290 likes | 510 Views
Web Forensics. Matthew M. Kimball. Overview. Purpose Where & How Data Is Stored Private Browsing Where Else to Look. Purpose. Reconstruct suspect’s browsing Cyberstalking Cyberterrorism Child Pornography Fraud IP Theft Cracks, Patches, Torrents. Where. Obvious
E N D
Web Forensics Matthew M. Kimball
Overview • Purpose • Where & How Data Is Stored • Private Browsing • Where Else to Look
Purpose • Reconstruct suspect’s browsing • Cyberstalking • Cyberterrorism • Child Pornography • Fraud • IP Theft • Cracks, Patches, Torrents
Where • Obvious • Cache / Temporary Internet Files • Cookies • Favorites • History • Less Obvious • DNS Cache • PlugIns • More to come…
Profiles • Profiles can be moved. • Profile ‘owner’ doesn’t indicate guilt. • Share passwords?
Internet Explorer • index.dat files • Cookies, History, & Temp • Stores: • Timestamps • Headers • Visited URLs • Cached pages • …in a binary format • View cache…see what they saw
FireFox • *.sqlite • about:cache • Memory • Disk • Offline • “Deleted” favorites are recoverable • FF automatically backups favorites • Not deleted when clearing data
FireFox • about:cache • browser.cache.disk.enable • = false…disable disk caching.
FireFox • about:cache • disk cache
FireFox • MozzilaCacheView
FireFox • MozillaHistoryView High visit count = intent = guilty
Opera • cookies4.dat • dcache4.url • Binary index of cache • opr*.* • Cached files in same format as originals but missing extension
Opera • opera:cache
What Is Really Meant By Private? • "Incognito is designed to hide your browsing from your computer, not hide it from the Web," says Google engineer Sundar Pichai.
Incognito & InPrivate • Still Stores on HDD • PC Inspector File Recovery • Recovered a lot but not Incognito or InPrivate data. • Since it’s written to the drive…it’s recoverable • Maybe not with free software but likely with FTK.
Where Else To Look • Downloads • Not deleted after using Incognito & InPrivate • Opera manages torrents • Mostly illegal… • Clipboard • clipbrd.exe • Extensions (FireFox)
Where Else To Look • SharedObjects / Plugins • Tested & failed a break.com visit. • Must disable on Macromedia’s website. • Requires more work to delete.
DNS Cache • Windows • /ipconfig displaydns • Lists websites even after clearing info stored by browsers. • /ipconfig flushdns • Clears DNS listings • Mac • dscacheutil -cachedump -entries Host • dscacheutil -flushcache
HOSTS • Maps host names to IP addresses. • Redirect www.csus.edu to site containing illegal images • Favorites addresses may be altered • Compare with HOSTS files, caches, and current content on site.
DNS Cache • Windows • Lists entries while using InPrivate & Incognito
RAM Disk • Allows RAM to act like a hard drive • Simply relocate where cache is stored • Erased just like RAM • Much more difficult to recover, if possible at all! • Unless it’s in swap or slack space
Still Can’t Find Anything? • Recover Deleted Files • Page files • Opera: Group Project • Slack space • ISP logs • Network & router logs
Tools • Web Historian • Pasco • IE Historian • FTK • EnCase
Summary • Prevents average users using the same computer from revealing your tracks… • If it wasn’t bleached/shredded…they will find it on the hard drive…