Forensic Focus - Computer Forensics, Computer Forensic Training, Digital Forensics
LoginRegisterForumsColumnistsPapersEducationGraduatesReviewsInterviewsNewsletterJobsEventsBlogAdvertise
Search Forensic Focus
Custom Search

Find us on Facebook
Follow Forensic Focus on Twitter
Columnists
"I erred." "I was mistaken."
Craig Ball
Single Sign On
Simon Biles
Copyright and games console modification
Dan Gaskell
To GUI or not to GUI?
Chris Hargreaves
'Web 2.0' as evidence
Sean McLinden
Sometimes it’s all about timing
Sam Raincock
Avoiding common job application errors
David Sullivan
Scalability: A Big Headache
Dominik Weber
Graduate Recruitment

computer forensics graduate jobs

Main Menu
MY ACCOUNT
COMMUNITY
EMPLOYMENT
EDUCATION
RESOURCES
MISC
Follow Forensic Focus

Join newsletter

Join LinkedIn group

Follow on Twitter

Subscribe to news

Subscribe to forums

Subscribe to blog

Subscribe to tweets

Members' blogs

External feeds

Bookmark & share: Bookmark and Share

Computer Forensics Newsletter
Newsletter

You must be a
registered user
to receive our newsletter

Register Now!

Memory Acquisitions
Go to page 1, 2  Next
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> Live and Network Forensics
View previous topic :: View next topic  
Author Message
unknown
Newbie


Joined: Nov 10, 2008
Posts: 21
Location: USA

PostPosted: Thu Nov 05, 2009 8:16 am    Post subject: Memory Acquisitions Reply with quote

It is increasingly more common to come accross machines with large amounts of ram. (4GB+) During these situations we discpline our approach around the order of volatility:

www.ietf.org/rfc/rfc3227.txt

However, it would be nice to do a raw capture of memory for analysis. Have any of you found a solution, or have a programatic approach, for addressing this gap? Do you focus on more analysis and collection at the time of the incident?

My thanks in advance for your feedback.
Back to top
View user's profile
Rossetoecioccolato
Newbie


Joined: Nov 03, 2007
Posts: 23
Location: USA

PostPosted: Thu Nov 05, 2009 9:52 am    Post subject: Re: Memory Acquisitions Reply with quote

What makes you think that there is a gap, unknown?
Back to top
View user's profile
unknown
Newbie


Joined: Nov 10, 2008
Posts: 21
Location: USA

PostPosted: Fri Nov 06, 2009 12:09 am    Post subject: Re: Memory Acquisitions Reply with quote

Maybe there is not. Do you have a method for capturing an image of a machine with 4GB or more of memory?
Back to top
View user's profile
Rossetoecioccolato
Newbie


Joined: Nov 03, 2007
Posts: 23
Location: USA

PostPosted: Fri Nov 06, 2009 1:01 am    Post subject: Re: Memory Acquisitions Reply with quote

Yes. And so does M. Suiche (as long as you stick with the default options in his new release). www.msuiche.net/2009/1...-and-x64/. The only "gap" is in some people's understanding of the subject matter. People try to read from physical addresses occupied by PCI BAR or HPET and then wonder why the system crashes when a crash is the expected result. With 32-bit client systems, which do not allow access to physical addresses above ~3.8 GiB via \Device\PhysicalMemory, the design flaw was harmless. But with the proliferation of 64-bit systems and 32-bit server systems equipped with more than 4 GiB of memory that is no longer the case.
Back to top
View user's profile
unknown
Newbie


Joined: Nov 10, 2008
Posts: 21
Location: USA

PostPosted: Fri Nov 06, 2009 12:05 pm    Post subject: Re: Memory Acquisitions Reply with quote

My sincerest thanks for sharing some of your knowledge on the subject matter. Smile
Back to top
View user's profile
Rossetoecioccolato
Newbie


Joined: Nov 03, 2007
Posts: 23
Location: USA

PostPosted: Sat Nov 07, 2009 5:43 pm    Post subject: Re: Memory Acquisitions Reply with quote

Tsukasa Ooi has some interesting observations in his PacSec presentation: a4lg.com/presentations...it.en.pdf.
Back to top
View user's profile
alawi
Newbie


Joined: Sep 03, 2009
Posts: 7
Location: Kuala lumpur

PostPosted: Mon Feb 08, 2010 11:14 pm    Post subject: Re: Memory Acquisitions Reply with quote

Dear all

I need your help guys am try to use mdd tool to dump memory, my machine use window vista.before i used it ,it was ok but suddenly this error come when am try to dump memory.
the below is the way i run mdd and the error i got.

C:\>mdd_1.3_2.exe -o kakamana.txt
-> mdd
-> ManTech Physical Memory Dump Utility
Copyright (C) 2008 ManTech Security & Mission Assurance

-> This program comes with ABSOLUTELY NO WARRANTY; for details use option `-w'
This is free software, and you are welcome to redistribute it
under certain conditions; use option `-c' for details.

-> ERROR: CreateService failed (1073)
-> ERROR: Failed to open PhysicalMemory section!


I need to know what to do to solve this problem

Please guys advise me.

thanks.
Back to top
View user's profile AIM Address Yahoo Messenger MSN Messenger
Patrick4n6
Senior Member


Joined: Apr 11, 2009
Posts: 376
Location: Memphis, TN, USA

PostPosted: Tue Feb 09, 2010 12:13 am    Post subject: Re: Memory Acquisitions Reply with quote

Are you running as administrator?

_________________
Tony Patrick, B. Inf Tech, CFCE
www.patrickcomputerforensics.com
Back to top
View user's profile Visit poster's website
alawi
Newbie


Joined: Sep 03, 2009
Posts: 7
Location: Kuala lumpur

PostPosted: Tue Feb 09, 2010 3:17 am    Post subject: Re: Memory Acquisitions Reply with quote

@Tony Patrick
yes tony , i run it as admin
Back to top
View user's profile AIM Address Yahoo Messenger MSN Messenger
trendsec
Newbie


Joined: Feb 05, 2010
Posts: 1
Location: SouthVille

PostPosted: Tue Feb 09, 2010 5:41 am    Post subject: Re: Memory Acquisitions Reply with quote

Hi everyone,

I am new to forensics but not with system administration, i just downloaded helix, iso, its pretty much solid linux distro, i ran vmware guest os xp, place the helix (iso) as the primary boot device, but when i choose the option to test cd it presented some errors, but this is not my primary concern because i redownloaded it many times, now to get to my point i used dd- to acquire image of the ram, -- i used the GetData Mount Image Pro v3.2.6.522 to mount but no success it did present me with errors, it says drive needed to formated; what is the best way of view live ram acquisition. i'll appreciate any help, pls correct if the location of the post is not the right location. Thank you.
-------------------------------------------------------
there are 3 sources
physical memory 490 mb --- *
physical drive 0
c:\(logical drive) - NTFS 7.99 GB


this one used live view with vmware developer module downloaded
*
ERROR> The image: image.dd does not appear to be a disk file or bootable partition
Please make sure that the image file(s) you chose is a valid disk image
ERROR> Image could not be launched in the VM.
Detected VMWare Workstation Installation

i
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum Index -> Live and Network Forensics All times are GMT - 6 Hours
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Use of this website signifies your agreement to the Terms of Use/Privacy Policy available here.

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2010 Forensic Focus


Interactive software released under GNU GPL, Code Credits, Privacy Policy
.: fisubsilver shadow phpbb2 style by Daz :: CPG-Nuke port by norseman :: ported to CPG-Dragonfly by jamin :.