funsec mailing list archives

Re: Looking Inside the Stolen VA Laptop


From: rms () bsf-llc com
Date: Thu, 29 Jun 2006 22:35:33 -0400 (EDT)

I suspect most laptop thieves aren't very smart.  They are after a laptop
to sell it at the local pawn shop or on Craig's list.  Therefore looking
at the last boot data is going to work most of the time to understand if
data was taken or not.

In Jon's original article, he also mentioned looking for evidence that the
hard drive was physically removed from the computer.

Booting a Knoppix CD-ROM will also hide any evidence of copying since
drive C: will be mounted read only.  This solution is a lot easier than
pulling out a hard drive.

Does anyone know of any cases of the data on a stolen laptop actually
being misused?

Richard

rms () bsf-llc com wrote:
One quick follow-up.  In Windows, access times on files are a very hit
or
miss proposition.  For example, copying a file using the Windows
Explorer
won't update the access time of the source file.  So if the VA database
file was copied to another drive, the access time on the original file
won't be changed.  This "feature" of Windows Explorer makes analysis
more
difficult.

You are assuming a stupid "I only know how to boot a Windows computer
and use it from the keyboard" type person.  Unless someone can attest
the COMPLETE history of where this laptop was from the time of theft
to time of recovery, do you really think that's a safe assumption to
make?

OTOH, the FBI will be able to tell when the computer was last booted and
what programs were run.  They can also tell if any external hard drives
were plugged into the machine or if any CD-ROMs were burned.

And where is this information found?  Take the drive out, stick it
in a USB enclosure, boot from a Linux CD, image the drive, put it
back in... There would be NO evidence of the boot, the file access,
etc.

--
Dave Dittrich                          Information Assurance Researcher,
dittrich () u washington edu              The iSchool
http://staff.washington.edu/dittrich   University of Washington

PGP key      http://staff.washington.edu/dittrich/pgpkey.txt
Fingerprint  FE97 0C57 0843 F3EB 49A1  0CD0 8E0C D0BE C838 CCB5



_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: