February 19th, 2009 by ahoog                              

ADP1

The Android Developer Phone (ADP or ADP1) is a version of the G1/HTC Dream for developers and engineers.  Some differences from the retail version include a slightly different look and feel, root access, unlokced SIM and an special bootloader (to name a few).  Here is a nice write up (with pictures) on the ADP1.

  • Share/Bookmark
February 15th, 2009 by ahoog                              

IMSI

The International Mobile Subscriber Identity (IMSI) is an 18-20 digit number uniquely identifying each SIM card.  The information can be used to identify, track or clone a subscriber and is sent as rarely as possible.  Instead,  a randomly generated Temporary Mobile Subscriber Identity (TMSI) is used whenever possible.

The first 3 digits of the IMSI represent [...]

  • Share/Bookmark
February 15th, 2009 by ahoog                              

SWGDE

Scientific Working Group on Digital Evidence (SWGDE) is a government and law enforcement only that “brings together organizations actively engaged in the field of digital and multimedia evidence to foster communication and cooperation as well as ensuring quality and consistency within the forensic community.”

In their Best Practices for Computer Forensics, they  have a section on [...]

  • Share/Bookmark
February 7th, 2009 by ahoog                              

IMEI

International Mobile Equipment Identifier (IMEI) is a code uniquely identifying the a GSM cell phone on the network generally displayed on a phone beneath the battery. They can have 15 (14 decimal digits plus a check digit) or 16 (IMEISV) digits and encoded in the number are the origin, model, and serial number [...]

  • Share/Bookmark
January 13th, 2009 by ahoog                              

tableau-parm

tableau-parm is a utility which runs on Linux for interaction with Tableau’s forensic write blockers.  If you use Tableau’s products and don’t run on Windows, you can use this utility to query information from the write blocker (i.e. hard drive information, HPA, DCO, etc.) and even remove HPA/DCO.  The Windows version of the utility by [...]

  • Share/Bookmark
January 5th, 2009 by ahoog                              

exifprobe

Exifprobe is a utility to read EXIF information from digital image files.  I compiles and runs easily on Linux. From the website:

“Exifprobe reads image files produced by digital cameras (including several so-called “raw” file formats) and reports the structure of the files and the auxilliary data and metadata contained within them. In addition to TIFF, [...]

  • Share/Bookmark
January 5th, 2009 by ahoog                              

EXIF

Exchangeable Image File Format (EXIF) is a standard for storing information (or metadata) with an digital image, generally one from a digital camera.  EXIF can contain valuable information about an image, in some cases it will even store the GPS coordinates of where the picture was taken.

Concerns over verifiability of EXIF data

While EXIF data can [...]

  • Share/Bookmark
January 5th, 2009 by ahoog                              

Scalpel

Scalpel is an open source file carving utility like foremost but with an emphasis on speed and efficiency. When analyzing a 15GB dd image, scalpel took just under 2 minutes while foremost took nearly 15 minutes. Foremost carved more files however most were invalid (this is anecdotal and may not always be the [...]

  • Share/Bookmark
December 23rd, 2008 by ahoog                              

Daubert

Daubert refers to the legal precedent set by the United States Supreme Court in 1993 which defined the criteria for admissibility of expert witness testimony in the Federal Courts.  The Daubert ruling (Daubert v. Merrell Dow Pharmaceuticals, 509 U.S. 579) superseded the long-standing Frye standard (set in 1923) for expert witness testimony.

Daubert criteria

The criteria set [...]

  • Share/Bookmark
December 22nd, 2008 by ahoog                              

Federal Rules of Evidence Rule 502

The Federal Rules of Evidence Rule 502 (Attorney-Client Privilege and Work Product; Limitations on Waiver) was enacted by Congress and made effective September 19, 2008.  This important rules was created to address the dramatically increasing costs of electronic discovery by providing a predictable and consistent standard to govern the waiver of privileged information.

Rising costs of [...]

  • Share/Bookmark