beyond extreme forensics update 3q / 2016 by alvaro soto

25

Upload: ec-council

Post on 14-Jan-2017

87 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto
Page 2: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

© Legal Disclaimer…

CopyrightDisclaimerUnderSec6on107oftheCopyrightAct1976,allowanceismadefor"fairuse"forpurposessuchascri6cism,comment,newsrepor6ng,teaching,scholarship,andresearch.FairuseisausepermiDedbycopyrightstatutethatmightotherwisebeinfringing.Non-profit,educa6onalorpersonaluse6psthebalanceinfavoroffairuse.Allmaterials/trademarksusedinthispresenta6onbelongtotheirrespec6veowners.

Page 3: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

What we do in Forensic Lab…

Page 4: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

What we do in the forensic lab…

Page 5: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Goals for this update from the lab...

Takeaquicklookaround:

•  Share“storiesfromtrenches”• Giveanawarnessofpoten6alissues/fixes• GiveyousomeresourcesforR&DandFunJ• Ques6ons/Answers…

AlvaroAlexanderSoto-LabDirector/[email protected]

Page 6: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

HDD Storage components review.

Page 7: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

HDD Storage components review.

Page 8: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Our main resources… and suggesBon for you to use too..

AlvaroAlexanderSoto-LabDirector/[email protected]

Page 9: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

EncrypBon everywhere… but…

Corrup6on.

AlvaroAlexanderSoto-LabDirector/[email protected]

Page 10: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

IoT / Firmware everywhere… but…

AlvaroAlexanderSoto-LabDirector/[email protected]

Page 11: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Inside HDD… Diags..

•  SAcorrup6on..• Motorstuck..• Heads..•  Electronics..•  Scratches..•  ESD•  Sounds/Clicks• Naturalelements…

Page 12: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

SA in somewhere…NegaBve Tracks..?

•  -1FFFFh•  -2FFFEh•  Etc…

Page 13: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Seagate DiagnosBc Serial Port

Page 14: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Tools..

Page 15: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

SA vulnerability / Fix…

• ATAPwd• Change/Off-H• HPA/DCO• Malware/Codeinjec6on• Hiddendata/Tools•  S/N• ….

Page 16: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Tools / RE Cracks / Filesystem Hacks

Page 17: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Sample Scenario: Data theQ problem..

•  SEDHDDsolu6onshererightnow!!!

• Reallyasolu6on?.....

•  Letstakealookaround…

Page 18: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

SED HDD

Page 19: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

SED HDD

Page 20: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Playing Cops and Robbers

Page 21: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto
Page 22: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

• BIOSMods

Page 23: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Job Done…lets go back to home

Page 24: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

Resources • hDps://www.itosaka.com/WordPress/wp-content/uploads/2009/07/Seagate-Diagnos6c-Command.pdf• hDp://openocd.org/

AlvaroAlexanderSoto-LabDirector/[email protected]

Page 25: Beyond eXtreme Forensics Update 3Q / 2016 by Alvaro Soto

THANKS!!!

Q&A–Experiencesharings...