<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISSP Fix &#187; forensic</title>
	<atom:link href="http://cisspfix.com/tag/forensic/feed" rel="self" type="application/rss+xml" />
	<link>http://cisspfix.com</link>
	<description>Here you can find every bit of information in an interactive way. Enjoy while learning, this will bring best out of you.</description>
	<lastBuildDate>Sat, 10 Dec 2011 05:07:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Wireshark&#8211;come shallow</title>
		<link>http://cisspfix.com/wireshark-come-shallow.html</link>
		<comments>http://cisspfix.com/wireshark-come-shallow.html#comments</comments>
		<pubDate>Thu, 12 Nov 2009 04:23:05 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[packet analyzer]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=89</guid>
		<description><![CDATA[Wireshark is an open source protocol analyzer that can capture traffic in real time. Wireshark is a free packet sniffer computer application. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar &#8230; <a href="http://cisspfix.com/wireshark-come-shallow.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fwireshark-come-shallow.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fwireshark-come-shallow.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Wireshark is an open source protocol analyzer that can capture traffic in real time. Wireshark is a free packet sniffer computer application. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but it has a graphical front-end, and many more information sorting and filtering options. It allows the user to see all traffic being passed over the network (usually an Ethernet network but support is being added for others) by putting the network interface into promiscuous mode.</p>
<p>Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by pcap. It has the following features:</p>
<ul>
<li>Data can be captured &#8220;from the wire&#8221; from a live network connection or read from a file that records the already-captured packets. </li>
<li>Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback. </li>
<li>Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility, tshark. </li>
<li>Captured files can be programmatically edited or converted via command-line switches to the &#8220;editcap&#8221; program. </li>
<li>Data display can be refined using a display filter. </li>
<li>Plugins can be created for dissecting new protocols.<br />
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fwireshark-come-shallow.html&amp;title=Wireshark%26%238211%3Bcome%20shallow"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/wireshark-come-shallow.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computer Investigation Process&#8230;</title>
		<link>http://cisspfix.com/computer-investigation-process.html</link>
		<comments>http://cisspfix.com/computer-investigation-process.html#comments</comments>
		<pubDate>Fri, 18 Sep 2009 04:34:04 +0000</pubDate>
		<dc:creator>cisspfix</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[CISSP]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[investigation]]></category>

		<guid isPermaLink="false">http://cisspfix.com/?p=50</guid>
		<description><![CDATA[&#8220;Necessity is the Mother of all Inventions&#8221;, sophistication of digital environment lead to the discovery of Computer Forensics. Computer Forensics is an investigative process of collecting and examining of electronic evidence to form a structured report which can be produced &#8230; <a href="http://cisspfix.com/computer-investigation-process.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcisspfix.com%2Fcomputer-investigation-process.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcisspfix.com%2Fcomputer-investigation-process.html&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>&#8220;Necessity is the Mother of all Inventions&#8221;, sophistication of digital environment lead to the discovery of Computer Forensics. Computer Forensics is an investigative process of collecting and examining of electronic evidence to form a structured report which can be produced in a court as a evidence. Computer Forensic is introduced when crime is facilitated either by using computer or on Computer or Network itself. Computer Forensic also deals with the issue, such as Privacy, Copy Infringement, and Software ownership. For the collection of Electronic Evidence, it is required to follow certain pre-established procedure and steps, which ensures the identity of culprit. By following such methodologies, computer crime investigation can be done effectively and efficiently. </p>
<p><strong>Investigating Computer Crimes</strong></p>
<p>If any forensic investigation involves Computer in one way or another, then the investigation is coined as Computer Forensic Investigation. Development of technology from the last two decades is so rapid that it made lot easier for criminals to hide information about their crimes, one advantage enjoyed by investigators is that any type of Computer Crime results in some type of clue and evidence stored on computer but still there are number of Cyber Crimes which requires Computer Forensic investigation, some of them are:</p>
<ul>
<li>Unauthorized access</li>
<li>Property Theft (misuse of information) </li>
<li>Forgery</li>
<li>Privacy breach </li>
<li>Computer fraud.</li>
<li>Child pornography</li>
</ul>
<p><strong>Methodology of Forensic Investigation </strong><br />
First and Foremost step of Investigation process is Complaint. Investigation will never going to occur if it remain un-noticed, unless appropriate authorities are not aware of the crime being committed, criminal gets away with crime. There are some fundamental steps involved in forensic investigation, </p>
<p><strong>Preparation (of the investigator, not the data)</strong></p>
<p>Computer Forensic Investigators must be prepared with the tools and procedures used during investigation, these tools include Hardware as well as Software which are used to secure evidence and data.</p>
<p><strong>Collection (the data) </strong></p>
<p>Next important step is to collect damaged data as efficiently as possible, damaged data typically includes deleted files, formatted hard disk, deleted partitions or any other form of electronic storage medium like compact disk, USB drives etc. Special care must be taken when handling computer evidence: most digital information is easily changed, and once changed it is usually impossible to detect that a change has taken place (or to revert the data back to its original state) unless other measures have been taken.</p>
<p><strong>Analysis </strong></p>
<p>This step involves proper examination and evaluation of gathered information. During analysis it is very important that the collected data and information aren&#8217;t modified in any way, otherwise property of data will change. Therefore it is very necessary to use tools that won&#8217;t modify data. Chiefly Forensic Analysis consists of manual review of material on the media, reviewing the Windows registry for suspect information, discovering and cracking passwords, keyword searches for topics related to the crime, and extracting e-mail and images for review.</p>
<p><strong>Reporting </strong></p>
<p>After the completion of Analysis, a detailed report is generated enlisting all possible evidences and information. This Report is produced as a legal evidence before court whenever required.</p>
<p><strong>The Role of Evidence </strong></p>
<p>Collection of Evidence is the sole reason behind the Forensic Investigation; therefore Evidence plays a vital role in Computer Forensic Investigation. The Digital Evidence should be properly studied, preserved and presented. These Evidences are presented in court during legal process and questioning. Collection of Evidence is done in several steps, first of which is Identification of Evidence followed by the Recovery of Evidence, this is accomplished viewing log files, recovering data using different forensic tools. One more important point which should be kept in mind during Investigation is security of Data, Digital Evidence and Data must be secured throughout the investigation.</p>
<p><strong>Volatile Evidence </strong></p>
<p>Data stored in temporary storage media [Random Access Memory(RAM), Cache Memory, Onboard memory of different peripherals like Graphics and video card etc ) are termed as Volatile Memory because data stored in it depends on the electricity for their existence, as soon as the system is powered off, stored data will be permanently vanished. It is therefore very important to collect such data first. </p>
<p><strong>Acquiring Evidence </strong></p>
<p>This is the next step of processing evidence. Acquisition process involves in making exact copy of digital evidence. It is very important that the original data isn&#8217;t altered, damaged or destroyed in doing so. </p>
<p><strong>Disk Imaging</strong></p>
<p>This technique is used to preserve the original evidence as it was seized. Disk imaging is different from back up of a disk in a way that while creating backup, only active files of a system are copied. Whereas during disk imaging exact replica of original disk is formed. </p>
<p><strong>Retaining Data and Timestamp:</strong> </p>
<p>Retaining the Date and Time of creation and modification of Data is a vital factor to be kept in mind in criminal issues. Timestamp in a file are very important evidence, since the timestamp is according to the system clock which is in turn depends on the time zone. It should always investigated that which time zone is configured on the system, it may be possible that criminal deliberately change the time zone so that the data does not co-relate with the real time.</p>
<p><strong>Investigating Company Policy Violations</strong> </p>
<p>Investigation Process of Companies are totally different from the other types of Investigations. Normally when Cyber crime occurs on house computers, police are called for proper investigation. In a Corporate World a team of some specialized skilled peoples are formed which is known as Incident Response Team. This team is responsible for finding the type of Cyber crime occurred and eventually contact police for further investigation, depending upon the type of crime occurred and what is found in investigation. This Incident Response Team also deal with the internal matter of the company like security breach by company employee, unauthorized access to company&#8217;s computer etc. It is not always necessary to include police investigation when policies are violated, sometime it is dealt by company itself by taking disciplinary action against the accused employee. But still Forensic Investigations is important because these procedures create a tighter case, thus leaving no point to argue the facts. </p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fcisspfix.com%2Fcomputer-investigation-process.html&amp;title=Computer%20Investigation%20Process%26%238230%3B"><img src="http://cisspfix.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://cisspfix.com/computer-investigation-process.html/feed</wfw:commentRss>
		<slash:comments>30</slash:comments>
		</item>
	</channel>
</rss>

