Wednesday, May 21, 2008

Lab 8 Hardy Weinberg Answers

University of Cream, the company and before DFLabs DEMO

Successful participation at the event in collaboration with the Università degli Studi di Milano - Polo di Crema, in the path information "meetings with companies." More than 100 people, including people in attendance and connected stream, followed and interacted with the seminar held by prof. Forte on "The new IT professionals: Digital Forensics." For those who could not follow the event, are shown later in this post the links to records (in audio version only or audio + video) of the seminar. During the second part of some employees of prof. Forte, presented the first demo of the project (PTK ptk.dflabs.com). We recall in this connection that Friday, May 30th, 18:00 GMT +1, the webcast presentation will be held in English, to coincide with the release of the beta version of the project. In the wake of the interest shown for the project PTK, followed by other seminars focused on the use of same and different features, Università degli Studi di Milano - Polo di Crema. Finally we want to thank all participants and the people who took you for your interest.

Video:
http://www.dti.unimi.it/files/seminario/allegati/20080519_dflabs.wmv

Audio only:
http://www.dti.unimi.it/files/seminario / allegati/20080519_dflabs.mp3

Wednesday, May 14, 2008

Can You Play Heartgold

PTK Meeting with the company DFLabs - Managing Infosecurity Risks

meeting with the

MONDAY 'May 19, 2008 at 14:30,
DTI Crema, Via Bramante 61

Seminar: New
professions' Computer: Digital Forensics
Rapporteur: Dario Forte, CEO of DFLabs Lecturer and Course Manager computer incidents to the DTI


Abstract:
The IT world is now changing, and with it the security sector. The Digital Investigation is a well-established discipline whose expertise was brought into vogue by the media including television. The DTI Crema has a tradition of excellence in the field, among other high demand from the world of work. The project will introduce the subject, with numerous case histories, ending with a thorough assessment of job opportunities in the industry.


PARTICIPATION

The seminar will be public and free admission to all stakeholders, both internal and external to the Department of Information Technology. Within the seminar will be presented for the first national demo beta PTK the new Italian project of Computer Forensics, is intended to be the advanced interface Sleuthkit.

Tuesday, May 13, 2008

Football Cake Raiders

Issued AFFLIB 3.2 with support for public key cryptography






E 'Today's announcement of the new version of the well known libraries AFF who since 2006 continue to evolve due to intensive development work Simson L. Garfinkel. The new version introduces a number of improvements in the control range of 'integrity copies and confidentiality of data. It 'now possible to run on the images produced, both in size that AFD AFF, two basic steps:

  • Signature Encryption
With regard to the signing process, the advantages are of course many, first of all the not having to delegate the entire processs of integrity to the use of hash algorithms such as MD5 or SHA1 but you can use asymmetric key digital signatures is in the process of generation of Forensic Images and during the process of creating copies of evidence. The whole process of Chain of custody is preserved and signed within the metadata that accompany any evidence.

Support all'encryption instead allows you to store data securely. The algortimo on which is AES-256 and, unlike some of protection mechanisms for evidence files with password, AFF provides that, unless Brute Force Attack, you can not access the content in light of the data bypassing control structures.

References: http://www.afflib.org/affcrypto.pdf


PTK, already able to recognize and AFF file import, support, in its Stable (September 2008), the entire process of managing evidence AFF 3.0.

Wednesday, May 7, 2008

Silverado Rockstar Wheels

Memory Dump Keyword Search

continue to be added new features to PTK. This week we want to propose an important role in analyzing the contents of a RAM Dump. Often one of the most important, as rigurda memory analysis, is to try to detect the presence of content is not saved to disk or encrypted on the HD but not in RAM. An example of this activity can be the search for saved passwords in certain sections of memory. May know the password authentication sessions related to web security systems or data encryption (ex. Truecrypt) or others for other purposes. The recovery of this information could greatly facilitate the analysis process of permanent storage media, without having to slow you down with long processes of password cracking. The new features section, thus providing a keyword search using standard keyword that is through the use of regular expressions.

Convinced that this new feature will collect a lot of interest we offer a screenshotsdi PTK in action.