<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Cobalt2020&amp;feedformat=atom</id>
		<title>Forensics Wiki - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/api.php?action=feedcontributions&amp;user=Cobalt2020&amp;feedformat=atom"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Special:Contributions/Cobalt2020"/>
		<updated>2013-06-19T05:40:37Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.21.1</generator>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Main_Page</id>
		<title>Talk:Main Page</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Main_Page"/>
				<updated>2012-02-05T16:46:43Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== what about the validation of legal/illegal licenses of commercial software? ==&lt;br /&gt;
&lt;br /&gt;
I'm sometimes requested by the Courts to process with investigations in order to detect is a company is using software (e.g. AutoCad, MS Office, Adobe) with licenses or not.&lt;br /&gt;
The evidence of such stuff is easy or not. The display of the &amp;quot;About&amp;quot; is sometimes enough but for some software the evidence is not so easy.&lt;br /&gt;
&lt;br /&gt;
May I propose we open a new section to address such topics?&lt;br /&gt;
&lt;br /&gt;
What do you think? --[[User:Chuv|Chuv]] 04:16, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
: Sounds like a good idea. How about [[How to determine if software is legally licensed]]? It should probably go in the [[:Category:Howtos]]. [[User:Jessek|Jessek]] 16:11, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Global Directory of Analysts == &lt;br /&gt;
&lt;br /&gt;
I am setting up a global directory of computer forensics analysts, and am looking for feedback to the idea. Although the directory is in the UK, I want it to be global. Any thoughts, please put them on Computer Forensics [http://www.computer-forensics.co.uk] in the forums section. Thanks and regards, Simon&lt;br /&gt;
: Given the lack of response I'm not sure this is a viable idea. [[User:Jessek|Jessek]] 21:13, 26 February 2007 (PST)&lt;br /&gt;
: Doesn't seem like a good idea to me. [[User:Simsong|Simsong]] 18:50, 15 March 2007 (PDT)&lt;br /&gt;
: Response is small because the very idea and both sites are not well known within North America.  Computer forensics here has been mostly a secondary role rather than a principal focus.  To raise awareness of both efforts, this wiki and computer-forensics.co.uk, you need to get their existence promoted in major publications and the primary professional organizations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== List of OS changed files at boot time or poweroff. ==&lt;br /&gt;
&lt;br /&gt;
Some times i found useful to know which files are changed on boot time of OS or on poweroff.  For example to know what happened with OS ( Windows or Linux or ... ) what files to exclude or include by investigation. So i started collect this information with qemu and mactime. I think this wiki is the best place to post it,  what do you think haw should i name it and the category? Also i will thankful if some one can correct my English.&lt;br /&gt;
&lt;br /&gt;
I would encourage you to post it at [[Files changed at boot:Windows XP]], [[Files changed at boot:Windows Vista]], and the like. [[User:Simsong|Simsong]] 18:53, 25 October 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Organizing Anti-Forensics and Page Naming query ==&lt;br /&gt;
I've made a start on trying to organize the Anti-Forensics information creating a number of sections including Category:Anti-Forensics.  I created a category for Category:Anti-Forensics Tools(uppercase) with out realising there was already a Category:Anti-forensics tools (lowercase).  Is there any standardization on whether page titles should be upper or lower case? I would have though upper case being the better option... &lt;br /&gt;
[[User:Fsck|Fsck]] 22:43, 4 July 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've started a weekly posting of forensics research. In my quick review of the other websites that come up when doing a google search for &amp;quot;computer forensics&amp;quot; it seems that nothing is really up-to-date, so perhaps we can start a more active community here. Perhaps this will grow into a blog roll. [[User:Simsong|Simsong]] 23:46, 5 July 2008 (UTC)&lt;br /&gt;
:: What about next Selected Forensics Research? Two months passed without updates [[User:.FUF|.FUF]] 21:10, 17 October 2008 (UTC)&lt;br /&gt;
:::I got radically overcommitted. I'll try to post something this weekend. [[User:Simsong|Simsong]] 06:35, 18 October 2008 (UTC)&lt;br /&gt;
== Removal of non-contributing users ==&lt;br /&gt;
&lt;br /&gt;
I've written a little SQL statement which will remove the 1100 or so usernames that have been registered but which have never contributed anything and have no talk. This was considered for the mediawiki project but never implemented (weird). Anyway, unless there is a suggestion, I'll go ahead and do it... [[User:Simsong|Simsong]] 05:10, 20 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Tools table ==&lt;br /&gt;
&lt;br /&gt;
Is it possible to add [[Wireshark]] and [[NetworkMiner]] to the Tools table on the Main Page (here: ''Network Forensics: Snort, ... '')? [[User:.FUF|.FUF]] 17:08, 11 September 2008 (UTC)&lt;br /&gt;
: Done [[User:Simsong|Simsong]] 04:40, 12 September 2008 (UTC).&lt;br /&gt;
&lt;br /&gt;
== Did you know? ==&lt;br /&gt;
&lt;br /&gt;
What about organizing &amp;quot;Did you know?&amp;quot; section with some interesting facts from articles (like in Wikipedia)? [[User:.FUF|.FUF]] 12:34, 29 October 2008 (UTC)&lt;br /&gt;
: I don't think that we have enough people to do this. [[User:Simsong|Simsong]] 06:50, 19 July 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Wiki News ==&lt;br /&gt;
&lt;br /&gt;
I have updated the version of SpamBlacklist. [[User:Simsong|Simsong]] 23:49, 30 October 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
I have fixed the server config file so we now get /wiki/ URLs. [[User:Simsong|Simsong]] 20:33, 3 November 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Forensics Mailing List ==&lt;br /&gt;
Hello all. I would like to ask, are there any mailing list focus on forensics? I need reference here. --[[User:Zakiakhmad|Zakiakhmad]] 09:48, 13 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
: It seems a little bit passive this discussion --[[User:Zakiakhmad|Zakiakhmad]] 03:16, 23 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== AJAX ==&lt;br /&gt;
&lt;br /&gt;
Ajax has been enabled by adding these settings to the LocalSettings.php file:&lt;br /&gt;
  $wgUseAjax = true;&lt;br /&gt;
  $wgEnableMWSuggest = true;&lt;br /&gt;
  $wgMWSuggestTemplate =SearchEngine::getMWSuggestTemplate() . '&amp;amp;limit=20';&lt;br /&gt;
&lt;br /&gt;
:Yours wikily, [[User:Simsong|Simsong]] 06:49, 19 July 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Zalety i Wady - obiektywnie wyłącznie inżynierowie forensics ==&lt;br /&gt;
&lt;br /&gt;
'''Analiza SIM karty danych i odzyskiwania usuniętych danych&lt;br /&gt;
ANALYSIS SIM CARD DATA AND RECOVER DELETED DATA'''&lt;br /&gt;
&lt;br /&gt;
Odzyskiwanie skasowanych wiadomości SMS / tekst i wykonać kompleksową analizę danych na karcie SIM. Karta SIM ma zajęcia nabycia karty SIM i elementy analizy zajęciu urządzenia parabenów i umieszcza je w specjalistyczne karty SIM nabycia kryminalistycznych i narzędzie do analizy. Karta SIM zawiera zajęcia programowe, jak Forensic SIM Card Reader. Jeśli masz już zajęcia Device &amp;amp; Device Seizure Toolbox, nie ma potrzeby, aby otrzymać karty SIM zajęcia, jak również dlatego, że zawierają składniki, aby wykonać kryminalistycznych badań karty SIM i analizy. Jest to narzędzie dla badacza, który chce nabyć tylko karty SIM i nie chcesz wykonać kryminalistycznych egzaminów wszystkich danych z telefonu komórkowego. Karta SIM zawiera bezpłatne zajęcia roczną subskrypcję z zakupu.&lt;br /&gt;
&lt;br /&gt;
SIM Card Seizure has unicode support to read multiple languages such as Arabic, Chinese, &amp;amp; Russian: Features:&lt;br /&gt;
&lt;br /&gt;
    * Forensic SIM Card Reader Included&lt;br /&gt;
    * Calculates MD5 &amp;amp; SHA1 Hash Values&lt;br /&gt;
    * Search Function&lt;br /&gt;
    * Recovers Deleted SMS Data*&lt;br /&gt;
    * Bookmarking Options&lt;br /&gt;
    * Report Creation Wizard&lt;br /&gt;
    * Save Workspaces for Further Review&lt;br /&gt;
    * Time Stamps Calculate GMT Offset&lt;br /&gt;
    * Access to Paraben's Forum&lt;br /&gt;
    * Access to Paraben's 24 Hour Support&lt;br /&gt;
&lt;br /&gt;
Data Acquired from SIM Cards&lt;br /&gt;
&lt;br /&gt;
    * Phase Phase ID&lt;br /&gt;
    * SST SIM Service table&lt;br /&gt;
    * ICCID Serial Number&lt;br /&gt;
    * LP Preferred languages variable&lt;br /&gt;
    * SPN Service Provider name&lt;br /&gt;
    * MSISDN Subscriber phone number&lt;br /&gt;
    * AND Short Dial Number&lt;br /&gt;
    * FDN Fixed Numbers&lt;br /&gt;
    * LND Last Dialed numbers&lt;br /&gt;
    * EXT1 Dialing Extension&lt;br /&gt;
    * EXT2 Dialing Extension&lt;br /&gt;
    * GID1 Groups&lt;br /&gt;
    * GID2 Groups&lt;br /&gt;
    * SMS Text Messages&lt;br /&gt;
    * SMSP Text Message parameters&lt;br /&gt;
    * SMSS Text message status&lt;br /&gt;
    * CBMI Preferred network messages&lt;br /&gt;
    * PUCT Charges per unit&lt;br /&gt;
    * ACM Charge counter&lt;br /&gt;
    * ACMmax Charge limit&lt;br /&gt;
    * HPLMNSP HPLMN search period&lt;br /&gt;
    * PLMNsel PLMN selector&lt;br /&gt;
    * FPLMN Forbidden PLMNs&lt;br /&gt;
    * CCP Capability configuration parameter&lt;br /&gt;
    * ACC Access control class&lt;br /&gt;
    * IMSI IMSI&lt;br /&gt;
    * LOCI Location information&lt;br /&gt;
    * BCCH Broadcast control channels&lt;br /&gt;
    * Kc Ciphering key&lt;br /&gt;
&lt;br /&gt;
Pytanie 1&lt;br /&gt;
_________&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Jakie zalety na pierwszy plan,  a jakie wady które można zignorować w śledztwie?&lt;br /&gt;
&lt;br /&gt;
==Spam==&lt;br /&gt;
In an attempt to deal with spam, account creation now requires confirmation.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Main_Page</id>
		<title>Talk:Main Page</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Main_Page"/>
				<updated>2012-02-05T16:45:55Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== what about the validation of legal/illegal licenses of commercial software? ==&lt;br /&gt;
&lt;br /&gt;
I'm sometimes requested by the Courts to process with investigations in order to detect is a company is using software (e.g. AutoCad, MS Office, Adobe) with licenses or not.&lt;br /&gt;
The evidence of such stuff is easy or not. The display of the &amp;quot;About&amp;quot; is sometimes enough but for some software the evidence is not so easy.&lt;br /&gt;
&lt;br /&gt;
May I propose we open a new section to address such topics?&lt;br /&gt;
&lt;br /&gt;
What do you think? --[[User:Chuv|Chuv]] 04:16, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
: Sounds like a good idea. How about [[How to determine if software is legally licensed]]? It should probably go in the [[:Category:Howtos]]. [[User:Jessek|Jessek]] 16:11, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Global Directory of Analysts == &lt;br /&gt;
&lt;br /&gt;
I am setting up a global directory of computer forensics analysts, and am looking for feedback to the idea. Although the directory is in the UK, I want it to be global. Any thoughts, please put them on Computer Forensics [http://www.computer-forensics.co.uk] in the forums section. Thanks and regards, Simon&lt;br /&gt;
: Given the lack of response I'm not sure this is a viable idea. [[User:Jessek|Jessek]] 21:13, 26 February 2007 (PST)&lt;br /&gt;
: Doesn't seem like a good idea to me. [[User:Simsong|Simsong]] 18:50, 15 March 2007 (PDT)&lt;br /&gt;
: Response is small because the very idea and both sites are not well known within North America.  Computer forensics here has been mostly a secondary role rather than a principal focus.  To raise awareness of both efforts, this wiki and computer-forensics.co.uk, you need to get their existence promoted in major publications and the primary professional organizations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== List of OS changed files at boot time or poweroff. ==&lt;br /&gt;
&lt;br /&gt;
Some times i found useful to know which files are changed on boot time of OS or on poweroff.  For example to know what happened with OS ( Windows or Linux or ... ) what files to exclude or include by investigation. So i started collect this information with qemu and mactime. I think this wiki is the best place to post it,  what do you think haw should i name it and the category? Also i will thankful if some one can correct my English.&lt;br /&gt;
&lt;br /&gt;
I would encourage you to post it at [[Files changed at boot:Windows XP]], [[Files changed at boot:Windows Vista]], and the like. [[User:Simsong|Simsong]] 18:53, 25 October 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Anti-forensic Tools Link on Homepage ==&lt;br /&gt;
&lt;br /&gt;
The anti-forensic tools link on the homepage of this wiki doesn't appear to go to the proper page, but rather goes to a pro-forensic tools page.  Do we have a page just for anti-forensic tools? It would appear to me that the internal link should point to that type of a page rather than one on pro-forensic tools.  Thoughts? [[User:Cobalt2020|AEI Forensics]]&lt;br /&gt;
&lt;br /&gt;
== Organizing Anti-Forensics and Page Naming query ==&lt;br /&gt;
I've made a start on trying to organize the Anti-Forensics information creating a number of sections including Category:Anti-Forensics.  I created a category for Category:Anti-Forensics Tools(uppercase) with out realising there was already a Category:Anti-forensics tools (lowercase).  Is there any standardization on whether page titles should be upper or lower case? I would have though upper case being the better option... &lt;br /&gt;
[[User:Fsck|Fsck]] 22:43, 4 July 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
I've started a weekly posting of forensics research. In my quick review of the other websites that come up when doing a google search for &amp;quot;computer forensics&amp;quot; it seems that nothing is really up-to-date, so perhaps we can start a more active community here. Perhaps this will grow into a blog roll. [[User:Simsong|Simsong]] 23:46, 5 July 2008 (UTC)&lt;br /&gt;
:: What about next Selected Forensics Research? Two months passed without updates [[User:.FUF|.FUF]] 21:10, 17 October 2008 (UTC)&lt;br /&gt;
:::I got radically overcommitted. I'll try to post something this weekend. [[User:Simsong|Simsong]] 06:35, 18 October 2008 (UTC)&lt;br /&gt;
== Removal of non-contributing users ==&lt;br /&gt;
&lt;br /&gt;
I've written a little SQL statement which will remove the 1100 or so usernames that have been registered but which have never contributed anything and have no talk. This was considered for the mediawiki project but never implemented (weird). Anyway, unless there is a suggestion, I'll go ahead and do it... [[User:Simsong|Simsong]] 05:10, 20 August 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Tools table ==&lt;br /&gt;
&lt;br /&gt;
Is it possible to add [[Wireshark]] and [[NetworkMiner]] to the Tools table on the Main Page (here: ''Network Forensics: Snort, ... '')? [[User:.FUF|.FUF]] 17:08, 11 September 2008 (UTC)&lt;br /&gt;
: Done [[User:Simsong|Simsong]] 04:40, 12 September 2008 (UTC).&lt;br /&gt;
&lt;br /&gt;
== Did you know? ==&lt;br /&gt;
&lt;br /&gt;
What about organizing &amp;quot;Did you know?&amp;quot; section with some interesting facts from articles (like in Wikipedia)? [[User:.FUF|.FUF]] 12:34, 29 October 2008 (UTC)&lt;br /&gt;
: I don't think that we have enough people to do this. [[User:Simsong|Simsong]] 06:50, 19 July 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Wiki News ==&lt;br /&gt;
&lt;br /&gt;
I have updated the version of SpamBlacklist. [[User:Simsong|Simsong]] 23:49, 30 October 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
I have fixed the server config file so we now get /wiki/ URLs. [[User:Simsong|Simsong]] 20:33, 3 November 2008 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Forensics Mailing List ==&lt;br /&gt;
Hello all. I would like to ask, are there any mailing list focus on forensics? I need reference here. --[[User:Zakiakhmad|Zakiakhmad]] 09:48, 13 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
: It seems a little bit passive this discussion --[[User:Zakiakhmad|Zakiakhmad]] 03:16, 23 March 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== AJAX ==&lt;br /&gt;
&lt;br /&gt;
Ajax has been enabled by adding these settings to the LocalSettings.php file:&lt;br /&gt;
  $wgUseAjax = true;&lt;br /&gt;
  $wgEnableMWSuggest = true;&lt;br /&gt;
  $wgMWSuggestTemplate =SearchEngine::getMWSuggestTemplate() . '&amp;amp;limit=20';&lt;br /&gt;
&lt;br /&gt;
:Yours wikily, [[User:Simsong|Simsong]] 06:49, 19 July 2009 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Zalety i Wady - obiektywnie wyłącznie inżynierowie forensics ==&lt;br /&gt;
&lt;br /&gt;
'''Analiza SIM karty danych i odzyskiwania usuniętych danych&lt;br /&gt;
ANALYSIS SIM CARD DATA AND RECOVER DELETED DATA'''&lt;br /&gt;
&lt;br /&gt;
Odzyskiwanie skasowanych wiadomości SMS / tekst i wykonać kompleksową analizę danych na karcie SIM. Karta SIM ma zajęcia nabycia karty SIM i elementy analizy zajęciu urządzenia parabenów i umieszcza je w specjalistyczne karty SIM nabycia kryminalistycznych i narzędzie do analizy. Karta SIM zawiera zajęcia programowe, jak Forensic SIM Card Reader. Jeśli masz już zajęcia Device &amp;amp; Device Seizure Toolbox, nie ma potrzeby, aby otrzymać karty SIM zajęcia, jak również dlatego, że zawierają składniki, aby wykonać kryminalistycznych badań karty SIM i analizy. Jest to narzędzie dla badacza, który chce nabyć tylko karty SIM i nie chcesz wykonać kryminalistycznych egzaminów wszystkich danych z telefonu komórkowego. Karta SIM zawiera bezpłatne zajęcia roczną subskrypcję z zakupu.&lt;br /&gt;
&lt;br /&gt;
SIM Card Seizure has unicode support to read multiple languages such as Arabic, Chinese, &amp;amp; Russian: Features:&lt;br /&gt;
&lt;br /&gt;
    * Forensic SIM Card Reader Included&lt;br /&gt;
    * Calculates MD5 &amp;amp; SHA1 Hash Values&lt;br /&gt;
    * Search Function&lt;br /&gt;
    * Recovers Deleted SMS Data*&lt;br /&gt;
    * Bookmarking Options&lt;br /&gt;
    * Report Creation Wizard&lt;br /&gt;
    * Save Workspaces for Further Review&lt;br /&gt;
    * Time Stamps Calculate GMT Offset&lt;br /&gt;
    * Access to Paraben's Forum&lt;br /&gt;
    * Access to Paraben's 24 Hour Support&lt;br /&gt;
&lt;br /&gt;
Data Acquired from SIM Cards&lt;br /&gt;
&lt;br /&gt;
    * Phase Phase ID&lt;br /&gt;
    * SST SIM Service table&lt;br /&gt;
    * ICCID Serial Number&lt;br /&gt;
    * LP Preferred languages variable&lt;br /&gt;
    * SPN Service Provider name&lt;br /&gt;
    * MSISDN Subscriber phone number&lt;br /&gt;
    * AND Short Dial Number&lt;br /&gt;
    * FDN Fixed Numbers&lt;br /&gt;
    * LND Last Dialed numbers&lt;br /&gt;
    * EXT1 Dialing Extension&lt;br /&gt;
    * EXT2 Dialing Extension&lt;br /&gt;
    * GID1 Groups&lt;br /&gt;
    * GID2 Groups&lt;br /&gt;
    * SMS Text Messages&lt;br /&gt;
    * SMSP Text Message parameters&lt;br /&gt;
    * SMSS Text message status&lt;br /&gt;
    * CBMI Preferred network messages&lt;br /&gt;
    * PUCT Charges per unit&lt;br /&gt;
    * ACM Charge counter&lt;br /&gt;
    * ACMmax Charge limit&lt;br /&gt;
    * HPLMNSP HPLMN search period&lt;br /&gt;
    * PLMNsel PLMN selector&lt;br /&gt;
    * FPLMN Forbidden PLMNs&lt;br /&gt;
    * CCP Capability configuration parameter&lt;br /&gt;
    * ACC Access control class&lt;br /&gt;
    * IMSI IMSI&lt;br /&gt;
    * LOCI Location information&lt;br /&gt;
    * BCCH Broadcast control channels&lt;br /&gt;
    * Kc Ciphering key&lt;br /&gt;
&lt;br /&gt;
Pytanie 1&lt;br /&gt;
_________&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Jakie zalety na pierwszy plan,  a jakie wady które można zignorować w śledztwie?&lt;br /&gt;
&lt;br /&gt;
==Spam==&lt;br /&gt;
In an attempt to deal with spam, account creation now requires confirmation.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2012-02-05T16:36:48Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Timestomp</id>
		<title>Talk:Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Timestomp"/>
				<updated>2012-02-05T16:35:48Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Delete Timestamps? ==&lt;br /&gt;
&lt;br /&gt;
The article text says something about TimeStomp being able to delete timestamps. That must surely be nonsense. &lt;br /&gt;
&lt;br /&gt;
A timestamp (FILETIME) is just a number from 0 up to some maximum.  It can be overwritten, it can be zeroed out, but it cannot be deleted. The timestamp 0 or 1 is as valid as any other timestamp.&lt;br /&gt;
&lt;br /&gt;
There are some utility libraries that cannot convert such timestamps to 'strings', and instead produce something like 'Illegal time', or just an empty string, but that is due to bugs in that particular software, and should not be assumed to be anything else.[[User:Athulin|Athulin]] 09:07, 14 December 2011 (PST)&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Wiebetech</id>
		<title>Wiebetech</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Wiebetech"/>
				<updated>2010-10-16T14:21:07Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://www.wiebetech.com/&lt;br /&gt;
&lt;br /&gt;
Various [[Write Blockers]], forensic field kits, etc.&lt;br /&gt;
&lt;br /&gt;
[[Category:Vendors]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Strings</id>
		<title>Strings</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Strings"/>
				<updated>2008-01-15T18:50:26Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Strings is a program that prints out any [[ASCII]] or [[Unicode]] strings in the input file. Forensic examiners can use strings to get a sense of the functionality of an unknown program. User prompts, error messages, and status messages can give hints, but should not be used as proof or lack or any functionality.&lt;br /&gt;
&lt;br /&gt;
Most [[Linux]] distributions and other UNIX-like operating systems have a strings program included. There is a [[Windows]] version of strings by [[Microsoft|Microsoft's]] [[Mark Russinovich]]. Note that the Windows version prints an output header and searches for both ASCII and Unicode strings by default. &lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://www.microsoft.com/technet/sysinternals/Miscellaneous/Strings.mspx Strings for Windows]&lt;br /&gt;
* [http://www.openbsd.org/cgi-bin/man.cgi?query=strings Manual page for BSD version of strings]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Incident_Response</id>
		<title>Incident Response</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Incident_Response"/>
				<updated>2008-01-15T18:43:01Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Added Sysinternals Link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
Incident Response is a set of procedures for an investigator to examine a computer security incident. This process involves figuring out what was happened and preserving information related to those events. Because of the fluid nature of computer investigations, incident response is more of an art than a science. &lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
Incident response tools can be grouped into three categories. The first category is '''Individual Tools'''. These are programs designed to probe parts of the operating system and gather userful and/or volatile data. The [[SysInternals]] suite is frequently cited as a good example of incident response tools. They are self-contained, useful, discrete, and do not create a large footprint on the victim system. &lt;br /&gt;
&lt;br /&gt;
Standalone tools have been combined to create '''Script Based Tools''' like [[First Responder's Evidence Disk|FRED]] or the [[Windows Forensic Toolchest|WFT]]. These tools combine a number of standalone tools that are run via a script or batch file. They require minimal interaction from the user and gather a fixed set of data. These tools are good in that they automate the incident response process and provide the examiner with a standard process to defend in court. They also do not require the first responder to necessarily be an expert with the individual tools. Their weakness, however, is that they can be inflexible. Once the order of the tools is set, it can be difficult to change. Some script based tools, such as [[Microsoft|Microsoft's]] [[COFEE]] allow the user to pick and choose which standalone tools will be used in a given examination.&lt;br /&gt;
&lt;br /&gt;
The final category of tools are '''Agent Based Tools''' such as [[Mandiant|Mandiant's]] [[First Response]]. These tools require the examiner to install a program on the victim which can then report back to a central server. The upshot is that one examiner can install the program on multiple computers, gather data from all of them, and then view the results in the aggregate. Finding the victim or victims can be easier if they stand out from the crowd.&lt;br /&gt;
&lt;br /&gt;
== See Also ==&lt;br /&gt;
&lt;br /&gt;
* [[List of Standalone Incident Response Tools]]&lt;br /&gt;
* [[List of Script Based Incident Response Tools]]&lt;br /&gt;
* [[:Category:Incident response tools|Incident response tools category]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
[http://technet.microsoft.com/en-us/sysinternals/0e18b180-9b7a-4c49-8120-c47c5a693683.aspx Sysinternals Suite]&lt;br /&gt;
&lt;br /&gt;
== Papers ==&lt;br /&gt;
&lt;br /&gt;
[http://dfrws.org/2002/papers/Papers/Jesse_Kornblum.pdf Preservation of Fragile Digital Evidence by First Responders]&lt;br /&gt;
&lt;br /&gt;
== Books ==&lt;br /&gt;
&lt;br /&gt;
There are several books available that discuss incident response. For [[Windows]], ''[http://www.windows-ir.com/ Windows Forensics and Incident Recovery]'' by [[Harlan Carvey]] is an excellent introduction to possible scenarios and how to respond to them.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/HTML</id>
		<title>HTML</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/HTML"/>
				<updated>2008-01-15T18:08:55Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Hypertext Markup Language''' ('''HTML''') [[file format]] is used to create/display web pages.&lt;br /&gt;
&lt;br /&gt;
Its main purpose is to align text, images, or links on a website in a specific way. Web pages with '''.html''' or '''.htm''' extensions are examples of static web site files. Any server or database technologies require another language on top of HTML to create dynamic features in a web site. HTML files are mere [[TXT|plain text files]] whose contents follow certain rules.&lt;br /&gt;
&lt;br /&gt;
HTML files are usually viewed using a [[Web Browser|web browser]], but can also be opened with a variety of other programs (i.e., notepad, hex editors, etc).&lt;br /&gt;
&lt;br /&gt;
HTML can trace its development from SGML as a text-based markup language. [http://en.wikipedia.org/wiki/SGML]&lt;br /&gt;
&lt;br /&gt;
== XHTML ==&lt;br /&gt;
&lt;br /&gt;
The '''Extensive Hypertext Markup Language''' ('''XHTML''') is similar in nature to HTML, but has a stricter [[XML]]-based syntax. &lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Html Wikipedia: HTML]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/Xhtml Wikipedia: XHTML]&lt;br /&gt;
* [http://en.wikipedia.org/wiki/SGML Wikipedia: SGML]&lt;br /&gt;
* [http://www.w3.org/TR/html401/ HTML 4.01 Specification]&lt;br /&gt;
* [http://www.w3.org/TR/xhtml11/ XHTML 1.1 Specification]&lt;br /&gt;
&lt;br /&gt;
[[Category:File Formats]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/AFIS</id>
		<title>AFIS</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/AFIS"/>
				<updated>2008-01-15T17:29:06Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Added link for more info.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''Automatic Fingerprint Identification System''' ('''AFIS''') is a system that reports if two [[fingerprint]]s are a likely match (that is, made by the same finger) or not a likely match.&lt;br /&gt;
&lt;br /&gt;
AFIS is not a digital forensics technique, but it is a forensic technique that uses digital computers.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
[http://en.wikipedia.org/wiki/Automated_Fingerprint_Identification_System AFIS explained on wikipedia]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/HFS%2B</id>
		<title>HFS+</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/HFS%2B"/>
				<updated>2008-01-15T17:25:41Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Added link &amp;amp; period.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;HFS+, or Hierarchical File System Plus, is the file system designed by Apple Computer[http://www.apple.com] to supersede HFS. First introduced with Mac OS 8.1, one of the biggest differences was the lower allocation block size of 4kb, which increased performance and lowered fragmentation [http://developer.apple.com/technotes/tn/tn1121.html#HFSPlus]. It also implemented Unicode (rather than Mac proprietary formats) for naming files.&lt;br /&gt;
&lt;br /&gt;
There are structurally many differences between HFS and HFS+, which are listed below[http://developer.apple.com/technotes/tn/tn1150.html#HFSPlusBasics]:&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;CENTER&amp;gt;&amp;lt;TABLE Border=1 cellpadding=2 cellspacing=0 width=75%&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;&amp;lt;B&amp;gt;Feature&amp;lt;/B&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;&amp;lt;B&amp;gt;HFS&amp;lt;/B&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;&amp;lt;B&amp;gt;HFS Plus&amp;lt;/B&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;&amp;lt;B&amp;gt;Benefit/Comment&amp;lt;/B&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;User visible name&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Mac OS Standard&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Mac OS Extended&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Number of allocation blocks&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;16 bits worth&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;32 bits worth&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Radical decrease in disk space used on large&lt;br /&gt;
                  volumes, and a larger number of files per volume.&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Long file names&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;31 characters&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;255 characters&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Obvious user benefit; also improves&lt;br /&gt;
                  cross-platform compatibility&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;File name encoding&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;MacRoman&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Unicode&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Allows for international-friendly file names,&lt;br /&gt;
                  including mixed script names&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;File/folder attributes&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Support for fixed size attributes (FileInfo and&lt;br /&gt;
                  ExtendedFileInfo)&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Allows for future meta-data extensions&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Future systems may use metadata for a richer&lt;br /&gt;
                  Finder experience&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;OS startup support&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;System Folder ID&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Also supports a dedicated startup file&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;May help non-Mac OS systems to boot from HFS&lt;br /&gt;
                  Plus volumes&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;catalog node size&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;512 bytes&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;4 KB&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Maintains efficiency in the face of the other&lt;br /&gt;
                  changes. (This larger catalog node size is due to&lt;br /&gt;
                  the much longer file names [512 bytes as opposed to&lt;br /&gt;
                  32 bytes], and larger catalog records (because of&lt;br /&gt;
                  more/larger fields)).&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;/TR&amp;gt;&lt;br /&gt;
            &amp;lt;TR&amp;gt;&lt;br /&gt;
               &amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Maximum file size&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;2&amp;lt;SUP&amp;gt;31&amp;lt;/SUP&amp;gt; bytes&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;2&amp;lt;SUP&amp;gt;63&amp;lt;/SUP&amp;gt; bytes&amp;lt;/p&amp;gt;&lt;br /&gt;
               &amp;lt;/TD&amp;gt;&amp;lt;TD&amp;gt;&lt;br /&gt;
                  &amp;lt;P&amp;gt;Obvious user benefit, especially for multimedia&lt;br /&gt;
                  content creators.&amp;lt;/p&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
                  &amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&amp;lt;/CENTER&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
An HFS+ volume contains five special files:&lt;br /&gt;
&amp;lt;ol&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&lt;br /&gt;
Catalog file - Describes the folder and file hierarchy of the volume. It is organized as a &amp;quot;balanced tree&amp;quot; for fast and efficient searches&lt;br /&gt;
&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Extents overflow file - Additional extents (contiguous allocation blocks allocated to forks) are stored in a b-tree in this file&lt;br /&gt;
&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&lt;br /&gt;
Allocation file - Specifies whether an allocation block is free (similar to $Bitmap in NTFS). This is stored in a bitmap, specifying a free allocation block with a &amp;quot;clear bit&amp;quot;&lt;br /&gt;
&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Attributes file - Contains attribute information regarding files or folders&lt;br /&gt;
&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&lt;br /&gt;
Startup file - Allows computers to boot that do have built in support for HFS+ file systems&lt;br /&gt;
&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ol&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
HFS+ also implements journaling, which allows fast recovery in the case of a crash or power outage. According to Apple, &amp;quot;The purpose of the journal is to ensure that when a group of related changes are being made, that either all of those changes are actually made, or none of them are made.&amp;quot;[http://developer.apple.com/technotes/tn/tn1150.html#Journal]&lt;br /&gt;
&lt;br /&gt;
Apple technical notes are available for the HFS+ file system from their [http://developer.apple.com/cgi-bin/search.pl?q=HFS+&amp;amp;num=10&amp;amp;site=default_collection website].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/FCCU_Gnu/Linux_Boot_CD</id>
		<title>FCCU Gnu/Linux Boot CD</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/FCCU_Gnu/Linux_Boot_CD"/>
				<updated>2008-01-15T17:22:13Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Textual Cleanup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Infobox_Software |&lt;br /&gt;
  name = FCCU GNU/Linux Forensic Boot CD |&lt;br /&gt;
  maintainer = [[Christophe Monniez]], [[Geert Van Acker]] |&lt;br /&gt;
  os = {{Linux}} |&lt;br /&gt;
  genre = {{Live CD}} |&lt;br /&gt;
  license = GPL for all the softwares included unless something else specified |&lt;br /&gt;
  website = [http://www.lnx4n6.be/ lnx4n6.be] |&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
The '''FCCU GNU/Linux Forensic Boot CD''' is a [[Live CD]] built on top of [[Knoppix]]. It focuses on [[incident response]] and [[computer forensics]]. The authors welcome comments and suggestions.&lt;br /&gt;
&lt;br /&gt;
== Tools included ==&lt;br /&gt;
&lt;br /&gt;
A list of included tools is available on [http://www.lnx4n6.be/index.php?sec=Documentation&amp;amp;page=bootcdcontent lnx4n6.be].&lt;br /&gt;
&lt;br /&gt;
== Current version ==&lt;br /&gt;
&lt;br /&gt;
The current version is 11.0 (19 October 2006).&lt;br /&gt;
&lt;br /&gt;
This version includes new tools made by [http://www.storm.net.nz/projects/16 MetlStorm] to acquire memory through the Firewire bus.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/MEDEX</id>
		<title>MEDEX</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/MEDEX"/>
				<updated>2008-01-15T17:17:44Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;MEDEX is Media Exploitation&lt;br /&gt;
&lt;br /&gt;
=See Also=&lt;br /&gt;
[[DOCEX]] Document Exploitation&lt;br /&gt;
&lt;br /&gt;
[[DOMEX]] Document and Media Exploitation&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Defeating_Whole_Disk_Encryption</id>
		<title>Defeating Whole Disk Encryption</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Defeating_Whole_Disk_Encryption"/>
				<updated>2008-01-15T17:15:17Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Textual Content Cleanup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;PGP Whole Disk Encryption has the ability to generate a &amp;quot;temporary key.&amp;quot; Normally the use of the temporary key leaves a trace on the disk being cracked. But according to a recent cyberspeak podcast, when this feature is used on a hard drive that has a write-blocker attached, it still works.&lt;br /&gt;
&lt;br /&gt;
Bitlocker: You can unlock a drive with the cscript command, leaving the master key in the clear by using these commands:&lt;br /&gt;
  cscript manage-bdg.wsf unlock c:&lt;br /&gt;
  cscript manage-bdg.wsf autounlock enable c:&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Timestomp</id>
		<title>Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Timestomp"/>
				<updated>2007-10-25T16:40:59Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace.jpg|thumb|100px|right|Timestomp MACE Values]] Timestomp is a utility co-authored by developers [[James C. Foster]] and [[Vincent Liu]].  The software's goal is to allow for the deletion or modification of time stamp-related information on files.&lt;br /&gt;
&lt;br /&gt;
Take for example the &amp;quot;Timestomp MACE Values&amp;quot; screenshot displaying a command prompt window displaying the MACE values for a document file titled &amp;quot;text.txt&amp;quot;.  There are (4) four date time and date stamps displayed that are useful to Forensic Examiners in reconstructing when data was last modified, accessed, created, or entered into the NTFS Master File Table by the Operating system or manually by the user.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace_change.jpg|thumb|100px|right|Timestomp MACE Change]] Using the Timestomp application, the modified date and time stamp can be completely changed (i.e., evidenced by the &amp;quot;Timestomp MACE Change&amp;quot; screenshot).  If I were to change it, along with the other entries to more believable dates and times, then the validity of the document falls into question as does its ability to completely slip by an examiner's watchful eye if looking for modified files in an entirely different year or date span.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace_change_proof.jpg|thumb|100px|right|Timestomp MACE Change Proof]] The &amp;quot;Timestomp MACE Change Proof&amp;quot; screenshot is a final shot of the Operating System's interpretation of the Modified time stamp.  It reflects the aforementioned change exactly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note: Although this program is designed to frustrate forensic analysis, it should be noted that its use can be easily detected. Because the program can delete all time stamp information, the lack of time stamp values would lead an examiner to the conclusion that something is amiss on the system.  Microsoft-based Windows operating system record at least some timestamp information. The total absence of such is a dead giveaway that a user has tried to hide something. On the flipside, if the values are simply changed to believable values, then there is little chance of the change(s) being noticed at a casual glance.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://www.metasploit.com/projects/antiforensics/timestomp.exe Download Timestomp.exe]&lt;br /&gt;
* [http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-foster-liu-update.pdf Presentation at Blackhat 2005]&lt;br /&gt;
&lt;br /&gt;
[[Category:Anti-forensics tools]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Timestomp</id>
		<title>Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Timestomp"/>
				<updated>2007-10-25T16:35:48Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace.jpg|thumb|100px|right|Timestomp MACE Values]] Timestomp is a utility co-authored by developers [[James C. Foster]] and [[Vincent Liu]].  The software's goal is to allow for the deletion or modification of time stamp-related information on files.  Take for example the following screenshot of a command prompt window displaying the MACE values for a document file titled &amp;quot;text.txt&amp;quot;.  There are (4) four date time and date stamps displayed that are useful to Forensic Examiners in reconstructing when data was last modified, accessed, created, or entered into the NTFS Master File Table by the Operating system or manually by the user.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace_change.jpg|thumb|100px|right|Timestomp MACE Change]] Using the Timestomp application, I have completely changed the modified date and time stamp (i.e., evidenced by the second screenshot).  If I were to change it, along with the other entries to more believable dates and times, then the validity of the document falls into question as does its ability to completely slip by an examiner's watchful eye if looking for modified files in an entirely different year or date span.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:timestomp_mace_change_proof.jpg|thumb|100px|right|Timestomp MACE Change Proof]] Here is a final screenshot of the Operating System's interpretation of the Modified time stamp.  It reflects the change exactly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Note: Although this program is designed to frustrate forensic analysis, it should be noted that its use can be easily detected. Because the program can delete all time stamp information, the lack of time stamp values would lead an examiner to the conclusion that something is amiss on the system.  Microsoft-based Windows operating system record at least some timestamp information. The total absence of such is a dead giveaway that a user has tried to hide something. On the flipside, if the values are simply changed to believable values, then there is little chance of the change(s) being noticed at a casual glace.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://www.metasploit.com/projects/antiforensics/timestomp.exe Download Timestomp.exe]&lt;br /&gt;
* [http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-foster-liu-update.pdf Presentation at Blackhat 2005]&lt;br /&gt;
&lt;br /&gt;
[[Category:Anti-forensics tools]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:Timestomp_mace_change_proof.jpg</id>
		<title>File:Timestomp mace change proof.jpg</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:Timestomp_mace_change_proof.jpg"/>
				<updated>2007-10-25T16:30:46Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Timestomp MACE value change proof&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Timestomp MACE value change proof&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:Timestomp_mace_change.jpg</id>
		<title>File:Timestomp mace change.jpg</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:Timestomp_mace_change.jpg"/>
				<updated>2007-10-25T16:30:13Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Timestomp MACE value change&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Timestomp MACE value change&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Timestomp</id>
		<title>Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Timestomp"/>
				<updated>2007-10-25T16:29:31Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
Timestomp is a utility co-authored by developers [[James C. Foster]] and [[Vincent Liu]].  The software's goal is to allow for the deletion or modification of time stamp-related information on files.  Take for example the following screenshot of a command prompt window displaying the MACE values for a document file titled &amp;quot;text.txt&amp;quot;.  There are (4) four date time and date stamps displayed that are useful to Forensic Examiners in reconstructing when data was last modified, accessed, created, or entered into the NTFS Master File Table by the Operating system or manually by the user. [[Image:timestomp_mace.jpg|Timestomp MACE Values]]&lt;br /&gt;
&lt;br /&gt;
Using the Timestomp application, I have completely changed the modified date and time stamp (i.e., evidenced by the second screenshot).  [[Image:timestomp_mace_change.jpg|Timestomp MACE Change]] If I were to change it, along with the other entries to more believable dates and times, then the validity of the document falls into question as does its ability to completely slip by an examiner's watchful eye if looking for modified files in an entirely different year or date span.&lt;br /&gt;
&lt;br /&gt;
Here is a final screenshot of the Operating System's interpretation of the Modified time stamp.  [[Image:timestomp_mace_change_proof.jpg|Timestomp MACE Change Proof]]  It reflects the change exactly.&lt;br /&gt;
&lt;br /&gt;
Note: Although this program is designed to frustrate forensic analysis, it should be noted that its use can be easily detected. Because the program can delete all time stamp information, the lack of time stamp values would lead an examiner to the conclusion that something is amiss on the system.  Microsoft-based Windows operating system record at least some timestamp information. The total absence of such is a dead giveaway that a user has tried to hide something. On the flipside, if the values are simply changed to believable values, then there is little chance of the change(s) being noticed at a casual glace.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
* [http://www.metasploit.com/projects/antiforensics/timestomp.exe Download Timestomp.exe]&lt;br /&gt;
* [http://www.blackhat.com/presentations/bh-usa-05/bh-us-05-foster-liu-update.pdf Presentation at Blackhat 2005]&lt;br /&gt;
&lt;br /&gt;
[[Category:Anti-forensics tools]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/File:Timestomp_mace.jpg</id>
		<title>File:Timestomp mace.jpg</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/File:Timestomp_mace.jpg"/>
				<updated>2007-10-25T16:19:11Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Screenshot of TimeStomp application being used to display MACE attributes of a text.txt file.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Screenshot of TimeStomp application being used to display MACE attributes of a text.txt file.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-10-25T16:11:15Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Why &amp;amp; Where ==&lt;br /&gt;
&lt;br /&gt;
I'm interested to see how forensicswiki.org will grow. I own &amp;amp; operate [http://www.aeicomputertech.com AEI Computer Tech], a [http://www.aeiforensics.com Forensic] &amp;amp; [http://www.aeidownloads.com IT-based] company.&lt;br /&gt;
&lt;br /&gt;
== Important Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_definitions.php Forensic &amp;amp; Technical Definitions]&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_file_signatures.php Known File Header Library]&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_mail_header_info.php Mail Header Instructions]&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_ports.php Known System Ports]&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_resources.php Forensic Resources &amp;amp; Articles]&lt;br /&gt;
&lt;br /&gt;
[http://www.aeicomputertech.com/forensics_tools.php Forensic Tools: Free, Commercial, &amp;amp; Government]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Main_Page</id>
		<title>Talk:Main Page</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Main_Page"/>
				<updated>2007-10-25T16:06:25Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== what about the validation of legal/illegal licenses of commercial software? ==&lt;br /&gt;
&lt;br /&gt;
I'm sometimes requested by the Courts to process with investigations in order to detect is a company is using software (e.g. AutoCad, MS Office, Adobe) with licenses or not.&lt;br /&gt;
The evidence of such stuff is easy or not. The display of the &amp;quot;About&amp;quot; is sometimes enough but for some software the evidence is not so easy.&lt;br /&gt;
&lt;br /&gt;
May I propose we open a new section to address such topics?&lt;br /&gt;
&lt;br /&gt;
What do you think? --[[User:Chuv|Chuv]] 04:16, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
: Sounds like a good idea. How about [[How to determine if software is legally licensed]]? It should probably go in the [[:Category:Howtos]]. [[User:Jessek|Jessek]] 16:11, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Link to Pages for Expanding ==&lt;br /&gt;
&lt;br /&gt;
Could we add a link to the Main Page for all of the other pages that need expanding (i.e. [[:Category:Articles that need to be expanded]])? I think we're more likely to get help if we advertise where we need it! [[User:Jessek|Jessek]] 05:52, 19 March 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Global Directory of Analysts == &lt;br /&gt;
&lt;br /&gt;
I am setting up a global directory of computer forensics analysts, and am looking for feedback to the idea. Although the directory is in the UK, I want it to be global. Any thoughts, please put them on Computer Forensics [http://www.computer-forensics.co.uk] in the forums section. Thanks and regards, Simon&lt;br /&gt;
: Given the lack of response I'm not sure this is a viable idea. [[User:Jessek|Jessek]] 21:13, 26 February 2007 (PST)&lt;br /&gt;
: Doesn't seem like a good idea to me. [[User:Simsong|Simsong]] 18:50, 15 March 2007 (PDT)&lt;br /&gt;
: Response is small because the very idea and both sites are not well known within North America.  Computer forensics here has been mostly a secondary role rather than a principal focus.  To raise awareness of both efforts, this wiki and computer-forensics.co.uk, you need to get their existence promoted in major publications and the primary professional organizations.&lt;br /&gt;
&lt;br /&gt;
== Hachoir framework ==&lt;br /&gt;
&lt;br /&gt;
Hi, I'm the author of [http://hachoir.org/ Hachoir], a generic framework for binary file manipulation. I don't know if I can add it in your wiki. I prefer to have your review first :-)&lt;br /&gt;
&lt;br /&gt;
Hachoir supports many file formats (more than 60 formats) and have many features:&lt;br /&gt;
 * Fault tolerant parser (truncated/buggy file or buggy parser)&lt;br /&gt;
 * Smart syntax: you don't have to care about endian or charset, and you can mix byte and bit fields&lt;br /&gt;
 * Few functions to modify files&lt;br /&gt;
 * File recognition using header/footer in a disk image (in any file) with few false positive (each file is checked using the parser)&lt;br /&gt;
 * Written in Python: OS independant and easy to script/extend&lt;br /&gt;
 * curses, wxWidgets and Gtk interfaces&lt;br /&gt;
 * Many programs based on hachoir-core and hachoir-parser:&lt;br /&gt;
   * hachoir-strip: remove metadata and other &amp;quot;useless&amp;quot; informations&lt;br /&gt;
   * hachoir-grep: find substring in a binary file (using hachoir parsers: so search is Unicode aware)&lt;br /&gt;
   * hachoir-subfile: find all subfiles in a file&lt;br /&gt;
   * etc.&lt;br /&gt;
&lt;br /&gt;
: Please add it. [[User:Simsong|Simsong]] 09:50, 15 March 2007 (PDT)&lt;br /&gt;
:: Done: [[Hachoir]] --[[User:Haypo|Haypo]] 18:44, 18 March 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== List of OS changed files at boot time or poweroff. ==&lt;br /&gt;
&lt;br /&gt;
Some times i found useful to know which files are changed on boot time of OS or on poweroff.  For example to know what happened with OS ( Windows or Linux or ... ) what files to exclude or include by investigation. So i started collect this information with qemu and mactime. I think this wiki is the best place to post it,  what do you think haw should i name it and the category? Also i will thankful if some one can correct my English.&lt;br /&gt;
&lt;br /&gt;
== Anti-forensic Tools Link on Homepage ==&lt;br /&gt;
&lt;br /&gt;
The anti-forensic tools link on the homepage of this wiki doesn't appear to go to the proper page, but rather goes to a pro-forensic tools page.  Do we have a page just for anti-forensic tools? It would appear to me that the internal link should point to that type of a page rather than one on pro-forensic tools.  Thoughts? [[User:Cobalt2020|AEI Forensics]]&lt;br /&gt;
&lt;br /&gt;
== File Header Page ==&lt;br /&gt;
&lt;br /&gt;
Do we have a page on this forensic wiki devoted to File Header information such as specific file header and footer signatures or at least a page of links to known file header compendiums? Do we want one? [[User:Cobalt2020|AEI Forensics]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Main_Page</id>
		<title>Talk:Main Page</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Main_Page"/>
				<updated>2007-10-25T16:04:27Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== what about the validation of legal/illegal licenses of commercial software? ==&lt;br /&gt;
&lt;br /&gt;
I'm sometimes requested by the Courts to process with investigations in order to detect is a company is using software (e.g. AutoCad, MS Office, Adobe) with licenses or not.&lt;br /&gt;
The evidence of such stuff is easy or not. The display of the &amp;quot;About&amp;quot; is sometimes enough but for some software the evidence is not so easy.&lt;br /&gt;
&lt;br /&gt;
May I propose we open a new section to address such topics?&lt;br /&gt;
&lt;br /&gt;
What do you think? --[[User:Chuv|Chuv]] 04:16, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
: Sounds like a good idea. How about [[How to determine if software is legally licensed]]? It should probably go in the [[:Category:Howtos]]. [[User:Jessek|Jessek]] 16:11, 19 July 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Link to Pages for Expanding ==&lt;br /&gt;
&lt;br /&gt;
Could we add a link to the Main Page for all of the other pages that need expanding (i.e. [[:Category:Articles that need to be expanded]])? I think we're more likely to get help if we advertise where we need it! [[User:Jessek|Jessek]] 05:52, 19 March 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== Global Directory of Analysts == &lt;br /&gt;
&lt;br /&gt;
I am setting up a global directory of computer forensics analysts, and am looking for feedback to the idea. Although the directory is in the UK, I want it to be global. Any thoughts, please put them on Computer Forensics [http://www.computer-forensics.co.uk] in the forums section. Thanks and regards, Simon&lt;br /&gt;
: Given the lack of response I'm not sure this is a viable idea. [[User:Jessek|Jessek]] 21:13, 26 February 2007 (PST)&lt;br /&gt;
: Doesn't seem like a good idea to me. [[User:Simsong|Simsong]] 18:50, 15 March 2007 (PDT)&lt;br /&gt;
: Response is small because the very idea and both sites are not well known within North America.  Computer forensics here has been mostly a secondary role rather than a principal focus.  To raise awareness of both efforts, this wiki and computer-forensics.co.uk, you need to get their existence promoted in major publications and the primary professional organizations.&lt;br /&gt;
&lt;br /&gt;
== Hachoir framework ==&lt;br /&gt;
&lt;br /&gt;
Hi, I'm the author of [http://hachoir.org/ Hachoir], a generic framework for binary file manipulation. I don't know if I can add it in your wiki. I prefer to have your review first :-)&lt;br /&gt;
&lt;br /&gt;
Hachoir supports many file formats (more than 60 formats) and have many features:&lt;br /&gt;
 * Fault tolerant parser (truncated/buggy file or buggy parser)&lt;br /&gt;
 * Smart syntax: you don't have to care about endian or charset, and you can mix byte and bit fields&lt;br /&gt;
 * Few functions to modify files&lt;br /&gt;
 * File recognition using header/footer in a disk image (in any file) with few false positive (each file is checked using the parser)&lt;br /&gt;
 * Written in Python: OS independant and easy to script/extend&lt;br /&gt;
 * curses, wxWidgets and Gtk interfaces&lt;br /&gt;
 * Many programs based on hachoir-core and hachoir-parser:&lt;br /&gt;
   * hachoir-strip: remove metadata and other &amp;quot;useless&amp;quot; informations&lt;br /&gt;
   * hachoir-grep: find substring in a binary file (using hachoir parsers: so search is Unicode aware)&lt;br /&gt;
   * hachoir-subfile: find all subfiles in a file&lt;br /&gt;
   * etc.&lt;br /&gt;
&lt;br /&gt;
: Please add it. [[User:Simsong|Simsong]] 09:50, 15 March 2007 (PDT)&lt;br /&gt;
:: Done: [[Hachoir]] --[[User:Haypo|Haypo]] 18:44, 18 March 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
== List of OS changed files at boot time or poweroff. ==&lt;br /&gt;
&lt;br /&gt;
Some times i found useful to know which files are changed on boot time of OS or on poweroff.  For example to know what happened with OS ( Windows or Linux or ... ) what files to exclude or include by investigation. So i started collect this information with qemu and mactime. I think this wiki is the best place to post it,  what do you think haw should i name it and the category? Also i will thankful if some one can correct my English.&lt;br /&gt;
&lt;br /&gt;
== Anti-forensic Tools Link on Homepage ==&lt;br /&gt;
&lt;br /&gt;
The anti-forensic tools link on the homepage of this wiki doesn't appear to go to the proper page, but rather goes to a pro-forensic tools page.  Do we have a page just for anti-forensic tools? It would appear to me that the internal link should point to that type of a page rather than one on pro-forensic tools.  Thoughts? [[User:Cobalt2020|AEI Forensics]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/New_Technology_File_System_(NTFS)</id>
		<title>New Technology File System (NTFS)</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/New_Technology_File_System_(NTFS)"/>
				<updated>2007-10-25T15:59:58Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The '''New Technology File System''' ('''NTFS''') is a [[file system]] developed and introduced by [[Microsoft]] in 1993 with [[Windows]] 3.1. As a replacement for the [[FAT]] file system, it quickly became the standard for [[Windows 2000]], [[Windows XP]] and [[Windows Server 2003]].&lt;br /&gt;
&lt;br /&gt;
The features of NTFS include:&lt;br /&gt;
&lt;br /&gt;
* [[Hard-links]]&lt;br /&gt;
* Improved performance, reliability and disk space utilization&lt;br /&gt;
* Security [[access control lists]]&lt;br /&gt;
* File system journaling&lt;br /&gt;
&lt;br /&gt;
== Time Stamps ==&lt;br /&gt;
&lt;br /&gt;
NTFS keeps track of lots of time stamps. Each file has a time stamp for 'Create', 'Modify', 'Access', and 'Entry Modified'. The latter refers to the time when the MFT entry itself was modified. These four values are commonly abbreviated as the 'MACE' values. Note that other attributes in each MFT record may also contain timestamps that are of forensic value.&lt;br /&gt;
&lt;br /&gt;
Additional information on how NTFS timestamps work when files are moved or copies is available here: [http://support.microsoft.com/kb/299648 Microsoft KB 299648]&lt;br /&gt;
&lt;br /&gt;
=== Changes in Windows Vista  ===&lt;br /&gt;
&lt;br /&gt;
In Windows Vista, NTFS no longer tracks the Last Access time of a file by default. This feature can be enabled by the user if desired.&lt;br /&gt;
&lt;br /&gt;
== Alternate Data Streams ==&lt;br /&gt;
The '''NTFS''' file system includes a feature referred to as Alternate Data Streams (ADSs).  This feature has also been referred to as &amp;quot;multiple data streams&amp;quot;, &amp;quot;alternative data streams&amp;quot;, etc.  ADSs were included in '''NTFS''' in order to support the resource forks employed by the Hierarchal File System (HFS) employed by Macintosh systems.  &lt;br /&gt;
&lt;br /&gt;
As of [[Windows XP]] SP2, files downloaded via Internet Explorer, Outlook, and Windows Messenger were automatically given specific &amp;quot;zoneid&amp;quot; ADSs.  The Windows Explorer shell would then display a warning when the user attempted to execute these files (by double-clicking them).&lt;br /&gt;
&lt;br /&gt;
Sysadmins should be aware that prior to Vista, there are no tools native to the [[Windows]] platform that would allow you to view the existence of arbitrary ADSs.  While ADSs can be created and their contents executed or viewed, it wasn't until the &amp;quot;/r&amp;quot; switch was introduced with the &amp;quot;dir&amp;quot; command on Vista that arbitrary ADSs would be visible.  Prior to this, tools such as [http://www.heysoft.de/Frames/f_sw_la_en.htm LADS] could be used to view the existence of these files.&lt;br /&gt;
&lt;br /&gt;
Examiners should be aware that most forensic analysis applications, including EnCase and ProDiscover, will display ADSs found in acquired images in red.&lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
* [http://en.wikipedia.org/wiki/NTFS Wikipedia: NTFS]&lt;br /&gt;
[[Category:Disk file systems]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Timestomp</id>
		<title>Talk:Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Timestomp"/>
				<updated>2007-10-24T18:30:48Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article references &amp;quot;MACE&amp;quot; values which I've never heard of. Now, humbly, that doesn't mean a whole lot ;) but I was curious if the author of this page meant to write MAC values instead. Thoughts? [[User:Cobalt2020|AEI Forensics]]&lt;br /&gt;
: I'm a n00b ;)  I just remembered what the E stands for (the Master File Table Entry Modified time stamp of the file).  Do we have a page on here for a proper explanation of the MACE acronym? [[User:Cobalt2020|AEI Forensics]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Timestomp</id>
		<title>Talk:Timestomp</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Timestomp"/>
				<updated>2007-10-24T17:20:14Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: New page: This article references &amp;quot;MACE&amp;quot; values which I've never heard of. Now, humbly, that doesn't mean a whole lot ;) but I was curious if the author of this page meant to write MAC values instea...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article references &amp;quot;MACE&amp;quot; values which I've never heard of. Now, humbly, that doesn't mean a whole lot ;) but I was curious if the author of this page meant to write MAC values instead. Thoughts? [[User:Cobalt2020|AEI Forensics]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Vincent_Liu</id>
		<title>Vincent Liu</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Vincent_Liu"/>
				<updated>2007-10-24T17:05:55Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Expand}}&lt;br /&gt;
&lt;br /&gt;
[[Category:People]]&lt;br /&gt;
&lt;br /&gt;
Vincent Liu is the co-author of the [[anti-forensic]] utility known as [[Timestomp]].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Organizations</id>
		<title>Talk:Organizations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Organizations"/>
				<updated>2007-10-24T16:53:54Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Why are we changing links away from internal pages? [[User:Jessek|Jessek]] 08:42, 22 October 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
I don't understand your question. [[User:Simsong|Simsong]]&lt;br /&gt;
: In a [http://www.forensicswiki.org/index.php?title=Organizations&amp;amp;diff=5989&amp;amp;oldid=5959 previous version] of this page, some of the links pointed to other wiki pages such as [[Defense Cybercrime Center]]. In the latest version, these links have been changed to the (external) web sites for the organizations, such as http://www.dc3.mil/ [[User:Jessek|Jessek]]&lt;br /&gt;
:: Ahh, I understand what he is saying.  A single link was changed by myself (not multiple) to an external website. Let me change it to be an internal and an external link. [[User:Cobalt2020|Cobalt2020]]&lt;br /&gt;
:: Do we have a template or a better way to delineate internal and external pages?  Or should the DoD link just be left internal as we have a page for it? [[User:Cobalt2020|Cobalt2020]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Organizations</id>
		<title>Organizations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Organizations"/>
				<updated>2007-10-24T16:52:57Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= US Government =&lt;br /&gt;
&lt;br /&gt;
* [http://cybercrime.gov/ Computer Crime and Intellectual Property Section of the Department of Justice]&lt;br /&gt;
* [http://www.ctin.org Computer Technology Investigators Network]&lt;br /&gt;
* [http://www.ojp.usdoj.gov/nij/ National Institute of Justice]&lt;br /&gt;
* [http://ncfs.ucf.edu/home.html National Center for Forensic Science]&lt;br /&gt;
* [http://www.cftt.nist.gov/ National Institute of Standards and Technology, Computer Forensic Tool Testing]&lt;br /&gt;
* [http://www.dc3.mil/dc3/dc3.htm Department of Defense Cyber Crime Center] &lt;br /&gt;
* Department of [[Defense Cybercrime Center]]&lt;br /&gt;
* [http://www.rcfl.gov/ FBI Regional Computer Forensic Laboratory Program]&lt;br /&gt;
* [http://www.osi.andrews.af.mil/ Air Force Office of Special Investigations]&lt;br /&gt;
&lt;br /&gt;
= Trade Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.naidonline.org/ National Association for Information Destruction]&lt;br /&gt;
&lt;br /&gt;
= Professional Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.sans.org/ The SANS Institute]&lt;br /&gt;
* [http://www.htcia.org/ High Technology Crime Investigation Association]&lt;br /&gt;
* [http://www.cops.org/ International Association of Computer Investigative Specialists]&lt;br /&gt;
* [http://www.rcfg.org/ Regional Computer Forensic Group]&lt;br /&gt;
* [http://www.htcn.org/ High Tech Crime Network]&lt;br /&gt;
* [http://www.aafs.org/ American Academy of Forensic Science] The AAFS Board of Directors has approved the creation of the Digital and Multi-media section, which will be voted upon during the AAFS business meeting (during the annual meeting) in Feb 2008.&lt;br /&gt;
* [http://www.infoperitos.com/ Infoperitos - Computer Expert Witness Group from the Spanish Computer Engineers Association]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:Organizations</id>
		<title>Talk:Organizations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:Organizations"/>
				<updated>2007-10-24T16:49:20Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Why are we changing links away from internal pages? [[User:Jessek|Jessek]] 08:42, 22 October 2007 (PDT)&lt;br /&gt;
&lt;br /&gt;
I don't understand your question. [[User:Simsong|Simsong]]&lt;br /&gt;
: In a [http://www.forensicswiki.org/index.php?title=Organizations&amp;amp;diff=5989&amp;amp;oldid=5959 previous version] of this page, some of the links pointed to other wiki pages such as [[Defense Cybercrime Center]]. In the latest version, these links have been changed to the (external) web sites for the organizations, such as http://www.dc3.mil/ [[User:Jessek|Jessek]]&lt;br /&gt;
