<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>jnavarro.net</title>
	<atom:link href="http://dervitx.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://dervitx.wordpress.com</link>
	<description>things i should not forget, and that, eventually, could interest people</description>
	<lastBuildDate>Sat, 14 Nov 2009 22:37:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='dervitx.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/6348d45d11a032a88b3025cbb862fc4c?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>jnavarro.net</title>
		<link>http://dervitx.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://dervitx.wordpress.com/osd.xml" title="jnavarro.net" />
	<atom:link rel='hub' href='http://dervitx.wordpress.com/?pushpress=hub'/>
		<item>
		<title>RVT v0.2.1 published</title>
		<link>http://dervitx.wordpress.com/2009/11/14/rvt-v0-2-1-published/</link>
		<comments>http://dervitx.wordpress.com/2009/11/14/rvt-v0-2-1-published/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 22:37:03 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=94</guid>
		<description><![CDATA[First of all, sorry for the lack of news and updates lately, but RVT is developed with the free and spare time of the members of the team, and I have not had a lot of that in the last months. RVT v0.2.1  include new features and some little improvements: LNK files parsing Harlan Carvey, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=94&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>First of all, sorry for the lack of news and updates lately, but RVT is developed with the free and spare time of the members of the team, and I have not had a lot of that in the last months.</p>
<p>RVT v0.2.1  include new features and some little improvements:</p>
<ul>
<li>LNK files parsing</li>
<li>Harlan Carvey, author of the well-known <a title="Windows Incident Response blog" href="http://windowsir.blogspot.com/" target="_blank">Windows Incident Response blog</a>, has kindly provided us with brilliant Perl code to parse Windows event files (EVT extension). Thus RVT now integrates the script &#8216;evt&#8217;, which can output text versions of the EVT files (script evt generate); it can also generate some stats about each EVT (script evt report). We would like to sincerely thank Harlan for his support and his useful code.</li>
<li>f-strings: an forensics version of Binutils strings command</li>
<li>extended shell history</li>
<li>and all the little changes and corrections published on this blog since v0.2</li>
<li>updated User Guide</li>
</ul>
<p>Read <a href="http://code.google.com/p/revealertoolkit/" target="_blank">The Revealer Toolkit website</a> for more information.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=94&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/11/14/rvt-v0-2-1-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT: images scanall: command obsolete</title>
		<link>http://dervitx.wordpress.com/2009/09/10/rvt-images-scanall-command-obsolete/</link>
		<comments>http://dervitx.wordpress.com/2009/09/10/rvt-images-scanall-command-obsolete/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 17:35:57 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=92</guid>
		<description><![CDATA[quick note: from SVN revision 70, &#8220;images scanall&#8221; command is no longer recognized, and is substituted for &#8220;images scan &#60;case&#62;&#8221;, where case can be a case number or the special word &#8220;all&#8221;, so &#8220;images scan all&#8221; is equivalent to the old &#8220;images scanall&#8221;. This will speed up the scanning for one case, that will be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=92&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>quick note</strong>: from SVN revision 70, &#8220;images scanall&#8221; command is no longer recognized, and is substituted for &#8220;images scan &lt;case&gt;&#8221;, where case can be a case number or the special word &#8220;all&#8221;, so &#8220;images scan all&#8221; is equivalent to the old &#8220;images scanall&#8221;.</p>
<p>This will speed up the scanning for one case, that will be critical for RWA, although it raises other problems (configuration update time) that will be solved soon.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=92&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/09/10/rvt-images-scanall-command-obsolete/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>f-strings, new RVT tool</title>
		<link>http://dervitx.wordpress.com/2009/09/06/f-strings-new-rvt-tool/</link>
		<comments>http://dervitx.wordpress.com/2009/09/06/f-strings-new-rvt-tool/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 12:25:22 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=83</guid>
