Saturday, February 23, 2013

GPS Improved Accuracy

GPS Improved Accuracy

Research conducted by Universidad Carlos III de Madrid (also known as UC3M) have found they can boost conventional standard GPS devices by a magnitude of 90% and significantly decrease the margin of error to improve positioning and location. UC3M see an objective to integrate their system into smartphones. This could assist the emergency services to improve pinpointing in emergency cases, in addition to added capability where handsets have modules included using existing conventional GPS capability.

A system that improves the precision of GPS in cities by 90 percent - http://www.uc3m.es/ 

Tuesday, February 19, 2013

Smart Device Usage

The latest report from Flurry reported through Venturebeat, a website that reports China technology usage, confirms China has out smart device usage that of the US. Moreover because the US only has 310-million population and China has 1.3-bilion population it is unlikely, Flurry believes, the US will ever rise to the top usage spot again because of population sizes. Well maybe so, but population size isn't all it is about, but requires regulation, liberalisation, free markets and economic indicators etc, too. What is interesting is that Flurry also envisage the only possible competitor to matching China's growth in smart device usage could probably come from India, which the report states has a 1.2-billion population.

A short note in the report identified other countries having growth in smart device usage. "Countries that grew faster than China in the past year were Columbia, Vietnam, Turkey, Ukraine and Egypt."

See report here: China becomes the world’s largest smartphone market - http://venturebeat.com/2013/02/18/china-becomes-the-worlds-largest-smartphone-market/

Further reading on possible outcomes for Chinese OSs - Originals and Copies. Britain and Smartphone Manufacturing http://trewmte.blogspot.co.uk/2012/10/originals-and-copies-britain-and.html

Sunday, February 17, 2013

Cyber Wrapping

Susan Brenner has had published her article 'Cyber-threats and the Limits of Bureaucratic Control' published in MINN. J. L. SCI. & TECH. [Vol. 14:1] and downloadable from the link below. Susan's brief synopsis is available here: http://cyb3rcrim3.blogspot.co.uk/2013/02/fyi-maybe-new-article-on-cyberthreats.html. A further link to material for review is here: University of Minnesota http://conservancy.umn.edu/handle/144222.

This is a very useful and informative article from Susan and sets out challenges about understanding the impact of 'cyber-' and how a "State" copes with control of such threats.

The marketplace is burgeoning with 'cyber courses' e.g. with content such as: "cyber attack and defense, digital analysis, computer forensics, security policies and strategies, risk analysis, ethical and legal issues, operational processes, cyber crime, and more" (http://www.excelsior.edu/web/news/college-news/-/blogs/five-cybersecurity-programs-certified-to-meet-the-nsa%E2%80%99s-committee-on-national-security-systems-cnss-training-standards) which appears to suggest cyber people have been unable to distinguish cyber as a platform of its own without subsuming e.g. computer forensics and therefore dismantling this job title and work in an attempt to top it.

My original thinking when getting to grips to understand what the cyber-people wanted to show when the approach started back in 2000 was that, irrespective of the technology, it is the fundamental messages/signals, instructions or information included and transmitted through electrical impulses, analogue/digital signalling and so on would complement existing investigatory, examination and forensics programmes and employment and tools. Instead, cyber appears to want to cast a veil over all of these mature approaches to make everything science/technology neutral and claim they are subsets of cyber.

Fundamentally, cyber is a subset to all forms of communication mediums, transmitters and receivers and the technology that interprets communications and signalling. Moreoever cyber-attack/crime/etc is a 50/50 proposition and a subset of "intention" (pragmatically and legally) and must be judged in that context when compared to a "mistake" where the person had no intention to generate an attack but an unwanted outcome occurs anyway.

Download: http://conservancy.umn.edu/bitstream/144222/1/Cyber-Threats-by-Susan-Brenner-MN-Journal-Law-Science-Tech-Issue-14-1.pdf

Sunday, February 10, 2013

One hit, hits all

As you know setting a 'percentage expectation' for disruptive events is common in any operating plan, QoS plan, security plan etc. Contingency (forward planning) of something that might/may happen as a percentage factored in advance in order to ensure support being available is standard practice.

The author Henry Basset's 'Red Sky Alliance' records in his blog (http://henrybasset.blogspot.co.uk/2013/02/attackers-collaborate-defenders-are.html):

"20-50 compromised computers per day (7 days/week) could (should) be expected."

The article does not state that 20-50 will happen daily. Moreover, it is very difficult to reconcile how events happening on weekdays will equally occur in the same percentage on weekends due to staff not working at that time, thus terminals not being used in the workplace, which is another factor suggesting the statement is geared towards forecast or contigency rather than actual fact.  

