<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tanasi.it &#187; forensic</title>
	<atom:link href="http://www.tanasi.it/tag/forensic/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tanasi.it</link>
	<description>Alessandro `jekil` Tanasi blog</description>
	<lastBuildDate>Fri, 02 Jul 2010 11:06:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>L&#8217;Hard Disk del Columbia</title>
		<link>http://www.tanasi.it/1238-lhard-disk-del-columbia.html</link>
		<comments>http://www.tanasi.it/1238-lhard-disk-del-columbia.html#comments</comments>
		<pubDate>Sat, 07 Jun 2008 16:13:44 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[In English]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[analisi forense]]></category>
		<category><![CDATA[columbia]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[hard disk]]></category>
		<category><![CDATA[ontrack]]></category>
		<category><![CDATA[shuttle]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=1142</guid>
		<description><![CDATA[Vi ricordate la tragedia dello shuttle Columbia che esplose ad alta quota nella fase di rientro nell&#8217;orbita terrestre? Cito qualche frase da questo articolo: &#34;Researchers have finally published the results of data recovered from a cracked and singed hard drive that fell to Earth in the debris from the Space Shuttle Columbia, which broke up [...]]]></description>
			<content:encoded><![CDATA[<p>Vi ricordate la tragedia dello <b>shuttle Columbia</b> che <b>esplose</b> ad <b>alta quota</b> nella fase di rientro nell&#8217;orbita terrestre? Cito qualche frase da <a href="http://www.sciam.com/article.cfm?id=hard-drive-recovered-from-columbia&#038;sc=rss">questo articolo</a>:</p>
<p><i>&quot;Researchers have finally published the results of data recovered from a cracked and singed<a href="http://www.sciam.com/article.cfm?id=how-a-hard-disk-drive-wor"> hard drive</a> that fell to Earth in the debris from the <a href="http://www.sciam.com/article.cfm?id=editors-commentarythe-col">Space Shuttle </a><em><a href="http://www.sciam.com/article.cfm?id=editors-commentarythe-col">Columbia</a>,</em> which broke up during reentry on February 1, 2003, killing all seven crew members.</i></p>
<p><i>When the Glenn engineers learned that the hard drive had indeed survived, they sent it to <a href="http://www.ontrackdatarecovery.com/" target="_blank">Ontrack Data Recovery</a> in Minneapolis to extract whatever data remained in the cracked hard drive disk<em></em>.<br />
The data came back about 99 percent complete, but the results were so<br />
complex that isolating the shear-thinning effect took an additional<br />
several years, Berg says.&quot;</i></p>
<p>Quindi dopo un <b>esplosione</b> e una <b>caduta libera</b> spettacolare i tecnici della Ontrack sono riusciti a recupare in camera bianca la quasi totalita` dei dati. Eppur a guardare bene le <b>foto</b> di quel che rimane sembra che l&#8217;hard disk sia messo nelle stesse condizioni se non meglio che dopo un normale <b>incendio</b> &quot;terrestre&quot;, quindi prima di gridare ai miracoli della computer forensics e` bene pensare a quali accorgimenti tecnologici sono stati usati per realizzare la &quot;scatola nera&quot; per la protezione dei dati di bordo, sarebbe molto interessante aver piu` informazioni sugli accorgimenti introdotti per proteggere gli hard disk.</p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1052-analisi-forense-di-un-atm-skimmer.html" title="Analisi forense di un ATM Skimmer">Analisi forense di un ATM Skimmer</a></li><li><a href="http://www.tanasi.it/1436-recuperare-una-partizione-cancellata.html" title="Recuperare una partizione cancellata">Recuperare una partizione cancellata</a></li><li><a href="http://www.tanasi.it/1056-how-to-recover-data-and-deleted-files-from-ext3-partitions.html" title="How to recover data and deleted files from Ext3 partitions">How to recover data and deleted files from Ext3 partitions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1238-lhard-disk-del-columbia.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analisi forense di un ATM Skimmer</title>
		<link>http://www.tanasi.it/1052-analisi-forense-di-un-atm-skimmer.html</link>
		<comments>http://www.tanasi.it/1052-analisi-forense-di-un-atm-skimmer.html#comments</comments>
		<pubDate>Sat, 25 Aug 2007 17:49:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[analisi forense]]></category>
		<category><![CDATA[ATM skimmer]]></category>
		<category><![CDATA[forensic]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=996</guid>
		<description><![CDATA[I reati di clonazione di bancomat e carte di credito compiuta con l&#8217;installazione abusiva di appositi strumenti elettronici chiamati ATM Skimmer nei terminali per il pagamento elettronico o negli sportelli bancomat sono molto frequenti.Un ATM Skimmer e` un dispositivo elettronico che il criminale inserisce abusivamente in un terminale per il pagamento o per il prelievo [...]]]></description>
			<content:encoded><![CDATA[<p>I reati di <b>clonazione di bancomat</b> e <b>carte di credito</b> compiuta con l&#8217;<b>installazione abusiva</b> di appositi strumenti elettronici chiamati <b>ATM Skimmer</b> nei terminali per il pagamento elettronico o negli sportelli bancomat sono molto frequenti.<br />Un <b>ATM Skimmer</b> e` un dispositivo elettronico che il <b>criminale</b> inserisce abusivamente in un terminale per il pagamento o per il prelievo di contante, cioe` dove viene strisciata la carta di credito nei negozi o nei bancomat, e che contiene una piccola circuiteria elettronica per al fine di:
<ol>
<li><b>Clonare</b> la carta di credito</li>
<li>Annotare il <b>codice segreto (PIN)</b> che in alcuni casi viene fatta con l&#8217;installazione di una microtelecamera</li>
<li><b>Memorizzare</b> il tutto in una memoria interna</li>
</ol>
<p>Questo in sintesi.<br />Sistemi di ultima generazione possono avere un <b>collegamento</b> verso il mondo esterno, telefonico o internet (WiFi o GPRS/UMTS) per trasmettere i dati memorizzati, in modo che il criminale non debba tornare a recuperarli.<br />Il panorama e` <b>ampio</b> e varia da dispositivi tascabili, che un cameriare puo` nascondere sotto la giacca, a circuiti elettronici da inserire nei terminali di pagamento di un negozio, a veri e propri bancomat fasulli da montare sopra gli sportelli delle banche.<br />Ricordiamo che l&#8217;utente e` protetto da queste frodi dal <a href="http://www.lonerunners.net/blog/archives/1068-Contestazione-delladdebito-su-Carta-di-Credito-come-riparare-alle-fregature.html">diritto di contestazione dell&#8217;addebito</a> di cui ho gia` parlato.<br />Spesso questa tipologia di truffa viene smascherata perche` viene scoperta <b>l&#8217;infrazione fisica</b> agli ambienti per poter piazzare gli skimmer nei terminali di pagamento o perche` un gran numero di carte di credito clonate sono state usate tutte dallo stesso terminale.<br />Un <b>analisi forense</b> di uno skimmer deve esser finalizzata a:</p>
<p><b>1 &#8211; Prendere conoscenza dell&#8217;hardware elettronico:</b>
<ul>
<li>E` un prodotto che si trova in commercio? (Esistono dei prodotti creati per fare debug che potrebbero essere usati allo scopo)</li>
<li>E` un prodotto commerciale addattato?</li>
<li>E` un prodotto <b>assemblato</b> in casa?</li>
<li>Identificazione di ogni componente elettronico, e grazie ai <b>datasheet</b> messi a disposizione dalle case madri cercare di capire cosa fanno le singole parti elettroniche</li>
<li>Identificazione degli input e degli output del sistema (in particolare se il sistema e` connesso al mondo esterno)</li>
</ul>
<p><b>2 &#8211; Analisi del software</b></p>
<ul>
<li>Dump di tutto il software e delle memorie</li>
<li>Reverse engeneering del software</li>
<li>Ricerca dei dati delle carte di credito clonate (fondamentale per l&#8217;incriminazione)</li>
</ul>
<p>Di norma svolgere un&#8217;analisi forense su uno skimmer non e` un compito difficile.</p>
<p>Links:
<ul>
<li><a href="http://www.lightbluetouchpaper.org/2006/03/30/fraud-or-feature/">Fraud or feature?</a></li>
<li> <a href="http://www.cl.cam.ac.uk/%7Emkb23/research/Phish-and-Chips.pdf">Phish and Chips</a></li>
<li><a href="http://www.cl.cam.ac.uk/~mkb23/interceptor/">Chip and PIN (EMV) Point-of-Sale Terminal Interceptor</a></li>
<li><a href="http://www.cl.cam.ac.uk/research/security/projects/banking/relay/bounding.pdf">Chip and PIN security and the relay attack</a></li>
<li><a href="http://www.cl.cam.ac.uk/research/security/projects/banking/tamper/">Tamper resistance of Chip &amp; PIN (EMV) terminals</a></li>
<li><a href="http://www.lightbluetouchpaper.org/2007/05/21/distance-bounding-against-smartcard-relay-attacks/">Distance bounding against smartcard relay attacks</a></li>
<li><a href="http://www.ag.gov.au/www/agd/rwpattach.nsf/VAP/(CFD7369FCAE9B8F32F341DBE097801FF)~0001MCCOC+-+credit+card+skimming+-+final+report+to+SCAG.DOC/$file/0001MCCOC+-+credit+card+skimming+-+final+report+to+SCAG.DOC">Credit Card Skimming</a></li>
<li><a href="http://www.fi.muni.cz/%7Exkrhovj/lectures/2006_PA168_EMV_slides.pdf">EMV: Integrated Circuit Card Specifications for Payment Systems</a></li>
