Analisis Facebook Forensik

Jumat, 31 Oktober 2014

How Important are Facebook Artifacts?
In March 2013, Facebook reportedly had just over 1 billion users worldwide. Founded in February 2004, it can be considered one of the grandfathers of social networking. Nearly ten years later and even with hundreds of other social networking sites out there, Facebook is still a very popular social medium. With increased popularity comes the potential that Facebook will be used in a crime or at least as a secondary source of evidence providing information about the crime.As a social network, the likelihood of a suspect using Facebook as a communications medium to discuss an incident can be quite high. This whitepaper discusses the common Facebook artifacts that can be potential sources of vital evidence key to   an investigation.


After reading this whitepaper you will be able to:

• Identify the common artifacts left behind when forensically examining Facebook activity
• Use digital forensics software to analyze and recover Facebook artifacts such as Chat, Messages,  
Wall Posts/Comments, Pictures, and URLs

• Understand the types of searches IEF performs and how to best use that information in your investigation
Generally there are six specific categories of artifacts that can be individually identified when examining a computer’s hard disk:

1. Facebook Chat

This artifact is most commonly found in memory as JavaScript Object Notation (JSON) text in a running computer and/or in the pagefile.sys & hiberfil.sys file(s).















2. Facebook Messages

Facebook Chat and Messages are now the same artifact, but in older versions of Facebook these were two different artifacts. This artifact is most commonly found in memory of a running computer and/or in the pagefile.sys and hiberfil.sys file(s).
3. Facebook Wall Post/Status Update/Comments

HTML that is carved from temporary internet files/web cache and memory.










Magnet Forensics - How To Uncover The Covered Tracks - 3 

4. Facebook Webpage Fragment

A fragment of HTML that is carved from temporary internet files/web cache and memory.


5. Facebook Pictures

Facebook pictures have a specific filename pattern and are found in temporary internet files/web cache. The filename contains three sets of numbers like the following:


‘1221785571_1221785571_10150672801465915_n.jpg’


The second set of numbers can indicate the Facebook user ID the photo belongs to and it can be queried through

Facebook’s ‘graph’ API here: https://developers.facebook.com/tools/explorer

6. Facebook URLs


A URL in any web related (browser) artifact that references Facebook URLs. These artifacts commonly reference other

Facebook users or specific Facebook activity.

“https://www.facebook.com/photo.php?fbid=

201526933901245715&set=at.10150672801465915.448027.507140714.552175374.1221785571&type=1& theater”

201526933901245715 is the photo ID

10150672801465915 is the album ID
1221785571 is the user ID

Viewed photos will appear in the cache file with the name:

‘1221785571_1221785571_10150672801465915_n.jpg’

Viewing messages for profile currently being used:

http://www.facebook.com/messages/joey.flowes



Now that  we’ve discussed  the kinds of artifacts  you are likely to encounter when examining evidence looking for Facebook activity or generally searching for any Facebook related activity, let’s look at how you can recover them.


Facebook can be an indispensable online resource when recovering forensic artifacts to use as digital evidence. It can provide a glimpse into an individual’s life, offer geographical information to indicate where a person was on a specific date, and can reveal the identities of close friends and family. With Facebook applications available on most mobile devices, further location data is available with GPS, making these forensic artifacts even more valuable to the investigator.


Recovering 6 Types of Facebook Forensic Artifacts

In this whitepaper, we’ll go over the 6 most common categories of forensic artifacts that are left behind by a person’s Facebook activity. We’ll also demonstrate how our digital forensics software,  IEF, can be used to analyze and recover forensic artifacts from the following categories:


  • Facebook Chat
  • Facebook Messages
  • Facebook Wall Posts/Comments
  • Facebook Webpage Fragment
  • Facebook Pictures
  • Facebook URLs

Facebook artifacts can be one of those artifacts that may not seem to apply to your specific case, but suddenly it gets thrust into the forefront of your investigation because of a conversation, wall post, association or other link made solely through the user Facebook account. Like general Internet history/activity, it’s one of those categories that you really can’t afford to not review.

Internet Evidence Finder (IEF) includes support for Facebook under the social media artifact category.






Finding & reviewing these types of artifacts are extremely simple when using Internet Evidence Finder. There are four search types that you can use in Internet Evidence Finder when looking for Facebook artifacts:


1.   Full Search

This is the default search type when using IEF to analyze NTFS, FATx, HFS+ & EXTx. This search type allows IEF to parse the file system of each volume and identify all the various objects (files, folders & unallocated space) to search them all. On NTFS partition, it also individually identifies file system objects such as the $MFT & $Logfile for targeted searching.


