Live CD-uri
   HELIX (http://www.e-fense.com/helix/)
    – Windows, Linux, (Solaris ) online forensic
    – Live CD
   FCCU GNU/Linux Forensic Boot CD
    – Live si analiza CD
   DEFT (http://www.stevelab.net/deft/)
   ASRData (http://www.asrdata.com)
Şi nu uita- i de optiunea „noswap“ în grub!!
Implica ii Legale
Orice caz trebuie tratat corespunzător.
Legisla ie ??? (Ministerul de Justi ie, Interne)
Competen a examinatorului (certificări)
– SANS
– International Association of Computer Investigative
  Specialists (IACIS)
– The International Society of Forensic Computer
  Examiners - ISFCE
– etc.
Resurse
Documenta ii şi proiecte
   –   Open Sourse Digital Forensic  http://www.opensourceforensics.org
   –   Honeynet Project                       http://www.honeynet.org
   –   ForensicWiki                           http://www.forensicswiki.org
   –   Computer Forensics Tool Testing        http://www.cftt.nist.gov/



Live CD-uri
   – Helix                             http://www.e-fense.com/helix
   – FCCU                              http://www.lnx4n6.be/
Informa ii
  Prezentare va fi disponibilă pe site-ul:
 – http://eliberatica.ro
 – http://securityaspects.wordpress.com
  Contact
  cezar (.) spatariu (at) gmail (.)com
  Şi nu uita i:
Not all „BAD GUYS“ are from ROMANIA☺

More Related Content

More from eLiberatica

"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...
"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe..."Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...
"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...eLiberatica
 
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008eLiberatica
 
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL..."Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...eLiberatica
 
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008eLiberatica
 
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008eLiberatica
 
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008eLiberatica
 
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic..."HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...eLiberatica
 
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott..."Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...eLiberatica
 
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"...
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"..."Open Source Software Middleware for The Internet of Things - Project ASPIRE"...
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"...eLiberatica
 
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008eLiberatica
 
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati..."Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...eLiberatica
 
"For the first time in Europe Digital ID providers and OpenID service for Rom...
"For the first time in Europe Digital ID providers and OpenID service for Rom..."For the first time in Europe Digital ID providers and OpenID service for Rom...
"For the first time in Europe Digital ID providers and OpenID service for Rom...eLiberatica
 
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008eLiberatica
 
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e..."Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...eLiberatica
 
"OSS in Public Administrations - A short Report from the European Level" by B...
"OSS in Public Administrations - A short Report from the European Level" by B..."OSS in Public Administrations - A short Report from the European Level" by B...
"OSS in Public Administrations - A short Report from the European Level" by B...eLiberatica
 
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008eLiberatica
 
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera..."The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...eLiberatica
 
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008eLiberatica
 
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008eLiberatica
 
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe..."The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...eLiberatica
 

More from eLiberatica (20)

"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...
"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe..."Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...
"Understanding Free Software and Open Source Licensing" by Zak Greant @ eLibe...
 
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008
"Sun Open Source Universe" by Vassilis Boulogiorgos @ eLiberatica 2008
 
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL..."Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...
"Komodo - Why we chose to make our product open source" by Shane Caraveo @ eL...
 
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008
"Dell and Open Source" by Serban Zirnovan @ eLiberatica 2008
 
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008
"SocrateOpen after two years" by Remus Cazacu @ eLiberatica 2008
 
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008
"Introducing Red Hat Training Center" by Radu Radulescu @ eLiberatica 2008
 
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic..."HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...
"HP vision Governing the use of open source" by Martin Michlmayr @ eLiberatic...
 
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott..."Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...
"Write the Future Open Standards Open Source OpenOffice" by Louis Suarez-Pott...
 
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"...
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"..."Open Source Software Middleware for The Internet of Things - Project ASPIRE"...
"Open Source Software Middleware for The Internet of Things - Project ASPIRE"...
 
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008
"Introducing eConference" by Eugen Rotariu @ eLiberatica 2008
 
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati..."Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...
"Mozilla Messaging and Thunderbird - why and how" by David Ascher @ eLiberati...
 
"For the first time in Europe Digital ID providers and OpenID service for Rom...
"For the first time in Europe Digital ID providers and OpenID service for Rom..."For the first time in Europe Digital ID providers and OpenID service for Rom...
"For the first time in Europe Digital ID providers and OpenID service for Rom...
 
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
"Standing on the Shoulders of Giants" by Brian King @ eLiberatica 2008
 
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e..."Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...
"Legal aspects related to a FLOSS based model business" by Bogdan Manolea @ e...
 
"OSS in Public Administrations - A short Report from the European Level" by B...
"OSS in Public Administrations - A short Report from the European Level" by B..."OSS in Public Administrations - A short Report from the European Level" by B...
"OSS in Public Administrations - A short Report from the European Level" by B...
 
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008
"BitDefender - What's Next" by Alexandru Balan @ eLiberatica 2008
 
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera..."The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...
"The Future of Enterprise Content Management" by Aleksander Farstad @ eLibera...
 
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008
"Integrating Open Source into Your Business" by Adam Jollans @ eLiberatica 2008
 
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008
"Open Source at Microsoft" by Zoli Herczeg @ eLiberatica 2008
 
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe..."The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...
"The Past Present and Future of the Mozilla Foundation" by Zak Greant @ eLibe...
 

"Open Source Resources Used in Computer Forensics" by Cezar Spatariu Neagu @ eLiberatica 2007

  • 1. Resurse Open Source în Computer Forensic 18 Mai 2007 Cezar Spatariu Neagu
  • 2. Agendă Cine sînt eu? Ce este Computer Forensic? De ce Computer Forensic cu ajutorul tool- urilor Open Source? Distribu ii, tool-uri şi resurse. Implica ii legale. Întrebări, răspunsuri, discu ii.
  • 3. Ce este computer forensic? Computer forensic is application of the scientific methods to digital media in order to establish factual information for juridical review. Fapte penale: – Îndreptate împotriva unui calculator. – Unde calculatorul con ine probe. – Unde calculatorul este instrument în comiterea infrac iunii.
  • 4. De ce computer forensic? Cine sînt tipii răi? Ce s-a intîmplat şi cînd? De ce s-a intîmplat? Ce putem face să nu se mai întîmple?
  • 5. De ce open source ? One of the questions I hear most often is: “why should I use Linux when I already have [insert Windows GUI forensic tool here]?” There are many reasons why Linux is quickly gaining ground as a forensic platform. I’m hoping this document will illustrate some of those attributes. · Control – not just over your forensic software, but the whole OS and attached hardware. · Flexibility – boot from a CD (to a complete OS), file system support, platform support, etc. · Power – A Linux distribution is a forensic tool. “The Law Enforcement and Forensic Examiner's Introduction to Linux A Beginner's Guide” NASA
  • 6. Computer Forensic înseamnă: Prelevarea datelor. Analiza probelor. Documentarea întregului proces.
  • 7. Probleme ‚To pull or not the cable?‘. This is the question. Offline Forensic Online Forensic – Root-kit-uri, criptoviruşi, malware (memory resident), – Medii criptate. – Sisteme ce nu pot fi oprite. Starea sistemului este modificată.DOCUMENTEAZĂ!
  • 8. Proprietă i O distribu ie (LiveCD) poate fi folosită dacă: – NU modifică sistemul de unde se prelevează.TESTEAZĂ!(vezi Knoppix) – Suportă un spectru larg de controlere. – Oferă programe (shell-uri şi binaries) pentru prelevare de probe online. – Oferă sisteme de logging pentru documentarea procesului de forensic.
  • 9. Tool pentru prelevare nc, hdparm, fdisk, mmls, lshw, cat /proc/… dd if=/dev/victimaHDD_MEM of=/media/caseNr.dd dclfdd if=/dev/victimaHDD_MEM of=/media/caseNr hash=sha1sum hashlog=/media/CaseNr/image.hash sha1sum ori md5sum? aimage (AFT Tools) linen ( EnCase Image Acquisition Tool )
  • 10. Tool-uri pentru analiză file, strings, scalpel,foremost (reconstituie fisiere) Autopsy (integrare cu NSRL), PyFLAG (case management) Sleuthkit ,Faust (analiza binary si shell script-uri) Antivirus (ClamAV. F-Prot) Rootkit detector (chkrootkit, rkhunter) Stego (Outguess, Stegdetect ) libewf Expert Witness Library - Encase
  • 11. Windows World Regviewer – Registry Viewer – (share-uri accesate, device-uri conectate, timeline, useri) GroKEVT – analiza Windows Event View Rifiuti – analiza Recycle BIN fcrackzip Internet Explorer pasco index.dat galleta cookie Firefox mork.pl
  • 12. Live CD-uri HELIX (http://www.e-fense.com/helix/) – Windows, Linux, (Solaris ) online forensic – Live CD FCCU GNU/Linux Forensic Boot CD – Live si analiza CD DEFT (http://www.stevelab.net/deft/) ASRData (http://www.asrdata.com) Şi nu uita- i de optiunea „noswap“ în grub!!
  • 13. Implica ii Legale Orice caz trebuie tratat corespunzător. Legisla ie ??? (Ministerul de Justi ie, Interne) Competen a examinatorului (certificări) – SANS – International Association of Computer Investigative Specialists (IACIS) – The International Society of Forensic Computer Examiners - ISFCE – etc.
  • 14. Resurse Documenta ii şi proiecte – Open Sourse Digital Forensic http://www.opensourceforensics.org – Honeynet Project http://www.honeynet.org – ForensicWiki http://www.forensicswiki.org – Computer Forensics Tool Testing http://www.cftt.nist.gov/ Live CD-uri – Helix http://www.e-fense.com/helix – FCCU http://www.lnx4n6.be/
  • 15. Informa ii Prezentare va fi disponibilă pe site-ul: – http://eliberatica.ro – http://securityaspects.wordpress.com Contact cezar (.) spatariu (at) gmail (.)com Şi nu uita i: Not all „BAD GUYS“ are from ROMANIA☺