It is not entirely clear either that the 'inventory computers' could corroborate a computer identified in that inventory being the disruptive source, as opposed to merely being a compromised device, thus repetition of events could continue to be propagated against that same device. A reason for that is that an inventory of computers may not take account for 'BYOD devices' (http://www.trewmte.blogspot.co.uk/2013/01/smartphone-byod.html), which, quite horrifically, are being proposed for business. Laundering such ideas as relevant, cost-effective (sorry, a cheap way for a company to provide IT/comms without cost to the company) and a must-have, apparently, on employee-centric wish-lists crudely ignores common-sense security policies, practices and procedures. Moreover, BYOD is more likely to increase the chances of ICT (information communications technology) disruption/compromise, which is crudely labelled 'cyber attack/crime'. Cyber attack/crime is itself is being used in an attempt to downgrade the important differences and characteristics between science technologies by applying to them a technology-neutral title, 'cyber' (c.f. Andrea C Simmons comments about cyber wrapping http://www.bcs.org/content/conBlogPost/1861 )

Promulgating the noun/adjective/verb 'cyber-', lauded as the title of the next big threat to the World will in itself generate changes down the line eventually forcing Governments to create localised technology standards to deliberately undermine and reduce the chances of global cyber attacks/crimes occuring based upon common code used by many countries. This perhaps can be illustrated in terms of  the enormous economic and fiscal effort that has gone into maintaining the 'Euro' contrasted with the 'British Pound'. Were it the case the Euro actually went down the localised British Pound would still be there. Local individual currency proving a far sounder bet than global common currency. Or looked at from a different angle, if a local individual currency did go down it wouldn't drag down other currencies partners. This tends to reinforce the positive that 'local standards' offer far better security and protection but minimises disruption, whereas global standards create the greater threat of 'one hit, hits all'.

EMV and ePayments

ParseIT
As some of you may know I have over the last several years been extending the range of my skillsets, beyond previous skills of mobile devices/PCs/laptop/MACs, to include EMV and the known CVV (Card Verification Value) code that is stored in the card’s magnetic stripe and iCVV (Integrated Chip Card Card Verification Value) code that is stored in the card’s chip. This work into includes the range of payments systems that are already or will be introduced to smart phone payment systems.

The transactional data contained in the 'exchange messages' are of paramount importance to post-fraud investigations; in the absence of an actual physical instrument involved in the originating activity associated with a transaction. Having the ability to examine copies of the original transactional data contained in electronic files requires a tool designed to output the field data into the known field structures/parameters as set out by iso8583. ParseIT is one of those free tools that provides a useful starting point to output the data to assist an investigation.

- ParseIT is a parser tool to analyze transactional messages from raw data and logs.
- ParseIT provides a simple and effective way to fast detect, parse and compare messages.
- The intuitive interface provides quick access to the fields of the message, their value, their description and their validation.

Because its free and doesn't require a commercial, then it is worth including in the investigators' soft toolkit.

http://www.kasys.ca/parseit.php

Download - http://www.kasys.ca/parseit/update/setup.exe

Sunday, January 27, 2013

Judge for yourself

I noted the reference made by Talwant Singh, Member (Judicial), E-Committee of Supreme Court of India, to a quote made by Hunter S Thompson ( http://en.wikipedia.org/wiki/Hunter_S._Thompson ) recently:  “We cannot expect people to have respect for law and order until we teach respect to those we have entrusted to enforce those laws.” Quite refreshing to see a senior public figure conversing in a language and using references understood by ordinary man and woman in the street. A few members of the British Judiciary I can recall in my life time over the last 50 years who were spoken about that endeavoured to keep that common touch: Lord Denning, Lord Wilberforce, Lord Woolf, Lord Bingham. I did hear from a few barristers, they thought, that Lord Justice Judge had endeavoured to make a good fist of it in keeping the lines of communication open. There are no doubt many others that are not on my radar but might be on yours. Have a look at wikipedia and see if there are any there that you know?

http://en.wikipedia.org/wiki/Master_of_the_Rolls
http://en.wikipedia.org/wiki/Category:British_judges

A barrister with a common touch whose work I learned about at school and on television (when I was growing up) was Edward Marshall Hall ( http://en.wikipedia.org/wiki/Edward_Marshall_Hall ).  So worth having a read about his work, too.

I have digressed slighly, sorry, from what I originally set out to say. So turning back to that intended topic, but non-judicial thought this time, that is this is not the first time a man from India has endeavoured to communicate with people from all walks of life. You may think I would reference Mahatma Gandi ( http://en.wikipedia.org/wiki/Mahatma_Ghandi ) at this stage, and that would be an excellent reference choice to make, but, no, I have someone else in mind: Joseph Rudyard Kiplinghttp://en.wikipedia.org/wiki/Rudyard_Kipling ). Kipling wrote that great and wonderful poem 'IF'. A poem that might rightly take its place in learning materials for school children. This poem teaches a wide range of communications skills (used in the english language) and social skills and at the same time seeks to empower each person to be an individual, keep inner strength, and at the same time not lose personal identity and values. Importantly, it defines that anyone should be able to talk with anyone no matter who they are.

