<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebCase WebLog</title>
	<atom:link href="http://veresoftware.com/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://veresoftware.com/blog</link>
	<description>Online Investigation Tools, Techniques, &#38; Issues</description>
	<lastBuildDate>Mon, 25 Jul 2011 12:48:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>So you thought Tor was bad enough. Check out Tor&#8217;s Hidden Web Services.</title>
		<link>http://veresoftware.com/blog/?p=430</link>
		<comments>http://veresoftware.com/blog/?p=430#comments</comments>
		<pubDate>Mon, 25 Jul 2011 12:48:43 +0000</pubDate>
		<dc:creator>tshipley</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Hidden Services]]></category>
		<category><![CDATA[Internet Crimes Against Children]]></category>
		<category><![CDATA[Internet evidence]]></category>
		<category><![CDATA[Internet investigations]]></category>
		<category><![CDATA[IP tracing]]></category>
		<category><![CDATA[online evidence]]></category>
		<category><![CDATA[Online investigation]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Tor]]></category>
		<category><![CDATA[tracing IP addresses]]></category>
		<category><![CDATA[Usenet]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=430</guid>
		<description><![CDATA[Recently and article appeared at NPR titled “Senators Target Internet Narcotics Trafficking Website Silk Road”. I only bothered to hit the link because I saw it mentioned on the website Anit-forensics.com. The short article complained of drugs blatantly sold on the Internet and something needed to be done about it and Congress is going to [...]]]></description>
			<content:encoded><![CDATA[<p>Recently and article appeared at NPR titled <a href="http://www.npr.org/2011/06/05/136971766/senators-target-website-that-sells-narcotics">“Senators Target Internet Narcotics Trafficking Website Silk Road”</a>. I only bothered to hit the link because I saw it mentioned on the website <a href="http://www.anti-forensics.com/us-senators-target-the-silk-road">Anit-forensics.com</a>. The short article complained of drugs blatantly sold on the Internet and something needed to be done about it and Congress is going to solve that one for us. Although selling drugs on the Internet is nothing new, the place on the Internet “openly” selling drugs was on the Tor network through the use of Tor’s “Hidden Services” function.  The “Silk Road” is an online market open for the sale of goods and named after the ancient road used to bring goods from the orient to the west.</p>
<p>For the power user of the Tor network Hidden Services is probably nothing new. For the average online investigator though you may have heard of Tor and may have even tried to use it (especially of you read my last article on using Tor in your investigations). But were you aware that webpages can be hidden within the Tor network? Have you ever seen a .onion domain name? if you haven’t then read on.</p>
<p>Hidden services were introduced to the Tor network in 2004. Tor’s Hidden Services are run on a Tor client using special server software. This “Hidden Service” uses a <a href="http://en.wikipedia.org/wiki/Pseudo_top-level_domain">pseudo top-level-domain</a> of “.onion”. Using this domain, the Tor network routes traffic through its network without the use of IP addresses.</p>
<p>To get to these hidden services you must be using the Tor Network and have your browser enable to use Tor.  How do you find sites using the hidden services? Start at the core…</p>
<p><a href="http://eqt5g4fuenphqinx.onion/">http://eqt5g4fuenphqinx.onion/</a> </p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_432" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 1 - Welcome to .onion" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-1-Welcome-to-.onion1-300x214.jpg" alt="Welcome to .onion" width="300" height="214" /> Welcome to .onion</dl>
</div>
<p>Core.onion according to its hidden services site has been in the network since 2007.</p>
<p>Once in the Core.onion you find a simple directory to start exploring Hidden Services on the Tor network.</p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_434" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 2 -TorDir" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-2-TorDir-300x158.jpg" alt="TorDir" width="300" height="158" /> TorDir</dl>
</div>
<p>TorDir is a directory of Hidden Services. It gives you access to a variety of sites that offer instant messaging services, email, items for sale, social media type sites and marketplaces.</p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_435" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 3 - Black Market" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-3-Black-Market-300x168.jpg" alt="Black Market" width="300" height="168" /> Black Market</dl>
</div>
<p align="center"> </p>
<p>In the markets a variety of things are for sale, most look to be illegal though. File sharing also looks to be popular and can be found in several .onion sites.</p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_436" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 4- File Sharing" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-4-File-Sharing-300x168.jpg" alt="File Sharing" width="300" height="168" /> File Sharing</dl>
</div>
<p align="center"> </p>
