Full Disclosure mailing list archives

Re: Paper: Anti Forensics: making computer forensics hard.


From: "Wendel Guglielmetti Henrique" <wsguglielmetti () gmail com>
Date: Wed, 11 Jul 2007 15:32:18 -0300

Yo,

In this paper (translated from Portuguese in 2006) is presented since basic
until advanced techniques used to defeat forensic analysis.

Including the following topics:

- What is computer forensics?
- What is Anti Forensics?
- Anti Forensics methods:
   Encryption.
   Steganography.
   Self Split Files + Encryption.
   Defeat "last modified files" technique.
   Wipe.
   Data Hiding: swap, file system bad blocks, unallocated spaces, ADS.
   Process dump.
   Integrity check (MD5 Collision).
   Database Rootkits.
   BIOS Rootkits.

You can check the full paper in:
http://ws.hackaholic.org/slides/AntiForensics-CodeBreakers2006-Translation-To-English.pdf

Wendel Guglielmetti Henrique
http://ws.hackaholic.org - personal page
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: