<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-36666403</atom:id><lastBuildDate>Wed, 07 May 2008 15:34:41 +0000</lastBuildDate><title>Forensic Focus Blog</title><description /><link>http://forensicfocus.blogspot.com/</link><managingEditor>admin</managingEditor><generator>Blogger</generator><openSearch:totalResults>34</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://www.forensicfocus.com/blog/feed.php" type="application/rss+xml" /><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.rojo.com/add-subscription?resource=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://blog.rojo.com/RojoWideRed.gif">Subscribe with Rojo</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.bloglines.com/sub/http://www.forensicfocus.com/blog/feed.php" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://fusion.google.com/add?feedurl=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Fwww.forensicfocus.com%2Fblog%2Ffeed.php" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-164445143233416193</guid><pubDate>Tue, 06 May 2008 18:41:00 +0000</pubDate><atom:updated>2008-05-07T08:34:41.443-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Criminal Justice and Immigration Bill</category><title>UK Criminal Justice Bill - Clause 62 (or is it 63, or 64?)</title><description>Although it hasn't yet caused much of a public stir, Clause 62 in the UK Criminal Justice Bill certainly hasn't gone unnoticed in the forensics community (judging by the number of news submissions received at Forensic Focus). There's also plenty of debate at various general IT sites such as &lt;a href="http://www.theregister.co.uk/2008/04/25/justice_bill_extreme_pron/comments/"&gt;The Register&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So, what is the clause? Well, the entire Criminal Justice and Immigration Bill is covered in some detail &lt;a href="http://services.parliament.uk/bills/2007-08/criminaljusticeandimmigration.html"&gt;here&lt;/a&gt; but the relevant clause can be found &lt;a href="http://www.publications.parliament.uk/pa/ld200708/ldbills/051/08051.46-51.html#j400"&gt;here&lt;/a&gt; (and I apologise for the confusion over the numbering of the clause, I've seen it specified as variously 62, 63 and 64).&lt;br /&gt;&lt;br /&gt;In a nutshell, the clause seeks to shift criminal responsibility from the producer (as specified in the existing Obscene Publications Act, although this will remain in force) to the person who possesses the image(s) in question.&lt;br /&gt;&lt;br /&gt;The background to the Bill is a tragic one, involving the murder of Jane Longhurst five years ago at the hands of a man addicted to violent pornography. Liz Longhurst, Jane's mother, then began to campaign against such images and was supported by the Home Secretary at the time.&lt;br /&gt;&lt;br /&gt;The proposed new laws are, however, controversial with campaigners fighting against their introduction primarily citing concerns over the (lack of) evidence linking pornography with violence, the vagueness of the offence and the risk that a large number of people will be criminalised unfairly.&lt;br /&gt;&lt;br /&gt;Regardless of what we might think of the clause on a personal level, it's clear that its introduction will have consequences for some forensic examiners in the UK. Only time will tell what impact, if any, it has on violent sex crime.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=30XtE2"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=30XtE2" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=WYXC1H"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=WYXC1H" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=FMG8KH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=FMG8KH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=UvHLzh"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=UvHLzh" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=H4VfOH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=H4VfOH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=HVTufh"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=HVTufh" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=G4ihWH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=G4ihWH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=EIlM8H"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=EIlM8H" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=1q1OzH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=1q1OzH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=I3CJKH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=I3CJKH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=RBQmhH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=RBQmhH" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/05/uk-criminal-justice-bill-clause-62-or.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7601369980522028037</guid><pubDate>Thu, 01 May 2008 16:00:00 +0000</pubDate><atom:updated>2008-05-01T09:08:10.910-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics jobs</category><category domain="http://www.blogger.com/atom/ns#">David Sullivan</category><category domain="http://www.blogger.com/atom/ns#">Appointments-UK</category><title>Interview with David Sullivan, Appointments-UK</title><description>&lt;span style="font-weight: bold;"&gt;Forensic Focus: Can you tell us something about your background? How did Appointments-UK come into being?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: I’ve enjoyed over twelve years in recruitment, starting out in the city [London] specialising in IT within Investment Banking.&lt;br /&gt;&lt;br /&gt;The area that really interested me was Information Security, and after a successful period in this sector, I further refined my focus into computer forensics. Then, in 2003, I decided to take the plunge and set up Appointments-UK.&lt;br /&gt;&lt;br /&gt;My reasons were simple and remain the underlying vision for my company today: when contacting a recruiter you want them to demonstrate good market knowledge and a genuine understanding of the companies, personalities, trends, conditions and pressures that impact your sector. At Appointments-UK all our people offer this.&lt;br /&gt;&lt;br /&gt;It has been a tremendous challenge and I’m pleased that organic growth has enabled me to develop a team of specialist recruiters in related areas: however, my personal operational focus remains in the computer forensics/electronic discovery market.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Forensic Focus: You operate in a dynamic, changing market place; what are the main challenges you face and what are your strategies to tackle these?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: The single biggest challenge I face is identifying suitably talented and skilled candidates. Advertising on specialist sites such as Forensic Focus produces results, but the niche nature of this sector means using generalist job sites (Monster, Jobsite etc) offers limited success. Recommendation remains the cornerstone in identifying suitable talent; in fact, well over three-quarters of our placements are due to networking.&lt;br /&gt;&lt;br /&gt;After five years in this sector I have a fantastic network of key people – many of whom I now know both socially as well as professionally – and this makes my job much simpler! I can rely on this group to keep me updated with what is really going on and who may be open to making a move.&lt;br /&gt;&lt;br /&gt;Another challenge we face is managing expectations. There is much hype around computer forensics as a growth area suffering from a shortage of candidates. This often leads to unrealistic expectations – especially around salaries -which needs to be tackled.&lt;br /&gt;&lt;br /&gt;This is particularly common with people moving to the Private Sector from Law Enforcement/Public Sector organisations. With earnings between £35 and 40k they often ‘need’ to realise a package of around £65k to compensate the loss of other benefits. In the majority of cases this is unlikely, and, in reality, when they first move the pay increase is likely to be minimal. However, based on performance the strong performers will soon see substantial increases in both salary and bonuses. As a benchmark, when somebody changes jobs it is very rare to see a basic salary increase by more than 20%.&lt;br /&gt;&lt;br /&gt;We don’t make promises where we cannot deliver and I often tell prospective candidates that they are, in my opinion, unrealistic in their salary expectations. Although I don’t pretend to always get it right, more often than not we see these people again when, after searching the market, it is our honest and informed service that they really need – once more, back to the very essence of what we provide; an honest assessment of the opportunities available based on a real understanding of the market.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Forensic Focus: What do you think of the rising number of educational courses in computer forensics? Is there a genuine demand from employers for an increased number of students?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: I enjoy playing my part in raising awareness of the opportunities available by speaking annually at a number of Universities that run Computer Forensic courses. It is vital that we reach and develop relationships with tomorrows talent today.&lt;br /&gt;&lt;br /&gt;The standard of courses is certainly mixed but there are some outstanding, inspiring people running excellent courses and being incredibly innovative (particularly, in my experience, Vasilios Katos and Cheryl Hennell at Portsmouth University and Angus Marshall at Teeside University).&lt;br /&gt;&lt;br /&gt;However, it remains clear that there will not be positions in Forensics for all the graduates, which is why it is so vital for them to be thinking seriously about their careers from Year One, and what they can do to give them an edge. I try to emphasise to the students that it is not necessarily the brightest who get the plum jobs, but those who prepare and position themselves correctly.&lt;br /&gt;&lt;br /&gt;Graduate vacancies do exist and as a company we placed 14 computer forensic graduates in a variety of companies last year. It is also worth noting that salaries vary tremendously: in my experience in 2007 new graduate salaries varied from £16k - £34k, but in terms of long-term careers, I don’t think it is necessarily always correct to go for the highest salaried position as some of those organisations paying less offer outstanding training and exposure which can be very beneficial in the longer term.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Forensic Focus: How can people break into computer forensics and is it a ‘career’?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: Here on Forensic Focus lots of people who are currently working in IT related roles ask how to get into Computer Forensics and I get numerous calls asking the same question. I think it is a difficult area as it is not like becoming a Doctor where the career path is structured and you know what you need to do. My advice is usually that they need to personally contact every Computer Forensics Manager in the UK, be persistent, happen to be in the right place at the right time and get lucky. Oh yes, and be willing to take a pay cut.&lt;br /&gt;&lt;br /&gt;Once you are in Computer Forensics there are some outstanding opportunities and if you are good, you can reach Senior Manager level very quickly. In my experience, the one thing that distinguishes those people who reach the very top is purely their ability to build relationships and develop new business. Technical expertise is important, but in the end, to reach the highest levels, it comes down to the ability to enable an organisation to sell the service.&lt;br /&gt;&lt;br /&gt;However, I should add that I do appreciate that lots of outstanding Public Sector/Law Enforcement Computer Forensic Practitioners have no interest in following this path working for Private Sector organisations.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Forensic Focus: What changes have you seen in the computer forensics recruitment market over the past 5 years? What trends do you see in the future?