		<description><![CDATA[f-strings, or Forensic Strings, is a new RVT tool that will be incorporated soon to the search engine of RVT. You know what binutils&#8217; strings command do: extract printable characters from a binary file.  Although it supports various character sets (plain ascii, utf8, utf16, in little and big endian), only support one each time you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=83&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>f-strings, or Forensic Strings, is a new RVT tool that will be incorporated soon to the search engine of RVT.</p>
<p>You know what binutils&#8217; strings command do: extract printable characters from a binary file.  Although it supports various character sets (plain ascii, utf8, utf16, in little and big endian), only support one each time you execute it. And it is not very good with mixtures of character sets on the same file.</p>
<p>f-strings extracts sequences of <em>all that seems </em>a printable character out of a binary file, written in plain ASCII, utf8 or utf16 (little endian only). That means that usually will extract more noise than binutils&#8217; strings, but only one execution is needed.</p>
<p>Moreover, f-strings translates special characters to their plain ASCII equivalents. For example, f-strings translates &#8216;á&#8217;, &#8216;Á&#8217;, &#8216;à&#8217;, &#8216;À&#8217;, &#8216;ä&#8217;, etc., to &#8216;a&#8217;. Also translates spanish and catalan special characters ( &#8216;ñ&#8217; and &#8216;ç&#8217;  to  &#8217;n&#8217; and  &#8217;c').</p>
<p>Finally, it lowercases all the output.</p>
<p>For example:</p>
<blockquote><p>$ cat accentuated.txt<br />
el sinvergüenza de José es un ñoño y es del barça</p>
<p>$ ./f-strings accentuated.txt<br />
el sinverguenza de jose es un nono y es del barca</p></blockquote>
<p>f-strings is open source (GNU/GPL v2.0), and can be downloaded from the Revealer Toolkit web page (<a title="f-strings.c" href="http://code.google.com/p/revealertoolkit/source/browse/trunk/tools/f-strings.c" target="_blank">here</a>).</p>
<p>Here you have the f-strings&#8217; help as printed with &#8216;<em>f-strings -h</em>&#8216;:</p>
<p><code>Revealer Tools, forensic strings, 09-2009<br />
USAGE:  f-strings  [-t] [-n &lt;number&gt; ] [-f]</code></p>
<p><code>-t             Print the location of the string in base 10<br />
-n     Locate &amp; print any sequence of printable characters<br />
of at least  characters (default 4)<br />
-h             Display this information</code></p>
<p><code>f-strings get a file and prints at stdout all printable characters<br />
like binutils' strings function, BUT:<br />
- convert all that 'seems' latin1, UTF-8 and UTF-16, little endian<br />
to plain ASCII<br />
- translates some special characters. For example, accented a's are translated<br />
to the ASCII character 'a'. All vowels, plus spanish and catalan special<br />
characters are translated<br />
- lowercases all printable characters</code></p>
<p><code>known issues:<br />
- only one file at each execution<br />
- offset is printed only in base 10, so argument -t do not<br />
accept subarguments, and '-t' is equivalent to '-t d' of<br />
binutils' strings<br />
- \x00 characters are ignored, so in a hard disk full of zeros<br />
with 'Hey ' at the begining and 'Ho' at the end, f-strings will<br />
extract the string 'Hey Ho'</p>
<p></code></p>
<p><code> more information at http://code.google.com/p/revealertoolkit/</code></p>
<p>Enjoy and feedback!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=83&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/09/06/f-strings-new-rvt-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT: step by step</title>
		<link>http://dervitx.wordpress.com/2009/08/28/rvt-step-by-step/</link>
		<comments>http://dervitx.wordpress.com/2009/08/28/rvt-step-by-step/#comments</comments>
		<pubDate>Fri, 28 Aug 2009 15:44:12 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=81</guid>
		<description><![CDATA[Step by step, some ugly parts of the code are being rewritten and getting better. On the last SVN revision, RVT stores on a text file (morgue/case/&#60;case&#62;_cmdLog.txt) a log of some commands executed on that case and their subobjects. Next step will be to work on command dependences. Also, some automatic reporting is begining to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=81&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Step by step, some ugly parts of the code are being rewritten and getting better. On the last SVN revision, RVT stores on a text file (morgue/case/&lt;case&gt;_cmdLog.txt) a log of some commands executed on that case and their subobjects. Next step will be to work on command dependences.</p>
<p>Also, some automatic reporting is begining to work, although will be greatly redesign in the next months. See RVT commands <em>script report</em> for more information.</p>
<p>Some other little improvements:</p>
<ul>
<li>greater command history (greater than one!)</li>
<li>improvement of lock files (XML configuration, mainly)</li>
<li>greater readpst verbosity on results</li>
<li>little sketch for a web interface</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=81&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/08/28/rvt-step-by-step/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT: parsing LNK files</title>
		<link>http://dervitx.wordpress.com/2009/08/17/rvt-parsing-lnk-files/</link>
		<comments>http://dervitx.wordpress.com/2009/08/17/rvt-parsing-lnk-files/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 18:37:35 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=77</guid>
		<description><![CDATA[support for parsing Microsoft Windows LNK files has been added to RVT. Just execute RVT &#62;  script lnk generate &#60;disk&#62; and a CSV file on output/lnk will be created with info of all LNK files of the disk (with LNK extension). This command requires other command to be executed before:  script files allocfiles or an [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=77&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>support for parsing Microsoft Windows LNK files has been added to RVT. Just execute</p>
<blockquote><p>RVT &gt;  script lnk generate &lt;disk&gt;</p></blockquote>
<p>and a CSV file on output/lnk will be created with info of all LNK files of the disk (with LNK extension). This command requires other command to be executed before:  <em>script files allocfiles</em> or an error will occur. Command dependencies is something we are working on and, I hope, will be solved in version 0.3.</p>
<p>This function depends also on the <em>dumplnk.pl</em> script adapted by Luis Gómez (RVT team member) from the original <em>lnk-parse.pl</em>, by Jacob Cunningham, all GNU/GPL (thanks, open source!), and distributed with RVT (look in the <em>tools</em> folder of the source code, or <a title="RVT tools" href="http://code.google.com/p/revealertoolkit/source/browse/#svn/trunk/tools%3Fstate%3Dclosed" target="_blank">here</a>)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/77/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=77&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/08/17/rvt-parsing-lnk-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT v0.2 virtual machine</title>
		<link>http://dervitx.wordpress.com/2009/07/18/rvt-v0-2-virtual-machine/</link>
		<comments>http://dervitx.wordpress.com/2009/07/18/rvt-v0-2-virtual-machine/#comments</comments>
		<pubDate>Sat, 18 Jul 2009 08:34:45 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=75</guid>
		<description><![CDATA[A VMWare virtual machine has been created with a completely functional RVT v0.2 system, folder structure and an example case. This VMWare  can easily be used also as a production system. Due to limitations in Google Code hosting, the VMWare is hosted in sourceforge.net: RVT-v0.2.tar.gz Authentication:   root / 12345  and  analyst / 12345 Log [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=75&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A VMWare virtual machine has been created with a completely functional RVT v0.2 system, folder structure and an example case. This VMWare  can easily be used also as a production system.</p>
<p>Due to limitations in Google Code hosting, the VMWare is hosted in sourceforge.net:</p>
<ul>
<li><a title="The Revealer Toolkit VMWare" href="https://sourceforge.net/projects/revealertoolkit/files/revealertoolkit/RVT-v0.2.tar.gz/download" target="_blank">RVT-v0.2.tar.gz</a></li>
<li>Authentication:   root / 12345  and  analyst / 12345</li>
</ul>
<p>Log in as <em>analyst</em> and run RVT with the command:</p>
<blockquote><p>$ rvt</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/75/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=75&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/07/18/rvt-v0-2-virtual-machine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT v0.2 released</title>
		<link>http://dervitx.wordpress.com/2009/07/01/rvt-v0-2-released/</link>
		<comments>http://dervitx.wordpress.com/2009/07/01/rvt-v0-2-released/#comments</comments>
		<pubDate>Wed, 01 Jul 2009 06:16:51 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=71</guid>
		<description><![CDATA[Finally, version 0.2 of the Revealer Toolkit is out. See more information at the project page. Code can be downloaded from: http://revealertoolkit.googlecode.com/files/RVT_v0.2.zip svn checkout http://revealertoolkit.googlecode.com/svn/branches/RVT-v0.2 RVT-v0.2-read-only Also, User Guide has been greatly improved with examples and operational guides (see http://revealertoolkit.googlecode.com/files/RVT-userGuide.pdf ). and finally, a Google Groups newsletter has been created and used for the community [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=71&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Finally, version 0.2 of the Revealer Toolkit is out. See more information at <a title="RVT project page" href="http://code.google.com/p/revealertoolkit/" target="_blank">the project page</a>. Code can be downloaded from:</p>
