Difference between pages "Residual Data on Used Equipment" and "Windows Vista"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m
 
 
Line 1: Line 1:
Used hard drives are frequently a good source of images for testing forensic tools. That's because many individuals, companies and organizations neglect to properly sanitize their hard drives before they are sold on the secondary market.
+
== New Features ==
 +
* [[BitLocker Disk Encryption | BitLocker]]
 +
* [[Windows Desktop Search | Search]] integrated in operating system
 +
* [[ReadyBoost]]
 +
* [[SuperFetch]]
 +
* [[NTFS|Transactional NTFS (TxF)]]
 +
* [[Windows NT Registry File (REGF)|Transactional Registry (TxR)]]
 +
* [[Windows Shadow Volumes|Shadow Volumes]]; the volume-based storage of the Volume Shadow Copy data
 +
* $Recycle.Bin
 +
* [[Windows XML Event Log (EVTX)]]
 +
* [[User Account Control (UAC)]]
  
You can find used hard drives on eBay, at swap meets, yard sales, and even on the street.  
+
== File System ==
 +
The file system used by Windows Vista is primarily [[NTFS]].
  
==ATMs==
+
In Windows Vista, NTFS no longer tracks the Last Access time of a file by default. This feature can be enabled by setting the NtfsDisableLastAccessUpdate value to '0' in the Registry key:
* '''2009-11-21''': Robert Siciliano, a security consultant to Intelius.com and personal ID theft expert, buys an ATM machine for $750 from a bar in Boston. The machine comes with more than 1000 credit and ATM card numbers. http://www.theregister.co.uk/2009/11/18/second_hand_atm_fraud_risk/
+
<pre>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem</pre>
==Hard Drives==
+
  
There have been several incidents in which individual have purchased a large number of hard drives and written about what they have found. This web page is an attempt to catalog all of those stories in chronological order.
+
Note that this feature has been around since as early as Windows 2000 [http://technet.microsoft.com/en-us/library/cc959914.aspx].
  
* '''2003-01''': [[Simson Garfinkel]] and Abhi Shelat at MIT publish a study in ''IEEE Security and Privacy Magazine''  which documents large amount of personal and business-sensitive information found on 150 drives purchased on the secondary market.
+
== Prefetch ==
 +
Note that the prefetch hash function is different then that of [[Windows XP]] and [[Windows 2003]].
  
* '''2006-06''': A man buys a family's hard drive at a fleamarket in Chicago after the family's hard drive is upgraded by Best Buy. Apparently somebody at Best Buy violated company policy and instead of destroying the hard drive, they sold it.  
+
== Registry ==
 +
The [[Windows_Registry|Windows Registry]] remains a central component of the Windows Vista operating system.
  
* '''2006-08-10''': The University of Glamorgan in Wales purchased 317 used hard drives from the UK, Australia, Germany, and the US. 25% of the 200 drives purchased from the UK market had been completely wiped. 40% of the purchased drives didn't work.  40% came from businesses, of which 23% contained enough information to identify the company. 5% had business sensitive information. 25% came from individuals, of which many had pornography, and 2 had to be referred to the police for suspected child pornography.
+
== See Also ==
 +
* [[Windows]]
 +
* [[Windows 7]]
 +
* [[Windows 8]]
  
* '''2006-08-14''': [http://news.bbc.co.uk/2/hi/business/4790293.stm BBC News] reports on bank account information recovered from used PC hard drives and being sold in Nigeria for £20 each. The PCs had apparently come from recycling points run by UK town councils that are then "recycled" by being sent to Africa.
+
== External Links ==
 +
* [https://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf Windows Vista Network Attack Surface Analysis], James Hoagland, Matt Conover, Tim Newsham, Ollie Whitehouse
  
* '''2006-08-15''': Simson Garfinkel presents results of a study of 1000 hard drives (750 working) at the 2006 Workshop on Digital Forensics. Results of the study show that information can be correlated across hard drives using Garfinkel's [[Cross Drive Analysis]] approach.
+
[[Category:Operating systems]]
 
+
* '''2007-02-06''': [http://www.fulcruminquiry.com Fulcrum Inquiry], a Los Angeles litigation support firm, purchased 70 used hard drives from 14 firms and discovered confidential information on 2/3rds of the drives.
+
 
+
* '''2007-08-30''': Bill Ries-Kinght, an IT consultant, purchases a 120GB Seagate hard drive on eBay for $69. Although the drive was advertised as being new, it apparently was previously used by the campaign of Mike Beebe, who won the Arkansas state governorship in November 2006. "Among the files were documents listing the private cell phone numbers of political allies, including US Senators Blanch Lincoln and Mark Pryor and US Representatives Marion Berry, Mike Ross and Vic Snyder. It also included talking points to guide the candidate as he called influential people whose support he sought," states an article published in [http://www.theregister.co.uk/2007/08/30/governors_data_sold_on_ebay/ The Register].
+
 
