[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Paper: Anti Forensics: making computer forensics hard.
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] Paper: Anti Forensics: making computer forensics hard.
- From: "Wendel Guglielmetti Henrique" <wsguglielmetti@xxxxxxxxx>
- Date: Wed, 11 Jul 2007 13:50:33 -0300
Yo,
In this paper (translated from Portuguese in 2006) is presented since basic
until advanced techniques used to defeat forensic analysis.
Including the following topics:
- What is computer forensics?
- What is Anti Forensics?
- Anti Forensics methods:
Encryption.
Steganography.
Self Split Files + Encryption.
Defeat "last modified files" technique.
Wipe.
Data Hiding: swap, file system bad blocks, unallocated spaces, ADS.
Process dump.
Integrity check (MD5 Collision).
Database Rootkits.
BIOS Rootkits.
You can check the full paper in:
http://ws.hackaholic.org/slides/AntiForensics-CodeBreakers2006-Translation-To-English.pdf
Wendel Guglielmetti Henrique
http://ws.hackaholic.org - personal page
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/