:: Ahh, I understand what he is saying.  A single link was changed by myself (not multiple) to an external website. Let me change it to be an internal and an external link. [[User:Cobalt2020|Cobalt2020]]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Organizations</id>
		<title>Organizations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Organizations"/>
				<updated>2007-10-18T17:49:20Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= US Government =&lt;br /&gt;
&lt;br /&gt;
* [http://cybercrime.gov/ Computer Crime and Intellectual Property Section of the Department of Justice]&lt;br /&gt;
* [http://www.ctin.org Computer Technology Investigators Network]&lt;br /&gt;
* [http://www.ojp.usdoj.gov/nij/ National Institute of Justice]&lt;br /&gt;
* [http://ncfs.ucf.edu/home.html National Center for Forensic Science]&lt;br /&gt;
* [http://www.cftt.nist.gov/ National Institute of Standards and Technology, Computer Forensic Tool Testing]&lt;br /&gt;
* [http://www.dc3.mil/dc3/dc3.htm Department of Defense Cyber Crime Center]&lt;br /&gt;
* [http://www.rcfl.gov/ FBI Regional Computer Forensic Laboratory Program]&lt;br /&gt;
* [http://www.osi.andrews.af.mil/ Air Force Office of Special Investigations]&lt;br /&gt;
&lt;br /&gt;
= Trade Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.naidonline.org/ National Association for Information Destruction]&lt;br /&gt;
&lt;br /&gt;
= Professional Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.sans.org/ The SANS Institute]&lt;br /&gt;
* [http://www.htcia.org/ High Technology Crime Investigation Association]&lt;br /&gt;
* [http://www.cops.org/ International Association of Computer Investigative Specialists]&lt;br /&gt;
* [http://www.rcfg.org/ Regional Computer Forensic Group]&lt;br /&gt;
* [http://www.htcn.org/ High Tech Crime Network]&lt;br /&gt;
* [http://www.aafs.org/ American Academy of Forensic Science] The AAFS Board of Directors has approved the creation of the Digital and Multi-media section, which will be voted upon during the AAFS business meeting (during the annual meeting) in Feb 2008.&lt;br /&gt;
* [http://www.infoperitos.com/ Infoperitos - Computer Expert Witness Group from the Spanish Computer Engineers Association]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Organizations</id>
		<title>Organizations</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Organizations"/>
				<updated>2007-10-18T17:49:04Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Added RCFL Link, Fixed Air Force and DoD links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= US Government =&lt;br /&gt;
&lt;br /&gt;
* [http://cybercrime.gov/ Computer Crime and Intellectual Property Section of the Department of Justice]&lt;br /&gt;
* [http://www.ctin.org Computer Technology Investigators Network]&lt;br /&gt;
* [http://www.ojp.usdoj.gov/nij/ National Institute of Justice]&lt;br /&gt;
* [http://ncfs.ucf.edu/home.html National Center for Forensic Science]&lt;br /&gt;
* [http://www.cftt.nist.gov/ National Institute of Standards and Technology, Computer Forensic Tool Testing]&lt;br /&gt;
* [http://www.dc3.mil/dc3/dc3.htm Department of Defense Cyber Crime Center]&lt;br /&gt;
* [http://www.rcfl.gov/ Regional Computer Forensic Laboratory Program]&lt;br /&gt;
* [http://www.osi.andrews.af.mil/ Air Force Office of Special Investigations]&lt;br /&gt;
&lt;br /&gt;
= Trade Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.naidonline.org/ National Association for Information Destruction]&lt;br /&gt;
&lt;br /&gt;
= Professional Organizations =&lt;br /&gt;
&lt;br /&gt;
* [http://www.sans.org/ The SANS Institute]&lt;br /&gt;
* [http://www.htcia.org/ High Technology Crime Investigation Association]&lt;br /&gt;
* [http://www.cops.org/ International Association of Computer Investigative Specialists]&lt;br /&gt;
* [http://www.rcfg.org/ Regional Computer Forensic Group]&lt;br /&gt;
* [http://www.htcn.org/ High Tech Crime Network]&lt;br /&gt;
* [http://www.aafs.org/ American Academy of Forensic Science] The AAFS Board of Directors has approved the creation of the Digital and Multi-media section, which will be voted upon during the AAFS business meeting (during the annual meeting) in Feb 2008.&lt;br /&gt;
* [http://www.infoperitos.com/ Infoperitos - Computer Expert Witness Group from the Spanish Computer Engineers Association]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-10-18T17:45:41Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Why &amp;amp; Where ==&lt;br /&gt;
&lt;br /&gt;
I'm interested to see how forensicwiki will grow. I own &amp;amp; operate [http://www.aeicomputertech.com AEI Computer Tech], a [http://www.aeiforensics.com Forensic] &amp;amp; [http://www.aeidownloads.com IT-based] company.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Anonymous_Web_Browsing_Tools</id>
		<title>Anonymous Web Browsing Tools</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Anonymous_Web_Browsing_Tools"/>
				<updated>2007-10-18T14:24:20Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Anonymizer.com is home to the Safe Surfing Suite of software. More information is available at: [http://www.anonymizer.com anonymizer.com]&lt;br /&gt;
&lt;br /&gt;
A website that allows the masking of the source IP address: [http://www.ibypass.com ibypass.com]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Anonymous_Web_Browsing_Tools</id>
		<title>Anonymous Web Browsing Tools</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Anonymous_Web_Browsing_Tools"/>
				<updated>2007-10-18T14:24:03Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Textual update&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Anonymizer.com is home to the Safe Surfing Suite of software. More information is available at:[http://www.anonymizer.com anonymizer.com]&lt;br /&gt;
&lt;br /&gt;
A website that allows the masking of the source IP address: [http://www.ibypass.com ibypass.com]&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-06-06T19:42:05Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Why &amp;amp; Where ==&lt;br /&gt;
&lt;br /&gt;
I'm interested to see how forensicwiki will grow. I own &amp;amp; operate AEI Computer Tech, a Forensic &amp;amp; IT-based company; the location of which is [http://www.aeicomputertech.com aeicomputertech.com].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User_talk:Cobalt2020</id>
		<title>User talk:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User_talk:Cobalt2020"/>
				<updated>2007-06-06T19:41:40Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: Removing all content from page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User_talk:Cobalt2020</id>
		<title>User talk:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User_talk:Cobalt2020"/>
				<updated>2007-06-06T19:41:08Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: New page: I own &amp;amp; operate AEI Computer Tech, a Forensic &amp;amp; IT-based company; the location of which is located at [http://www.aeicomputertech.com aeicomputertech.com].&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I own &amp;amp; operate AEI Computer Tech, a Forensic &amp;amp; IT-based company; the location of which is located at [http://www.aeicomputertech.com aeicomputertech.com].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:MD5</id>
		<title>Talk:MD5</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:MD5"/>
				<updated>2007-06-06T19:37:50Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://deepbyte.com/blog/2006/02/is_the_md5_hash_unreliable.html is broken. [[User:Cobalt2020|Cobalt2020]] 12:37, 6 June 2007 (PDT)&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/Talk:MD5</id>
		<title>Talk:MD5</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/Talk:MD5"/>
				<updated>2007-06-06T19:37:43Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: New page: http://deepbyte.com/blog/2006/02/is_the_md5_hash_unreliable.html is broken.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://deepbyte.com/blog/2006/02/is_the_md5_hash_unreliable.html is broken.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-03-14T14:04:09Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: /* Cobalt's Userpage */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Why &amp;amp; Where ==&lt;br /&gt;
&lt;br /&gt;
I'm interested to see how forensicwiki will grow. My own forensic-related website/company is located at aeicomputertech.com [http://www.aeicomputertech.com].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-03-14T14:03:55Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Cobalt's Userpage ==&lt;br /&gt;
&lt;br /&gt;
I'm interested to see how forensicwiki will grow. My own forensic-related website/company is located at aeicomputertech.com [http://www.aeicomputertech.com].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-03-14T14:03:16Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I'm interested to see how forensicwiki will grow. My own forensic-related website/company is located at [http://www.aeicomputertech.com].&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-03-14T14:02:52Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I'm interested to see how forensicwiki will grow. My own forensic-related website/company is located at www.aeicomputertech.com.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/wiki/User:Cobalt2020</id>
		<title>User:Cobalt2020</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/wiki/User:Cobalt2020"/>
				<updated>2007-03-14T13:58:50Z</updated>
		
		<summary type="html">&lt;p&gt;Cobalt2020: New page: I'm interested to see how forensicwiki will grow.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I'm interested to see how forensicwiki will grow.&lt;/div&gt;</summary>
		<author><name>Cobalt2020</name></author>	</entry>

	</feed>