Ethical Hacking Training at InfoSec Institute Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Forensic Copy of Files off a CD... |
|---|---|
| Date: | Mon, 4 Oct 2004 14:35:34 -0400 |
Jon,
Any good opposing counsel would take this to town. How do you know the tool didn't fail during the reset process, leaving some reset and others unset? Is the evidence you are introducing reset or original? Could you be confused? Can you prove you reset these but not those? < For example, here is one arguement against this type of manipulation: http://ftimes.sourceforge.net/Files/Papers/baselining.pdf <
I looked through your paper but it does not appear to add anything with respect to the merits of timestamp restoration than already stated in your post cited above. Is there anything else? Couldn't your difficulty be resolved by robust error logging? Regards, George. ----------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Forensic Copy of Files off a CD..., Evidence Technology |
|---|---|
| Next by Date: | Shred. Was: Securely wiping..., Nathan R. Valentine |
| Previous by Thread: | RE: Forensic Copy of Files off a CD..., Evidence Technology |
| Next by Thread: | Re: Forensic Copy of Files off a CD..., Jason Coombs PivX Solutions |
| Indexes: | [Date] [Thread] [Top] [All Lists] |