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: Five years ago, nearly all recruitment was word of mouth between people working in the area and potential candidates I called had often never spoken to a recruiter before. Today, there are a number of specialist recruiters of varying quality operating in this market. There are some very good ones (such as Mark Woodward, who also advertises on this forum) but – and this is a general problem in recruitment - there are others who don’t provide such a high quality service, make false promises etc and this can make it harder for us to gain the trust of potential candidates.&lt;br /&gt;&lt;br /&gt;As the sector continues to expand and mature, I think we will continue to see an increase in the more general positions being filled by advertising on specialist forums like Forensic Focus and Digital Detective. Companies will do much of this recruitment directly rather than via recruiters (the adverts on Forensic Focus show this happening).&lt;br /&gt;&lt;br /&gt;However, for bulk recruiting, very specialist or senior roles, we will continue to see increased demand for pure headhunting and/or working exclusively with one Recruitment Company, which really has an understanding of the recruiting organisation. We have this relationship with some companies in the sector already and, it is not surprising, that we find the very best people for these organisations. As recruiters, if we can really get to know a company culture and work as a genuine Partner, it is so much easier to find the very best and most suitable people in the market, as opposed to currently on the market.&lt;br /&gt;&lt;br /&gt;The only Public Sector/Law Enforcement organisation we currently recruit for in this area is the Metropolitan Police. I would anticipate that more Public Sector organisations will realise the cost-savings they can make by using external recruiters.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Forensic Focus: What do you do to relax when you're not working?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;David Sullivan: I sail competitively, surf whenever I can and have developed a (healthy!) love of live poker.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;David Sullivan specialises in Computer Forensics recruitment at &lt;a href="http://www.appointments-uk.co.uk/"&gt;Appointments-UK&lt;/a&gt; and can be contacted at David @ appointments-uk.co.uk or on 01787 461082
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=oIidch"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=oIidch" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tOUozH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tOUozH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=d40rNH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=d40rNH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=w8dG3h"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=w8dG3h" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=M7069H"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=M7069H" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=VpYhQh"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=VpYhQh" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=m1jBtH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=m1jBtH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=nNzxDH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=nNzxDH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=haDFiH"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=haDFiH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=TExr8H"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=TExr8H" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZLwn2H"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZLwn2H" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/05/interview-with-david-sullivan.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3469809533043859401</guid><pubDate>Thu, 24 Apr 2008 11:18:00 +0000</pubDate><atom:updated>2008-04-24T04:39:26.198-07:00</atom:updated><title>Reporting (again) and interviews</title><description>Some very interesting opinions have been raised in the "&lt;span class="maintitle"&gt;&lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2443"&gt;Reporting - time for standardization?&lt;/a&gt;" thread and I'd like to give people some more time to add their own thoughts before moving the discussion on. It's a somewhat more emotive topic than I might have expected but that's no bad thing, I suppose!&lt;br /&gt;&lt;br /&gt;On another matter entirely, I've got a couple of good interviews lined up for publication shortly but again I'd like to encourage more suggestions for interviewees. Input from experienced professionals is always welcome but I also think it's useful to talk to those new to the profession - &lt;/span&gt;&lt;span class="maintitle"&gt;and yes, you can suggest yourself.&lt;br /&gt;&lt;br /&gt;Well, it's lunchtime and a beautiful day outside so time to drag myself away from the computer. Bye for now!&lt;br /&gt;&lt;/span&gt;
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=Y7zEq5"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=Y7zEq5" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5FqrJCG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5FqrJCG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=GG6UgNG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=GG6UgNG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=eWOFeXg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=eWOFeXg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZpDA69G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZpDA69G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ANqJRvg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ANqJRvg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=1WxP4eG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=1WxP4eG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=SABEkkG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=SABEkkG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ggmPtgG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ggmPtgG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=yGvudEG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=yGvudEG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Ytf1K5G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Ytf1K5G" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/reporting-again-and-interviews.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1584860787815163372</guid><pubDate>Tue, 22 Apr 2008 16:54:00 +0000</pubDate><atom:updated>2008-04-22T10:05:43.816-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">standards</category><category domain="http://www.blogger.com/atom/ns#">reporting</category><title>Reporting - time for standardization?</title><description>[This is a repost of my forum post &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2443"&gt;here&lt;/a&gt;. Comments welcome but perhaps most usefully posted as replies in the forum. Also, a tip of the hat to forum members BitHead and kovar for providing the impetus.]&lt;br /&gt;&lt;br /&gt;I'd like to pick up on one or two comments from an &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2416" target="_blank" title="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2416" class="postlink" rel="nofollow"&gt;earlier thread&lt;/a&gt; and bring the subject of report standardization into the spotlight.&lt;br /&gt;&lt;br /&gt;This is a subject area which has cropped up before (in these forums and elsewhere) and also one which has given me pause for thought in practice - in common with most of us here, I imagine. I think the time is right to give some serious consideration as to whether the standard of reporting delivered by computer forensics practitioners is all that it could be and, more specifically, is the introduction of a suitably structured and widely accepted model a worthwhile goal to aim for.&lt;br /&gt;&lt;br /&gt;A number of benefits have already been suggested for such a model, some of these being increased efficiency, increased accuracy, improvements in communicating with other parties and an increase in professional credibility. In addition, two paths have been suggested for achieving this goal - one, get the major computer forensic groups and organisations to agree on such a model and push it out to their members, the other, develop a model at a grass roots level and grow support and acceptance for it amongst members of the various computer forensics forums.&lt;br /&gt;&lt;br /&gt;I'd like to request further comments from all of us here. Do you think there's anything wrong &lt;span style="font-style: italic;"&gt;in principle&lt;/span&gt; with a standardized reporting model? If not, could such a model be developed which serves to provide the benefits mentioned above without undue restriction being placed on the report writer? What would be the best way of creating such a model? Would the time and effort spent developing a suitable model be worthwhile?&lt;br /&gt;&lt;br /&gt;All thoughts welcome!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=1e6OqO"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=1e6OqO" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=vJ0zCbG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=vJ0zCbG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wEHHzjG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wEHHzjG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=y8cmOsg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=y8cmOsg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=gAGsPtG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=gAGsPtG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=bbRHoCg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=bbRHoCg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=8SXAO2G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=8SXAO2G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=9krF3pG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=9krF3pG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wj2Br7G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wj2Br7G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZFoUbBG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZFoUbBG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=7m4AwIG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=7m4AwIG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/reporting-time-for-standardization.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5443218675857866574</guid><pubDate>Fri, 18 Apr 2008 16:56:00 +0000</pubDate><atom:updated>2008-04-18T10:18:09.651-07:00</atom:updated><title>Posts from the blogoshpere</title><description>Not much time today, just enough to link to a few interesting blog posts elsewhere (some old, some new):&lt;br /&gt;&lt;a href="http://forensicir.blogspot.com/2008/02/reflections.html"&gt;&lt;br /&gt;Reflections of a computer forensics blogger&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://computer.forensikblog.de/en/2008/04/ftk_2_0_performance.html#more"&gt;FTK 2.0 performance&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forensickb.com/2008/03/ghost-as-forensic-tool.html"&gt;Ghost as a forensic tool&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.forensicblog.org/2007/07/30/the-admissibility-vs-weight-of-digital-evidence/"&gt;&lt;br /&gt;Admissibility vs weight of digital evidence&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OK, gotta run. Have a great weekend everyone!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=OLoQXB"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=OLoQXB" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=W3PX6EG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=W3PX6EG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=mH0TA2G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=mH0TA2G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=3uBPHyg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=3uBPHyg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Vx1ZDqG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Vx1ZDqG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=nKc7rPg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=nKc7rPg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=YGlgsRG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=YGlgsRG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=4UAwKdG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=4UAwKdG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=D9AqvYG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=D9AqvYG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=4Xbqx2G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=4Xbqx2G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=7zRLYdG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=7zRLYdG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/posts-from-blogoshpere.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-309547916310169011</guid><pubDate>Mon, 14 Apr 2008 12:22:00 +0000</pubDate><atom:updated>2008-04-14T05:36:34.887-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">forensic focus stats</category><title>Site stats</title><description>One of the things I forget to do for long periods (the last time I did it was over a year ago!) is to update the stats page to show how many people are visiting Forensic Focus. The figures for last month break down like this:&lt;br /&gt;&lt;br /&gt;Unique visitors 20995&lt;br /&gt;Number of visits 74665&lt;br /&gt;Pages 218510&lt;br /&gt;&lt;br /&gt;The full list of stats for each month since January 2004 can be viewed &lt;a href="http://www.forensicfocus.com/advertising-statistics"&gt;here&lt;/a&gt;. Although I do a little bit in the way of advertising and many pages have been picked up by Google, I'm convinced that a lot of the site's continued growth is due to word of mouth. Many of those who sign up for new accounts tell me that Forensic Focus was mentioned by someone they work with or by a teacher on a training course.&lt;br /&gt;&lt;br /&gt;So, a big thank you is due to all those who have helped the site grow and I hope it continues to be a source worthy of recommendation. Like the old saying goes, if you're happy with it - tell someone else. If you're not - tell me!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=QISREr"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=QISREr" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5E35SeG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5E35SeG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=3FdPhwG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=3FdPhwG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=McnJPvg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=McnJPvg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=oTuv6yG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=oTuv6yG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=UuNNCng"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=UuNNCng" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=QiX3NBG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=QiX3NBG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=0Hak66G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=0Hak66G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=DyxiXsG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=DyxiXsG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cWhRn6G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cWhRn6G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=pc6Sc5G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=pc6Sc5G" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/site-stats.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-396752389417855921</guid><pubDate>Tue, 08 Apr 2008 13:34:00 +0000</pubDate><atom:updated>2008-04-08T07:41:44.858-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics costs prices</category><title>Why the hell is everything so expensive?</title><description>I don't usually rant, possibly because I'm not sure I'd be able to stop, but one thing I've noticed is just how incredibly expensive everything is in the world of computer forensics. Not just the usual wallet-draining culprits like high end hardware but other stuff too - software, training, books, software, training... (sorry, I'm starting to repeat myself, I knew this would happen).&lt;br /&gt;&lt;br /&gt;I once tried to explain computer forensics to a good friend of mine with little knowledge of technical matters. They said something rather insightful: "So, it's basically just copying stuff and looking at it?" Now, we all know there's more to it than that, but there's a kernel of truth in that statement which leads me to wonder about at least some of the pricing structures out there.&lt;br /&gt;&lt;br /&gt;OK, rant over, and to some degree this is an "&lt;a href="http://en.wikipedia.org/wiki/Aunt_Sally"&gt;Aunt Sally&lt;/a&gt;". But not entirely...
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=1NrLx1"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=1NrLx1" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Cd2wBKG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Cd2wBKG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=TgFyLuG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=TgFyLuG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ztD1bPg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ztD1bPg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=uGxf5CG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=uGxf5CG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=OdYscXg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=OdYscXg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=TEL15PG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=TEL15PG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=9Is1tGG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=9Is1tGG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=RYawzWG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=RYawzWG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=7uMqVEG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=7uMqVEG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=eiiOb2G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=eiiOb2G" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/why-hell-is-everything-so-expensive.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-3397896978742694809</guid><pubDate>Mon, 07 Apr 2008 16:56:00 +0000</pubDate><atom:updated>2008-04-07T10:23:35.294-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">forensics</category><category domain="http://www.blogger.com/atom/ns#">hotplug</category><category domain="http://www.blogger.com/atom/ns#">wiebetech</category><title>The problem with power</title><description>Perhaps unusually for someone with an interest in computing, my knowledge of electricity - the driving power behind computers the world over - is sketchy to say the least. Beyond remembering which way to twist a light bulb and avoiding the temptation to stick a fork in the toaster, I'm something of a novice in understanding how this mysterious force actually works.&lt;br /&gt;&lt;br /&gt;As a result, I was mightily impressed by Wiebetech's HotPlug device which Paul Mah recently &lt;a href="http://blogs.techrepublic.com.com/security/?p=437"&gt;blogged&lt;/a&gt; about at TechRepublic. Here's the YouTube video where James Wiebe explains how the system works:&lt;br /&gt;&lt;br /&gt;&lt;a style="left: 0px ! important; top: 15px ! important;" title="Click here to block this object with Adblock Plus" class="abp-objtab-015619521239901868 visible ontop" href="http://www.youtube.com/v/erq4TO_a3z8&amp;amp;hl=en"&gt;&lt;/a&gt;&lt;object height="355" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/erq4TO_a3z8&amp;amp;hl=en"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.youtube.com/v/erq4TO_a3z8&amp;amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Clever, huh? The downside is it's yet another box to drag along with you but, hey, us IT guys have got to get our exercise somewhere.&lt;br /&gt;&lt;br /&gt;And for anyone else struggling to replace a light bulb (I'm sure there's a joke here somewhere) just remember: "lefty loosy, righty tighty". It even works with taps...in the Northern Hemisphere anyway :-)
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=u7eZW2"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=u7eZW2" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=UH9yaFG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=UH9yaFG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=iQbQvVG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=iQbQvVG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZWugNRg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZWugNRg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=84UHcKG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=84UHcKG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Ay5Y4Zg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Ay5Y4Zg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=m6mJVaG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=m6mJVaG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=qgzyGrG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=qgzyGrG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=RpyAwCG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=RpyAwCG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wQMrF4G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wQMrF4G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=dcW3IhG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=dcW3IhG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/problem-with-power.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1638034512460498651</guid><pubDate>Thu, 03 Apr 2008 20:06:00 +0000</pubDate><atom:updated>2008-04-03T13:27:45.038-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics licensing</category><title>Licensing</title><description>Ah, back in the blogging seat at long last!&lt;br /&gt;&lt;br /&gt;Keen forumites will have noticed my &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2386"&gt;recent post&lt;/a&gt; in the Legal forum asking for a little help in putting together some resources on licensing issues for computer forensics practitioners (tip of the hat to David for the suggestion).&lt;br /&gt;&lt;br /&gt;There have already been a few very useful suggestions, in particular the map at &lt;a href="http://www.investigation.com/surveymap/surveymap.html"&gt;www.investigation.com/surveymap/surveymap.html&lt;/a&gt; would seem to be a very handy reference for investigators in the US. I want to stress that I'd like to include as many other countries as possible though, so if you're familiar with the relevant licensing procedures in your neck of the woods please reply to the forum post or PM me (note: I'm also including formal vetting procedures and the like under the heading of "licensing" where these are required in order to carry out forensic work - in other words the end result may not necessarily be termed a license in your local lingo).&lt;br /&gt;&lt;br /&gt;On the subject of licensing, I have the impression it's (perhaps unsurprisingly) about as popular as a root canal in some places. Got a strong feeling about it? Post a comment and get it off your chest :-)
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=dBuci3"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=dBuci3" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=qxAbe9G"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=qxAbe9G" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=huk6AOG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=huk6AOG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=GM1ZfBg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=GM1ZfBg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=rnWVAMG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=rnWVAMG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=897Aptg"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=897Aptg" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=zkbSwEG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=zkbSwEG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=hw59riG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=hw59riG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=shenTuG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=shenTuG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=zkfriWG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=zkfriWG" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=PRCe4OG"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=PRCe4OG" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/04/licensing.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4804872785076317439</guid><pubDate>Tue, 26 Feb 2008 20:58:00 +0000</pubDate><atom:updated>2008-02-26T13:26:20.263-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics podcasts</category><title>Computer forensics podcasts</title><description>While computer forensics blogs are quite easy to find, podcasts are somewhat conspicuous by their absence - not altogether surprising, of course, given the effort required to produce something worth listening to. In fact, the only one I listen to anything like regularly is Bret and Ovie's &lt;a href="http://cyberspeak.libsyn.com/"&gt;CyberSpeak&lt;/a&gt;, and despite being very enjoyable, even that doesn't always concentrate on purely forensic issues.&lt;br /&gt;&lt;br /&gt;Does anyone have any other recommendations for computer forensic podcasts? Please leave a comment and I'll add them to the relevant links page for others to see.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=pGpgTs"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=pGpgTs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tkoZ52E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tkoZ52E" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=TDZmBlE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=TDZmBlE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=mbTMKxe"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=mbTMKxe" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=KLcvOJE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=KLcvOJE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=zK36Xye"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=zK36Xye" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=XJs1gFE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=XJs1gFE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=s1YlhuE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=s1YlhuE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=qGFwK6E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=qGFwK6E" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=RvkOv3E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=RvkOv3E" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=2YAa9IE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=2YAa9IE" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/02/computer-forensics-podcasts.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-5447970682294982125</guid><pubDate>Fri, 22 Feb 2008 14:31:00 +0000</pubDate><atom:updated>2008-02-22T08:26:19.652-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">cold boot</category><category domain="http://www.blogger.com/atom/ns#">bitlocker</category><category domain="http://www.blogger.com/atom/ns#">key recovery</category><category domain="http://www.blogger.com/atom/ns#">truecrypt</category><category domain="http://www.blogger.com/atom/ns#">encryption</category><title>Cold Boot Attacks on Encryption Keys</title><description>Already generating &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2288"&gt;some discussion&lt;/a&gt; in the forums and elsewhere on the web is the recently released paper "&lt;a href="http://citp.princeton.edu/pub/coldboot.pdf"&gt;Lest We Remember: Cold Boot Attacks on Encryption Keys&lt;/a&gt;" from researchers at Princeton University. The researchers' main finding is that data remains in DRAM for longer than generally expected. Furthermore, this period can be extended significantly by cooling the memory chips in question (a somewhat unsophisticated but effective methodology of achieving this cooling effect being the use of an inverted "canned air" canister!)&lt;br /&gt;&lt;br /&gt;In addition to the &lt;a href="http://citp.princeton.edu/pub/coldboot.pdf"&gt;paper&lt;/a&gt;, there is also a YouTube video:&lt;br /&gt;&lt;br /&gt;&lt;a style="left: 0px ! important; top: 15px ! important;" title="Click here to block this object with Adblock Plus" class="abp-objtab-035614508802438616 visible ontop" href="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1&amp;amp;border=0"&gt;&lt;/a&gt;&lt;a title="Click here to block this object with Adblock Plus" class="abp-objtab-035614508802438616" href="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1&amp;amp;border=0"&gt;&lt;/a&gt;&lt;object height="355" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1&amp;amp;border=0"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.youtube.com/v/JDaicPIgn9U&amp;amp;rel=1&amp;amp;border=0" type="application/x-shockwave-flash" wmode="transparent" height="355" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;In terms of the underlying principles involved, there's nothing particularly new here. Data retention in memory has been known about and discussed for a number of years. The paper is interesting, perhaps even important, for a number of reasons though. Firstly, the extent to which data remains available and the ease with which the window of recovery can be extended will be surprising to many. Secondly, in addition to the main finding the paper also discusses techniques used to reconstruct data where some amount of decay has occurred - potentially crucial in the recovery of encryption keys. Thirdly, it addresses one of the key challenges facing forensic examiners as the use of BitLocker and products such as TrueCrypt continues to grow.&lt;br /&gt;&lt;br /&gt;As many commentators have already mentioned on news sites or blogs (including the researchers' &lt;a href="http://www.freedom-to-tinker.com/?p=1257"&gt;own blog&lt;/a&gt;) the threats to security or opportunities for forensic analysis are highly dependent on a variety of factors - the state of a machine, the particular implementation of BitLocker in use, the speed with which cooling can be applied etc. In the real world, this would seem to represent a fairly limited threat to anyone who has had their laptop stolen by an opportunist thief, although situations where a device has been specifically targeted for the data it may contain are a different matter. I think it's much more interesting to consider the forensic possibilities and implications. How long will it be before this type of consideration becomes an integral part of our thought processes when preparing to seize a suspect device? What effect will existing legislation have on your actions? Why didn't I invent this technique when I cleaned my keyboard after having that sandwich for lunch?&lt;br /&gt;&lt;br /&gt;Food for thought indeed...
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=0EufXB"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=0EufXB" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=WEll2YE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=WEll2YE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Uc8xrrE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Uc8xrrE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Ilx6fTe"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Ilx6fTe" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=SSyC3IE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=SSyC3IE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=8rXl31e"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=8rXl31e" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=016thEE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=016thEE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=SlsTlxE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=SlsTlxE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=IAl0qiE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=IAl0qiE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=uNDHFzE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=uNDHFzE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=GrV97JE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=GrV97JE" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/02/cold-boot-attacks-on-encryption-keys.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2991755001749923856</guid><pubDate>Thu, 21 Feb 2008 18:24:00 +0000</pubDate><atom:updated>2008-02-21T11:09:55.070-08:00</atom:updated><title>YouTube and the power of the dark side</title><description>Sharp eyed visitors may have noticed the addition of a &lt;a href="http://www.forensicfocus.com/computer-forensics-videos"&gt;Videos link&lt;/a&gt; to the Resources menu on the left hand side at Forensic Focus. The link is to a page of YouTube videos related to computer forensics - some instructional, some news reports and some...um...other (such as "Cat Fancy".) I hope they're somewhat educational or at least mildly diverting. Needless to say please feel free to recommend further additions to the page.&lt;br /&gt;&lt;br /&gt;You may notice that the top video is slightly larger than the rest. In theory this should be a sort of automated player which delivers a selection of computer forensics related videos by itself without needing me to specify them individually (the basic idea being that it picks up on keywords supplied when I set it up.) Well, that's the theory. In practice it doesn't seem to work too well - either it displays no videos at all or the ones it does show are unrelated to the subject area. Maybe the technology will improve, though, so I'll leave it in place for the time being.&lt;br /&gt;&lt;br /&gt;An unexpected benefit of the poor targeting, though, is that it's introduced me to Chad Vader. I'm sure most of you cool cats have already seen this successful viral video series but for those who haven't, here's episode 1.&lt;br /&gt;&lt;br /&gt;May the force be with you!&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/4wGR4-SeuJ0&amp;amp;rel=1"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/4wGR4-SeuJ0&amp;amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=DSHgqX"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=DSHgqX" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wusBdvE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wusBdvE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=88J2oEE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=88J2oEE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=EhCxsze"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=EhCxsze" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=v82mzCE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=v82mzCE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ydHLcoe"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ydHLcoe" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=CAQoliE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=CAQoliE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=mXyoW3E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=mXyoW3E" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=9aYPExE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=9aYPExE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tetLPuE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tetLPuE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=KUeqT9E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=KUeqT9E" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/02/youtube-and-power-of-dark-side.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-7066543431657153645</guid><pubDate>Fri, 01 Feb 2008 15:04:00 +0000</pubDate><atom:updated>2008-02-01T08:05:08.519-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">EnCase</category><category domain="http://www.blogger.com/atom/ns#">EnScripts</category><category domain="http://www.blogger.com/atom/ns#">Lance Mueller</category><title>Lance Mueller's blog...and funny T-Shirt quotes!</title><description>Lance Mueller's blog - &lt;a href="http://www.forensickb.com/"&gt;Computer Forensics, Malware Analysis &amp;amp; Digital Investigations&lt;/a&gt; - is definitely one of the better ones out there. Updated frequently, highly detailed, nicely illustrated (i.e. lots of pretty pictures) and with some newly posted forensic practicals it's a great resource to add to your blog tracker, especially if you're an EnCase user.&lt;br /&gt;&lt;br /&gt;On a less serious note, don't miss &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2222"&gt;this thread&lt;/a&gt; in the forums where we've been trying to come up with some suitably amusing quotes for a CF club fundraiser. I have to admit I like Harlan's suggestion, despite the somewhat disturbing imagery it conjurs up ;-)
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=NWcfZL"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=NWcfZL" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=dbqnjeE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=dbqnjeE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=kk6BfDE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=kk6BfDE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5sQZnae"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5sQZnae" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=jjuRAUE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=jjuRAUE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZjDYCve"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZjDYCve" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tr0WC7E"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tr0WC7E" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=MimbQxE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=MimbQxE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=7AvwtSE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=7AvwtSE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=30CIbcE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=30CIbcE" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=gy7jBEE"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=gy7jBEE" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/02/lance-muellers-blogand-funny-t-shirt.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-429113900537922927</guid><pubDate>Wed, 23 Jan 2008 14:30:00 +0000</pubDate><atom:updated>2008-01-23T10:47:24.306-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">validating</category><category domain="http://www.blogger.com/atom/ns#">write blockers</category><category domain="http://www.blogger.com/atom/ns#">write blocking</category><title>Validating write blockers</title><description>In the &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2066"&gt;Recommended forensic hardware thread&lt;/a&gt; in the Hardware forum I recently wrote the following about a hardware write blocker I'd just come across which I hadn't seen before:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;I think this brings up the interesting question of how we (as practitioners) test the write blocking capability of new devices both to satisfy ourselves that they work as advertised and to be able to show that in court.&lt;br /&gt;&lt;br /&gt;For the sake of argument, let's imagine that we *need* to use one of these IOI products (if we want to be specific we'll say it's the FW2ATA525-MR1-WP already mentioned) but it's not a device you've used or tested before, it hasn't been used in a court case in your area and you have only the manufacturer's word that it works properly. What methodology are you going to employ to test it in some formal sense?&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;In practice, I suspect most of us use write blockers which are seen as industry standards and have already gone through some form of validation procedure. Typical choices would be Guidance Software's FastBloc devices or something from the Tableau product line, both examples of items from well respected specialist companies. Not only have these devices presumably undergone extensive testing by manufacturers concerned to protect their reputation as industry leaders but we also have the results of independent testing to refer to, perhaps the best well known being the &lt;a href="http://www.cftt.nist.gov/hardware_write_block.htm"&gt;NIST hardware write block testing program&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;What of new devices from relatively unknown manufacturers though? How do we reassure ourselves and the courts that they work as advertised? The obvious answer is that we test them ourselves but &lt;span style="font-weight: bold; font-style: italic;"&gt;how exactly&lt;/span&gt; do we do that, what methodology do we use?&lt;br /&gt;&lt;br /&gt;In theory, write blocking is easy to understand: we want to prevent any alterations to the attached evidence device while allowing all data to be retrieved. In practice the situation is more complex, there are many different commands which can be sent to a storage device from a variety of different components in a host computer (BIOS, OS, application software, etc.) and we need to satisfy ourselves that a write blocking device operates as expected (preventing alteration/allowing retrieval) under all circumstances. Similarly, testing methodologies can be either straightforward or complex. For example, compare the validation methodology suggested in the &lt;a href="http://www.e-fense.com/helix/Docs/Helix0307.pdf"&gt;Helix manual&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;This process is based on the National Center for Forensic Science (NCFS) 5 step validation process for testing write protection devices (Erickson, 2004). It was originally designed to test the Windows XP SP2 USB software write blocker, but has been adapted to test any hardware and/or software write blockers.&lt;br /&gt;&lt;br /&gt;Step #1 – Prepare the media&lt;br /&gt;&lt;br /&gt;a) Attach the storage media you will be testing with to your forensic workstation&lt;br /&gt;in write-enabled mode.&lt;br /&gt;b) Wipe the media - validate that this has been successful.&lt;br /&gt;c) Format the media with a file format of your choosing.&lt;br /&gt;d) Copy an amount of data to the media.&lt;br /&gt;e) Delete a selection of this data from the media.&lt;br /&gt;f) On the desktop of your forensic workstation create 3 folders. Call these Step-1, Step-2 and Step-5.&lt;br /&gt;g) Image the media into the Step-1 folder and note the MD5 hash.&lt;br /&gt;&lt;br /&gt;Step #2 – Testing the media&lt;br /&gt;&lt;br /&gt;a) Remove and then replace the testing media into your forensic workstation.&lt;br /&gt;b) Copy some data to the media.&lt;br /&gt;c) Deleted a selection of this data from the media.&lt;br /&gt;d) Image the media into the Step-2 folder and note the MD5 hash.&lt;br /&gt;e) Validate that this hash value is ''different'' to that produced in Step #1.&lt;br /&gt;&lt;br /&gt;Step #3 – Activate the write blocking device&lt;br /&gt;&lt;br /&gt;a) Remove the media from your forensic workstation.&lt;br /&gt;b) Attach and/or activate the write protection device.&lt;br /&gt;c) Follow any specific activation procedures for the specific blocker.&lt;br /&gt;&lt;br /&gt;Step #4 – Test the write blocking device&lt;br /&gt;&lt;br /&gt;a) Insert the media into your forensic workstation.&lt;br /&gt;b) Attempt to copy files onto the media.&lt;br /&gt;c) Attempt to delete files from the media.&lt;br /&gt;d) Attempt to format the media.&lt;br /&gt;&lt;br /&gt;Step #5 – Check for any changes to the media&lt;br /&gt;&lt;br /&gt;a) Image the media into the Step-3 folder and note the MD5 hash.&lt;br /&gt;b) Validate that this MD5 hash is the ''same'' as the MD5 hash from Step #2.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;with the methodology outlined by NIST in their &lt;a href="http://www.cftt.nist.gov/HWB-ATP-19.pdf"&gt;test plan&lt;/a&gt; available at &lt;a href="http://www.cftt.nist.gov/hardware_write_block.htm"&gt;http://www.cftt.nist.gov/hardware_write_block.htm&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you're thinking the easy way round this is just to avoid the issue and buy one of the well known write blockers instead, the bad news is that testing your device (regardless of manufacturer) is almost certainly something you should be doing anyway. There's a good thread &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=1586"&gt;here&lt;/a&gt; in the forums discussing when and why write blockers should be tested.&lt;br /&gt;&lt;br /&gt;Of course, we need to see validation within the wider context of the entire forensic process which involves, potentially at least, presenting evidence in court. As a result, there may be certain testing methodologies which are already specified or recommended wherever we find ourselves working.&lt;br /&gt;&lt;br /&gt;I think I'm going to dig a little further into this and see what various agencies have to say. I'll report back when I have some news but in the meantime any thoughts or comments would be very welcome. How would you validate a new write blocker? Do you regularly test your existing device? How reliable are hardware write blockers (have you had one fail on you)? Let me know.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=kfYE6v"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=kfYE6v" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=vSoLEDD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=vSoLEDD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=D91NAcD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=D91NAcD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Z5N4qod"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Z5N4qod" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=g4ZvLAD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=g4ZvLAD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5vB0Gxd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5vB0Gxd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=e6pdcdD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=e6pdcdD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=vXXyFXD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=vXXyFXD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=QGJelYD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=QGJelYD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=buE80jD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=buE80jD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=105yg9D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=105yg9D" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/validating-write-blockers.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1594169932920596748</guid><pubDate>Tue, 15 Jan 2008 14:17:00 +0000</pubDate><atom:updated>2008-01-15T06:20:55.754-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics events</category><title>Events calendar updated</title><description>Just a quick note to say that the &lt;a href="http://www.forensicfocus.com/computer-forensics-events"&gt;events calendar&lt;/a&gt; has now been updated with relevant events covering the rest of the year. If anyone know of other events which should be included (primarily conferences) please add them to the calendar by going to the appropriate day/days and clicking the "Add Event" button (I'll then review/approve the new addition). Thanks!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=H7Zlng"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=H7Zlng" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZK5U29D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZK5U29D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=lyrVN2D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=lyrVN2D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=uHBI3Kd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=uHBI3Kd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=XtvjGSD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=XtvjGSD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=4taNeid"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=4taNeid" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=jOmjQID"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=jOmjQID" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tWcdFwD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tWcdFwD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=sAC4WmD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=sAC4WmD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cDfg7BD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cDfg7BD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Xa9RT3D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Xa9RT3D" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/events-calendar-updated.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4277386960764597961</guid><pubDate>Wed, 09 Jan 2008 14:51:00 +0000</pubDate><atom:updated>2008-01-09T07:41:07.433-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">global computer forensics</category><title>Computer forensics around the world</title><description>One of the interesting things about running Forensic Focus is seeing which countries our visitors are coming from. Of course, as an English language site it's not particularly surprising to note that a significant number of visitors come from the US and the UK. However, I'm always delighted to see just how many visitors come from other countries - not just other English speaking or Western European countries, but countries from every corner of the globe. Interest in computer forensics is certainly a worldwide phenomenon.&lt;br /&gt;&lt;br /&gt;From some of the emails I've received over the past few years and posts to the forums (not to mention news items posted to the homepage) it's clear that the state of computer forensics differs widely from one country to another. What do I mean by "state"? A number of things, touching upon but not limited to issues surrounding: legislation, awareness, training, best practice, job opportunities, etc. It's also clear that things are changing and progress is being made in many places.&lt;br /&gt;&lt;br /&gt;An opportunity exists for those of us in countries with more fully developed computer forensics infrastructures to assist newcomers to the field and, from what I understand, a number of countries are actively seeking experienced practitioners from outside their borders to assist with this process. That's not to say that building awareness and implementing change is a straightforward process, and no one knows a country better than its own citizens, but lessons learned elsewhere can often save valuable time and effort. Ultimately, though, computer forensics exists within a larger framework built around the use of and access to technology, the political climate, even social norms and values. The shape of forensic computing in one country may differ from that seen in other areas of the globe.&lt;br /&gt;&lt;br /&gt;I'd be interested to hear what others think of the global state of our profession. Which countries are world leaders in computer forensics and why? Which countries are furthest behind? Is the development and use of high tech investigative powers always a positive thing? Please leave a comment!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=8Glj2M"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=8Glj2M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=1R8lddD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=1R8lddD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=dOAeqmD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=dOAeqmD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=YSxFvOd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=YSxFvOd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=FlZUZ6D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=FlZUZ6D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=8pfr7Dd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=8pfr7Dd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cZnrqXD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cZnrqXD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5DVwX3D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5DVwX3D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Bdz66yD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Bdz66yD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=vqVOQmD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=vqVOQmD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=yzHUSFD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=yzHUSFD" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/computer-forensics-around-world.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-1798717789135977241</guid><pubDate>Sat, 05 Jan 2008 16:27:00 +0000</pubDate><atom:updated>2008-01-05T08:31:47.150-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">computer forensics education</category><category domain="http://www.blogger.com/atom/ns#">computer forensics training</category><title>Training and education links page updated</title><description>The training and education links page at&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forensicfocus.com/computer-forensics-training-education" target="_blank" title="http://www.forensicfocus.com/computer-forensics-training-education" class="postlink" rel="nofollow"&gt;http://www.forensicfocus.com/computer-forensics-training-education&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;has been updated. Links are now listed by country on separate pages and non-working links have been removed.&lt;br /&gt;&lt;br /&gt;The procedure for adding a new link has also been simplified, just &lt;a href="http://www.forensicfocus.com/index.php?name=Web_Links&amp;amp;l_op=addlink" target="_blank" title="http://www.forensicfocus.com/index.php?name=Web_Links&amp;amp;l_op=addlink" class="postlink" rel="nofollow"&gt;click here&lt;/a&gt;.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=qgaOFp"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=qgaOFp" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=RFFbRjD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=RFFbRjD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=DnyTjjD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=DnyTjjD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wMoJd6d"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wMoJd6d" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=LxNuEaD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=LxNuEaD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=IUmTwEd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=IUmTwEd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=I52zQ9D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=I52zQ9D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cRAb7HD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cRAb7HD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=EbuNfKD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=EbuNfKD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5naap5D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5naap5D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=CjtFjaD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=CjtFjaD" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/training-and-education-links-page.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4099048169444201409</guid><pubDate>Fri, 04 Jan 2008 13:43:00 +0000</pubDate><atom:updated>2008-01-04T06:35:46.840-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">forensic reports</category><category domain="http://www.blogger.com/atom/ns#">forensic hardware</category><category domain="http://www.blogger.com/atom/ns#">X-Ways</category><category domain="http://www.blogger.com/atom/ns#">terms of engagement</category><title>X-Ways interview and a few other items</title><description>For those who didn't catch last month's newsletter a quick note to say that Stefan Fleischmann has very kindly agreed to answer interview questions this month. If you have any questions about Stefan's &lt;a href="http://www.x-ways.com/"&gt;X-Ways&lt;/a&gt; range of software products please feel free to post them to &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2117"&gt;this forum topic&lt;/a&gt;. Alternatively, if you prefer, you can always drop me a line privately (email, PM or &lt;a href="http://www.forensicfocus.com/contact"&gt;contact form&lt;/a&gt;). The X-Ways lineup includes not only X-Ways Forensics but also X-Ways Capture for live analysis and I for one am certainly looking forward to speaking to Stefan and learning more about both of these products. If there's anything you'd like to ask please don't let this opportunity go by!&lt;br /&gt;&lt;br /&gt;In other news the &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2066"&gt;forum discussion&lt;/a&gt; of recommended forensic hardware now finally has a summary page to go with it at&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forensicfocus.com/recommended-hardware"&gt;http://www.forensicfocus.com/recommended-hardware&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This should be very much a "living document" with updates and additions strongly encouraged - please use the forum topic mentioned above to continue the discussion.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2109"&gt;Another topic&lt;/a&gt; which came up quite recently in the forums is that of report writing. This too now has a dedicated page at&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.forensicfocus.com/computer-forensics-reports"&gt;http://www.forensicfocus.com/computer-forensics-reports&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and again I'd like to encourage further additions to this page (sample reports, relevant links and articles on CF report writing).&lt;br /&gt;&lt;br /&gt;Finally, a quick plug for &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2123"&gt;this post&lt;/a&gt; by kovar concerning terms of engagement. It seems to me this is another useful area for discussion, in particular for those in private practice, and at some stage will probably also warrant a separate page as a quick reference. Please help if you can!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=78fnnS"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=78fnnS" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=gBkeTJD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=gBkeTJD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=fCgi1MD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=fCgi1MD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=nKwAWYd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=nKwAWYd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=SmlD5hD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=SmlD5hD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=8WcZQ4d"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=8WcZQ4d" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tEOw1UD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tEOw1UD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=X3PQaPD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=X3PQaPD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tCiNHrD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tCiNHrD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=EoCF5fD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=EoCF5fD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5q7PcOD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5q7PcOD" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/x-ways-interview-and-few-other-items.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6638023909072303094</guid><pubDate>Tue, 01 Jan 2008 14:50:00 +0000</pubDate><atom:updated>2008-01-01T06:50:42.039-08:00</atom:updated><title>Happy New Year!</title><description>A very happy New Year to all readers and all the best for 2008!&lt;br /&gt;&lt;br /&gt;I'm looking forward to getting back in the saddle this month after the usual craziness of December. Hope everyone enjoyed themselves...see you soon in the forums!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=HSbfLX"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=HSbfLX" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=B7U2gQD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=B7U2gQD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=MEriNuD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=MEriNuD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=dSaHrKd"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=dSaHrKd" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ARvhgbD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ARvhgbD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=KYME0Ud"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=KYME0Ud" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=eMIHQED"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=eMIHQED" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=wTeTQ5D"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=wTeTQ5D" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=usOrQVD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=usOrQVD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=lU6AlBD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=lU6AlBD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=K0snkzD"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=K0snkzD" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2008/01/happy-new-year.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2529115712508991947</guid><pubDate>Mon, 24 Dec 2007 17:41:00 +0000</pubDate><atom:updated>2007-12-24T09:42:05.649-08:00</atom:updated><title>Merry Christmas!</title><description>A very merry Christmas to all!&lt;br /&gt;&lt;br /&gt;Hope you have a great time over the festive period.&lt;br /&gt;&lt;br /&gt;Drive carefully, stay safe and see you after Boxing Day...
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=u2iJwn"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=u2iJwn" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=1yL0syC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=1yL0syC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tINZqUC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tINZqUC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=QnAJ1wc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=QnAJ1wc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=2zAUtLC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=2zAUtLC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=q3gABZc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=q3gABZc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=smwPuJC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=smwPuJC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=s3kEWfC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=s3kEWfC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=3N8fNgC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=3N8fNgC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cdNJa7C"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cdNJa7C" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=GbaxXMC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=GbaxXMC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/12/merry-christmas.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-6460645808963264464</guid><pubDate>Mon, 17 Dec 2007 13:53:00 +0000</pubDate><atom:updated>2007-12-17T06:11:15.194-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">hard disk reliability</category><category domain="http://www.blogger.com/atom/ns#">Simson Garfinkel</category><category domain="http://www.blogger.com/atom/ns#">DOMEX</category><title>Document &amp; Media Exploitation - more interesting than it sounds!</title><description>There's an article from Simson Garfinkel at the ACM Queue website &lt;a href="http://www.acmqueue.com/modules.php?name=Content&amp;amp;pa=showpage&amp;amp;pid=512"&gt;here&lt;/a&gt; which I think many will find interesting (don't let the rather dull title put you off, it's a great read). It covers something called DOMEX which we're told is defined by the US Intelligence community as "the processing, translation, analysis, and dissemination of collected hard-copy documents and electronic media, which are under the U.S. government's physical control and are not publicly available". Essentially it's about the challenge of bringing relevant information or evidence to light in the face of various obstructions (large disk sizes, encryption, time constraints etc.) Simson calls for more work to be done with a view to improving or automating many of the processes currently carried out by forensic examiners and ends by discussing the wider implications of such improvements.&lt;br /&gt;&lt;br /&gt;Oh, and there's another good article at the same website &lt;a href="http://acmqueue.com/modules.php?name=Content&amp;amp;pa=showpage&amp;amp;pid=506"&gt;here&lt;/a&gt; about hard disk reliability. Both articles are well worth a read!
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=Xh0FEw"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=Xh0FEw" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=IBqEoFC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=IBqEoFC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=2inQbEC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=2inQbEC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=H7yMACc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=H7yMACc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Lv0UeDC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Lv0UeDC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=qQZlBFc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=qQZlBFc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=oAdtThC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=oAdtThC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=CKcAu6C"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=CKcAu6C" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=qA8GzaC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=qA8GzaC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=bKwTkiC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=bKwTkiC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=eFRJwBC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=eFRJwBC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/12/document-media-exploitation-more.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2882061183490898336</guid><pubDate>Mon, 10 Dec 2007 10:11:00 +0000</pubDate><atom:updated>2007-12-10T03:39:53.599-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">forensic hardware</category><title>Forensic workstation recommendations</title><description>Just a quick note to highlight &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;amp;file=viewtopic&amp;amp;t=2066"&gt;this thread&lt;/a&gt; in the forums where we're trying to put together a list of hardware suggestions/recommendations for anyone considering building or buying a forensic workstation for imaging and analysis.&lt;br /&gt;&lt;br /&gt;Do please chime in with any thoughts, not just for the main components (motherboard, chip etc.) but also for the less "sexy" items. Can you recommend a particular case, for example, which you've found has worked well - perhaps due to it's connection possibilities or some ergonomic feature which you particularly liked? What about a particular brand or type of hard drives - are some more reliable than others in your experience?&lt;br /&gt;&lt;br /&gt;The focus of the recommendations is on hardware which gets the job done but also represents value for money. Hopefully once complete it will serve as a useful reference for new practitioners entering the field or anyone upgrading from an older system.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=a5A5bw"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=a5A5bw" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ida6iXC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ida6iXC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=KoyaAOC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=KoyaAOC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=pQJhhSc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=pQJhhSc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=UQgk8rC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=UQgk8rC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=2MugjRc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=2MugjRc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=peGLjXC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=peGLjXC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=a0Z5XtC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=a0Z5XtC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=7uDi2NC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=7uDi2NC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=H6LNMeC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=H6LNMeC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=JCJU9yC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=JCJU9yC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/12/forensic-workstation-recommendations.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-2743477300313534023</guid><pubDate>Thu, 06 Dec 2007 11:26:00 +0000</pubDate><atom:updated>2007-12-06T05:33:50.785-08:00</atom:updated><title>Sharing knowledge (part three)</title><description>All good things come in threes (apart from Star Wars, of course, as I may have mentioned previously) so here's the last part of this "sharing knowledge" trilogy.&lt;br /&gt;&lt;br /&gt;We talked earlier about asking and responding to questions as they arise, the type of situation you see in the forums or our - very quiet! - &lt;a href="http://www.forensicfocus.com/computer-forensics-list"&gt;email discussion list&lt;/a&gt;. I'd like to wrap up by encouraging everyone to share their knowledge in a more proactive fashion, either in the form of articles or papers (which I'm very happy to publish at the Forensic Focus site and in the monthly newsletter) or by contributing to one of the forensic wikis which are out there.&lt;br /&gt;&lt;br /&gt;Let me be the first to admit - if it isn't already blindingly obvious - I'm not a great writer. I also find it hard going at times. I don't always find it particularly easy to express myself and the process of editing and revising what I do put together can be time consuming (I'm not just referring to contributing to the this site, I'm speaking more generally in this case). With that being said, though, with a little bit of planning and enough effort to actually get started I have found that it &lt;span style="font-style: italic;"&gt;is&lt;/span&gt; possible to put something together which has some value.&lt;br /&gt;&lt;br /&gt;It's clear to anyone who browses the Forensic Focus &lt;a href="http://www.forensicfocus.com/computer-forensics-forums"&gt;forums&lt;/a&gt;, or those of other computer forensics sites, that there are many very experienced members and there are also those who can write very well (some of the more lengthy and detailed posts are almost full articles in their own right). There are also some who have the ability to share their knowledge by putting pen to paper but don't do so, often through lack of time but also because they're concerned about how what they've written will be received - the fear of criticism holds back many people I've spoken to privately over the past few years. This latter point is a great pity, many of those same people are those with very useful information and interesting perspectives. Whether held back by lack of time or lack of confidence, I really do want to encourage everyone to think again about writing something for the wider forensic community.&lt;br /&gt;&lt;br /&gt;The obvious question which remains is what to write? The answer, I think, is simply anything which might be useful to someone else (and I often think the easiest way to judge that is to ask yourself if you would find it useful, or would have done so at some stage in the past). I also want to stress that, at Forensic Focus at least, basic forensics or discussion of fundamental principles is also very much on topic, just as much as advanced techniques. In addition, aspects of computer forensic work outside the purely technical are very welcome - examples might be professional challenges, career development, legal issues, even just personal thoughts and reflections. In essence, if it's a topic which interests you then it will probably be of interest to someone else.&lt;br /&gt;&lt;br /&gt;If you'd like to share your knowledge and experience then I encourage you to write something and send it through either to me, for Forensic Focus, or consider submitting to one of the wikis. The ultimate goal is to expand the list of useful resources available to anyone with an interest in this field, from those just thinking about it as a career to those who've seen and done almost (but not quite) everything. I hope you'll decide to help.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=FpSyyj"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=FpSyyj" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=5YyzHqC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=5YyzHqC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=tKqbEEC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=tKqbEEC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=rzRxyvc"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=rzRxyvc" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=D3wEQyC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=D3wEQyC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=DDxg51c"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=DDxg51c" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=55qh8TC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=55qh8TC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Uh3IGBC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Uh3IGBC" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=jFGg47C"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=jFGg47C" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=egZAU4C"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=egZAU4C" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=8ZYOOHC"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=8ZYOOHC" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/12/sharing-knowledge-part-three.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-4797289094127801568</guid><pubDate>Fri, 30 Nov 2007 12:38:00 +0000</pubDate><atom:updated>2007-11-30T06:36:30.520-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">sharing knowledge</category><title>Sharing knowledge (part two)</title><description>I talked briefly last time about the difference between those who enjoy sharing their knowledge and those who prefer to keep things to themselves. I feel strongly that the vast majority of members at Forensic Focus (and similar sites) fall into the former camp which means we have a tremendous resource at our disposal. Like anything of value, though, it needs careful handling. Just as those who are in a position to help may feel a responsibility to provide accurate information (and don't forget that many answers provided in the forums are highly detailed and have involved considerable time and effort to compose), so those who are seeking answers have an obligation to frame their questions appropriately and do what they can to help themselves before seeking advice.&lt;br /&gt;&lt;br /&gt;Forensic Focus is openly and unashamedly a site for both old hands and newcomers to the field, it's certainly not just a site for experienced practitioners. One of the reasons behind that is a focus not just on today's challenges but on tomorrow's too, and more specifically on those members who, although they may be new to computer forensics right now, will be the ones who drive it forward in 5, 10, or 20 years from now (by which time the only computer I'll be using will be one of those gadgets you get at Christmas to keep track of your golf score). So if you're a beginner and there's something you don't understand, what should you do? Here are some thoughts, and I encourage others to add theirs:&lt;br /&gt;&lt;br /&gt;- Before even going online, think about the resources you already have to hand. Books and training course notes are often excellent reference sources. If you have neither, now might be a good time to consider laying down some sound fundamentals. Computer forensics courses (both academic or commercial, classroom based or distance learning) have experienced tremendous growth in the past few years. If a course is not appropriate, at the very least read as much as you can. I often still refer to books I've purchased over the years and building a library of the best reference works should be a priority. Subscribe to news feeds and blogs too so you're up to date with general developments.&lt;br /&gt;&lt;br /&gt;- Whether your question is general or specific, try a little hands on research and testing yourself. Often, putting together a small network or even a single PC for testing purposes can be achieved at little expense. Want to know what happens to the registry when an external disk has been used and removed? Give it a go and try for yourself. Many useful forensic tools are open source and freely available and in the course of using them you will often build your knowledge in other areas.&lt;br /&gt;&lt;br /&gt;- If you have a question about a particular item of hardware or software, consider trying the manufacturer's support site or forum first before looking in a forensic forum for someone with relevant experience. The same applies to forensic hardware and software, often the manufacturer's own web site or forum will get you the answer you need quicker.&lt;br /&gt;&lt;br /&gt;- Some software packages come in for particular scrutiny during an investigation of course, primarily those developed by Microsoft due to their dominance in the OS and browser markets. Fortunately Microsoft makes a lot of information available through its own web site (you can search through it &lt;a href="http://support.microsoft.com/search/?adv=1"&gt;here&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;- It almost goes without saying, but Google really is your friend. If you don't find what you're looking for immediately, though, don't give up. Read some of the &lt;a href="http://www.google.com/intl/en/help/refinesearch.html"&gt;advanced search tips&lt;/a&gt; for other ways of searching.&lt;br /&gt;&lt;br /&gt;- Before posting in the forums, have a good &lt;a href="http://www.forensicfocus.com/index.php?name=Forums&amp;file=search"&gt;search&lt;/a&gt; of the existing posts. As you're doing so you'll probably ask yourself why there aren't many stickied posts or FAQs and I think you'd be right. It's something I intend to improve next year.&lt;br /&gt;&lt;br /&gt;- If you've done all the above (with a particular emphasis on a solid Google and forum search) but haven't found what you're after &lt;span style="font-weight:bold;"&gt;PLEASE DO&lt;/span&gt; ask in the forums - that's what they're there for and I'm certainly not trying to put anyone off from posting. However, there are a few important points to keep in mind when you do post, namely:&lt;br /&gt;&lt;br /&gt;1. Always post in the most appropriate forum (yes, there's &lt;a href="http://www.forensicfocus.com/computer-forensics-forums"&gt;more than one&lt;/a&gt;!)&lt;br /&gt;&lt;br /&gt;2. Give as much information as you can about the problem straight away. Most people are very willing to help but it can be frustrating if there are obvious gaps which need to be filled before they can do so. Describe the general context of the situation, explain something about your own background or experience if you're new to the board, describe any hardware or software in detail (including version numbers) etc. The more information you can give, the more likely you are to get a useful reply.&lt;br /&gt;&lt;br /&gt;3. Say what you've already done to answer the question or solve the problem. Don't be afraid to admit your own limitations. This has two benefits. Firstly, it prevents other from going over the same ground but perhaps more importantly it shows that you've already put your own effort in and just can't get any further. In that case most people will be only too happy to help and you'll get the result you're looking for.&lt;br /&gt;&lt;br /&gt;I hope the above is useful and helps us build our friendly community still further.&lt;br /&gt;&lt;br /&gt;Have I missed something? Would you like to add your own tip for making the most of our shared knowledge pool? Don't hesitate to comment.
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=NeB3Ug"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=NeB3Ug" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=vcYeseB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=vcYeseB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=VXDQGUB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=VXDQGUB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=KcK26ib"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=KcK26ib" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=lhXaIcB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=lhXaIcB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=QFteE9b"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=QFteE9b" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=GATj7KB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=GATj7KB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=UXNFyjB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=UXNFyjB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=MIkbcpB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=MIkbcpB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=jX7FZkB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=jX7FZkB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ht9v5cB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ht9v5cB" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/11/sharing-knowledge-part-two.html</link><author>admin</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-36666403.post-205793678548561401</guid><pubDate>Tue, 27 Nov 2007 16:26:00 +0000</pubDate><atom:updated>2007-11-28T02:48:12.511-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">sharing knowledge</category><title>Sharing knowledge</title><description>Everyone working in a computer forensics role has at least one thing in common - they know a lot more now than they did when they started. No matter how knowledgeable someone is today, there was a time when they knew next to nothing about forensic matters.&lt;br /&gt;&lt;br /&gt;Something not everyone has in common, though, is a willingness to share that knowledge. In the 15 or so years that I've been involved with IT (not just forensics) I've had the good and bad fortune to meet some very different personality types, on the one hand true professionals who are only too happy to share what they know and on the other those who take an almost perverse delight in hoarding their knowledge. I've often thought about what it is that makes one person willing to give up their time to teach others while someone else will only ever seem to act in their own interests. I don't necessarily have a good answer to that question but what I have noticed is that those most willing to share their knowledge have always been those who truly understood the subject matter at a deeper level and genuinely enjoyed thinking and talking about it. They felt secure in their own position yet were comfortable talking about their own limitations.&lt;br /&gt;&lt;br /&gt;No matter how much we know now, the pace of change is such that there will always be something new to learn tomorrow. Furthermore, the scope of high tech investigations is such that no one can possibly know everything. At some stage we all need to turn to the resources which are available in order to increase our knowledge. Those resources are many and varied. For most forensic examiners studying, training and research (if you're lucky) are the main paths to increasing knowledge and understanding. Frequently, though, a problem or question arises the answer to which is not covered in any training course and the time to research it in the lab is simply not available. On these occasions we need to turn to others who may already have answered the same question.&lt;br /&gt;&lt;br /&gt;How we ask that question, especially for those new to the field, can be crucial in determining the type of response we receive. More on that tomorrow...
&lt;p&gt;&lt;a href="http://feeds.feedburner.com/~a/ForensicFocusBlog?a=d8Telf"&gt;&lt;img src="http://feeds.feedburner.com/~a/ForensicFocusBlog?i=d8Telf" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=bolfdMB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=bolfdMB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=zi9oLpB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=zi9oLpB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=4jW8Edb"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=4jW8Edb" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ZyR7f7B"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ZyR7f7B" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=q3hmB9b"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=q3hmB9b" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=a7WcyhB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=a7WcyhB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=ln0Q4XB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=ln0Q4XB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=cWU9x2B"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=cWU9x2B" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=CprgLTB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=CprgLTB" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/ForensicFocusBlog?a=Nd3EDoB"&gt;&lt;img src="http://feeds.feedburner.com/~f/ForensicFocusBlog?i=Nd3EDoB" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</description><link>http://forensicfocus.blogspot.com/2007/11/sharing-knowledge.html</link><author>admin</author></item></channel></rss>