<p>To make purchases bitcoin seems to be the most popular virtual currency and is regularly mentioned throughout the .onion sites.</p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_437" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 5 -Bitcoin" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-5-Bitcoin-300x168.jpg" alt="Bitcoin" width="300" height="168" /> Bitcoin</dl>
</div>
<p align="center"> </p>
<p>Another good location to start finding out about what Tor’s Hidden Services have to offer is a wiki located at:</p>
<p><a href="http://xqz3u5drneuzhaeo.onion/users/hackbloc/index.php/Mirror/kpvz7ki2v5agwt35.onion/Main_Page">http://xqz3u5drneuzhaeo.onion/users/hackbloc/index.php/Mirror/kpvz7ki2v5agwt35.onion/Main_Page</a></p>
<p> </p>
<p>Also, if you are an IRC fan Tor hidden services can be used there also. The <a href="http://freenode.net/irc_servers.shtml">Freenode website</a> gives the instructions on how to access Freenode IRC servers on Tor’s Hidden Services.</p>
<p>If you are interested in learning more about Tor’s Hidden Services here are a few sites that can get you on your way:</p>
<p><a href="http://www.onion-router.net/Publications/locating-hidden-servers.pdf">http://www.onion-router.net/Publications/locating-hidden-servers.pdf</a></p>
<p><a href="http://www.irongeek.com/i.php?page=videos/tor-hidden-services">http://www.irongeek.com/i.php?page=videos/tor-hidden-services</a></p>
<p><a href="http://www.torproject.org/docs/tor-hidden-service.html.en">http://www.torproject.org/docs/tor-hidden-service.html.en</a></p>
<p> </p>
<p>Not to make it any worse but if you have not heard Ip2 (another anonymizing network that is becoming increasingly popular) also has its own “eeepsites” similar to the Hidden Services offered in Tor that a user can post content to like a website.</p>
<p>Hidden Services are going to increasingly become a location that will be misused by many. It will also become a place on the Internet that investigators will need to become increasingly familiar with if they are to further their online investigations.</p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=430</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tor and its use during online investigations</title>
		<link>http://veresoftware.com/blog/?p=395</link>
		<comments>http://veresoftware.com/blog/?p=395#comments</comments>
		<pubDate>Mon, 18 Jul 2011 12:10:37 +0000</pubDate>
		<dc:creator>tshipley</dc:creator>
				<category><![CDATA[Investigative Tools]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[internet anonymizers]]></category>
		<category><![CDATA[Internet evidence]]></category>
		<category><![CDATA[Internet investigations]]></category>
		<category><![CDATA[Online investigation]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Tor]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=395</guid>
		<description><![CDATA[When investigating crimes on the Internet the investigator needs to consider how much information that he presents to servers and webpages that he may be investigating.  Hiding oneself on the Internet used to be the purview of hackers. However, technology changes and so has the ability to easily implement the same techniques hackers use to [...]]]></description>
			<content:encoded><![CDATA[<p>When investigating crimes on the Internet the investigator needs to consider how much information that he presents to servers and webpages that he may be investigating.  Hiding oneself on the Internet used to be the purview of hackers. However, technology changes and so has the ability to easily implement the same techniques hackers use to hide themselves during your investigations. There are many techniques for eluding identification on the Internet. Proxies have been used for years for this purpose. Proxies act as just that a &#8220;Proxy&#8221; or a go between. It’s a computer that acts on your behalf and forwards to the server you are looking at any requests you make. The server you are investigating only sees the &#8220;Proxy&#8221;.</p>
<p>Another significant tool in the &#8220;I need to hide on the Internet&#8221; world is the venerable tool &#8220;Tor&#8221;. Tor (The Onion Router) was developed from a concept originally written about by the U.S. Navy. According to the <a href="http://www.torproject.org/">Tor website</a>,  &#8220;Tor protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody watching your Internet connection from learning what sites you visit, and it prevents the sites you visit from learning your physical location.&#8221;</p>
<p>Using Tor during online investigations is much easier now that it has been in the past. This is due to the increase in most users Internet bandwidth, the constant upgrading and improving of the Tor software and it easy integration into the popular browsers. So how does the investigator implement Tor during his investigations? Well the simplest method is to use the Tor network to hide browsing activity. If you are investigating a webpage or website we know that there is certain information that our browser tells that server or website about who we are and potentially where we are. Our browsers can reveal our IP addresses what kind of browser we are using and its version. We can use Tor to prevent a suspect webpage from identifying us.</p>
