<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>forensics &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/forensics/</link>
	<description>Feed of posts on WordPress.com tagged "forensics"</description>
	<pubDate>Fri, 25 Dec 2009 01:17:05 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[The Spectrum of Rape, Stalking and Offenders]]></title>
<link>http://medicalcontroversy.wordpress.com/2009/12/24/the-spectrum-of-rape-stalking-and-offenders/</link>
<pubDate>Thu, 24 Dec 2009 12:25:50 +0000</pubDate>
<dc:creator>Thilini Mahaliyana</dc:creator>
<guid>http://medicalcontroversy.wordpress.com/2009/12/24/the-spectrum-of-rape-stalking-and-offenders/</guid>
<description><![CDATA[What is Rape Sexual assault (including rape as sub-category) is a common crime in Australia affectin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3>What is Rape</h3>
<p>Sexual assault (including rape as sub-category) is a common crime in Australia affecting 0.3-0.7% of the total population per year and affecting close to 20% of 18-24 year old women in the past 12 months(!) Only 15% of sexual assaults are reported to the police.</p>
<p>Let us define rape. This is difficult as can be evidenced by a quick google search for <a title="bloody hell" href="http://www.google.com/search?client=opera&#38;rls=en-GB&#38;q=define:rape&#38;sourceid=opera&#38;ie=utf-8&#38;oe=utf-8">definitions of rape</a>. Let us go with the following for now:</p>
<blockquote><p><strong>&#8220;Rape is defined as forced, manipulated or coerced sexual intercourse (or other sexual act) against the will of the victim. If the act occurs while the victim is unconscious, asleep or otherwise unable to communicate unwillingness, it is still considered rape.&#8221;</strong></p></blockquote>
<p><em>(As per Massacheusetts law)</em></p>
<h3>What is Stalking</h3>
<p>Stalking too is a common phenomenon, affecting some 23% of people throughout their lifetime, and with rates of 32% amongst people aged 18-35.</p>
<p>There are various definitions of stalking in legal and academic literature. The nature of the behaviours and the intent are controversial areas- if the intent is romantic in nature, is it stalking? Similarly, if it is a seemingly innocent gesture but is repeated and done in such a way to cause (reasonable) fear, is it stalking? Consensus however is reached when it comes to the effect on the victim: it is necessary that the conduct causes the victim to fear for his/her safety. Thus I use the following definition:</p>
<blockquote><p>&#8220;Stalking refers to a course of conduct by which one person repeatedly inflicts on another unwanted intrusions to such an extent that the recipient fears for his or her safety.&#8221;</p></blockquote>
<p><span style="font-style:italic;">(Purcell, Pathé, Mullen 2004)</span></p>
<h3>Who Rapes, Stalks- and Why?</h3>
<p>Many models have been proposed for rape, stalking, sexual murder and sexual assault, striving to represent the diversity of motive and execution evident in the crime.</p>
<h4>Summary of Convicted Rapists</h4>
<p>Not all rapists (I must point out once again) are psychopathic- fully <strong>half</strong> are non-psychopathic.</p>
<p>&#62;95% of reported rapes have a male perpetrator. However female rapists are likely very underrepresented due to sociocultural factors and attitudes.</p>
<p>It is also to be noted that rapists carry a recidivism rate (for all crimes) of roughly 50%- the highest rate for violent offenders; convicted paedophiles carry a rate of between 10-50% depending on study and subcategorisation, which includes both child rapists as well as those attracted to children.</p>
<h4>Summary of Convicted Stalkers</h4>
<p>Stalking has only recently entered the popular lexicon despite reports of stalking behaviours since at least the 1800s; it became a common term only some time in the 1980&#8217;s, as a response to celebrity stalkers. This became more generalised to harrassment and predatory behaviour towards non-famous victims.</p>
<p>In contrast with rape, the gender split with perpetrators is roughly 50/50. Once again, this difference may represent greater social acceptability for people to report female stalkers than female rapists.</p>
<p>Various studies of stalkers have also shown that concurrent psychiatric problems (whether psychosis, mood disorder or personality related) were almost universal in this group.</p>
<h4>The FBI Model of Violent Crime</h4>
<p>The FBI have a model which divides rapists (and other violent criminals) into &#8220;organised&#8221; and &#8220;disorganised&#8221; subtypes. Organised being those who plan carefully, leave few traces of their crime, do not do random acts of &#8220;ultra-violence&#8221;. Disorganised being those who display &#8220;chaotic&#8221; features (such as ultra-violence, lack of planning, messiness, etc.)</p>
<p>The FBI model has very little evidence to back it and unsurprisingly is widely derided as simplistic, artificial, unreaistic and, well, incorrect.</p>
<h4>More Modern Typologies of Rape, Stalking and Sexual Murder</h4>
<p>The only reason for the multiplicity of categories in the diagram below is because of the overlap present in the typologies of rapists, sexual murderers and stalkers in the studies below. These studies took data from crime scenes, criminals and victims and came up with distinct behavioural and motivational clusters.</p>
<p><a title="Click for bigger version :: Sexual Crimes and their Typologies (by study) by Snipergirl, on Flickr" href="http://www.flickr.com/photos/snipergirl/2471859216/"><img src="http://farm3.static.flickr.com/2370/2471859216_3289c8eb28.jpg" alt="Sexual Crimes and their Typologies (by study)" width="500" height="116" /></a></p>
<p><span style="font-style:italic;">(Click for larger version)</span></p>
<p>However, when you compare the studies it would be more accurate to speak of roughly 6 subtypes as follows:</p>
<ul>
<li>1a: Violent, aggressive types who are motivated by pure revenge against the victim. Thus, entirely violent, paranoid motivations, associated with paranoia as well as Cluster B* (antisocial, narcissistic, borderline, histrionic) personality traits.</li>
<li>1b: Violent, angry and power-obsessed types who are motivated because of (perceived) rejection by the victim. Thus, sex/intercourse is also a factor. Associated with Cluster B traits.</li>
<li>2a: Socially inept, intimacy seeking, incompetent types who do not know any other sure-fire method of procuring intimacy/intercourse and/or who rape because they feel socially inadequate and insecure. They are purely motivated by the desire for sex/intimacy and only use as much force is necessary to get what they want. Murder is an accidental sequel to this. Usually socially inept/of low IQ.</li>
<li>2b: Delusional, intimacy seeking types who believe that their victim is in love with them back. Associated with psychosis and schizophrenia.</li>
<li>3: Sadistic, fetishistic, predatory types who plan meticulously and whose motivation is complex violent sexual fetish- an extreme form of the combination of sex and violence. Very dangerous, unrepentant, skilled. Associated with psychopathy and extreme paraphilias.</li>
<li>4: &#8220;Other&#8221;. This more nebulous group includes oppportunistic, inept, short term, unplanned acts of random violence, often associated with the commission of other crimes including robbery.</li>
</ul>
<p><span style="font-style:italic;">*Cluster B personality disorders include: antisocial (violence, disregard for others&#8217; rights, egocentrism, low empathy, includes the subgroup of psychopaths), narcissistic (egocentricity, inflated self-esteem, callous disregard for others), histrionic (attention-seeking, shallow but dramatic moods, egocentrism, overdramatic), borderline (unpredictable behaviour, low self-esteem, inner emptiness, clingy behaviour, mood swings, rapid change from idolisation to demonisation). This group of disorders has high overlap and there is a (possibly cultural) propensity for men to be diagnosed (or misdiagnosed) with APD or narcissism vs women and BPD or histrionicity.</span></p>
<p>So you see, it is not as simple as &#8220;organised&#8221; vs &#8220;disorganised&#8221;, &#8220;sane&#8221; vs &#8220;insane&#8221;, or &#8220;rape as power&#8221;. Rape has many many motivations including power, sex, revenge, delusion, opportunity. Similarly it is not just psychopaths who rape. <span style="font-style:italic;">Fully half</span> of all rapes are committed by people who have other psychological problems, or even no identifiable psychological problem at all.</p>
<p>The results of the rape are also varied. Someone who is motivated by an inept desire for intercourse may end up killing the victim. Someone motivated by psychopathic predatory thoughts may only stalk their victim and never proceed to rape or sexual murder.</p>
<h4>MTC:R3 &#8211; Towards a More Complex Model of Rape</h4>
<p>I did lie. There was some significance to the multiplicity of categories.</p>
<p><a title="The MTC:R3 - Taxonomy of Rapists by Snipergirl, on Flickr" href="http://www.flickr.com/photos/snipergirl/2516957992/"><img src="http://farm4.static.flickr.com/3227/2516957992_4245b8f2a4.jpg" alt="The MTC:R3 - Taxonomy of Rapists" width="500" height="355" /></a></p>
<p><span style="font-style:italic;">(Click for larger version)</span></p>
<p>The Massachusetts Treatment Center Rapist typology, Version 3 (Knight &#38; Prentky, 1990)</p>
<p>This taxonomy (think species) of rapists is more nuanced and based on a larger set of data. Rather than relying on 4-6 unrelated categorisation, it incorporates underlying psychopathology, motive and the level of violent and/or sexual motivation that is behind these rapes.</p>
<p>There is, then, an interesting distinction that comes about which I shall illustrate below:</p>
<p><a title="MTC:R3 - red = sexualisation, yellow = violence by Snipergirl, on Flickr" href="http://www.flickr.com/photos/snipergirl/2518790348/"><img src="http://farm3.static.flickr.com/2339/2518790348_bc1d872c6d.jpg" alt="MTC:R3 - red = sexualisation, yellow = violence" width="500" height="306" /></a></p>
<p><span style="font-style:italic;">(Click for larger version)</span></p>
<p>I have recoloured the diagram so that the level of red represents sexualisation and the level of yellow represents violence.</p>
<p>In non-psychopathic sexual offenders, violence and sexualisation are inversely correlated- they range from red to yellow with only a very muted orange in-between. However, in psychopathic sexual offenders, violence and sexualisation are positively correlated- they are only various shades of orange. Note that this is true only for psychopathic RAPISTS, not for ALL psychopaths. Thus, perhaps in that minority of psychopaths who rape, violence and sex are much of the same emotion. This is in fact reinforced by the finding that while the VRAG (violent risk appraisal guide) which includes the PCL:R (the most common scale for measuring psychopathy) is a reasonable predictor for psychopathic rape and recidivism, an adjusted scale known as the SORAG (sex offending risk appraisal guide) which includes physical measurement of sexual arousal to sexual deviance in fact correlates with this criminal behaviour much better.</p>
<p>And here we reach perhaps the crux of what I used to not understand about this crime. How such a thing could be done.</p>
<h3>How could someone do this?</h3>
<p>Some people do not know how to have sex, so they force it out of someone to get their way; they do not know much better. Some people are particularly angry and want to hurt and humiliate someone in particular and they know the effect that rape has; it is not about sex, it is about power and violence. Some people are just so horny and angry at the same time, or so turned on by domination and humilation that they plot and plan and find a victim to lash out at and fulfil their fantasies.</p>
<p>And.</p>
<p>Some people do it because there&#8217;s someone right there and they just <span style="font-style:italic;">can</span>, very easily- maybe just ignore that they&#8217;re saying no or that they passed out or that they&#8217;re drunk or drugged or happened to be there, pretend that it was the heat of the moment and they were really asking for it and how could someone stop themselves in that situation. I mean, <span style="font-style:italic;">you </span>understand don&#8217;t you? It&#8217;s not like [<span style="font-style:italic;">person</span>] would&#8217;ve ever been in that position if they didn&#8217;t really want it, and you know how [<span style="font-style:italic;">person</span>] is such a tease and they put me in this position where I just couldn&#8217;t help myself. What are you gonna do in that situation? Just stop?</p>
<p>I guess my point is that many people are apologists for the opportunity rapist and the date rapist. In fact, there are many who argue that it is not rape or that in that situation maybe they would do the same thing, or that the victim is to blame for the assault. Look at the underlying thought process and see its real meaning though:</p>