<li><a href="http://www.ccul.org/a_education/tips_atmfraud.cfm">Sample ATM Skimmer Device</a></li>
</ul>
<ul class="related_post"><li><a href="http://www.tanasi.it/1238-lhard-disk-del-columbia.html" title="L&#8217;Hard Disk del Columbia">L&#8217;Hard Disk del Columbia</a></li><li><a href="http://www.tanasi.it/1056-how-to-recover-data-and-deleted-files-from-ext3-partitions.html" title="How to recover data and deleted files from Ext3 partitions">How to recover data and deleted files from Ext3 partitions</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1052-analisi-forense-di-un-atm-skimmer.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to recover data and deleted files from Ext3 partitions</title>
		<link>http://www.tanasi.it/1056-how-to-recover-data-and-deleted-files-from-ext3-partitions.html</link>
		<comments>http://www.tanasi.it/1056-how-to-recover-data-and-deleted-files-from-ext3-partitions.html#comments</comments>
		<pubDate>Sat, 04 Aug 2007 19:51:00 +0000</pubDate>
		<dc:creator>jekil</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[In English]]></category>
		<category><![CDATA[Techie]]></category>
		<category><![CDATA[ext3]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[recover]]></category>
		<category><![CDATA[recover deleted files]]></category>
		<category><![CDATA[recover files]]></category>

		<guid isPermaLink="false">http://localhost/wordpress/?p=998</guid>
		<description><![CDATA[A lot of times aroud the net i read posts like &#34;help help! my cat walking over my keyboard delete some files and i must recover it&#34; and a lot of times the answars is &#34;you can&#8217;t undelete or recover files from ext3 partitions, i am sorry&#34;.This is wrong. Files from ext3 partitions can be [...]]]></description>
			<content:encoded><![CDATA[<p>A lot of times aroud the net i read posts like &quot;<i>help help! my cat walking over my keyboard <b>delete</b> some files and i must recover it</i>&quot; and a lot of times the answars is &quot;<i>you can&#8217;t <b>undelete or recover files from ext3 partitions</b></i>, i am sorry&quot;.<br />This is wrong.</p>
<p><b>Files from ext3 partitions can be recovered</b>. Found <b>evidence</b> and<b> recover files</b> from file systems is a common task of a forenser.</p>
<p>Example : We see how try to recover data from a partition, like /dev/sda1.<br />First of all you need a dump, a copy of our partition where we can work:</p>
<p><font face="courier new,courier,monospace">dd if=/dev/sda1 of=dump.dd</font></p>
<p>Now install <a href="http://www.sleuthkit.org">Sleuth Kit</a>, and to view all of the <b>deleted file names</b> in an image use:</p>
<p><font face="courier new,courier,monospace">fls -rd dump.dd | less</font></p>
<p>This shows us the full path that the deleted files are located. <br />The number at the beginning of the line is the inode number. <br />The &#8216;*&#8217; shows that it is deleted and the &#8216;d&#8217; and &#8216;r&#8217; show the type (directory and file). <br />The first letter identifies the directory entry type value (which does not exist in all file system types) and the second letter is the type according to the inode. <br />In most cases these should be the same, but it may not for deleted files if the inode has been reallocated to a file of a different type.<br />We can examine an inode using istat, here i examine inode number 123:</p>
<p><font face="courier new,courier,monospace">istat dump.dd 123</font></p>
<p>To identify the group where the file that we want to recover is in we get the list of file system groups:</p>
<p><font face="courier new,courier,monospace">fsstat dump.dd</font></p>
<p>Now we can identify tha inode range, like 45 &#8211; 67, that we want. To search<br />
for the deleted file, we extract the unallocated space:</p>
<p><font face="courier new,courier,monospace">dls dump.dd 45-67 &gt; files.dls</font></p>
<p>We can analyze files.dls with a <b>data carving software</b> like <a href="http://foremost.sourceforge.net/">foremost</a> or the great <a href="http://www.cgsecurity.org/wiki/PhotoRec">photorec</a> and we get all recovereble files.</p>
<ul class="related_post"><li><a href="http://www.tanasi.it/1238-lhard-disk-del-columbia.html" title="L&#8217;Hard Disk del Columbia">L&#8217;Hard Disk del Columbia</a></li><li><a href="http://www.tanasi.it/1052-analisi-forense-di-un-atm-skimmer.html" title="Analisi forense di un ATM Skimmer">Analisi forense di un ATM Skimmer</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.tanasi.it/1056-how-to-recover-data-and-deleted-files-from-ext3-partitions.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