<ul>
<li><a rel="nofollow" href="http://revealertoolkit.googlecode.com/files/RVT_v0.2.zip">http://revealertoolkit.googlecode.com/files/RVT_v0.2.zip</a></li>
<li>svn checkout <a rel="nofollow" href="http://revealertoolkit.googlecode.com/svn/branches/RVT-v0.2">http://revealertoolkit.googlecode.com/svn/branches/RVT-v0.2</a> RVT-v0.2-read-only</li>
</ul>
<p>Also, User Guide has been greatly improved with examples and operational guides (see <a title="RVT User Guide" href="http://revealertoolkit.googlecode.com/files/RVT-userGuide.pdf" target="_blank">http://revealertoolkit.googlecode.com/files/RVT-userGuide.pdf</a> ).</p>
<p>and finally, a Google Groups newsletter has been created and used for the community to share doubts, ideas and problems ( <a title="RVT newsletter" href="http://groups.google.com/group/revealertoolkit" target="_blank">http://groups.google.com/group/revealertoolkit</a> ). Do not hesitate to contact us!</p>
<p>Stay tunned because important improvements are planned for future versions.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=71&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/07/01/rvt-v0-2-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT tools:  plot_time.pl, plotting your timelines</title>
		<link>http://dervitx.wordpress.com/2009/05/24/rvt-tools-plot_time-pl-plotting-your-timelines/</link>
		<comments>http://dervitx.wordpress.com/2009/05/24/rvt-tools-plot_time-pl-plotting-your-timelines/#comments</comments>
		<pubDate>Sun, 24 May 2009 18:58:00 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=62</guid>
		<description><![CDATA[RVT comes with a bunch of useful tools, not totally related with the forensic framewok, but too little to be published for themselves. plot_time.pl, located under the RVT/tools folder of the RVT&#8217;s svn repository (check it out), it&#8217;s a Perl script that plots bar graphs out of files in which each line contains values, being [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=62&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>RVT comes with a bunch of useful tools, not totally related with the forensic framewok, but too little to be published for themselves.</p>
<p>plot_time.pl, located under the <em>RVT/tools</em> folder of the RVT&#8217;s svn repository (<a title="RVT svn" href="http://code.google.com/p/revealertoolkit/source/checkout" target="_blank">check it out</a>), it&#8217;s a Perl script that plots bar graphs out of files in which each line contains values, being one of them <em>time</em>. It will be handful to represent values on time, or to count the numbers of lines by period of time. This script needs <a title="gnuplot homepage" href="http://www.gnuplot.info/" target="_blank"><em>gnuplot 4.2 </em>or greater</a> on your path. Moreover, it uses the powerful Perl module <a title="Date::Manip" href="http://search.cpan.org/~sbeck/Date-Manip-5.54/lib/Date/Manip.pod" target="_blank"><em>Date::Manip</em></a> to parse almost every known date format, and can be installed easily from CPAN or APT (apt-get installlibdate-manip-perl).</p>
<p>plot_time.pl works in two modes: representing values as a function of time (mode 1) and representing <em>count</em> of lines as a function of periods of time (integrates the appearance of values over every period defined).</p>
<p><strong>Mode 1.</strong> Let&#8217;s be <em>itimeline-02.csv</em> a timeline generated with RVT, and let&#8217;s imagine that we want to represent graphically the size of the files, as a function of time, on July 5th 2008. We execute the following command:</p>
<blockquote><p>perl plot_time.pl -interval=&#8217;20080705 + 1 day&#8217; -tf 1 -vf 2 itimeline-02.csv</p></blockquote>
<p>Where &#8216;tf&#8217; option marks that the first field is the &#8216;time field&#8217;, and &#8216;vf&#8217; option establishes that the value to be plotted is the second (file size). The following graph is generated:</p>
<div id="attachment_66" class="wp-caption aligncenter" style="width: 650px"><a href="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode11.png"><img class="size-full wp-image-66" title="itimeline-02.csv.mode1" src="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode11.png?w=700" alt="plot_time.pl generated graph in Mode 1"   /></a><p class="wp-caption-text">plot_time.pl generated graph in Mode 1</p></div>
<p><strong>Mode 2.</strong> This mode is activated with the &#8216;-sum&#8217; option, and the period is established with &#8216;-period&#8217; option, with anything that Date::Manip can understand (&#8216;day&#8217;, &#8216;hour&#8217;, &#8230;). So, executing the following command on the same data:</p>
<blockquote><p>perl plot_time.pl -interval=&#8217;20080705 + 1 day&#8217; -tf 1 -sum -period=&#8217;hour&#8217; itimeline-02.csv</p></blockquote>
<p>generates the following graph:</p>
<div id="attachment_67" class="wp-caption aligncenter" style="width: 650px"><a href="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode2.png"><img class="size-full wp-image-67" title="itimeline-02.csv.mode2" src="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode2.png?w=700" alt="plot_time.pl generated graph in Mode 2"   /></a><p class="wp-caption-text">plot_time.pl generated graph in Mode 2</p></div>
<p>Also:</p>
<ul>
<li>you can pipe your filtered timelines into plot_time.pl ( f.ex.:  grep -i &#8216;myfile.png&#8217; itimeline-02.csv | perl plot_time.pl &#8230; )</li>
<li>plot_time.pl skips comment lines, and also it can skip a number of lines with &#8216;-skiplines&#8217; option</li>
<li>plot_time.pl will ignore lines that match a regular expression when option &#8216;-excluderegexpr&#8217; is used</li>
<li>see <em>plot_time.pl &#8211;help</em> for more info</li>
</ul>
<p>We are now planning some new features on plot_time.pl, so stay tunned!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/62/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=62&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/05/24/rvt-tools-plot_time-pl-plotting-your-timelines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>

		<media:content url="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode11.png" medium="image">
			<media:title type="html">itimeline-02.csv.mode1</media:title>
		</media:content>

		<media:content url="http://dervitx.files.wordpress.com/2009/05/itimeline-02-csv-mode2.png" medium="image">
			<media:title type="html">itimeline-02.csv.mode2</media:title>
		</media:content>
	</item>
		<item>
		<title>RVT:  support for F-Response</title>
		<link>http://dervitx.wordpress.com/2009/05/14/rvt-support-for-f-response/</link>
		<comments>http://dervitx.wordpress.com/2009/05/14/rvt-support-for-f-response/#comments</comments>
		<pubDate>Thu, 14 May 2009 18:50:15 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Revealer Toolkit]]></category>
		<category><![CDATA[RVT]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=55</guid>
		<description><![CDATA[last revision of RVT contains a little, tiny,  (it&#8217;s true, i swear!) change for making RVT directly functional with F-Response. However, the process of installing a new f-response generated device it&#8217;s manual. Follow the next steps in order  to add remote f-response devices your Revealer morgue: assign one, or more, iscsi nodes generated with f-response [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=55&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>last revision of RVT contains a little, tiny,  (it&#8217;s true, i swear!) change for making RVT directly functional with <a title="F-Response" href="http://www.f-response.com/" target="_blank">F-Response</a>. However, the process of installing a new f-response generated device it&#8217;s manual. Follow the next steps in order  to add remote f-response devices your Revealer morgue:</p>
<ul>
<li>assign one, or more, iscsi nodes generated with f-response to linux devices. Documentation on open-iscsi commands are found <a href="https://www.f-response.com/index2.php?option=com_content&amp;do_pdf=1&amp;id=32" target="_blank">elsewhere</a></li>
<li>assigned devices can be seen with the following open-iscsi command:</li>
</ul>
<blockquote><p><em>iscsiadm -m session -P 3</em></p></blockquote>
<ul>
<li>now, on your <em>morgue/images/&lt;case&gt;</em> directory, create a symbolic link to each of the devices, with the right RVT nomenclature (&lt;case&gt;-&lt;device&gt;-&lt;disk&gt;.dd).  Check the permissions!</li>
</ul>
<blockquote><p><em># ln -s /dev/sdX 100xxx-yy-z.dd</em></p></blockquote>
<ul>
<li>run RVT, scan your morgue and use all the functions at convinience!</li>
</ul>
<blockquote><p><em>RVT&gt; images scanall</em></p></blockquote>
<p>Feedback if you find problems!</p>
<p><em><br />
</em></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/55/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=55&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/05/14/rvt-support-for-f-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
		<item>
		<title>How to calculate the hash of a CD or DVD on Mac OS X</title>
		<link>http://dervitx.wordpress.com/2009/05/11/hashes-of-cd-or-dvd-on-macosx/</link>
		<comments>http://dervitx.wordpress.com/2009/05/11/hashes-of-cd-or-dvd-on-macosx/#comments</comments>
		<pubDate>Mon, 11 May 2009 20:23:55 +0000</pubDate>