<blockquote><p>&#8220;I raped because I could&#8221;</p></blockquote>
<p>It is an abnormal thought process. It is in fact a psychopathic thought process. It is not the product of the usual human mind. The &#8220;I could not stop myself&#8221; and the &#8220;she was asking for it&#8221; are merely excuses and justifications for the true reason- &#8220;because I could&#8221;.</p>
<h3>Discussion</h3>
<p>I believe that it is facile and simplistic to conclude that distinguishing particular patterns of rape means that some rapes (as defined above) are not rapes or that rape is a lesser crime according to motivation or psychopathology. The effect on the victim of the rape is dependent on many factors including the psychology of the victim- we do not claim that it is not a rape if the victim recovers better from the psychological trauma, so why should we claim that it is not a rape if the motivation for the rape was X, Y or Z?</p>
<p>Sentencing is yet another issue and an altogether unrelated one. Sentencing takes into account societal impact, likelihood of recidivism and other factors- it is not and should not be interpreted purely as a measure of morality. It is a means by which society maintains social control, order, attempts to reduce the likelihood of crime and segregates the potential recidivist from potential future victims.</p>
<p>Some rapists, stalkers, sexual murderers are far more amenable to rehabilitation than others. Some rehabilitation exercises do reduce recidivism and some do not. These factors are very important to find because of the following statistics:</p>
<ul>
<li>50% of rapists re-offend in some way</li>
<li>50% do not</li>
<li>Nearly all stalkers who harrass their victims have an associated psychiatric diagnosis- which may vary from frank schizophrenia/psychosis to an embedded personality disorder.</li>
<li>Non-psychopathic offenders respond well to rehabilitation and therapy- some reoffend anyway but in significantly lower numbers</li>
<li>Psychopathy as a personality trait has shown very little promise for treatment and psychotherapies used for non-psychopathic offenders in fact increase or have no effect on recidivism rate- but early research suggests psychopathic offenders <span style="font-style:italic;">may </span>show lower recidivism rates as a result of punishment/behaviour based regimens</li>
</ul>
<p>Thus, as a heterogenous group of people it is important that society does more research and action into finding appropriate stategies for managing these complex crimes. There is some suggestion that the gradually increasing sentence and taboo against rape has in fact led to a far lower rate of conviction for offenders than previously- someone is far more likely to plead guilty to a 2 year sentence than a 10 year one.</p>
<p>Perhaps we should champion a graded system for rape and sexual assault- the first offence being 2 years and psychiatric evaluation, treatment and rehabilitation. The 2nd offence, 5 years with treatment and close community monitoring, the 3rd 10 years with treatment and very intensive community monitoring. First time offenders would be more likely to admit to their crime and all would undergo measures to attempt to rehabilitate them. However the punishment would increase with each subsequent offence- and remember it is much easier to reconvict someone than to convict someone on a first time offence. Accordingly there should be close surveillance of this vulnerable group to lessen the risk of re-offending.</p>
<p>With stalking, the psychiatric diagnosis is paramount; some stalkers are experiencing a frank psychotic episode and requite psychiatric hospitalisation and treatment. Others may be motivated by a personality disorder such as borderline personality or psychopathy. Depending on what this is, treatment and punishment should proceed accordingly.</p>
<h3>Conclusion</h3>
<p>Rape and stalking are common crimes affecting a large percentage of the population. They are also under-reported crimes. Thus it is highly likely if not definitely true that we all know someone who has been raped, stalked or both. Even if the number of perpetrators is low &#8211; this would imply a high re-offending rate, consistent with the data. Not only are these crimes common, but their incidence far outweighs the likelihood of a false report. False reports no doubt happen and it is very unfortunate and vindictive if they do so; however such events are very rare indeed and far more common is true rape, stalking and sexual assault.</p>
<p>Rapists and stalkers both commit their crimes for a variety of reasons, sexual, violent or both. These reasons include desire for intimacy, revenge/retaliation, sexual fetishism and pure opportunity. Both rapists and stalkers have a high rate of recidivism and co-existing psychiatric diagnosis, whether it be psychotic, mood-related or personality disorder including psychopathy. They are a complex group of criminals with varying motivations and modes of activity but this makes their crimes no less wrong.</p>
<p>Similarly, victims range from young women of reproductive age to babies to old women to old men to young men and anywhere in between. This variability indeed highlights the fact that no victim of rape or stalking is deservent of the crime but is in fact a &#8220;convenient object&#8221; for the commission of the crime. If it were not them, it would be someone else, so to speak.</p>
<p>It is important that we recognise that these crimes do happen to people we know and are far more common than we realise. It is also very important not to blame the victim and to realise that most of the perpetrators are mentally ill individuals who require psychiatric treatment, rehabilitation and/or even segregation from the greater community.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Biography #108]]></title>
<link>http://kevinjamesbarr.wordpress.com/2009/12/22/biography-108/</link>
<pubDate>Wed, 23 Dec 2009 01:25:15 +0000</pubDate>
<dc:creator>kevinjamesbarr</dc:creator>
<guid>http://kevinjamesbarr.wordpress.com/2009/12/22/biography-108/</guid>
<description><![CDATA[December 17, 2009 I had my sixth shot today. No side effects other than occasional itchy skin. I giv]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>December 17, 2009</strong></p>
<ul>
<li style="text-align:justify;">I had my sixth shot today. No side effects other than occasional itchy skin. I give another blood test on the 30th of December. Hopefully it will show no copies in my blood.</li>
</ul>
<p><strong>December 19, 2009</strong></p>
<ul>
<li style="text-align:justify;">I attended the 21st annual Oppenheimer Park festival. It was really quite good with plenty for everyone. I managed to get a winter vest, gloves and hats, and a sweater.</li>
<li style="text-align:justify;">Not doing much on the home front. I am just downloading a bunch of music that I got at the library.</li>
</ul>
<p><strong>December 22, 2009</strong></p>
<ul>
<li style="text-align:justify;">I have been waiting to see if my lawyer is going to contact me or not so that I can make plans to appeal the Conditional Discharge that I again received.</li>
</ul>
<p style="text-align:center;"><em><strong><span style="color:#ff0000;">Bah Humbug and Season&#8217;s Greetings</span></strong></em></p>
<p style="text-align:justify;">Play the following for your enjoyment:</p>
<p style="text-align:justify;">Robert Plant&#8217;s &#8220;<em>Darkness, Darkness</em>&#8220;;  Van Halen&#8217;s &#8220;<em>Mean Street</em>&#8220;; Bad Finger&#8217;s &#8220;<em>No Matter What</em>&#8220;; Simon &#38; Garfunkel&#8217;s &#8220;<em>I Am A Rock</em>&#8221; and John  Lennon&#8217;s &#8220;<em>Imagine</em>&#8220;.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Adventures In Body Modification]]></title>
<link>http://williamthecoroner.wordpress.com/2009/12/21/new-adventures-in-body-modification/</link>
<pubDate>Mon, 21 Dec 2009 16:29:33 +0000</pubDate>
<dc:creator>williamthecoroner</dc:creator>
<guid>http://williamthecoroner.wordpress.com/2009/12/21/new-adventures-in-body-modification/</guid>
<description><![CDATA[Melt Restaurant in Lakewood, Ohio is offering a 25% discount for life for their customers who get a ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.upi.com/Odd_News/2009/12/17/Eatery-offers-discounts-for-tattooed/UPI-13841261078481/">Melt Restaurant in Lakewood, Ohio is offering a 25% discount for life for their customers who get a tattoo of their logo, a grilled cheese sandwich, on their bodies</a>.  H/T <a href="http://thedrawncutlass.blogspot.com/">Bob</a></p>
<p>I&#8217;ve seen many interesting tattoos as a forensic pathologist.  The guy who shot his wife and then turned the gun on himself, who had tat of a naked woman in chains kneeling in front of a grotesque skull castle.  That was when I started really noticing and researching tattoos.  The alcoholic who had &#8220;your name&#8221; tattooed on his penis, and used it to win bar bets (and died of cirrhosis).  The man who was shot by police with the word &#8220;Outlaw&#8221; written across his chest in fractur script.  </p>
<p>I&#8217;ve seen plenty of Harley Davidson tattoos.  I&#8217;m not sure that I would be willing to get a brand name upon my body, even if it was a brand I liked.  I tend to favour classic tattoo iconography, companies and brands both change too often.  I also think that a human analogue of a NASCAR vehicle is&#8230;creepy.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Countdown 01/01/2010]]></title>
<link>http://therevelationpainting.wordpress.com/2009/12/21/countdown-01012010/</link>
<pubDate>Mon, 21 Dec 2009 14:00:22 +0000</pubDate>
<dc:creator>the revelation painting</dc:creator>
<guid>http://therevelationpainting.wordpress.com/2009/12/21/countdown-01012010/</guid>
<description><![CDATA[Come see the progress! http://www.therevelationpainting.com You are the first to see it.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong><span style="color:#ff0000;">Come see the progress!<br />
<a href="http://www.therevelationpainting.com">http://www.therevelationpainting.com</a><br />
You are the first to see it.</span></strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[COFEE, DECAF and all that crap]]></title>
<link>http://happyasamonkey.wordpress.com/2009/12/21/cofee-decaf-and-all-that-crap/</link>
<pubDate>Mon, 21 Dec 2009 06:47:26 +0000</pubDate>
<dc:creator>happyasamonkey</dc:creator>
<guid>http://happyasamonkey.wordpress.com/2009/12/21/cofee-decaf-and-all-that-crap/</guid>
<description><![CDATA[Apologies for the semi-serious post. There&#8217;ll be a funny Christmas one along soon. First there]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Apologies for the semi-serious post. There&#8217;ll be a funny Christmas one along soon.</p>
<p>First there was COFEE. I wrote about COFEE in my <a href="http://happyasamonkey.wordpress.com/2009/11/11/computer-forensics-in-the-geek-press-a-taxonomy/">first blog</a> on here, but it was mostly as a way of introducing a piss-taking article about the different groups who comment on computer forensics in the online geek press.</p>
<p>In case you don&#8217;t know, COFEE is a bundle of freely available, mundane volatile-data collection tools released by Microsoft to LE only. It isn&#8217;t exciting, but the fact that it was shrouded in mystery at Microsoft&#8217;s behest made for some hugely entertaining speculative column inches on t&#8217;internet.</p>
<p>Then a few weeks ago, COFEE was leaked onto said t&#8217;internet and merriment ensued. At first the frenziedly self-polluting masses whooped with joy at the release of this pernicious tool &#8211; it was Darth Vader&#8217;s helmet, the eye of Sauron, Freddy&#8217;s claws, Silas&#8217;s cilice, the evil Nazi&#8217;s monocle &#8211; and it was IN THEIR GRASP! This&#8217;d really stick it to the man! Yeah! Then they paused for a bit (while other people who actually knew what they were doing had a look at COFEE and reported back), and they realised that it was a bit crap really.</p>
<p>The mob by this time were in a witch-burning mood, and they weren&#8217;t going to be thwarted by the fact that their bride of Satan was revealed to be just some unpopular bint with a hook nose. So they created an effigy, and this effigy was given a non-too-subtle  placard reading &#8216;Law Enforcement Computer Forensics Practitioners&#8217;. &#8216;Look!&#8217;, they howled, &#8216;this thumbdrive of Sysinternals apps is the SUM TOTAL OF POLICE KNOWLEDGE! This is the only forensic tool that the police have ever used, ever, in their lives, ever! Ever! They go swanning into houses, plug in this thing and send people to prison&#8230;with this crap!&#8217;</p>
<p>And lo, the LE forensics folk said &#8216;LOL&#8217;. And most of the private sector folk had already realised that they&#8217;d never actually been called on to look at evidence gathered with COFEE by the police, and they weren&#8217;t too bothered either, particularly when they attended a mixed-class live forensics course (such as the excellent ones run by <a href="http://www.csitech.co.uk/">Nick Furneaux</a>) and realised that everyone was using the same tools anyway.</p>