If

If you can keep your head when all about you
Are losing theirs and blaming it on you;
If you can trust yourself when all men doubt you,
But make allowance for their doubting too;
If you can wait and not be tired by waiting,
Or, being lied about, don't deal in lies,
Or, being hated, don't give way to hating,
And yet don't look too good, nor talk too wise;

If you can dream - and not make dreams your master;
If you can think - and not make thoughts your aim;
If you can meet with triumph and disaster
And treat those two imposters just the same;
If you can bear to hear the truth you've spoken
Twisted by knaves to make a trap for fools,
Or watch the things you gave your life to broken,
And stoop and build 'em up with wornout tools;

If you can make one heap of all your winnings
And risk it on one turn of pitch-and-toss,
And lose, and start again at your beginnings
And never breath a word about your loss;
If you can force your heart and nerve and sinew
To serve your turn long after they are gone,
And so hold on when there is nothing in you
Except the Will which says to them: "Hold on";

If you can talk with crowds and keep your virtue,
Or walk with kings - nor lose the common touch;
If neither foes nor loving friends can hurt you;
If all men count with you, but none too much;
If you can fill the unforgiving minute
With sixty seconds' worth of distance run -
Yours is the Earth and everything that's in it,
And - which is more - you'll be a Man my son!

Lastly, because maintaining a common touch is an important life skill, there is something else about the poem 'If' which has an interesting reference. According to the Kipling Society, Rudyard Kipling knew Cecil Rhodes, Lord Milner and Dr Jameson ( http://www.kipling.org.uk/kip_fra.htm ) and it is the qualities of these men that inspired the peom 'IF'. Why might this be of interest? Messrs Milner and co were sent on an errand to South Africa as the British Government had received word that some British land and mine owners had allowed their avarice and greedy to get so out of control they had decended into total loss of control of their positions, property and money. When Lord Milner and entourage arrived at site the owners were living in the servants' sheds in drunkenness, filth and depravity, whilst the servants were living in the owners' mansions, wearing the owners clothes and spending their money. Milner looked to immediately establish a refreshment on education for these land and mine owners and took skills taught at Toynbee Hall in the EastEnd of London. Toynbee Hall it is known is renowned for it educational principles and later adopted by Hull House in Chicago. Hull House, as you may know, formed the first edcuational programme that later became the foundation for the Open University. Milner's work resulted in the education programme in South Africa being called the 'Kindergarten', which taught that even rulers need humility if they are to communicate with people they expect will serve them. It does make me wonder whether Milner, Rhodes and Jameson had sought observations from Kipling learned from his life skills and whether the poem 'IF' contains elements from conversations which Rudyard Kipling had with these men due to their friendship?

Friday, January 25, 2013

Kindness Cures Recession

Kindness Cures Recession

Such a simple act, yet its remedies are far reaching.

Kindness is an act of generosity without expecting or demanding
anything in return.

Kindness Cures Recession.






Tuesday, January 22, 2013

S**T Talker

No doubt most of us, one time or another, have experienced a deja vu moment. A feeling of fleetingly living the same life-experience again. I think moments like this are summed up brilliantly by Pink Floyd in the words of the song Comfortably Numb:

"When I was a child
I caught a fleeting glimpse
Out of the corner of my eye

I turned to look but it was gone
I cannot put my finger on it now
The child is grown
The dream is gone
I... Have become comfortably numb
"

Anyway, I digress slightly, but hope it conveys what I was thinking, feeling when I was listening to a Music Radio Station, I believe it was Magic 105.4, and the people in the studio were having a laugh and messing around with an american female 1970s style electronically synthesized voice. You may recall the sort of thing if you had seen repeats of early versions of Department S, Mission Impossible, Ironside and so on and those voice distortion devices that were placed against the phone mic to disguide the voice of the caller.  It was at this moment, when I heard it on the radio that my mind was racing, where had I heard something similar in electronic voice alteration/manipulation? Having racked my my mind for a few days I realised that it reminded me of a computer program called Shit Talker.  I unreservedly apologies to readers of this blog, I am not being offensive, it is the name of the program.

Although we had some laughs in the office; believe it or not, it is relevant to investigations when checking out hoax and other types of calls. Of course, today, with voice detection and recognition techniques these type of programs do not present a problem. But if, sometime, you want to have a laugh in the company of friends then the program is still available http://unaesthetic.net/st/dl.shtml . I wouldn't use it on the phone though, it isn't a good idea.

Monday, January 21, 2013

Smartphone BYOD

Smartphone BYOD

The article about Application Performance Management highlights five factors to influence APM in 2013. Approaching APM not from the service angle (end-to-end interoperability) but what the user gains from it is an uncertainty with BYOD (e.g. mobile tablet etc), as stated by the article. BYOD is not simply about browsing habit to prove an issue or trend but whether such devices are used (a) as company property? (b) what work material is available? (c) is that on-site access or off-site access? (d) are external private access points accessible? (e) are there, regarding (d), obligations to reveal? .....and so on

During the heady parts of the recession, and even now, many companies operational costs and write down (depreciation) on operational assets (phones, computers etc) have been slimlined and moved some obligations on to staff to use their own smartphones and tablets, thus the company also realises reductions in capital expenditure by avoiding mobile services contracts, too.