+
* '''2008-01-28''': Gregory Evans, a security consultant in Marina Del Ray, Calif., bought a $500 computer at a swap meet from a former mortgage company. It contained credit reports on 300 people in a deleted file, according to an article published in [http://www.nydailynews.com/money/2008/01/28/2008-01-28_sensitive_info_lives_on_in_old_computers.html The New York Daily NEws]. The security consultant was also able to recover the usernames and passwords of the mortgage company's former employees.
+
 
+
*'''2009-02-10''': Michael Kessler, CEO of Kessler International, a New York City forensics firm, bought 100 "relatively modern drives, the vast majority of them Serial ATA" from eBay over the course of 6 months. The drives ranged in size from 400GB to 300GB. 40% of the drives were found to contain sensitive data. [http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=storage&articleId=9127717&taxonomyId=19&intsrc=kc_top]
+
 
+
*'''2009-05-07''': University of Glamorgan bought disks in its annual survey of used hard drives and found "Details of test launch procedures for the THAAD (Terminal High Altitude Area Defence) ground-to-air missile defence system. [http://news.bbc.co.uk/2/hi/uk_news/wales/8036324.stm Missile data found on hard drives, BBC News, May 7, 2009]
+
 
+
*'''2009-07-30''': Reporters working for the PBS show Frontline on an article about electronic waste find hard drives in Ghana that contain "hundreds and hundreds of documents about government contracts" from a hard drive that had been previously used by a TSA subcontractor. The documents were marked "competitive sensitive" and covered contracts with the Defense Intelligence Agency. The hard drive was not encrypted.  [http://itworld.com/security/69758/reporters-find-northrop-grumman-data-ghana-market Reporters find Northrop Grumman data in Ghana market, Robert McMillan, IT World, June 24, 2009]
+
 
+
*'''2009-09-23''': US DoD sells computers without cleaning them first. http://fcw.com/articles/2009/09/23/inspector-general-audit.aspx
+
 
+
==Cell Phones==
+
* [http://www.wired.com/techbiz/media/news/2003/08/60052 BlackBerry Reveals Bank's Secrets], Wired, August 8, 2005.
+
* [http://www.taipeitimes.com/News/feat/archives/2008/09/28/2003424400 Who has your old phone's data], Pete Warren, The Guardian, London, Sept. 28, 2008, page 13.
+
* [http://www.myfoxdc.com/myfox/pages/News/Detail?contentId=8055902&version=1&locale=EN-US&layoutCode=TSTY&pageId=3.2.1 McCain Campaign Sells Info-Loaded Blackberry to FOX 5 Reporter], by Tisha Thompson and Rick Yarborough, FOX 5 Investigative Unit, 11 December 2008.  (See also [http://www.theregister.co.uk/2008/12/12/mccain_blackberry/])
+
 
+
==Cameras==
+
* [http://www.telegraph.co.uk/news/uknews/3107003/Camera-sold-on-eBay-contained-MI6-files.html Camera sold on eBay contained MI6 files], Jessica Salter, Telegraph, September 30, 2008.
+
 
+
==Network Equipment==
+
* [http://www.pcpro.co.uk/news/227190/council-sells-security-hole-on-ebay.html Council sells security hole on Ebay], Matthew Sparkes, PC Pro, September 29, 2008 - Kirkless Council (UK) sells a Cisco [[VPN]] 3002 Concentrator on Ebay for 99 pence. The device is purchased by Andrew Mason, a security consultant, who discovers that the Cisco [[VPN]] device still has the full configuration for the Kirkless Council and the device hasn't been deactivated.
+
 
+
==MP3 Players==
+
* [http://news.yahoo.com/s/ap/20090127/ap_on_re_as/as_new_zealand_us_military_files NZ man's MP3 player holds US military files], Associated Press, Jan 27, 2009. A man from New Zealand bought an MP3 player at a thrift shop in Oklahoma that had 60 US military files, "including names and telephone numbers for American soldiers."
+
 
+
==See Also==
+
[[Residual Data]]
+

Revision as of 12:14, 20 October 2013

New Features

File System

The file system used by Windows Vista is primarily NTFS.

In Windows Vista, NTFS no longer tracks the Last Access time of a file by default. This feature can be enabled by setting the NtfsDisableLastAccessUpdate value to '0' in the Registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem

Note that this feature has been around since as early as Windows 2000 [1].

Prefetch

Note that the prefetch hash function is different then that of Windows XP and Windows 2003.

Registry

The Windows Registry remains a central component of the Windows Vista operating system.

See Also

External Links