<p>And then there was DECAF. This was released as an antidote to COFEE, a set of tools that would detect when some jackbooted minion of the state plugged COFEE into a computer, and drive a stake through its cold, black heart. The ignorant masses rejoiced again, for they had found a witchfinder general who would stop the evil minions of The Man from erm&#8230; using their lawful powers to catch criminals. Whatever. Comments threads in news articles were positively <em>dripping</em> with the froth expelled by these people, as they did their utmost to imitate the taxonomy I&#8217;d set out in my first post (<a href="http://forums.theregister.co.uk/forum/2/2009/12/14/microsoft_cofee_vs_decaf/">don&#8217;t believe me?</a>)</p>
<p>In the latest instalment of this saga, the authors of DECAF have revealed that their toolkit was a <a href="http://www.decafme.org/">stunt</a> (along with what surely wins the prize for &#8216;<a href="http://praetorianprefect.com/wp-content/uploads/2009/12/decafme_message.jpg">most incongruously placed proselytizing</a>&#8216;). It&#8217;s not a hoax as such &#8211; the tools work, if you can be bothered to reactivate them &#8211; but they seem to have released their set of mundane, push-button tools to make a point about governments relying on mundane, push-button tools to do their work for them. DECAF, like COFEE, is a bit crap. As this <a href="http://praetorianprefect.com/archives/2009/12/reactivating-decaf-in-two-minutes/">excellent article</a> at Praetorian Prefect points out, the time that paedos spend trying to get it work is time away from their offending &#8211; and if it gives them a false sense of security, all the better. I can just imagine them howling with rage as their computers are taken out in black bin bags &#8220;You didn&#8217;t use COFEE! Go on, plug COFEE in and see what happens! Not fair! Some tape-changer on Slashdot said that you all use COFEE&#8221;</p>
<p>DECAF&#8217;s purpose is very noble, and it&#8217;s hard to argue with the sentiment&#8230;except that as far as I can see, we <em>haven&#8217;t</em> been &#8220;relying on a tool to automate the process of forensics&#8221;, not in the way that the DECAF authors meant anyway. I work in the UK, and I&#8217;ve never heard of <em>anyone</em> using COFEE in anger. Just because MS released it to LE, doesn&#8217;t mean we use it. It&#8217;s one of the options out there, but there are toolkits that do more, do it better, and do it with tools that have been widely tested and that don&#8217;t rely on secrecy to protect them (from what? I don&#8217;t know, MS never said). Automating&#8217;s fine, and no one working in LE has the luxury of approaching every job with nothing but a hex editor and DD in their hand any more, but you&#8217;ve also got to be able to understand and validate your findings. <em>That&#8217;s</em> the message that they should have been trying to get across.</p>
<p>COFEE was never a tool for forensics people, it was a tool for untrained first responders, probation officers, sex offender units etc. The argument about whether these people should be touching a suspect&#8217;s computer is one for another day (and probably another blog), but my feeling is that if the circumstances dictate, the powers to search are there and it&#8217;s the difference between getting some vital evidence on an offender and not getting it, then the evidence should be got and the technical provenance can be discussed reasonably by the experts before court.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quickpost: Read-Only USB Stick]]></title>
<link>http://blog.didierstevens.com/2009/12/20/quickpost-read-only-usb-stick/</link>
<pubDate>Sun, 20 Dec 2009 20:52:33 +0000</pubDate>
<dc:creator>Didier Stevens</dc:creator>
<guid>http://blog.didierstevens.com/2009/12/20/quickpost-read-only-usb-stick/</guid>
<description><![CDATA[When someone asks me for a read-only USB stick, I recommend to use an SD card with a SD-to-USB adapt]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>When someone asks me for a read-only USB stick, I recommend to use an <a href="http://en.wikipedia.org/wiki/Secure_Digital" target="_blank">SD card</a> with a SD-to-USB adapter, because these are easier to find than USB sticks with write-protection. Most SD cards have a write-protection tab.</p>
<p><img class="alignnone size-full wp-image-1882" title="20091220-214410" src="http://didierstevens.wordpress.com/files/2009/12/20091220-214410.png" alt="" width="500" height="679" /></p>
<p>But last time I got a surprise: when testing a new SD card reader, I was able to write to the write-protected SD card. Turns out that this particular SD card reader doesn&#8217;t support the write-protection tab and always allows the OS to write to the SD card.</p>
<hr /><a href="http://blog.didierstevens.com/2007/11/01/announcing-quickposts/">Quickpost info</a></p>
<hr />
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 7 CD Emulator]]></title>
<link>http://digitaldilemma.wordpress.com/2009/12/20/windows-7-cd-emulator/</link>
<pubDate>Sun, 20 Dec 2009 03:21:46 +0000</pubDate>
<dc:creator>xaviermorgan</dc:creator>
<guid>http://digitaldilemma.wordpress.com/2009/12/20/windows-7-cd-emulator/</guid>
<description><![CDATA[I was downloading some things from Microsoft Dreamspark, and I needed to mount an ISO without actual]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I was downloading some things from Microsoft Dreamspark, and I needed to mount an ISO without actually burning a DVD/CD. </p>
<p>I bounced around to several sites, and I found a couple of things.&#160; There is an attractive project on sourceforge (windcdemu) that does not work in Windows 7.&#160; You can find the project at <a title="http://wincdemu.sysprogs.org/" href="http://wincdemu.sysprogs.org/">http://wincdemu.sysprogs.org/</a> if you want to give it a shot.&#160; </p>
<p>I went further and found <u><strong>Virtual Clone Drive</strong></u>: <a title="http://www.slysoft.com/en/download.html" href="http://www.slysoft.com/en/download.html">http://www.slysoft.com/en/download.html</a></p>
<p>This fellow has this in his list of software as the last item.&#160; It is freeware.&#160; I installed the software, and it required a reboot.</p>
<p><a href="http://digitaldilemma.files.wordpress.com/2009/12/image.png"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="image" border="0" alt="image" src="http://digitaldilemma.files.wordpress.com/2009/12/image_thumb.png?w=244&#038;h=85" width="244" height="85" /></a> </p>
<p>I mounted the drive by right clicking on the ISO:</p>
<p><a href="http://digitaldilemma.files.wordpress.com/2009/12/image1.png"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="image" border="0" alt="image" src="http://digitaldilemma.files.wordpress.com/2009/12/image_thumb1.png?w=354&#038;h=265" width="354" height="265" /></a> </p>
<p>And there I had it.&#160; My ISO of Visual Studio 2010 worked like a champ!</p>
<p><a href="http://digitaldilemma.files.wordpress.com/2009/12/image2.png"><img style="border-bottom:0;border-left:0;display:inline;border-top:0;border-right:0;" title="image" border="0" alt="image" src="http://digitaldilemma.files.wordpress.com/2009/12/image_thumb2.png?w=408&#038;h=204" width="408" height="204" /></a> </p>
<p>I saw a reference to this in one article.&#160; It appears to be a Microsoft CD ROM emulator.&#160; </p>
<p>The Microsoft product did not work for me, but you can try it to see if the .sys file works for you.&#160; It seems a little old, and it might not be Windows 7 compatible.&#160; You can try it if you want:</p>
<p><img title="Download" alt="Download" src="http://support.microsoft.com/library/images/support/kbgraphics/public/EN-US/Download.gif" />For more information, see the Readme.txt file for Virtual CD-ROM Control Panel. This file is included in the Virtual CD-ROM Control Panel download.     <br />The following file is available for download from the Microsoft Download Center:</p>
<p><a href="http://download.microsoft.com/download/7/b/6/7b6abd84-7841-4978-96f5-bd58df02efa2/winxpvirtualcdcontrolpanel_21.exe">Download the Microsoft Virtual CD-ROM Control Panel package now.</a> (<a href="http://download.microsoft.com/download/7/b/6/7b6abd84-7841-4978-96f5-bd58df02efa2/winxpvirtualcdcontrolpanel_21.exe">http://download.microsoft.com/download/7/b/6/7b6abd84-7841-4978-96f5-bd58df02efa2/winxpvirtualcdcontrolpanel_21.exe</a>) </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Computer Forensics Tools]]></title>
<link>http://elidaslokes.wordpress.com/2009/12/18/computer-forensics-tools/</link>
<pubDate>Fri, 18 Dec 2009 18:30:18 +0000</pubDate>
<dc:creator>elidaslokes</dc:creator>
<guid>http://elidaslokes.wordpress.com/2009/12/18/computer-forensics-tools/</guid>
<description><![CDATA[In generale, un ricercatore di computer forensic utilizzerà uno strumento per raccogliere dati da un]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p> In generale, un ricercatore <b>di computer</b> forensic utilizzerà uno strumento per raccogliere dati da un sistema (ad esempio un <b>computer</b> o una rete di <b>computer)</b> senza alterare i dati su quel sistema. Questo aspetto di un&#39;inchiesta, la cura per evitare di alterare i dati originali, è un principio fondamentale del <b>computer</b> esame medico-legale e di alcuni degli strumenti disponibili includono funzionalità specificamente progettato per sostenere questo principio. In realtà non è sempre facileraccogliere dati senza alterare il sistema in qualche modo (anche l&#39;atto di chiusura di un <b>computer</b> al fine di trasporto, essa cambia causa più probabile che i dati su tale sistema), ma un investigatore esperto sarà sempre possibile per proteggere l&#39;integrità dei dati originali quando possibile. Per fare questo, gli esami <b>di computer</b> forensic implicano la realizzazione di molti dei una copia esatta di tutti i dati su un disco. Questa copia è chiamato l&#39;immagine e il processo di creazione di un&#39;immagine èspesso definito come l&#39;imaging. E &#39;questa l&#39;immagine che di solito è l&#39;oggetto di un successivo esame. </p>
<p> Un altro concetto chiave è che i dati cancellati, o parti di essi, possono essere recuperabile. In linea generale, quando i dati vengono eliminati, non è fisicamente cancellati dal sistema ma solo un riferimento alla posizione dei dati (su un disco rigido o altro supporto) viene rimosso. Così i dati possono essere ancora presente, ma il sistema operativo del <b>computer</b> non è più &#34;sa&#34; su di esso. Con l&#39;imaginge l&#39;esame di tutti i dati su un disco, piuttosto che solo le parti conosciute del sistema operativo, potrebbe essere possibile recuperare i dati che sono stati eliminati accidentalmente o intenzionalmente. </p>
<p> Sebbene la maggior parte di strumenti del mondo reale sono destinate a svolgere un compito specifico (il martello per piantare chiodi, il cacciavite per girare una vite, ecc), alcuni strumenti sono progettati per essere multi-funzionale. Allo stesso modo alcuni strumenti <b>di computer</b> forensic sono progettati con un solo obiettivo in mente, mentre altri possono offrire unintera gamma di funzionalità. La natura unica di ogni inchiesta dovrà stabilire quale strumento di toolkit per lo sperimentatore è il più adeguato per il compito in mano. </p>
<p> Così come in diverse funzionalità e la complessità, <b>computer</b> forensic strumenti differiscono anche in termini di costi. Alcuni dei leader di mercato commerciale dei prodotti costano migliaia di dollari, mentre altri strumenti sono completamente gratuiti. Ancora una volta, la natura dell&#39;esame forense e l&#39;obiettivo della inchiesta dovrà stabilire lapiù strumenti adeguati per essere utilizzati. </p>
<p> La collezione di strumenti a disposizione del ricercatore continua ad espandersi e molti strumenti vengono regolarmente aggiornati dai loro sviluppatori per consentire loro di lavorare con le ultime tecnologie. Inoltre, alcuni strumenti di fornire funzionalità simili, ma una diversa interfaccia utente, mentre altri sono unici nelle informazioni che forniscono al esaminatore. In questo contesto è compito dell&#39;esaminatore <b>computer</b> forensic a giudicare quali strumenti sono lapiù adeguata per un accertamento, tenuto conto della natura delle prove che devono essere raccolti e il fatto che a un certo punto può essere presentata ad un tribunale. Senza dubbio, il numero crescente di entrambe le cause civili e penali in cui gli strumenti <b>di computer</b> forensic svolgere un ruolo importante fa di questo un campo affascinante per tutti i soggetti coinvolti. </p>
<p>See Also :  <a href="http://buydewalttools.co.cc" rel="dofollow" title="">Dewalt</a>  <a href="http://healthy-i-diet.blogspot.com" rel="dofollow" title="healthy i diet">healthy i diet</a> </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hidden Hymn]]></title>