Strange that so much effort and money has been spent and is being spent on cybercrime detection and prevention and yet the more likely statistic as to where an ICT attack would occur seems not to be determined from yet another market survey but plain, good old-fashioned common sense. If employees bring their own devices to work employers cannot legislate as to what happens whilst at work. If employers don't pay for communications devices/services because they want to turn an operating profit or 'twinkle' before their shareholders then it is not difficult to comprehend, from a security point of view, that smartphones are potential carries of 'digital infection' that are deliberately being allowed to propagate with BYOD. National societies have watched over the last two decades at the decay in common-sense and seen the removal of barriers that locked pandora's box shut. Why have the barriers been taken away? For the sake of emotional gratification of earning a short-term profit, globalisation and commercialisation that required reduction and removal of local barriers originally put in place by mandatory regulation.  

The task for digital investigators is to now re-engage with digital access policies in companies and discover the implemented and evolving communications route plan.

http://www.apmdigest.com/compuwares-top-5-apm-predictions-for-2013

Additional research

zdnet - http://www.zdnet.com/byod-mobile-workers-thumbing-nose-at-it-security-7000003519/

Forbes - http://www.forbes.com/sites/markfidelman/2012/05/02/the-latest-infographics-mobile-business-statistics-for-2012/
 

 Network World - http://www.networkworld.com/news/2012/061912-byod-20somethings-260305.html

Monday, January 14, 2013

Programming Mobile Parameters - the new area of mobile forensics

Programming Mobile Parameters - the new area of mobile forensics

Shortly I shall be running a course at the LinkedIn MTEB Subgroup 'ForensicMobex' identifying parameters programming for mobile phones. The purpose of the course is in support of the discussion at http://trewmte.blogspot.co.uk/2012/10/mobile-examination-hw-sw-considerations_29.html that access to evidential data goes beyond the common selection and choice of data extracted and harvested by mobile phone forensic tools.

The material for this course originates from of the MTEB mobile phone programming course.

The image (see weblink below) shows many parameters involved in programming a mobile phone and the image represents just one of the many pages, each of which shall be explored and discussed:

http://tinyurl.com/bjd4az8

The second image (see weblink below) in the top left hand corner identifies the radio transmissions technologies that can be discussed dependent on the interest of the group:

http://tinyurl.com/byvgl9q

To join the course requires participation from each stakeholder joining and those who have already joined this group.

Sunday, January 06, 2013

Mobile Phone Examiner Exam Guides

Discussion held at ForensicMobex (MTEB subgroup) on LinkedIn.

Mobile Phone Examiner Exam Guides

It has been noticed that a number of the mobile phone examiner exam guides set out to suggest the questions in the guide will help the person sitting the exam to pass the exam. However, some of the questions can be confusing in the way they have been stated.

In running this series of responses, the responses are not intended or desired to be critical of anyone or examining body. The following series of responses are merely produced to offer helpful observations to answering those exam questions.

Just follow the discussions marked as Mobile Phone Examiner Exam Guides 2,3,4, etc

Friday, January 04, 2013

Cellphone Surveillance

Cellphone Surveillance

Have you ever tried traversing the ground (metaphorically speaking) between two opposite and opposing opinions? It is never easy. Here is an informative and interesting short article (weblinks below) on how far cellphone surveillance generates contentions. The Courts faced between balancing the needs of law and governance, (unelected) government - that of public servants using technology as a tool in the need for surveillance and detection of crime - and those of the citizen living in a democracy.

The reference materials used in the article are most important as they underpin the author's opinion to establishing the believed causal link to effect and affect (I guess) - that of surveillance gluttony at a cost to deminishing democracy and freedoms. The other side of that coin, which in fairness is not extrapolated at all to the same degree in this article, that of what has surveillance and detection achieved? I am mindful that the Judges founded their Court rulings on the evidence before them and the article illuminates the fulcrum for this is that 'things' get pushed too far for comfort when it comes to infringing law and governance and citizen's freedoms. The article appears to suggest (but I accept I could have misunderstood the message) that totalitarism is the occupational desire of (unelected) government in order for it to perform and to provide treatment to a problem or issue.


http://reason.com/archives/2012/12/17/your-cellphone-is-spying-on-you?goback=.gde_128064_member_199071347

http://reason.com/archives/2012/12/17/your-cellphone-is-spying-on-you/1

Tuesday, January 01, 2013

Directory of Data Recovery Soft Tools

Directory of Data Recovery Soft Tools

Practitioners of eDiscovery or data recovery approach the matter from many angles. Primarily, any ESI (electronically stored information) data requires understanding and analysis of devices and systems which may contain/store the ESI. Take the eDiscovery issue. There are the argumentative issues of what is viewable and what is not:
  
"If there is a large volume of ESI, you should discuss the best method for it to be searched, collected, filtered and reviewed with your lawyer."
www.out-law.com/en/top...privilege/


However, there is a myraid of issues involved prior to even enabling ESI to become visible and legible. Indeed, tools that can be used for common and standard office based systems can have limited or absolutely no effect for industrial based devices and systems. Today's savvy investigator is not only expected to technology aware but also technology astute where ESI is concerned:

"A typical smart phone contains a 2 GB removable memory card, which can contain the equivalent of 40 banker’s boxes of paper, or 100,000 pages."
A Litigation Neccesity: Electronically Stored Information (ESI) Review Tools
 

This is not an exhaustive directory listing below and even then I shall need to add another 400 entries or more as there are so many varieties out there. If your product is not listed here send an email to me (trewmte@gmail.com) with details and I shall include it in the directory list.