		<dc:creator>dervitx</dc:creator>
				<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[mac os x]]></category>

		<guid isPermaLink="false">http://dervitx.wordpress.com/?p=27</guid>
		<description><![CDATA[The daily work of the forensic investigator requires precision and a deep control of the technical tools involved. For example, is well known that the smallest, tiny, tamper of a bit when calculating the hash of a digital file makes the result to change completely. This could be critical when initiating a chain of custody [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=27&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The daily work of the forensic investigator requires precision and a deep control of the technical tools involved. For example, is well known that the smallest, tiny, tamper of a bit when calculating the hash of a digital file makes the result to change completely. This could be critical when initiating a chain of custody of digital evidences, so i always use linux when possible due to the absolute control of everything needed in the process.</p>
<p>The problem appears when an adquisition has to be done at your customer&#8217;s offices, and when digital evidences must be burned on CD and hashed  in front of your customer, the lawyer, the notary, the guy you are going to investigate &#8230;   on your shiny Mac. Here are the steps that i use on these special occasions:</p>
<ul>
<li>first, on the desktop, and create a <em>Burn Folder</em> right-clicking and selecting <em>Burn Folder</em> from the emergent menu</li>
<li>i drag and drop on it all the files that will be included as electronic evidences on this chain of custody</li>
<li>a double-click on the folder opens it. A button named <em>Burn</em> appearson the upper-right corner, so you can press it after introducing a blank CD or DVD</li>
</ul>
<p>Now, the interesting stuff:  you need to calculate the hash and probably to burn <em>identical</em> copies with an <em>identical </em>cryptographic hash.</p>
<ul>
<li>introduce the CD or DVD and, on a terminal, write down the command <em> diskutil list </em>that will provide  a list of devices used by your CD</li>
</ul>
<blockquote><p>$ diskutil list/dev/disk2<br />
&#8230;</p>
<p>#:                       TYPE NAME                    SIZE       IDENTIFIER<br />
0:        CD_partition_scheme                        *6.8 Mi     disk2<br />
1:     Apple_partition_scheme                         6.0 Mi     disk2s1<br />
2:        Apple_partition_map                         31.5 Ki    disk2s1s1<br />
3:                  Apple_HFS Carpeta de grabación   4.9 Mi     disk2s1s2</p></blockquote>
<ul>
<li>install a hash command line tool. I use <em>sha256deep</em> included in the Mac Port md5deep (sudo port install md5deep)</li>
<li>you must hash the <em>Apple_partition_scheme</em> associated raw device.  In this example, the associated raw device will be /dev/rdisk2s1  . Be careful in using  <em>rdisk</em>, not <em>disk</em>, because the second requires you to unmount the CD:</li>
</ul>
<blockquote><p><em>$ sha256deep /dev/rdisk2s1</em></p>
<p><em>108143e8b1460cc2e8983bcc06cf792ea9837174c203c8cd4ab50ee87c9c5d9d  /dev/rdisk2s1</em></p></blockquote>
<p>Making copies of the CD:</p>
<ul>
<li>For some reason i don&#8217;t know, a <em>dd</em> command won&#8217;t work, so i use cat:</li>
</ul>
<blockquote><p><em>$ cat /dev/rdisk2s1 &gt; image.cdr</em></p></blockquote>
<p><em></em></p>
<ul>
<li>check the hash:</li>
</ul>
<blockquote><p><em>$ sha256deep image.cdr</em></p>
<p><em>108143e8b1460cc2e8983bcc06cf792ea9837174c203c8cd4ab50ee87c9c5d9d  image.cdr</em></p></blockquote>
<ul>
<li>and burn the image so many times you need it with Toaster or Disk Utility</li>
</ul>
<p>Note:</p>
<ul>
<li>this method will also work  with monosession CD recorded elsewhere. In those cases, diskutil should not show the Apple partition scheme but the data directly after the CD scheme:</li>
</ul>
<blockquote><p>/dev/disk2<br />
#:                       TYPE NAME                    SIZE       IDENTIFIER<br />
0:        CD_partition_scheme                        *785.4 Mi   disk2<br />
1:              CD_ROM_Mode_1 wifislax-3.1            683.9 Mi   disk2s0</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/dervitx.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/dervitx.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/dervitx.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=dervitx.wordpress.com&amp;blog=6123396&amp;post=27&amp;subd=dervitx&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://dervitx.wordpress.com/2009/05/11/hashes-of-cd-or-dvd-on-macosx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8edfc2c2cb63c0fedf325be6ebc8b0b7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jose</media:title>
		</media:content>
	</item>
	</channel>
</rss>