<link>http://digitaldetective.wordpress.com/2009/12/17/hidden-hym/</link>
<pubDate>Thu, 17 Dec 2009 23:35:04 +0000</pubDate>
<dc:creator>digitaldetective</dc:creator>
<guid>http://digitaldetective.wordpress.com/2009/12/17/hidden-hym/</guid>
<description><![CDATA[There is something quintessentially British about the unique blend of gusto and gibberish which make]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><em>There is something quintessentially British about the unique blend of gusto and gibberish which makes up a Gilbert and Sullivan operetta</em>.  <em>What is less well known, perhaps, is that Arthur Sullivan also wrote</em> <em>the music to the world-famous hymn</em> &#8216;Onward Christian Solidiers&#8217;.  <em> </em></p>
<p><em>It seems he also tried his hand at a lyric to the tune, which was later discarded.  Now, though, the sole surviving copy of that lyric has emerged &#8211; yet another extraordinary treasure recently found amongst a cache of forgotten manuscripts.</em></p>
<p><em>We are delighted to reproduce the full lyric here. </em></p>
<p><em> Tune:  <a href="http://www.cyberhymnal.org/mid/s/t/g/st_gertrude.mid">St Gertrude by A. Sullivan</a></em></p>
<p><strong><span style="text-decoration:underline;">Hymn for the Unsung Heros</span></strong><em><br />
</em></p>
<p>Onward First Responders, marching as to war,<br />
With the ACPO Guidelines going on before.<br />
<em>Tableau</em>s at the ready, armed against the foe,<br />
Forward into battle see those White Hats* go!<br />
(*LE singers may substitute “Blue lights” here. &#8211; AS.)</p>
<p>Refrain</p>
<p><em>Onward First Responders, marching as to war,<br />
With the ACPO Guidelines going on before.</em></p>
<p>Dawn of retribution! Watch the suspects stare;<br />
They and their Redeemer know what you’ll find there!<br />
All their nasty surfing, docs and pix and more;<br />
See, they fear the advent of the long arm of the Law.</p>
<p>Refrain</p>
<p>Image every hard drive, every USB,<br />
Make a very detailed chain of custody,<br />
There will be no tiny evidential fault<br />
Bag and tag and walk the lot then slap it in the vault.</p>
<p>Refrain</p>
<p>Run it up in EnCase, data carve ‘til dawn<br />
Bookmark hot and gmails, all the dodgy porn,<br />
Short and sweet the statement witnessing the crime<br />
Which gets them off the premises or even doing time.</p>
<p>Refrain</p>
<p>Like Olympic medalists going at full steam<br />
Onward First Responders!  Ply that data stream!<br />
Vanquish all the villains, work with all your might<br />
Show the unbelievers just how ev’ry bit can byte</p>
<div id="attachment_50" class="wp-caption alignleft" style="width: 208px"><a href="http://digitaldetective.wordpress.com/files/2009/12/sullivan2-copy.jpg"><img class="size-full wp-image-50" title="ASullivan@gmail" src="http://digitaldetective.wordpress.com/files/2009/12/sullivan2-copy.jpg" alt="Arthur Sullivan plus computer" width="198" height="219" /></a><p class="wp-caption-text">Arthur Sullivan at his other keyboard</p></div>
<p><em>All together now&#8230;</em></p>
<p><em>Onward First Responders, marching as to war,<br />
With the ACPO Guidelines going on before.</em></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Moving Fast!]]></title>
<link>http://brandylewisforensics.wordpress.com/2009/12/17/moving-fast/</link>
<pubDate>Thu, 17 Dec 2009 05:23:39 +0000</pubDate>
<dc:creator>Brandy Lewis</dc:creator>
<guid>http://brandylewisforensics.wordpress.com/2009/12/17/moving-fast/</guid>
<description><![CDATA[Wow! I did not realize how fast time flies when you have so much to catch up on! Research Methods wa]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Wow! I did not realize how fast time flies when you have so much to catch up on! Research Methods was tough but, I made it through with an A-. There is a lot of information to learn and it doesn&#8217;t seem as if there is enough time in the day to learn it all! I just finished midterms for the fall quarter in Criminal Evidence. I&#8217;m going to post my final project for Research Methods. =)</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[THE PROJECT.]]></title>
<link>http://ryanhurst.wordpress.com/2009/12/16/the-project/</link>
<pubDate>Wed, 16 Dec 2009 20:48:13 +0000</pubDate>
<dc:creator>ryanhurst</dc:creator>
<guid>http://ryanhurst.wordpress.com/2009/12/16/the-project/</guid>
<description><![CDATA[CAPITAL LETTERS! Yep, this is the big one. The FINAL PROJECT for my degree. The largest piece of wor]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>CAPITAL LETTERS!</strong></p>
<p>Yep, this is the big one. The FINAL PROJECT for my degree. The largest piece of work on the degree, makimg up roughly 30% of the final classification, or so I&#8217;m told. Oh, I did a grade prediction today, by the way, and I&#8217;m predicted a First Class Honours, should things continue in the merry way they have been.</p>
<p>Since the degree is modular &#8211; as may now are &#8211; the project is draped over 3 modules: planning, implementation and evaluation. Meh. What&#8217;s important is what it&#8217;s subject is &#8211; I&#8217;ll quote my project aim: </p>
<blockquote><p><em>&#8216;investigate and critically evaluate the current effectiveness of methodologies in use by Digital Forensics Analysts with specific regard to digital evidence collection &#38; management, identifying and implementing ways of improving efficiency and effectiveness&#8217;</em></p></blockquote>
<p>If you see through the pseudo-intellectualist wording that modern education asks for, you see that what I&#8217;m going to do is look at evidence triage, common and brand new methods for collecting evidence, chain of custody, storage and pre-investigation prep. The eventual aim is to look at how things are done now &#8211; and improve or expand them, and write a new methodology detailing what we believe is safe, efficient and useful practise. I say &#8216;we&#8217;, as I&#8217;m doing this in partnership with Richard Heselwood, another student from my university group. The RH theme will bring greatness, I&#8217;m sure.</p>
<p>Now, I know some people have been surprised at our choice of subject. Some people expect forensic apps to be developed, or investigations to be carried out. The latter I did like the idea of: a large, complex, multi-source, multi-faceted case to get to grips with, requiring knowledge of different OSs, varied techniques and so on. But getting hold of the evidence that someone has staged for you is very difficult &#8211; you&#8217;d need to convince an experienced forensic analyst to spend a lot of time setting up multiple disks with multiple OSs, lots of settings, apps installed and then simulate months of usage in a short period of time. It&#8217;s difficult and unfair on the <del datetime="2009-12-16T20:14:26+00:00">victim</del> volunteer. Developing an application was the first thing I ruled out, mainly because I don&#8217;t want to overwhelm the forensic mindset with that of the programmer. I realise that to create a forensically sound application requires knowledge of forensics, but spending months programming would drive me to distraction.</p>
<p>So the idea of creating my own methodology for forensics cropped up, seemingly at random. It just so happened that Richard was having similar ideas, and on a year-defining walk to Greggs the Bakers near campus, for an inspirational Cornish Pasty, we revealed our ideas to each other and they went together like pastry and filling.</p>
<p>Post Christmas, we&#8217;ll have got the main research regarding how one actually writes a methodology out of the way. We&#8217;ll know what areas need attention, and can start giving them some. We&#8217;ll also have found virginal territory &#8211; things that <a href="http://www.acpo.police.uk/">Acpo</a> haven&#8217;t touched on, for example. They will get the full cycle of research, ideas, implementation, testing, and alteration &#8211; a kind of bespoke development life cycle that we&#8217;ll use. I&#8217;ll be uploading a friendlier version of our plan, and I&#8217;ll blog to it &#8211; so each key point in the plan will have a post related to it &#8211; so you can see how we&#8217;re running education alongside self-propelled brilliance (ahem). Extras about the Enron work, a tad on the E-commerce site I&#8217;m developing and a LOT on the main forensics content (Jan onwards) will also follow in the New Year.</p>
<p><em>Note: I&#8217;m trying to stick to Wednesdays for posting, so it&#8217;s regular. Second posts in any given week will be on Saturday</em></p>
<p>Merry Christmas and a Happy New Year<br />
Ryan</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cd Tutorial Komputer - Computer Forensics Jobs]]></title>
<link>http://cdtutorialproactive.wordpress.com/2009/12/16/cd-tutorial-komputer-computer-forensics-jobs/</link>
<pubDate>Wed, 16 Dec 2009 07:02:24 +0000</pubDate>
<dc:creator>caksub3</dc:creator>
<guid>http://cdtutorialproactive.wordpress.com/2009/12/16/cd-tutorial-komputer-computer-forensics-jobs/</guid>
<description><![CDATA[cd tutorial proactive Komputer forensik adalah sebuah karier yang tumbuh cepat lapangan menawarkan p]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><div class="wp-caption alignleft" style="width: 260px"><img title="cd tutorial proactive" src="http://cdtutorialproactive.files.wordpress.com/2009/12/computer.jpeg?w=250&#038;h=200" alt="cd tutorial proactive" width="250" height="200"><p class="wp-caption-text">cd tutorial proactive</p></div>
<p> Komputer forensik adalah sebuah karier yang tumbuh cepat lapangan menawarkan potensi luar biasa untuk pekerjaan dalam penegakan hukum <a href="http://cdtutorialproactive.wordpress.com" title="cd tutorial proactive"><b>cd tutorial proactive</b></a> militer badan intelijen perusahaan <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-java-marc-antoine-cruisin-jazz-music-cd-review" title="Cd Tutorial Java">Cd Tutorial Java</a> dan bisnis. Peluang pekerjaan meroket sepadan dengan lonjakan cepat dalam kejahatan komputer. </p>
<p> Kejahatan komputer pada awalnya hanya punya kejadian sporadis. Sekarang itu telah menjadi kenyataan hidup <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-gratis-free-online-resources-for-photoshop-tutorial/" title="Cd Tutorial Gratis">Cd Tutorial Gratis</a> yang harus ditangani oleh lembaga penegak hukum. Sebagai aplikasi komputer dan Internet <a href="http://cdtutorialproactive.wordpress.com/2009/12/03/cd-tutorial-flash-usb-flash-drive-sistem-operasi/" title="Cd Tutorial Flash">Cd Tutorial Flash</a> telah menjadi bagian tak terpisahkan dari kehidupan contoh-contoh perbuatan salah dengan bantuan komputer adalah urutan hari. <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-web-design-pelajari-dengan-minisite-video-mengapa-menonton-minisite-video-tutorial-apakah-smart-dan-biaya-efektif/" title="Cd Tutorial Web Design">Cd Tutorial Web Design</a> </p>
<p> Untuk mengatasi kejahatan komputer sendiri harus dipindai <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-php-suatu-ketika-di-masa-di-php-tutorial-script/" title="Cd Tutorial Php">Cd Tutorial Php</a> secara menyeluruh untuk menentukan apakah mereka telah digunakan untuk kegiatan ilegal atau tidak sah atau penipuan. </p>
<p> Ini dapat dilakukan hanya oleh ahli forensik <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-autocad-autocad-pelatihan-dan-dukungan-untuk-versi-lama/" title="Cd Tutorial Autocad">Cd Tutorial Autocad</a> komputer yang memperoleh alat melalui on-the-pengalaman kerja program sertifikasi dan kualifikasi lainnya. </p>
<p> Forensik komputer profesional dikenal oleh banyak gelar seperti penyidik forensik komputer analis media digital dan digital detektif forensik. Setiap <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-photoshop-tutorial-photoshop-cs2/" title="Cd Tutorial Photoshop">Cd Tutorial Photoshop</a> satu menggambarkan karier yang sama seperti yang berkaitan dengan penyelidikan media digital. </p>
<p> Komputer spesialis forensik mendapatkan gaji mulai dari . sampai . per tahun tergantung pada satu S keterampilan dan pengalaman dan perusahaan dan organisasi yang bekerja untuk. Perusahaan swasta menawarkan gaji lebih menguntungkan daripada lembaga penegak hukum. </p>
<p> Seorang sarjana dalam forensik komputer dapat membantu memajukan karier membuat satu memenuhi syarat untuk posisi sebagai pemimpin tim forensik atau biro pengawas. Lima puluh persen dari pekerjaan FBI memerlukan <a href="http://cdtutorialproactive.wordpress.com/2009/12/01/cd-tutorial-joomla-kegunaan-utama-layanan-multimedia/" title="Cd Tutorial Joomla">Cd Tutorial Joomla</a> aplikasi forensik komputer. </p>
<p> Consulting adalah bidang yang <a href="http://cdtutorialproactive.wordpress.com/2009/12/03/cd-tutorial-adobe-photoshop-tips-untuk-mencari-free-adobe-photoshop-tutorial/" title="cd tutorial proactive"><b>cd tutorial proactive</b></a> menarik untuk forensik komputer profesional karena mereka independen dan bebas agen. Mereka mengambil tugas di akan dan biaya dalam jumlah besar dan kuat untuk menghabiskan waktu mereka dalam pekerjaan. Mereka tagihan klien per jam. Remunerasi per jam berkisar dari sampai tergantung pada jenis pekerjaan mereka selesai. </p>