Updated List 22/01/2013
Elcomsoft EPRB, Elcom Soft Co. Ltd - Password, Recovery (http://www.elcomsoft.com/)
Unstoppable Copier, Roadkil - Damage recovery (http://www.roadkil.net/)
DataGrab, Foolish IT - Desktop, Recovery (http://www.foolishit.com)
TCHunt, 16 Systems - Recovery, Forensic (http://16s.us/TCHunt/index.php)

Directory List Started 01/01/2013
Avanquest, Stellar Phoenix - Rescue, Recovery (http://www.avanquest.com/)
GetData, RecoverMyFiles - Recovery (http://www.recovermyfiles.com/

CnW Recovery - Forensic, Recovery (www.cnwrecovery.com)
PureDarwin - Rescue
Live Android - Rescue
Blackberry - Recovery, Rescue
AccessData FTK - Forensic
EnCase - Forensic
DidJiX - Media Production
Slax - Desktop, OS Installation
Puppy Linux - Desktop
Passmark, OSforensics - Rescue, Password
Securemac - Resecue, Password
John the Ripper, Resecue, Password
Arch Linux - OS Installation, Rescue
Linux Mint - Desktop, OS Installation
Tails - Secure Desktop
Tiny Core Linux - Desktop
Passware Inc, Rescue Password
OSXDaily, Rescue, Password
Oxid.it, Rescue, Password
AVG Rescue CD - Windows Antivirus
Redo Backup and Recovery - System Administration
Finnix     - System Administration
BackBox - Security
Ubuntu Mini Remix - Desktop
Edubuntu - Education, OS Installation
Kubuntu - Desktop, OS Installation
Lubuntu - Desktop, OS Installation
Ubuntu     - Desktop, OS Installation
Ubuntu Studio - Media Production
Xubuntu - Desktop, OS Installation
GParted LiveCD     - System Administration
Parted Magic - System Administration
CAINE     - Forensics
ArtistX - Desktop
Slackware (Disc 1) - Rescue
GeeXboX - Home Entertainment
Bodhi Linux - Desktop
Sabayon  - Desktop, Gaming, OS Installation
SystemRescueCD - Rescue
Scientific Linux - Desktop, OS Installation, Rescue
PCLinuxOS - Desktop, OS Installation
Knoppix  - Desktop, OS Installation
AV Linux - Media Production, OS Installation
BackTrack - Security
Synergy Linux - Desktop, OS Installation
antiX     - Desktop, OS Installation
Bridge Linux - Desktop
Damn Small Linux  - Desktop, OS Installation
Zeroshell - Firewall
Kororaa  - Desktop, OS Installation
CentOS     - Desktop, Rescue
BitDefender Rescue CD - Windows Antivirus
Porteus  - Desktop
Clonezilla - System Administration
F-Secure Rescue CD - Windows Antivirus
VectorLinux - Desktop, OS Installation
Fedora Design Suite - Media Production
Fedora Desktop Edition - Desktop, OS Installation
Fedora Electronic Laboratory - Science
Fedora Games Spin - Gaming
Fedora KDE Plasma Desktop Spin - Desktop, OS Installation
Fedora LXDE Desktop - Desktop, OS Installation
Fedora Robotics Suite - Robotics
Fedora Scientific - Science
Fedora Security Lab - Security
Fedora Xfce Spin - Desktop, OS Installation
Grml - Rescue, System Administration
Sugar on a Stick - Education
Kanotix - Desktop, OS Installation
Ophcrack LiveCD - Security
Chakra     - Desktop
Lightweight Portable Security - Secure Desktop
ArchBang - Desktop
Mythbuntu - Home Entertainment, OS Installation
Ubuntu Cloud Live - System Administration
Ubuntu Rescue Remix - Forensics, Rescue
Swift Linux - Desktop
Snowlinux - Desktop, OS Installation
SliTaz     - Desktop
Gentoo     - OS Installation, Rescue
GNOME Live Media - Desktop
XBMCbuntu - Home Entertainment
Càtix     - Desktop
DragonFly BSD - Desktop, OS Installation
Parsix     - Desktop
paldo     - Desktop
ReactOS - Desktop
KahelOS - Desktop
DEFT Linux - Security
GhostBSD - Desktop
PC-BSD     - Desktop, OS Installation
Webconverger - Kiosk
Dreamlinux - Desktop
aptosid - Desktop, OS Installation
austrumi - Desktop
pfSense - Firewall
REMnux     - Security
TurnKey Linux Development - Server, System Administration
Ubuntu Privacy Remix - Secure Desktop
Ultimate Edition - Desktop
CrunchBang Linux - Desktop, OS Installation
openSUSE - Desktop, OS Installation
CDlinux - Desktop, Rescue
jggimi     - Desktop
Berry Linux - Desktop
Hiren's BootCD     - Diagnostics, Rescue, System Administration, Windows Antivirus
Knoppix Japanese Edition - Desktop
Debian     - Desktop, OS Installation, Rescue
BSDRP     - Firewall
Avira AntiVir Rescue System - Windows Antivirus
Baltix     - Desktop
OpenIndiana - Desktop, OS Installation, Server
PelicanHPC - Clustering
dyne:bolic- Desktop, Media Production
Mandriva - Desktop
Plop Linux - Rescue
Toorox     - Desktop
Network Security Toolkit - Security
Ultimate Boot CD - Diagnostics, Rescue, System Administration
stresslinux - Diagnostics
Symphony OS - Desktop, OS Installation
Forensic Hard Copy - Forensics
RIPLinuX - Rescue
OpenDiagnostics Live CD - Diagnostics, Windows Antivirus
MeeGo - Desktop
Thinstation - Thin Client
linuX-gamers.net live - Gaming
Zenwalk Live - Desktop
FuguIta - Desktop
MEPIS - Desktop, OS Installation
Trinity Rescue Kit - Rescue
Bootable Cluster CD - Clustering
Kaspersky Rescue Disk - Windows Antivirus
m0n0wall - Firewall
SuperGamer - Gaming
Devil-Linux - Firewall
Knoppel - Desktop
Windows PE - OS Installation, Rescue, System Administration
PLD RescueCD - Rescue
TiNA Knoppix - Science
Doscore - Desktop
redWall Firewall - Firewall
4MLinux - Server
Pardus Live CD - Desktop
LinuxConsole  - Gaming
Openwall GNU/*/Linux - Server
PC Tools Alternate Operating System Scanner - Windows Antivirus
Puppy Arcade - Gaming
SchilliX - OS Installation
Vyatta Core - Firewall
ULTILEX - Desktop, Rescue, System Administration
Frenzy     - Rescue, Security
T2 @Live - Desktop
Guadalinex - Desktop
Panda SafeCD - Windows Antivirus
Bio-Linux - Science
Darik's Boot And Nuke (DBAN) - System Administration
LiveCD-OpenBSD     - System Administration
LiveUSB-OpenBSD - System Administration
MarBSD     - Desktop
BOSS Live CD - Security
Musix GNU+Linux - Media Production
floppyfw - Firewall
puredyne - Media Production
Elive     - Desktop
PTS Desktop Live - Diagnostics
Kleo - System Administration
PaiPix - Science
Skolelinux - Desktop, Education
xPUD - Desktop
Helix  - Forensics
GNUstep live CD - Desktop
Pentoo     - Security
BSDanywhere - Desktop
SLAMPP - Server
Crash Recovery Kit for Linux - Rescue
Jibbed     - Desktop
Linux-EduCD - Education
JUX - Education
ROCK Linux - Desktop
avast! BART CD     - Windows Antivirus
STUX - Desktop
NimbleX - Desktop
BeleniX - Desktop
LUC3M - Desktop
KnoppMyth  - Home Entertainment
g:Mini     - Desktop
GoboLinux - Desktop
MirOS BSD - Server
Adios - Education
LFS LiveCD - OS Installation, Rescue
MitraX     - Desktop
AliXe     - Desktop
Kate OS LIVE - Desktop
cdlinux.pl - Desktop
Kaella     - Education
Mutagenix - Desktop, Diagnostics, OS Installation, Rescue
Pyro Live CD - Robotics
Danix     - Desktop
Freeduc - Desktop, Education, GIS
X-Evian - Media Production
eduKnoppix - Education
Trinux     - Security
KCPenTrix - Security
Stanix Professional - Desktop
INSERT     - Rescue, Security
FreeSBIE - Desktop
LG3D LiveCD - Desktop
Kazit - Desktop
Xfld - Desktop
BDI-Live - CNC Metalworking
Formilux - Desktop
Dappix     - Desktop
aquamorph - Desktop
Legnoppix - Robotics
GIS-Knoppix - GIS
Quantian - GIS, Science
Kaboot     - Desktop, Rescue, Science
KnoSciences - Education
FCCU GNU/Linux Forensic Boot CD - Forensics
Anonym.OS - Secure Desktop
Operator - Security
ABC Linux - Desktop
Ging - Desktop
ffsearch-LiveCD - Server
AmaroK Live - Home Entertainment
loonix-live - Desktop
ATMission - Desktop, Server
PXES - Thin Client
VigyaanCD - Bioinformatics, Education
KANOTIX CPX-MINI - Desktop, OS Installation
Hikarunix - Gaming
CDMEDICPACSWEB     - Medical
Klax - Desktop
Feather Linux - Desktop
eMoviX     - Home Entertainment
SNAPPIX - Development
Xebian     - Desktop
Snøfrix - Education
SLYNUX     - Desktop, OS Installation
Benix Kanotix - Desktop
Julex - Desktop
PHLAK - Security
Freepia - Home Entertainment
AdvanceCD - Gaming
KNOPPIX-BV1AL - Desktop
Archie     - Desktop
CHAOS - Clustering
ELE - Secure Desktop
WOMP! - Home Entertainment
Flash Linux - Desktop
Shabdix - Education
Blin Linux - Desktop
LLGP - Gaming
Sentry Firewall CD - Firewall
Timo's Rescue CD - Rescue
Lisp Resource Kit - Development, Education
Sulix - Desktop
MiniKnoppix - Rescue
Toothpix - Medical
PLD Live CD - Desktop
Salvare - Rescue
NIOde - Development
ClusterKnoppix - Clustering
LAMPPIX - Server
bioknoppix - Bioinformatics, Education
MoviX2     - Home Entertainment
GNU/Linux Kinneret - Education
Luit Linux - Desktop
MiniKazit - Desktop, OS Installation
jollix     - Gaming, Home Entertainment
Arabbix - Desktop
muLinux - Desktop
eLearnix - Education
KnoppiXMAME - Gaming
FlashMob ISO - Clustering
StreamBOX-LiveCD - Media Production
ByzantineOS - Home Entertainment
MoviX - Home Entertainment
LiveOIO - Medical
PlumpOS - Clustering
Local Area Security Linux - Desktop, Security
Pollix   - Development
TPM Security Server - Forensics, Security
Phrealon - System Administration
Knoppix STD - Security
tlf-morphix - Hobby
KnoppixQuake - Server
Ankur - Desktop
Morphix-NLP - Science
FreeBSD LiveCD  - Desktop, OS Installation, Rescue
Emergency CD - Rescue
KibZiLLa - Desktop
Lin4Astro - Astronomy
Gentoox - Desktop
OpenGroupware Knoppix CD - Server
Cool Linux CD - Desktop
3Anoppix - Desktop
FIRE - Forensics
LNX-BBC - Desktop, Rescue
BerliOS MiniCD - Desktop
MIOLUX     - Desktop, Rescue
SuperRescue - Rescue
Lonix - Rescue     2002.10
PCG-C1VN Live CD - Desktop
WarLinux - Security
DemoLinux - Desktop
tomsrtbt - Rescue
Virtual Linux - Desktop
PLAC - Forensics, Rescue
Repairlix - Rescue