2.   Quick Search


This search type causes IEF to search specific file system objects and common files and folder locations that normally contain Internet-related artifacts. For example this type of search would target the default locations for supported browser histories, but would not check every single file/folder.



3.   Sector Search

This is the default search type when examining a drive/image that contains an unknown file system. This allows IEF to search each sector for known artifacts even if the file system itself cannot be read/interpreted.





4.   Custom Search

The custom search type allows the user to specify which areas of the volume to search by selecting/deselecting the various options.



When looking for Facebook artifacts, using IEF with the “Full search” type would be the recommended option since it would look everywhere (including unallocated space for deleted Facebook artifacts). As long as the browser history was not moved to a non-standard location, you could also use the “Quick search” option. The “Custom search” option would also work as long as you chose to search all files or common areas/folder locations. Once IEF is completed with the artifact search, Facebook artifacts are individually identified and categorized separately from common web browsing artifacts.




You can then review each Facebook artifact category separately by clicking on the respective artifact subcategory and viewing the details in the table view.




Each found artifact will have a file (if the artifact was found in a specific file) or physical offset (if the artifact was found in unallocated or when using the sector search option) displayed in the lower details pane so you can find the same artifact by using other 3rd party tools for validation and additional research.





As always, if you have any comments, suggestions or questions,


http://www.magnetforensics.com/recovering-facebook-artifacts/



AS Kembali Tuntut Hacker China

Selasa, 15 Juli 2014

AS Kembali Tuntut Hacker China

Jakarta - Pemerintah Amerika Serikat terus melanjutkan usahanya dalam memerangi aksi mata-mata cyber oleh China. Baru-baru ini, Departemen Hukum AS menuntut seorang jago komputer berkebangsaan China. 

Su Bin -- sosok yang dimaksud -- dituduh telah mencuri informasi rahasia mengenai pesawat militer buatan kontraktor Departemen Pertahanan Amerika Serikat. Dalam melakukan peretasan tersebut, Bin disebutkan bekerja sama dengan dua orang peretas lainnya.

Ketiganya dituduh mulai mengumpulkan informasi rahasia itu sejak tahun 2009 hingga 2013. Ada tiga pesawat yang data-datanya berhasil mereka curi, dua buah pesawat jet fighter buatan Lockheed Martin F-22, dan F-35, serta pesawat cargo C-17 buatan Boeing.

Bin yang tinggal di Kanada pun dianggap masih mempunyai dokumen setebal 1.467 halaman yang berisi target peretasan lain yang juga potensial. 

Seperti yang dilansir The Verge, Senin (14/7/2014), hasil peretasan tersebut kemungkinan akan dijual oleh Bin ke perusahaan pembuat pesawat di China.

Keterkaitan Bin dengan pemerintah China belum jelas, tapi sepertinya ia meretas untuk memperkaya diri sendiri. Namun informasi yang ia curi kemungkinan besar tetap bermuara di perusahaan milik pemerintah China.

Awal tahun 2014, pemerintah AS juga mengajukan tuntutan kriminal terhadap lima orang peretas asal China, yang dituduh telah mencuri data rahasia dari perusahaan Negeri Paman Sam. 

Praktik spionase semacam ini diperkirakan telah merugikan AS sebesar USD 24 miliar hingga USD 120 miliar per tahun.

Tugas Digital Evidence 4

Sabtu, 28 Juni 2014

bisa juga dilihat di sini.

Laporan Kasus FEDA BankRobber.dd

Senin, 23 Juni 2014


link yang berkaitan dengan kasus ini
steganografi-pesan-tersembunyi
analisis-kasus-computer-crime-dengan 5W+1H

Eksplorasi bukti digital di Web Browser

Sabtu, 21 Juni 2014

Analysis Web Browser Forensic Using Browser Forensic Tools

Jumat, 20 Juni 2014

Browser history is one part in the search of digital evidence. As part of a lot of Digital Forensics investigations, obtaining information of the user’s browsing habits is an important step. There are various kind of Browser forensic tools, depend on the web browser itself. I will give some web browser analysis tools that useful in forensic investigation.


