Banner leads to the best police officer books written by over 220 state and local police officers who have authored over 550 books, many on law enforcement.

Trends, tactics and terrorism - Open Source Information for law Enforcement
Hi Tech Criminal Justice online
 Join our Newsletter

 Enter Your Email:
Privacy Policy

the latest book on leadership, leading and leaders

 Home Page | Links to Resources | Contact Us

Google


Members

Help

Home
Login | Register 



Criminal Justice Online > Criminal Justice Technology > Forensic Science > taking computer forensics to the "next level"...

 Moderated by: cjustice  

New Topic

Reply

Print
AuthorPost
Gabrielelohim
Member
 

Joined: Sat Feb 16th, 2008
Location:  
Posts: 4
Status:  Offline
Mana: 
 Posted: Wed Apr 30th, 2008 09:12 am

Quote

Reply
to the administrator / moderator(s) of this site... granted i have only posted on this site two (2) times, however 695+ people have viewed my post(s) and no-one has replied...??? am i posing my questions in the "wrong area"???

as is inevitable, time and stubbornness usually answers ones questions for them lol :cool:

the answer to my first question posed in post 1 was simple... BUY ANOTHER COMPUTER... i did and everything works perfectly now...

the answer to my second question posed in post 2 ended up being simple as well... (thank the godz that the password was a simple one =) had it been seven (7) characters or more using a combination of alpha numerics, and specials, i probably would not have been able to break the AES-256 bit encryption. as it was a brute force / xeive attack cracked the encryption in a little over 36 hours... (a side note to those of you that may want to try to get into the file, the zip file itself is corrupted, let alone the file inside being encrypted)

having said that lol, i have another computer forensic question for any gurus that may be lurking ;)

a few of the students in this program and i actually "stumped" the forensic expert(s) / lawyer(s) that run said program recently... the only answer we got from them was a "stumbling", "you did what???" that's really cool but i don't think it is "legally forensically sound"...

what we did was take the bit-stream ISO image from FTK imager, and use it to virtually recreate the target machine using VMware...

i understand their argument when they say if you even touch the virtual recreation you have compromised the "evidence"... and having done that any discovery will not stand up in a court of law...

but my point is this... the examiner / investigator can ALWAYS simply reset the virtual recreation of the target machine back to its original state, regardless of what they do with it...

given this fact, the virtually recreated target machine meets the scientific criteria of being able to REPRODUCE YOUR RESULTS...

having said this, wouldn't it be much simpler for the expert witness to explain to the "lay client or juror" that is not so tech savvy, what the suspect has done by pointing and clicking to where the "demonstrative evidence" resides, rather than trying to explain in layman's terms the intricacies of known forensic tools such as FTK or Encase???

all-right sorry for being so long winded... i guess what i'm asking is, is it possible to "image a virtual machine" so that the same SHA-1 and MD5 hash values found in the original image, are retuned from the image of the virtually recreated "target machine"???


peace,

Gabrielelohim

Last edited on Wed Apr 30th, 2008 09:58 am by Gabrielelohim


 Current time is 03:01 am

Criminal Justice Online > Criminal Justice Technology > Forensic Science > taking computer forensics to the "next level"...

Visit our Sponsors

Computer Forensics

Colleges and Universities

Phoenix University

Technology Schools

 

Powered by WowBB 1.7 - Copyright © 2003-2006 Aycan Gulez
cjhitech theme by: wowbbthemes.com
Page processed in 0.2359 seconds (15% database + 85% PHP). 18 queries executed.