Saturday, December 29, 2012

Quarter of a Million

Quarter of a Million








































Given the vast numbers using the internet finding trewmte.blogspot must seem like trying to find a grain of sand on a beach or winning the national lottery, yet I am very pleased to see the content at my blog has now been read by over a quarter of million viewers in just over six years.

It really is gratifying to see from the early days in later 1980s when it was possible to count on two hands the number of examiners involved the profession up to today where there are thousands of people involved in this branch of forensic science and mobile phone examination, generally, that the viewers of this blog are a testament to the growth in our profession.

Thanks to everyone who has taken time to drop in and see my observations and reporting on mobile phone forensics, evidence, data discovery and commentary about the technological changes that have and are taking place.
  

Sunday, December 16, 2012

ForensicMobex

ForensicMobex has moved to MTEB LinkedIn Group as a subgroup:

Stakeholder Information
-----------------------
Mission Statement: Expert discussion group relating to the examination of and/or evidence from mobile/smart phones, PDAs/IPODs/IPADs/USB, SIM/USIM and other storage devices. The use of logical or physical procedures; the relevation of harvested data; use programs and other tools; interpretation of data.

Mission Aims & Objectives of this group: to improve communications between experts, assist diagnostic approach and build issues of professional interest, as well as improving knowledge skills and awareness.

This group is at all times company, make/model, OS, tool, platform and app neutral. You, the Stakeholder, warrants to MTEB, MTEB ForensicMobex SIG and the owner of the group that you undertake to indemnify MTEB, MTEB ForensicMobex SIG and the owner of the group regarding the distribution and use of material where it holds copyright invested in it.

By joining this group each member becomes a stakeholder in the group and agrees to regular active participation, which is monitored regularly. A stakeholder who fails to contribute meaningful content such as knowledge and/or experiences, identify research papers (with links) and/or materials/tools identification etc then membership will be suspended. This policy has been agreed to ensure fairness to all contributor members.

*We do NOT accept impersonal anonymous IDs, recruiters and HR people
*We do NOT accept students unless they demonstrate prior skills and experience
*We do NOT accept those with less than 5 connections to other LinkedIn members.

If your Profile doesn't immediately convince us that you have the skills and experience outlined we will NOT admit you.

Listing a job title or role, owning or managing a business or one of its departments in your Profile is not enough to join. We want to know that you have the skills and experience to fit in with one of the best expert groups on LinkedIn.

Please make sure your profile is up to date before applying for membership.

Tuesday, December 11, 2012

A European Focused Mobile Consumer Survey

A European Focused Mobile Consumer Survey

Informa Telecom and Media have published the results of their Smartphone Usage and Behaviour Survey 2012 conducting the survey in four european countries UK, Spain, Germany and the Netherlands http://www.informatandm.com/mobile-consumer-survey/ .

The results for the UK identified the brand of mobile phone owned in particular age groups.













The responses to the survey confirm that the smartphone market in the UK is segmented and therefore mobile operators attempting to forecast device usage and data/services activity may require enabling customers the selection and choice of a range of platforms to sink their teeth into optimising any consumer initiative to enable the growth of smartphones to continue.

For examiners the survey illustrates that predominantly the smartphones to be examined fall into a fairly small category, which could be quite useful for forecasting future examinations and, in particular, the expenditure on tools etc.

Blackberry Enterprise Solutions

BB Manuals and Guides



For me, at any rate, using this link probably leads to the best way to get instant access (that is at a glance, click the link) to manuals and guides specific to versions of Blackberry Enterprise Solutions - http://docs.blackberry.com/en/admin/?userType=2

There is also further BB support links to various manuals and help here: http://docs.blackberry.com/en/ and for the Blackberry knowledge base here: http://btsc.webapps.blackberry.com/btsc/microsites/searchEntry.do

Monday, November 26, 2012

US Handset Serial Number Databases

US Handset Serial Number Databases

US operators maintain their own stolen and blacklisted cellphone databases. As of the 31st October 2012 the GSM operators AT&T and T-Mobile began sharing their databases. CDMA operators Verizon and Sprint have taken the decision to merge their databases but that will not be complete until November 2013, so we are told.

The said objective of these initiatives are to improve track and trace. As an example, GSM uses a 56-bit decimal digit s/n, whereas CDMA uses a 56-bit hexadecimal digitals s/n. However, in the US there are variations of s/ns to consider.

The engine for these changes is driven by the FCC initiative - http://www.fcc.gov/document/announcement-new-initiatives-combat-smartphone-and-data-theft

To accommodate this and other cellphone/cellular changes I have altered my CDMA training material and GSM training material. As consequence these changes will also have an impact on WCDMA and LTE, either on a national level or international level. These training materials have also changed, too.

_________________
Institute for Digital Forensics (IDF) - LinkedIn
Mobile Telephone Examination Board (MTEB) - LinkedIn

Thursday, November 22, 2012

EU Cybercrime (aka real name ICT ecrime)

EU Cybercrime (aka real name ICT ecrime)

Setting up the the criminal legal framework:

Judicial cooperation in criminal matters: combating attacks against information systems

Subject
3.30.06 Information and communication technologies
3.30.25 International information networks and society, internet
7.40.04 Judicial cooperation in criminal matters

http://www.europarl.europa.eu/oeil/popups/ficheprocedure.do?id=587653

Having a common European ICT eCrime Judicial protocol must equally rely on a common European Prosecution able to deal with ICT eCrime to assets:

https://www.era.int/cgi-bin/cms?_SID=47326840bea04c616952d8eb19eaceb72b2cb9a400217108097437&_sprache=en&_persistant_variant=/Our%20programme/Browse%20all%20events&_bereich=artikel&_aktion=detail&idartikel=123340

The establishment of the European Public Prosecutor's Office (EPPO) is envisaged in Article 86 TFEU. The EPPO would be responsible for investigating, prosecuting and bringing to justice those who damage assets managed by or on behalf of the EU.  The European Council may adopt a decision extending the powers of the EPPO to include serious crime having a cross-border dimension.





Tuesday, November 20, 2012

Mobile Flash Data Erasure

Mobile Flash Data Erasure

Secure your smartphone and tablet


                                                  Photo courtesy of Blancco

The growth in smart phones naturally means consumers will see even more utilities and tools similiar to those found on PCs, laptops and notebooks etc. A trend that is growing in relation to cleansing of personal details and company information stored logically and physically is called mobile flash data erasure (MFDE).

Service erasure
A group called www.tabernus.com/ promote "Tabernus also provides erasure solutions for Mobile Phones, USB, SSD (solid state devices) & other types of Flash removable memory and may other data holding devices too!"

Software erasure
Of course, there is a comparison for mobile phone flash erasure available from  http://www.blancco.com/us/erase-smartphones/

The above examples are in addition to hardware encryption:

Device specific denied data access
Hardware Encryption: The iPhone 3GS and later, and all iPads, support built-in hardware encryption. All user data can be automatically encrypted in hardware at all times. This is used primarily for wiping the device rather than to stop attacks. Erasing the entire flash storage would be slow, so instead wiping works by destroying the encryption key, which instantly makes all user data inaccessible (Securosis).

And flash memory management:

Flash Memory Management Systems
Wear leveling ( http://en.wikipedia.org/wiki/Wear_leveling ) as well routines used in garbage collection solutions ( http://en.wikipedia.org/wiki/Garbage_collection_%28SSD%29#Garbage_collection and http://en.wikipedia.org/wiki/Garbage_collection_%28computer_science%29 ) can lead to potential loss due to overwriting existing deleted data.

From an examiner's point of view, MFDE is most likely to have a huge impact on deleted data recovery (DDR) from flash chips. The methodology and science behind Chip Off and JTAG is currently used for recovery of deleted data from a  range of mobile devices. Overwriting 0101010101 (zeros and ones) or null values over particular areas or the entire area of the flash memory may make Chip Off and JTAG redundant in certain types of investigations and cases in the future.