<p> Akan ada terus meningkatnya permintaan untuk memenuhi syarat keamanan dan komputer forensik profesional. Keterampilan komputer dan jaringan tidak lagi mencukupi sebagai jaminan sangat penting untuk server stasiun kerja atau router. </p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/JqEoSipJE6s&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/JqEoSipJE6s&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2 in one week: DNA testing clears wrongly convicted]]></title>
<link>http://the44diaries.wordpress.com/2009/12/15/2-in-one-week-dna-testing-clears-wrongly-convicted/</link>
<pubDate>Wed, 16 Dec 2009 00:11:26 +0000</pubDate>
<dc:creator>GeoT</dc:creator>
<guid>http://the44diaries.wordpress.com/2009/12/15/2-in-one-week-dna-testing-clears-wrongly-convicted/</guid>
<description><![CDATA[Donald Eugene GatesWASHINGTON (AP) &#8212; A man who spent 28 years behind bars for a rape and murde]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><img src="http://the44diaries.wordpress.com/files/2009/12/true-crime-500x136.jpg" alt="" title="true-crime-500X136" width="500" height="136" class="aligncenter size-full wp-image-21254" /></p>
<p> <div class="wp-caption alignleft" style="width: 196px"><img alt="" src="http://www.google.com/hostednews/ap/media/ALeqM5ihi8pQ56lkD_1l2Gd4QPiEak8IHQ?size=s2" width="186" height="131" /><p class="wp-caption-text"> Donald Eugene Gates</p></div>WASHINGTON (AP) &#8212; A man who spent 28 years behind bars for a rape and murder he said he didn&#8217;t commit walked out of a federal prison in Arizona on Tuesday with $75 and a bus ticket to Ohio after DNA testing showed he was innocent.</p>
<p>The conviction of Donald Eugene Gates, 58, was based largely on the testimony of an FBI forensic analyst whose work later came under fire and a hair analysis technique that has been discredited.</p>
<p>&#8220;I feel beautiful,&#8221; Gates told The Associated Press by telephone after leaving the U.S. penitentiary in Tucson, Ariz.</p>
<p>Just hours before, the same judge who had presided over Gates&#8217; trial years ago in D.C. Superior Court ordered his release.</p>
<p>Prosecutors had agreed Gates should be released. However, at their request, Senior Judge Fred B. Ugast delayed Gates&#8217; formal exoneration until next week to give the government a chance to conduct one more round of DNA testing.</p>
<p>Ben Friedman, a spokesman for the U.S. attorney&#8217;s office in Washington, said Gates would be the first D.C. defendant who spent significant time in prison to be exonerated based on DNA evidence.</p>
<p>Gates was convicted of the 1981 rape and murder of Catherine Schilling, a 21-year-old Georgetown University student, in Washington&#8217;s Rock Creek Park. He was sentenced to 20 years to life in prison.</p>
<p>But the conviction was based largely on the testimony of FBI hair analyst Michael P. Malone whose work came under fire in 1997. At that time, the FBI&#8217;s inspector general found that Malone gave false testimony in proceedings that led to the impeachment and ouster of U.S. District Judge Alcee Hastings in 1989.</p>
<p>Ugast was incredulous that prosecutors had failed to inform him after Malone&#8217;s work was called into question. He ordered the U.S. attorney&#8217;s office to review all its cases in which Malone testified &#8211; something he said should have been done earlier.</p>
<p>Sandra K. Levick, one of Gates&#8217; attorneys from the D.C. Public Defender Service, said she came across the inspector general&#8217;s report while doing her own research for the case. She then obtained more information through a Freedom of Information Act request that showed the FBI had issued warnings about the work of Malone and 12 other analysts who were criticized by the inspector general. As part of a review requested by the FBI, prosecutors confirmed they had relied on Malone&#8217;s work to obtain Gates&#8217; conviction.</p>
<p>read more: <a href="http://hosted.ap.org/dynamic/stories/U/US_DC_WRONG_MAN_CONVICTED?SITE=AP&#38;SECTION=HOME&#38;TEMPLATE=DEFAULT&#38;CTIME=2009-12-15-18-41-33"><img alt="" src="http://hosted.ap.org/templates/AP/data/logo.gif" class="alignnone" width="120" height="32" /></a></p>
<p><strong>News Report from: </strong> <a href="http://www.wusa9.com/news/local/story.aspx?storyid=94963"><img alt="" src="http://t0.gstatic.com/images?q=tbn:5y5U3ivZw4FaqM:http://i197.photobucket.com/albums/aa2/ljmastis/wusa.jpg" class="alignnone" width="148" height="65" /></a></p>
<p><span style="display:block;width:500px;margin:0 auto;">  <embed src='http://widgets.vodpod.com/w/video_embed/Groupvideo.4212397' type='application/x-shockwave-flash' AllowScriptAccess='always' pluginspage='http://www.macromedia.com/go/getflashplayer' wmode='transparent' flashvars='' />
<div style="font-size:10px;">     more about &#34;<a href="http://vodpod.com/watch/2702402-untitled?pod=ttgeottgmailcom">untitled</a>&#34;, posted with <a href="http://vodpod.com?r=wp">vodpod</a>  </div>
<p></span></p>
<p><font size="+1"><font color="red">Fla. man exonerated by DNA after 35 years in jail </font></font></p>
<p><a href="http://www.cfnews13.com/News/Local/2009/12/17/dna_frees_wrongly_accused_man_after_35_years.html"><img alt="" src="http://www.cfnews13.com/uploadedImages/Stories/Local/bainfree.jpg" class="alignleft" width="160" height="110" /></a> BARTOW, Fla. (AP) &#8212; A Florida man who spent 35 years in prison has been freed after DNA evidence exonerated him. James Bain was sentenced to life in prison in 1974 for kidnapping and raping a 9-year-old boy. He&#8217;s been pushing for DNA testing and he finally got it after the Innocence Project of Florida got involved in his case.</p>
<p>Tests released last week showed he could not have committed the crime. A judge ordered him freed on Thursday and he walked out of a courthouse a free man.</p>
<p>source: <a href="http://hosted.ap.org/dynamic/stories/U/US_OLD_RAPE_DNA?SITE=AP&#38;SECTION=HOME&#38;TEMPLATE=DEFAULT&#38;CTIME=2009-12-17-11-04-54"><img alt="" src="http://hosted.ap.org/templates/AP/data/logo.gif" class="alignnone" width="120" height="32" /></a></p>
<p><span style="display:block;width:500px;margin:0 auto;">  <embed src='http://widgets.vodpod.com/w/video_embed/Groupvideo.4225904' type='application/x-shockwave-flash' AllowScriptAccess='always' pluginspage='http://www.macromedia.com/go/getflashplayer' wmode='transparent' flashvars='' />
<div style="font-size:10px;">     more about &#34;<a href="http://vodpod.com/watch/2711438-untitled?pod=ttgeottgmailcom">&#124; theledger.com &#124; The Ledger &#124; Lakela&#8230;</a>&#34;, posted with <a href="http://vodpod.com?r=wp">vodpod</a>  </div>
<p></span></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Excellent Nonfiction ]]></title>
<link>http://dcteeny.wordpress.com/2009/12/15/469/</link>
<pubDate>Tue, 15 Dec 2009 22:29:06 +0000</pubDate>
<dc:creator>dcteeny</dc:creator>
<guid>http://dcteeny.wordpress.com/2009/12/15/469/</guid>
<description><![CDATA[YALSA&#8217;s award selection committee has spent the year reviewing nonfiction books for young adul]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><h3>YALSA&#8217;s award selection committee has spent the year reviewing nonfiction books for young adults, ages 12–18, published between November 1, 2008 and October 31, 2009. As a result, five nonfiction titles make up the first <span style="color:#000000;">Award for Excellence in Nonfiction for Young Adults.</span></h3>
<h2><em><strong><a href="http://catalog.douglascountylibraries.org/?q=almost%20astronauts"><img class="alignleft size-full wp-image-483" title="almost astonauts" src="http://dcteeny.wordpress.com/files/2009/12/almost-astonauts1.gif" alt="" width="121" height="133" /></a>Almost Astronauts: 13 Women Who Dared to Dream</strong></em></h2>
<h3>by Tanya Lee Stone.</h3>
<p style="text-align:left;">
<p style="text-align:left;">
<p style="text-align:left;">When NASA was launched in 1958, 13 women proved they had as much of the right stuff as men to be astronauts, but their way to space was blocked by prejudice, insecurity, and a scrawled note written by one of Washington&#8217;s most powerful men. This is the fascinating, frustratingly true story of the Mercury 13 women. Today, dreams of space exploration are a reality for women who meet the challenge. We&#8217;ve come a long way, baby!</p>
<p style="text-align:left;"><em><strong><a href="http://catalog.douglascountylibraries.org/?q=charles%20and%20Emma"><img class="alignleft size-full wp-image-473" title="CharlesEmma" src="http://dcteeny.wordpress.com/files/2009/12/charlesemma.gif" alt="" width="88" height="136" /></a></strong></em></p>
<p style="text-align:left;">
<h2 style="text-align:left;"><em><strong> Charles and Emma: The Darwins’ Leap of Faith</strong></em><em> </em></h2>
<h3 style="text-align:left;">by Deborah Heiligman</h3>
<p style="text-align:left;">
<p style="text-align:left;">The teaching the Darwin&#8217;s evolution theory in schools causes intense controversy today, as it did in Darwin&#8217;s time. This debate raged within Charles Darwin himself, and played an important part in his marriage and family life. His deeply religious wife, Emma,  gave Charles a lot to think about as he worked on his theory. This biography is a thought-provoking, humanizing account of the man behind Darwin&#8217;s famous theory, and his great love for his faith-filled wife. History, science, religion and romance &#8211;there is much here for readers to appreciate.</p>
<h2><em><strong><a href="http://catalog.douglascountylibraries.org/?q=claudette%20colvin"><img class="alignleft size-full wp-image-475" title="iclaudette Colvin" src="http://dcteeny.wordpress.com/files/2009/12/iclaudette-colvin.gif" alt="" width="141" height="155" /></a>Claudette Colvin: Twice Toward Justice</strong></em></h2>
<p style="text-align:left;">
<h3 style="text-align:left;">by Phillip Hoose</h3>
<p style="text-align:left;">Every young American student learns about Rosa Parks, and the spark that led to desegregaton of city buses in the heart of 1950&#8217;s Alabama. How many know the largely untold story of Claudette Colvin?  Nine months before Parks staged her own bus ride protest, 15-year old Colvin was arrested and jailed after refusing to give her up seat on a bus to a white woman. Interviews with Colvin shed light on both the  Montgomery bus boycott and the landmark  <em>Browder v. Gayle</em> case, in which she was a key defendant.</p>
<h2><strong><a href="http://catalog.douglascountylibraries.org/?q=great%20and%20only%20barnum"><img class="alignleft size-full wp-image-477" title="greatBarnum" src="http://dcteeny.wordpress.com/files/2009/12/greatbarnum.gif" alt="" width="94" height="112" /></a>The Great and Only Barnum: The Tremendous, Stupendous Life of Showman P. T. Barnum</strong></h2>
<p style="text-align:left;">
<h3 style="text-align:left;">by Candace Fleming, illustrated by Ray Fenwick</h3>
<p style="text-align:left;">Part colorful performer, part flimflam man, P.T. Barnum is an undisputed American legend.  Fleming&#8217;s book gives a fun historical account of the ultimate showman and his life. To sweeten the deal, photos and illustrations provide a  feast for the eyes that is difficult to resist.</p>
<h2><strong><em><a href="http://dcteeny.wordpress.com/files/2009/12/wrhttp://catalog.douglascountylibraries.org/?q=written%20in%20the%20boneittenbone.gif"><img class="alignleft size-full wp-image-479" title="WrittenBone" src="http://dcteeny.wordpress.com/files/2009/12/writtenbone.gif" alt="" width="97" height="125" /></a>Written in Bone: Buried Lives of Jamestown and Colonial Maryland </em></strong></h2>
<p style="text-align:left;">
<h3 style="text-align:left;">by Sally M. Walker</h3>
<p style="text-align:left;">In a fascinating story of forensic archaeology, author Sally M. Walker assists as scientists investigate colonial-era graves near Jamestown, Virginia: a teenage boy, a ship&#8217;s captain, an indentured servant, a colonial official and his family, and an enslaved African girl. All are reaching beyond the grave to tell us their stories, which are written in bone.</p>
<p style="text-align:left;"><strong>﻿~DJC</strong></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fuzzy hashing, memory carving and malware identification]]></title>
<link>http://infosanity.wordpress.com/2009/12/15/fuzzy-hashing-memory-carving-and-malware-identification/</link>
<pubDate>Tue, 15 Dec 2009 21:26:31 +0000</pubDate>
<dc:creator>Andrew Waite</dc:creator>
<guid>http://infosanity.wordpress.com/2009/12/15/fuzzy-hashing-memory-carving-and-malware-identification/</guid>
<description><![CDATA[I&#8217;ve recently been involved in a couple of discussions for different ways for identifying malw]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I&#8217;ve recently been involved in a couple of discussions for different ways for identifying malware. One of the possibilities that has been brought up a couple of times is fuzzy hashing, intended to locate files based on similarities to known files. I must admit that I don&#8217;t fully understand the maths and logic behind creating fuzzy hash signatures or comparing them. If you&#8217;re curious Dustin Hurlbut has released a <a title="Hurlbut: Fuzzy hashing for investigators" href="http://www.accessdata.com/downloads/media/Fuzzy_Hashing_for_Investigators.pdf">paper on the subject,</a> Hurlbut&#8217;s abstract does a better job of explaining the general idea behind fuzzy hashing.</p>
<blockquote><p>Fuzzy hashing allows the discovery of potentially incriminating documents that may not be located using traditional hashing methods. The use of the fuzzy hash is much like the fuzzy logic search; it is looking for documents that are similar but not exactly the same, called homologous files. Homologous files have identical strings of binary data; however they are not exact duplicates. An example would be two identical word processor documents, with a new paragraph added in the middle of one. To locate homologous files, they must be hashed traditionally in segments to identify the strings of identical data.</p></blockquote>
<p>I have previously experimented with a tool called ssdeep, which implements the theory behind fuzzy hashing. To use ssdeep to find files similar to known malicious files you can run ssdeep against the known samples to generate a signature hash, then run ssdeep against the files you are searching, comparing with the previously generated sample.</p>
<p>One scenarios I&#8217;ve used ssdeep for in the past is to try and group malware samples collected by malware honeypot systems based on functionality. In my attempts I haven&#8217;t found this to be a promising line of research, as different malware can typically have the same and similar functionality most of the samples showed a high level of comparison whether actually related or not.</p>
<p>Another scenario that I had developed was running ssdeep against a clean WinXP install with a malicious binary. In the tests I had run I haven&#8217;t found this to be a useful process, given the disk capacity available to modern systems running ssdeep against a large HDD can be a time consuming process. It can also generate a good number of false positives when run against the OS.</p>
<p>After recently reading Leon van der Eijk&#8217;s post on <a title="Leon's memory carving article" href="http://lvdeijk.wordpress.com/2009/11/17/carving-malware-from-live-memory/">malware carving</a> I have been mulling a method for combining techniques to improve fuzzy hashing&#8217;s ability to identify malicious files, while reducing the number of false positives and workload required for an investigator. The theory was that, while any unexpected files on a system are not desirable, if they aren&#8217;t running in memory then they are less threatening than those that are active.</p>
<p>To test the theory I infected an XP SP2 victim with a sample of Blaster that had been harvested by <a title="InfoSanity: Dionaea" href="http://infosanity.wordpress.com/category/dionaea/">my Dionaea honeypot</a> and dumped the RAM following Leon&#8217;s methodology. Once the image was dissected by foremost I ran ssdeep against extracted resources. Ssdeep successfully identified the malicious files with a 100% comparison to the maliciuos sample. So far so good.</p>
<p>With my previous experience with ssdeep I ran a control test, repeating the procedure against the dumped memory of a completely clean install. Unsurprisingly the comparison did not find a similar 100% match, however it did falsely flag several files and artifacts with a 90%+ comparison so there is still a significant risk of false positives.</p>
<p>From the process I have learnt a fair deal (reading and understanding Leon&#8217;s methodolgy was no comparison to putting it into practice) but don&#8217;t intend to utilise the methods and techniques attempted in real-world scenarios any time soon. Similar, and likely faster, results can be achieved by following Leon&#8217;s process completely and running the files carved by Foremost against an anti-virus scan.</p>
<p>Being able to test scenarios similar to this was the main reason for me to build up the my test and development lab which I have described previously. In particular, if I had run the investigation on physical hardware I would likely not have rebuilt the environment for the control test with a clean system, losing the additional data for comparison, virtualisation snap shots made re-running the scenario trivial.</p>
<p>&#8211;Andrew Waite</p>
<p>P.S. Big thanks to Leon for writing up the memory capture and carving process used as a foundation for testing this scenario.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Release Anti-Forensics Tool]]></title>
<link>http://komplettie.wordpress.com/2009/12/15/hackers-release-anti-forensics-tool/</link>
<pubDate>Tue, 15 Dec 2009 10:50:59 +0000</pubDate>
<dc:creator>komplettie</dc:creator>
<guid>http://komplettie.wordpress.com/2009/12/15/hackers-release-anti-forensics-tool/</guid>
<description><![CDATA[Microsoft’s Computer Online Forensic Evidence Extractor package, commonly known simply as COFEE and ]]></description>
<content:encoded><![CDATA[Microsoft’s Computer Online Forensic Evidence Extractor package, commonly known simply as COFEE and ]]></content:encoded>
</item>
<item>
<title><![CDATA[COFEE leaked everywhere...]]></title>
<link>http://fortuzero.wordpress.com/2009/12/14/cofee-leaked-everywhere/</link>
<pubDate>Mon, 14 Dec 2009 10:43:52 +0000</pubDate>
<dc:creator>fortuzero</dc:creator>
<guid>http://fortuzero.wordpress.com/2009/12/14/cofee-leaked-everywhere/</guid>
<description><![CDATA[http://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Online_Forensics_Evidence_Extractor%29_tool_an]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Online_Forensics_Evidence_Extractor%29_tool_and_documentation,_Sep_2009">http://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Online_Forensics_Evidence_Extractor%29_tool_and_documentation,_Sep_2009</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Forensic Paper]]></title>
<link>http://weaklinksecurity.wordpress.com/2009/12/13/forensic-paper/</link>
<pubDate>Sun, 13 Dec 2009 22:47:57 +0000</pubDate>
<dc:creator>Chris</dc:creator>
<guid>http://weaklinksecurity.wordpress.com/2009/12/13/forensic-paper/</guid>
<description><![CDATA[Years ago I had to write this extensive paper for to earn a GIAC Certified Forensics Analyst title. ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Years ago I had to write <a title="Vera's forensic paper on GIAC" href="http://www.giac.org/certified_professionals/practicals/gcfa/0073.php" target="_blank">this extensive paper</a> for to earn a GIAC Certified Forensics Analyst title.</p>
<p>Christopher Vera – SANS GCFA Practical v.1.3<br />
Analysis of Unknown Binary, Forensic Tool Validation, and Legal Issues of Incident Handling for GIAC Certified Forensic Analyst Certification, Version 1.3<br />
Abstract: The investigator: analyzes an unknown binary using several Linux and Windows forensic tools revealing an ICMP Backdoor; Tests Dependency Walker as a forensic tool for analyzing unknown Windows binaries; Explores the legal issues of a system administrator of an imaginary ISP sharing possible forensic evidence with a government agent acting under color of law.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Biography #107]]></title>
<link>http://kevinjamesbarr.wordpress.com/2009/12/12/biography-107/</link>
<pubDate>Sat, 12 Dec 2009 18:40:49 +0000</pubDate>
<dc:creator>kevinjamesbarr</dc:creator>
<guid>http://kevinjamesbarr.wordpress.com/2009/12/12/biography-107/</guid>
<description><![CDATA[November 03, 2009 I have moved from Grace Mansion to Central Residence on the 1st of September 2009.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:justify;"><strong>November 03, 2009</strong></p>
<ul style="text-align:justify;">
<li>I have moved from <strong><span style="color:#ff0000;">Grace Mansion</span></strong> to <strong><span style="color:#ff0000;">Central Residence</span></strong> on the 1<sup>st</sup> of September 2009. It is small but it has it’s own bathroom. It has radiated heat and it is on so hopefully they will keep it on during the winter months. It is run by the <strong>City of Vancouver</strong>. So far I have no complaints with it other than it is small.</li>
<li>I received my single bed from Welfare (Wraggs) and the bedding and pillow to go with it. I wasn’t going to bother with a bed until my next address, because then I definitely need somebody with a Van or Truck or I will have to hire someone to move. As it was, it cost me $60 to move into here and I have nothing but two tables, my computer, a chair, clothing, books, and cookware. And now I have a bed to boot! This place is small but it has it’s own bathroom (shower &#38; toilet) which is why I took it in the first place. But, it beats sleeping on the floor, especially since I am going to be starting the <strong><span style="color:#ff0000;">Hep “C”</span></strong> treatment shortly.</li>
</ul>
<p style="text-align:justify;"><strong>November 06, 2009</strong>:</p>
<ul style="text-align:justify;">
<li>I received the regular flu shot and the H1N1 flu shot today at the Pender Street Clinic. No line-up or hurry or fright. I suspect my arm to be sore for a few days at least?</li>
<li>I started the treatment for <strong><span style="color:#ff0000;">Hep “C”</span></strong> on November 06, 2009 and am to get an injection of <strong>PEGASYS RBV ®</strong> or <strong>Peginterferon Alfa – 2A</strong> once a week for the next year. In addition to this shot, I am to take <strong>Ribavirin</strong> or <strong>COPEGUS ®</strong> twice a day for a year. I am enrolled as a guinea pig in a German study taken through UBC at the Pender Street Clinic to treat <strong><span style="color:#ff0000;">Hep “C”</span></strong>. I was not accepted as a “normal” in the Government paid programs, and as such enrolled in this treatment study. I have nothing to lose and my health to, again, have in plenty if I succeed.</li>
<li>As of yet I have noticed no side effects in regards to this medication. <strong>NOTHING</strong>. I do realize that I may yet pay for no side effects at the moment later in the program, but for now I am treating these treatments as successful. I have blood work to give on December 04, 2009 and will have the results back roughly two weeks later, where they will be checking my liver enzymes to see how much of the <strong><span style="color:#ff0000;">Hep “C”</span></strong> virus is detectable in my blood, or something to that effect?</li>
<li>If I am undetectable after one month of treatment then I will only have to take the medication for six months instead of a year, but that is highly unlikely but not unheard of. So I am prepared for the full year treatment program.</li>
<li>Before I began treatment I had a quick eye exam done; 2 E.C.G.’s; a liver biopsy; and 2 Ultrasounds of my liver. I also agreed to go back on some anti-depressants as is recommended in the Study brochure.</li>
<li>I am taking <strong>CITALOPRAM 10 mg. PMS</strong>. This is the low dosage and as of yet I haven’t noticed any noticeable difference in my mood. I did not go on the anti-depressant because I was expecting a rough year in terms of my Depression, but rather because it was noticed in prior subjects that they had symptoms of feeling low and had suicides, so to be on the safe side I agreed to go back on this anti-depressant.</li>
<li>The whole idea of getting treated for <strong><span style="color:#ff0000;">Hep “C”</span></strong> is my doing because I want another chance at my health, and yet I have to report to the Pender Street Clinic once a week for my shot and to refill my other medications for this treatment as well as attend their support group once or twice a week. Then I have to report to either <strong><span style="color:#ff0000;">Dave Bernier</span></strong> or <strong><span style="color:#ff0000;">Dr. Levy</span></strong> or both and repeat again what I had said at the Pender Street Clinic. <strong>Bah Humbug!</strong></li>
</ul>
<p style="text-align:justify;"><strong>November 18, 2009</strong></p>
<ul style="text-align:justify;">
<li style="text-align:justify;"><strong><span style="color:#ff0000;">Dave Bernier</span></strong> did another home visit with me. Well it was actually a meeting at a local coffee shop. He asked the same stupid questions as he does all the time. I would have thought he would have come up with some new questions? He asked about my Hep “C” treatment program and any side effects that I may be having. <strong>NO SIDE EFFECTS</strong>. Yeah! So far?! <strong>Bah Humbug</strong>!</li>
</ul>
<p style="text-align:justify;"><strong>December 01, 2009</strong></p>
<ul style="text-align:justify;">
