Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Incident Response for Cheapskates - BSidesTO 2013

Incident Response for Cheapskates - BSidesTO 2013

Lee Brotherston

October 05, 2013
Tweet

More Decks by Lee Brotherston

Other Decks in Technology

Transcript

  1. Oxford Semiconductor Oxford Semiconductor OXUF922 Bridge Chip OXUF922 Bridge Chip

    Oxford Semiconductor Oxford Semiconductor OXUF922 Bridge Chip OXUF922 Bridge Chip Agere Agere FW801 FW801 Agere Agere FW801 FW801 Flash Flash SST SST 39VF100 39VF100 Flash Flash SST SST 39VF100 39VF100 RAM RAM IDT IDT 71V016SA 71V016SA RAM RAM IDT IDT 71V016SA 71V016SA Firewire Firewire Firewire Firewire USB USB USB USB IDE IDE IDE IDE Write Blocker Diagram Write Blocker Diagram
  2. Arm Arm Processor Processor OXUF922 Bridge Chip OXUF922 Bridge Chip

    DMA DMA 1394 / USB / 1394 / USB / UART / IDE / UART / IDE / Serial Serial Queue Queue Manager Manager RAM RAM Control Control
  3. Hardware Write Blockers Hardware Write Blockers Run Software! Run Software!

    Attribution: Brad McMahon Attribution: Brad McMahon Attribution: Brad McMahon Attribution: Brad McMahon
  4. # parted /mnt/usbdsk/target0_img.dd # parted /mnt/usbdsk/target0_img.dd GNU Parted 2.3 GNU

    Parted 2.3 Using /mnt/usbdsk/target0_img.dd Using /mnt/usbdsk/target0_img.dd Welcome to GNU Parted! Type 'help' to view a list of commands. Welcome to GNU Parted! Type 'help' to view a list of commands. (parted) unit (parted) unit Unit? [compact]? B Unit? [compact]? B (parted) print (parted) print Model: (file) Model: (file) Disk /mnt/usbdsk/target0_img.dd: 500107862016B Disk /mnt/usbdsk/target0_img.dd: 500107862016B Sector size (logical/physical): 512B/512B Sector size (logical/physical): 512B/512B Partition Table: msdos Partition Table: msdos Number Start End Size Type File Number Start End Size Type File 1 1048576B 210763775B 209715200B primary ntfs 1 1048576B 210763775B 209715200B primary ntfs 2 210763776B 107586662399B 107375898624B primary ntfs 2 210763776B 107586662399B 107375898624B primary ntfs 3 107586662400B 479341645311B 371754982912B primary ntfs 3 107586662400B 479341645311B 371754982912B primary ntfs 4 479341645312B 500103450111B 20761804800B primary diag 4 479341645312B 500103450111B 20761804800B primary diag (parted) quit (parted) quit # mount -o loop,ro,offset=210763776 /mnt/usbdsk/target0_img.dd /mnt/image/ # mount -o loop,ro,offset=210763776 /mnt/usbdsk/target0_img.dd /mnt/image/ # ls /mnt/image/ # ls /mnt/image/ pagefile.sys Program Files System Volume pagefile.sys Program Files System Volume Information Documents and Settings PerfLogs Information Documents and Settings PerfLogs Program Files (x86) Recovery Users Program Files (x86) Recovery Users ProgramData $Recycle.Bin ProgramData $Recycle.Bin Windows Windows
  5. Thank you Thank you Any Questions? Any Questions? Lee Brotherston

    - Lee Brotherston - @leEb_public - @leEb_public - [email protected] [email protected] Lee Brotherston - Lee Brotherston - @leEb_public - @leEb_public - [email protected] [email protected]
  6. Some Things I Mentioned Some Things I Mentioned • Flow-tools:

    Flow-tools: http://www.splintered.net/sw/flow- http://www.splintered.net/sw/flow- tools/ tools/ • Sleuthkit & Autopsy: Sleuthkit & Autopsy: http://www.sleuthkit.org/ http://www.sleuthkit.org/ • Volatility: Volatility: https://www.volatilesystems.com/default https://www.volatilesystems.com/default /volatility /volatility • C.A.IN.E: C.A.IN.E: http://www.caine-live.net/ http://www.caine-live.net/ • Dc3dd: Dc3dd: http://sourceforge.net/projects/dc3dd/ http://sourceforge.net/projects/dc3dd/