funsec mailing list archives
Re: Looking Inside the Stolen VA Laptop
From: rms () bsf-llc com
Date: Thu, 29 Jun 2006 22:35:33 -0400 (EDT)
I suspect most laptop thieves aren't very smart. They are after a laptop to sell it at the local pawn shop or on Craig's list. Therefore looking at the last boot data is going to work most of the time to understand if data was taken or not. In Jon's original article, he also mentioned looking for evidence that the hard drive was physically removed from the computer. Booting a Knoppix CD-ROM will also hide any evidence of copying since drive C: will be mounted read only. This solution is a lot easier than pulling out a hard drive. Does anyone know of any cases of the data on a stolen laptop actually being misused? Richard
rms () bsf-llc com wrote:One quick follow-up. In Windows, access times on files are a very hit or miss proposition. For example, copying a file using the Windows Explorer won't update the access time of the source file. So if the VA database file was copied to another drive, the access time on the original file won't be changed. This "feature" of Windows Explorer makes analysis more difficult.You are assuming a stupid "I only know how to boot a Windows computer and use it from the keyboard" type person. Unless someone can attest the COMPLETE history of where this laptop was from the time of theft to time of recovery, do you really think that's a safe assumption to make?OTOH, the FBI will be able to tell when the computer was last booted and what programs were run. They can also tell if any external hard drives were plugged into the machine or if any CD-ROMs were burned.And where is this information found? Take the drive out, stick it in a USB enclosure, boot from a Linux CD, image the drive, put it back in... There would be NO evidence of the boot, the file access, etc. -- Dave Dittrich Information Assurance Researcher, dittrich () u washington edu The iSchool http://staff.washington.edu/dittrich University of Washington PGP key http://staff.washington.edu/dittrich/pgpkey.txt Fingerprint FE97 0C57 0843 F3EB 49A1 0CD0 8E0C D0BE C838 CCB5
_______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- Re: NASA HQ Raided In Kiddie Porn Probe Dude VanWinkle (Apr 01)
- <Possible follow-ups>
- Re: NASA HQ Raided In Kiddie Porn Probe Rob, grandpa of Ryan, Trevor, Devon & Hannah (Apr 04)