Odessa is an acronym for “Open Digital Evidence Search and Seizure Architecture” The intent of this project is to provide a completely open and extensible suite of tools for performing digital evidence analysis as well as a means of generating a usable report detailing the analysis and any findings. Odessa including Galleta, a tool for analyzing Internet Explorer cookies, Pasco, a tool for analyzing the Microsoft Windows index.dat file, and Rifiuti, a tool for investigating the Microsoft Windows recycle bin info2 file.


WBF (Web Browser Forensic) http://manuel.santander.name/wbf.html
wbf (Web Browser Forensics) is a C program intended to parse firefox, opera and epiphany web browser history files distributed in terms of the GNU General Public License.

BFT (Browser Forensic Toolkit) http://www.darkcomet-rat.com/bft.dc
This software is an advanced local browser history search engine, in less than few seconds it will extract the chosen keywords of most famous web browser, actually Internet Explorer, Google Chrome, Mozilla FireFox, RockMelt, Comodo Dragon and Opera. The program will attempt to find the keyword(s) in the history title and search, if the keyword is present or suspected to be, it will be display in the result list with his URL and Title.

CacheGrab® is our standalone cache and history recovery tool that can be used on any logically mounted volume or virtual file system, including disks mounted using Physical Disk Emulation. CacheGrab does not require any purchase or licensing and may be used freely. Users should note that this version of the program only searches logical volumes at this time, and the ability to search physical disks and unallocated space will be available with the release of CacheGrab® Version 2, sometime later this year.

Firefox Cache Forensic is Command-line tools and documentation for forensic analysis of the Firefox Cache.

Woanware Chrome Forensic http://www.woanware.co.uk/?page_id=70
ChromeForensics is an application to extract various bits of activity information from the Google Chrome web browser and the open source version Chromium. All of the core actions e.g. import and export are run on separate threads so there are no graphical user interface (GUI) hangs etc. The user interface displays the Favorite Icons and Thumbnails extracted from the database, which is one area that sets it apart from the other Chrome forensic apps.

Features

➢ Imports Visits/History, Keyword Search Terms, Downloads, Autofill information, Cookies, ➢ Favorite Icons, Thumbnails, History Index ➢ Exports to CSV and HTML ➢ Fast ➢ Displays Favorite Icons and Thumbnails in Grid

You can download Woanware Chrome Forensic Here : http://www.woanware.co.uk/downloads/ChromeForensics.v.1.0.5.zip

Woanware Firefox Forensic Tools http://www.woanware.co.uk/?page_id=96

FireFoxForensics is an application to extract various bits of activity information from the Mozilla FireFox web browser. All of the core actions e.g. import and export are run on separate threads so there are no graphical user interface (GUI) hangs etc. The user interface displays the Favorite Icons and extracted from the database, which is one area that sets it apart from the other FireFox forensic apps.

Features

➢ Imports moz_places/moz_historyvisits, moz_bookmarks, moz_favicons, moz_downloads, moz_cookies, moz_logins ➢ Exports to CSV and HTML ➢ Fast ➢ Displays Favorite Icons in Grid ➢ Custom WHERE clause queries ➢ Advanced querying ➢ Prefined search engine queries e.g. Google, Google Images, Yahoo and Bing

You can download Woanware Firefox Forensic Here : http://www.woanware.co.uk/downloads/FireFoxForensics.v.1.0.5.zip

Woanware Opera Forensic http://www.woanware.co.uk/?page_id=164

OperaForensics is a tool to extract the information stored in the Opera dcache4 file

Features

➢ Exports to CSV ➢ Exports to HTML with the images from the actual cache file displayed

Yolu can download Woanware Opera forensic here : http://www.woanware.co.uk/downloads/OperaForensics.v.1.0.0.zip


ChromeAnalysis Plus is a software tool for extracting and analysing internet history from the Google Chrome web browser.


FoxAnalysis Plus is a software tool for extracting and analysing internet history from the Mozilla Firefox web browser

Orion Browser Dumper V1 (New)

Orion Browser Dumper
This software is an advanced local browser history extractor (dumper), in less than few seconds (like for Browser Forensic Tool) it will extract the whole history content of most famous web browser, Actually Internet Explorer, Mozilla FireFox, Google Chrome, COMODO Dragon, Rockmelt and Opera.

Source : http://thehackernews.com/2012/05/orion-browser-dumper-v1.html

I just give recommendation free or opensource tools for browser forensic tools. I will update next days more specifics about exploration digital evidendence potencial in browsers. Thanks a lot, and enjoy it.