<li>I had my <strong><span style="color:#ff0000;">Review Board</span></strong> today and wouldn&#8217;t you know I received another <strong><span style="color:#ff0000;">Conditional Discharge</span></strong>! <strong>Bah Humbug!</strong> I think I will appeal this decision but will discuss this with my Legal Aid Lawyer.</li>
</ul>
<p style="text-align:justify;"><strong>December 10, 2009</strong></p>
<ul style="text-align:justify;">
<li>I got the results back from my previous blood tests and it is looking promising. It has dropped from millions of copies of the virus in my blood to 25 copies of the virus in my blood. Hopefully my next blood tests will show &#8220;0&#8243; counts or copies in my blood and if that is the case then I only have to take this medication for 6 months as apposed to a year.</li>
<li style="text-align:justify;">Overall I am feeling good. <span style="color:#000000;"><strong>No Side Effects</strong></span> to report from the <strong><span style="color:#ff0000;">Hep &#8220;C&#8221; </span></strong>treatment yet. My depression is not present yet this year and hopefully it won&#8217;t show up.</li>
</ul>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Performance Indicators – Totty, Coffee and Craic]]></title>
<link>http://happyasamonkey.wordpress.com/2009/12/10/performance-indicators-%e2%80%93-totty-coffee-and-craic/</link>
<pubDate>Thu, 10 Dec 2009 20:59:08 +0000</pubDate>
<dc:creator>happyasamonkey</dc:creator>
<guid>http://happyasamonkey.wordpress.com/2009/12/10/performance-indicators-%e2%80%93-totty-coffee-and-craic/</guid>
<description><![CDATA[In my last post, I touched briefly on performance indicators. For those of you who slept during that]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><!-- 		@page { margin: 2cm } 		P { margin-bottom: 0.21cm } 		H2 { margin-bottom: 0.21cm } 		H2.western { font-family: "Arial", sans-serif; font-size: 14pt; font-style: italic } 		H2.cjk { font-family: "DejaVu Sans"; font-size: 14pt; font-style: italic } 		H2.ctl { font-family: "DejaVu Sans"; font-size: 14pt; font-style: italic } --></p>
<p>In my last post, I touched briefly on performance indicators. For those of you who slept during that bit, they&#8217;re the areas in which a police force has to score to win the approval of the Home Office – things like &#8216;crimes detected&#8217;, &#8216;acquisitive crime rate&#8217;, &#8216;public satisfaction&#8217; etc. A force gets points for doing well in these areas, and these points allow the force to &#8216;level up&#8217; and unlock new weapons, characters and secret missions. Or something. I fell asleep in that bit and may have dreamt some of my impressions of what PIs are about.</p>
<p>Whether dreams or reality though, most of them were pretty uninspiring. If I were to be moving to a new force, I certainly  wouldn&#8217;t be looking at the PIs to give me an idea of what it might be like to work there. With this in mind, I thought it was high time that computer forensics labs had some performance indicators of their own. Feel free to rate your own workplace according to these criteria – it should apply to private folk as well as the 5-0. Marks are given out of 10.</p>
<h2>HMIC&#8217;s Performance Indicators for HTCUS</h2>
<p>(&#8216;HMIC&#8217; here stands for &#8216;Happy Monkey&#8217;s Inspectorate of Computerforensicsunits&#8217;. No similarity to Her Majesty&#8217;s Inspectorate of Constabularies is intended or should be inferred).</p>
<ol>
<li><strong>Craic. </strong>On 	walking into the office, is there a good vibe? Are staff talking to 	each other or sitting in sullen silence? The latter may indicate 	that the office is going through a civil war, which happens from 	time to time. Is there laughter? Don&#8217;t be discouraged if one member 	of staff is chasing another around the room with a knife in hand – 	this is common practice in some HTCUs and should be taken as a sign 	of affection. &#8216;Vibe&#8217; is difficult to measure quantitatively and an 	expert may be called in to assist. We suggest Bez from the Happy 	Mondays.</li>
<li><strong>Coffee.</strong> Do staff have access to drinkable coffee? Although it is not unknown 	for some public sector employees to dismiss decent coffee as a 	bourgeois frippery and claim a preference for instant, it is 	important that good coffee is on hand. Coffee may be filtered, 	steamed or pressed, but there should be access to a grinder. 	Facilities for roasting beans will gain a unit an &#8216;exceptional&#8217; 	rating for this indicator, but it is not essential. Access to a 	Starbucks, Neros or similar does not score for this indicator. A 	range of interesting teas will attract bonus points.</li>
<li><strong>Eyecandy. </strong>While 	it is not important for the unit to contain a given proportion of 	attractive staff (indeed it has proved infeasible to impose a quota 	on even normal-looking practitioners in this field), an office 	should have access to a source of totty, whether in a canteen, 	corridors of admin offices or a snack van shared with other 	organisations. Inspectors of both sexes should be sent to judge this 	indicator but should not engage any of the totty in conversation.</li>
<li><strong>Equipment. </strong>Do 	staff have at least two decent-sized monitors? Is there enough desk 	space? Is there adequate Internet provision?</li>
<li><strong>Relaxation Venues. </strong>The availability of a nearby pub or bar is essential. Preferably one where the landlord won&#8217;t bar patrons after overhearing a &#8216;what&#8217;s the weirdest thing you&#8217;ve seen this week&#8217; competition.</li>
<li><strong>Good music. </strong>Always a contentious issue. Commercial radio makes this monkey&#8217;s ears bleed, and Radio 4 doesn&#8217;t really cut it in a busy, noisy office.  Spotify can save the day, but it&#8217;s important to have a regular shout for requests, to make sure everyone&#8217;s happy. Their ads are getting increasingly irritating though &#8211; almost enough to make one subscribe. Almost.</li>
<li><strong>War Stories.</strong> Are there people with enough varied experience to be able to supply a steady stream of war stories over the years? Veracity of the stories is not measured in this indicator and repetition of stories is acceptable, if the story is funny enough.</li>
<li><strong>Biscuits.</strong> Is there a well-stocked biscuit tin? If some disturbed freak keeps putting digestives in there, this will score minus points. What sort of person sees a shelf full of biscuits and chooses digestives, ffs? Even the name&#8217;s wrong, it sounds like something old people eat to help them with their bowel movements.</li>
</ol>
<p>The Office of Monkey scores:</p>
<ol>
<li>9</li>
<li>8</li>
<li>8</li>
<li>8</li>
<li>0 (Nearest hostelry smells of wee)</li>
<li>5 (varies between elevator music and cock-rock)</li>
<li>8</li>
<li>9 (Although there&#8217;s someone who think it&#8217;s amusing to buy Netto digestives and pass them off as his tea kitty contribution, the tea kitty administrator generally does sterling work with biscuits.</li>
</ol>
<p>Giving a grand total of <strong>55 </strong>out of a possible 80! This isn&#8217;t fantastic, and shows a need for improvement in some areas.</p>
<p>So start totting up your own scores! I want a representative sample of UK computer forensics offices in the comments &#8211; it&#8217;d be good to see how the figures compare between LE/Private as well, so please say what sort of place you work in. Feel free to post suggestions for other indicators, too.</p>
<p>This post was brought to you with the help of The Damned, The Cult, Sisters of Mercy, Bauhaus and OMD (I was really reliving my youth tonight!) Also some generic plonk from Bargain Booze and a bag of Twiglets. Nom.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[INITIAL OBSERVATIONS FROM MISSION TO MAGUINDANAO]]></title>
<link>http://harryroque.com/2009/12/10/initial-observations-from-mission-to-maguindanao/</link>
<pubDate>Thu, 10 Dec 2009 02:35:40 +0000</pubDate>
<dc:creator>harryroque</dc:creator>
<guid>http://harryroque.com/2009/12/10/initial-observations-from-mission-to-maguindanao/</guid>
<description><![CDATA[The independent Investigative team consisting of Mr. Chris Cobb-Smith and myself was contacted by At]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>The independent Investigative team consisting of Mr. Chris Cobb-Smith and myself was contacted by Atty. Harry Roque of Centerlaw for the purpose of an independent account based on forensic evidence on behalf of the victims.   The mission was conducted in partnership with the Commission on Human Rights which has the constitutional mandate to conduct investigations of human rights involving civil and political rights.<br />
The team arrived in Cotabato City on November 29, 2009 and returned to Manila on December 7.  We stayed in the area gathering information from direct inspection, talking to relatives, potential witnesses, law enforcement officers and Civil Society activists. This is by no means an exhaustive account of the reconstruction of the facts since for the time being we have not received all documentation collected by different agencies. Our visit however allowed us to have a better understanding of the circumstances in which the crime occurred as well as allow us to piece together some factual information presented in this briefing. </p>
<p>INTERVIEWS<br />
During our time in the area we were able to talk to members of the PNP, victim families, confidential sources and Civil Society organizations.  </p>
<p>SITE INSPECTION<br />
The site where 57 bodies were recovered the previous week is located on the top a small hill some three kilometers from the main highway at Barangay San Juan y Ampatuan city.<br />
The site occupies an area of some 500 square meters were three graves of various dimensions were excavated. Upon arrival the site still shown large heaps of dirt extracted during the excavation of the graves and a large number of personal artifacts, car pieces, newspapers and assorted rubbish strewn across the surface. It was cleared that the site had been severely disturbed since discovery and a number of artifacts, primarily recovery by-products such as gloves, empty water bottles and the like, were added.   </p>
<p>Upon our arrival to the site it was clear that there still were a number of valuable pieces of evidence that should be collected.  We undertook two full examinations using metal detectors in order to locate shell casings and slugs that may assist in determining the minimal number of shooters at the scene. The location of the slugs would facilitate determining whether some of the victims were shot outside the vehicles and then placed back inside likely to be buried in them.<br />
We excavated the three graves to ascertain whether any mortal remains would have been left behind due to the hastiness with which the original exhumation was performed. We also used a cadaver-sniffing dog to verify the empty graves and associated backfill and the surrounding area to exclude the existence of further remains. This way we determined that the scene did not contain any further bodies.<br />
At the site, in our two visits, we recovered over 30 shell casings (5.66 x 45mm). In addition some 4 slugs were also recovered and their position recorded.    This is in addition to the over 120 recovered by the police when they processed the scene.<br />
While searching the scene we also came across personal effects, clothes and an intact partial upper denture.  The denture was identified by the dentist, family and fiancé of journalist Robert Momay as belonging to Momay.<br />
We examined the available documentation to determine that there were three cadavers still unidentified. The three unidentified bodies had all their teeth or complete upper and lower dentures.   This affirms that the mortal remains of Momay were not at the site.   However, since his ID and denture were found at the site it was likely that he was originally disposed there.<br />
The vehicles recovered in grave 3 were mangled into a mass of metal.  We had access to observe them at the PNP base in General Santos. It was still possible to observe that the back rest of both the passenger’s and rear right seats showed some perforations that could have been caused by a shotgun.  One of the vehicles Tamaraw FX was being driven by Mr.  Jephon Cadagdagon, a businessman from General Santos we raise the question as to whether he was travelling indeed alone or may have been taking passengers in his way through the area.<br />
Based on the above we have the following preliminary observations and                                              hypotheses, which need further consideration and investigation:<br />
1.     The event has been defined by the bodies recovered and not by the number of alleged victims reported.<br />
2.      In talking with various persons present at the scene after the killings occur it is clear that the presence of the AFP as a security force while welcome was also a disrupting element in the processing of the scene. Likewise desperate relatives also participated in the recovery process making the situation still more complex.<br />
3.     The process of examination of the mortal remains was not centralized; it was spread through a number of funeral homes and undertaken by PNP and NBI teams. A preliminary review of autopsy reports from each of those teams show in some cases considerable differences in detail and description of injuries related to the cause and manner of death.<br />
4.     It seems apparent that the identification of the bodies relied heavily on the recognition by their relatives despite the fact that many of them sustained high velocity gunshot wounds in the face and/or were heavily decomposed making them definition unrecognizable. The delay in recovering the bodies made them less recognizable due to the advance decomposition.<br />
5.     It is likely that the body of Mr. Robert Momay was handed over to a different family.<br />
6.     This would imply that there is at least one more victim, not recovered nor reported and associated to this event.<br />
7.     The preliminary observations regarding the seats of the Tamaraw FX carcass found in grave 3 raises the possibility that the driver of the vehicle was not alone.<br />
8.     If the latter is true the number of victims could still be higher buried or hidden at another location (since they were not in the 3 graves).</p>
<p>EARLY RECOMMENDATIONS (Based on the observations on the 12 day mission)<br />
In the regrettable scenario that future cases of this kind occur it is recommended that primary responders do not cause irreversible damage to the scene obliterating the recovery of important evidence<br />
1.     It is necessary ascertaining whether the versions indicating that upon arrival to the scene and despite the presence of AFP personnel there were other armed men presumably linked to the alleged perpetrators which only allow the recovery of the mortal remains of the immediate family of Buluan vice-mayor, Esmael Mangudadatu.<br />
2.     No attempts to define a possible universe of victims and to collect Ante Mortem data for each using common formats such as the Disaster Victim Identification (DVI-Interpol) system were used. By doing that at an early stage some of the problems outlined here could have been avoided. It is clear that the event has been defined by the bodies recovered and not by the number of alleged victims reported.<br />
3.     In the future it is more efficient to pool resources together rather than atomize them duplicating efforts or simply by carrying parallel but not necessary complementary investigations. The data collected, the results and the hypothesis of each investigation, such as it has been discussed here are difficult to collate.<br />
4.     Any attempt to perform an efficient investigation in a case of this magnitude needs the rapid deployment of experts; while the deployment of international experts in this case was substantially short considering the circumstances it occurred almost a week after the facts.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Book of Exifodus]]></title>
<link>http://digitaldetective.wordpress.com/2009/12/09/the-book-of-exifodus/</link>
<pubDate>Wed, 09 Dec 2009 22:36:55 +0000</pubDate>
<dc:creator>digitaldetective</dc:creator>
<guid>http://digitaldetective.wordpress.com/2009/12/09/the-book-of-exifodus/</guid>
<description><![CDATA[Biblical scholars have hailed the most recent find amongst a cache of  lost literary works as nothin]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><em>Biblical scholars have hailed the most recent find amongst a cache of  lost literary works as nothing short of miraculous.  Now read on&#8230;<br />
</em></p>
<p>Exifodus, Chapter III</p>
<p>1. And there was, at that time, in the Land of Geek-i-on two nations.</p>
<p>2. And their names were the El-ee-ites and the Pri-vat-ites.</p>
<div id="attachment_41" class="wp-caption alignright" style="width: 161px"><a href="http://digitaldetective.wordpress.com/files/2009/12/moses1-copy1.jpg"><img class="size-medium wp-image-41" title="Moses surfs" src="http://digitaldetective.wordpress.com/files/2009/12/moses1-copy1.jpg?w=151" alt="" width="151" height="300" /></a><p class="wp-caption-text">Moses with his netbook</p></div>
<p>3. Now the nations and the tribes thereof did live in that place as neighbours, yet they would not dwell together.</p>
<p>4. Worshipped they also at the the same temple, sharing the practices and rituals of their creed, Day-Tar-An-al-ysis.  Yet was there no love lost between them.</p>
<p>5. Thus went they about their business, ignoring each other for the most part.</p>
<p>6. But it came to pass that the Pri-vat-ites were fruitful and increased abundantly and multiplied and the land was filled with them.</p>
<p>7. Moreover, they grew rich off the fat of the land.</p>
<p>8. Then said the El-ee-ites to one another, the Pri-vat-ites getteth themselves a stack of shekels whilst we must labour hard and long to make a fraction thereof.</p>
<p>9. And they waxed wroth.</p>
<p>10. And there were those among them who rose up saying: Is not this land ours alone?  Did not the Lord give it to our forefathers forever, even unto the end of time?</p>
<p>11. For we are the peace-keepers in His house and the watchmen at His gate. And none may leave our courts unless we sign off countless reams of paperwork.</p>
<p>12. And there were others who said, this is right-wise galling.  Locketh we not away the evil-doers and the runners of red lights?  Where is our just reward?</p>
<p>13. But the Lord gave them no respite.</p>
<p>14. So it came to pass that many El-ee-ites took up their golden handshake and went out from their own lands and into the lands of the Pri-vat-ites.</p>
<p>15. And in the process of time, their numbers increased manyfold. For they perceived that their bretheren also grew rich in that place.</p>
<p>16. Thus it was that the throng increased until it became a multitude and there was an exodus of epic proportions.</p>
<p>17. Yea, even in every sense of that word.</p>
<p>18. Now many El-ee-ites found work for their hands.  Yet also did many fall by the wayside.</p>
<p>19. For though they set up on their own or with others of their kind, they found the game was in no wise as cushy as it first appearèd.</p>
<p>20. Verily, the days were many when the phone rangeth not at all.</p>
<p>21. For the followers of Day-Tar-An-al-ysis had become so great in number that the market-place was exceeding full.</p>
<p>22. Then was there a wailing and a gnashing of teeth, for a recession came also to the land of Geek-i-on.</p>
<p>23. And many that had jobs before now lost them, and those that were new to the field were left high and dry.</p>
<p>24. Then did the El-ee-ites mourn in their exile for their own lands, saying Was there not an over-abundance of stuff to be looked at every day? Even a Welsh mountain full of dodgy boxes?</p>
<p>25. And was there not also tea, cake, biscuits and canned drinks in abundance at all hours?</p>
<p>26. And they went unto their temples to call upon the Lord for guidance but there was no access day to day for any to come therein.</p>
<p>27. A great wilderness opened out before them and they became as strangers in a strange land.</p>
<p>28. Even the tribes of Re-cru-ter-ites who had once welcomed them now turned them from their doors saying Knowest thou not that For-en-sics is finishèd?  Therefore go we up into the pastures of e-discovery, for there the land runneth with milk and honey.</p>
<p>29. And they went on their way rejoicing.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Computer Forensics...?]]></title>
<link>http://ryanhurst.wordpress.com/2009/12/09/why-computer-forensics/</link>
<pubDate>Wed, 09 Dec 2009 13:40:08 +0000</pubDate>
<dc:creator>ryanhurst</dc:creator>
<guid>http://ryanhurst.wordpress.com/2009/12/09/why-computer-forensics/</guid>
<description><![CDATA[Recently, I&#8217;ve met a lot of first year students, several of which have asked me why I chose to]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong>Recently, I&#8217;ve met a lot of first year students, several of which have asked me why I chose to study Computer Forensics.</strong></p>
<p>I prefer not to think of what I&#8217;m doing as studying CF. To me, I&#8217;m preparing for a career, not studying in isolation from the future. Every schoolchild is groomed for further and higher education, with a view to gaining skills for jobs, and that is precisely what I&#8217;m doing. Putting aside the fact that I attribute huge value to the &#8216;life of the mind&#8217; type of education that is available at Oxbridge, most obviously, I am quite happy with the idea of &#8216;learn to earn&#8217;. It&#8217;s realistic, useful.</p>
<p>So, why a CF career? Of all the types of computing career, or the types of law enforcement career &#8211; why CF? Well, I&#8217;ve known since I was old enough to understand the concept of a career, that I wanted to be involved in fighting crime. This changed from the 7 years old&#8217;s James Bond fantasy, to Computer Forensics &#8211; via ideas of being a Police Officer, Armed Response or Intelligence. The computing area of forensics &#8211; arguably the lion&#8217;s share of the field of computer forensics &#8211; works for me almost by default. I simply found I was good at using a computer as a child, and that I understood the lower layers of computing as I began programming and networking at secondary school. I picked up programming languages quicky, I &#8216;got&#8217; the <a href="http://en.wikipedia.org/wiki/OSI_model">OSI Model</a> &#8211; it came naturally.</p>
<p>But Computing does not stimulate me in the way langauge, writing, journalism and crucially, fighting crime do. It amazes me, challenges me and interests me &#8211; but I could NEVER work in a career that is purely about computing problems. I don&#8217;t mind wrestling with programming or scripting &#8211; but I don&#8217;t want to release applications, I want to write EnScripts, timelining apps. I don&#8217;t want to design networks for big business, but I might want to streamline the office network to get more out of distributed processing. I know the power of knowledge of computing, and how it can make the fight against crime a broader one. It delights me when I apply my knowledge of this File System or that logging method, to carry out the act of forensics successfully &#8211; but the file system itself bores me stupid. I will happily study it for hours on end though, because it helps me with forensics. That&#8217;s the way I approach the career: knowledge for the end-purpose of forensics and fighting crime. The elephant in the room is defence work of course &#8211; I shall deal with that in another post.</p>
<p>CF allows me to ensure my computing mindset isn&#8217;t wasted, and that my real interest in forensics and investigating crime is satisfied. If the world was kind to idealists, I would write for a living, but I think one needs a career that is reliable, with a supplementary interest that you can afford to not work. I do believe that you can do a job that you good at, but that is not your number one desire &#8211; that&#8217;s my situation, but as people have remarked, I am HUGELY passionate about Computer Forensics, and I&#8217;m determined &#38; dedicated to succeed in my career.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Up in the Air]]></title>
<link>http://davekalin.wordpress.com/2009/12/11/up-in-the-air/</link>
<pubDate>Fri, 11 Dec 2009 10:17:49 +0000</pubDate>
<dc:creator>davekalin</dc:creator>
<guid>http://davekalin.wordpress.com/2009/12/11/up-in-the-air/</guid>
<description><![CDATA[I had the pleasure of seeing the film &#8220;Up in the Air&#8221; last night (very good film, by the]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>I had the pleasure of seeing the film &#8220;Up in the Air&#8221; last night (very good film, by the way) and it got me thinking about how companies need to follow the proper procedures when laying off employees. That&#8217;s where I come in&#8230; <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Earlier this year I was working on a Computer Forensics case for a large corporation who was laying off a big group of employees. Because of the size of the group (over 700) they decided to lay off everyone at once instead of in face-to-face meetings. They herded people into the lunch room to explain the situation and severance packages, and some people immediately got up during the meeting and went back to their cubicles, presumably to pack their belongings. However, many of these &#8220;early departers&#8221; were also found to be copying lots of company confidential data to CD&#8217;s and USB flash drives.  Based on the registry data on the hard drive and the timestamps of the user&#8217;s folder, I was able to determine what files were copied at the last minute, and HR was able to pursue the proper actions with the laid-off employees.</p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
