Those of you familiar with CSI (or have surely heard of it) are all too familiar with the process they use to catch the criminals - scientific analysis, forensics, gadgetry, and smarmy head investigators. Reoccurring themes include DNA analysis or other types of human-related evidence. However, in the information world, catching a criminal after the crime is in another league of its own. This article presents an account of a recent DefCon presentation which focused on breaking the actual forensics software used to analyze compromised systems. The most interesting line in the article referred to the weaknesses in one of the most popular forensics tools - "Most of these can and will be fixed in the near future, but at least one is a design flaw, not a bug.". Read on to find out how your forensics tools are only as good as the makers of them, and how it can result in a perfect getaway. . The link for this article located at The Inquirer is no longer available. . Disruption in forensic software can severely affect digital investigations. If data recovery tools fail, it risks the integrity of evidence, leading to errors and misjudgments. Forensics Tools, Security Analysis, Digital Forensics, Cybersecurity Techniques, Software Vulnerabilities. . LinuxSecurity.com Team
Remote-Exploit has announced the release of BackTrack 2.0, SLAX-based live CD with a comprehensive collection of security and forensics tools: After many months of work, we're finally happy enough with BackTrack to call it v.2.0 Final. . New exciting features in BackTrack 2: updated kernel 2.6.20 with several patches; Broadcom-based wireless card support; most wireless drivers are built to support raw packet injection; Metasploit2 and Metasploit3 framework integration; alignment to open standards and frameworks like ISSAF and OSSTMM; re-designed menu structure to assist the novice as well as the professional; Japanese input support - reading and writing in Hiragana, Katakana and Kanji. The link for this article located at LinuxTracker is no longer available. . New exciting features in BackTrack 2: updated kernel 2.6.20 with several patches; Broadcom-based wir. remote-exploit, announced, release, backtrack, slax-based, comprehensive. . LinuxSecurity.com Team
The Auditor security collection is a GPL-licensed live CD based on Knoppix, with more than 300 security software tools. Auditor gives you easy access to a broad range of tools in almost no time. . How can Auditor help you with IT security? Many security engineers arrive on a client's site and find that the network documentation required for solving the task properly is incorrect or even obsolete. In Auditor's Scanning submenu you'll find the Nmap network scanner. You can choose the traditional shell version or Nmap FE, which provides a graphical front-end for Nmap. After you have gained a basic overview of the network you can use NBTScan, a NetBIOS name scanner, and Nessus, a vulnerability scanner. If the audit includes Web applications, try the Nikto and Amap application scanners. Let's say you've been called in to examine a possible compromised server, and until the integrity of the server has been established you are not allowed to install any forensic software or even take the server offline. You can take your Auditor CD and start running the chkrootkit utility to see if any known rootkits are installed on the server. If you find any suspicious activity, you can take a disk image with the dd command and examine it for any possible rootkits or strange processes. You can also use the Autopsy Forensic Browser, a graphical interface that can analyze Windows, Linux, and BSD file systems (NTFS, FAT, Ext2/3) to search for files. If you are analysing a Linux or Unix system, you can use Nibbler to extracts known offsets from binaries to find hidden trojan horses. The link for this article located at linux.com is no longer available. . How can Auditor help you with IT security? Many security engineers arrive on a client's site and fin. auditor, security, collection, gpl-licensed, based, knoppix, secur. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.