<p>Let’s take a look at how to install and implement Tor so we can us it during our investigations. Installation for Tor is pretty starting forward now. Go to the <a href="https://www.torproject.org/">Tor project website</a> and download the current “<a href="https://www.torproject.org/download/download.html.en">Vidalia</a>” (like the onion) Windows installer. Click on the executable file and the project installs. The trick to using Tor is setting the proxy setting in your browser to use the Tor network. Your browser normally makes a call out through your Internet Service to servers on the Internet. These servers easily identify who you are by your Internet Protocol (IP) address so they can communicate back with you.  This exposure of your IP address is what can tell the bad guy who you are and possible who where you are in the world. The Tor network in its simplest description strips that information out and only provides the end user with an IP address belonging to the Tor network and not you. Thus you have effectively hidden from the end website you are visiting or target user that you may be communicating with through the Internet (Please note this is an over simplification of the process and exact details of how the Tor network works can be found on the project website).</p>
<p>So once Tor is installed your next actions are to set up your browser to use the Tor network as its proxy (proxy being a server acting as your entry point to the Internet and in this hiding your real IP address). Using Windows Internet Explorer version 8 go to Tools|Internet Options|</p>
<div class="wp-caption aligncenter" style="width: 310px"><img title="Image 1 - Tor" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-1-Tor1-300x260.jpg" alt="Changing Internet Explorer Settings" width="300" height="260" /><p class="wp-caption-text">Changing Settings in Internet Explorer</p></div>
<p> The select “Connections” and click on “LAN Settings”.</p>
<div class="wp-caption aligncenter" style="width: 226px"><img title="Image 2 -Tor IE LAN settings" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-2-Tor-IE-LAN-settings.jpg" alt="Image 2 -Tor IE LAN settings" width="216" height="275" /><p class="wp-caption-text">IE LAN Settings</p></div>
<p> </p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_405" class="wp-caption aligncenter" style="width: 264px;"><img src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-3-Tor-IE-LAN-settings-2.jpg" alt="IE LAN Settings Address and Port" width="254" height="220" /> IE LAN Settings Address and Port</dl>
</div>
<p>In the Local Area Network (LAN) Settings box you need to click on the box “Use a Proxy server for your LAN” in the address box add 127.0.0.1 and add in the Port box 8118. Click OK twice to exit and you are now able to use the Tor network.  You will continue to use the Tor network as your proxy until you uncheck the “Proxy server” box. This will then return you to your normal web access.</p>
<p>The Tor Project has a page you can go to that will verify that you are using the Tor Network or you can go to one of the websites on the Internet that grabs your IP address like <a href="http://whatismyipaddress.com/">http://whatismyipaddress.com/</a>. </p>
<p>In the Windows taskbar a little Onion symbol when opened will show you the “Vidalia” Control Panel. The control panel lets you know you are connected to the Tor network  and can change the IP address you are coming from by clicking on the “Use new identify” button.</p>
<div class="wp-caption aligncenter" style="width: 310px"><img title="Image 4 - Tor Control Panel" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-4-Tor-Control-Panel-300x226.jpg" alt="Tor Control Panel" width="300" height="226" /><p class="wp-caption-text">Control Panel</p></div>
<p>Once connected click on the setting button in the control panel. For our investigative purposes click on “Run as client only”.  This will ensure that other users of the network are not using your system as a relay server on the network (Tor data would actually be passing through your computer). </p>
<div class="mceTemp mceIEcenter">
<dl id="attachment_407" class="wp-caption aligncenter" style="width: 310px;"><img title="Image 5 - Tor Settings" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/Image-5-Tor-Settings-300x271.jpg" alt="Tor Settings" width="300" height="271" /> Tor Settings</dl>
</div>
<p>To see the other computers, and their description, on the Tor system click on the “View the Network” button.</p>
<p>We are no ready to go online and start our investigation without being identified.</p>
<p>Things to note here, the online application being used by the tor network in this configuration is Windows Internet Explorer. If you send an email to the target from your normal email client on your desktop, use another browser, instant messaging, or use P2P software you will potentially expose who you really are by your IP address. To use any other applications through the Tor network you need to set them up to use the Tor proxy settings.</p>
<p>Other things to consider in your Browser set up that need to be turned off.  Turn off running scripts, ActiveX and cookies. Also block pop-ups. But “I can’t access all the good content on the Internet”. Correct you can’t but then the end user can’t identify you either. Each of these features enhance our web surfing experience, but they also require code be downloaded through your browser and run on your machine. This can allow for the code to default to a port it use that is not being redirected to the Tor network, thereby exposing who you are. This may not be important in all the cases you work, but be aware of it. If you lock down your browser and don’t get the content you want you can always relax the controls and go back and look at the site, but at least you are aware then of the risks and make that decision based on the investigation.</p>
<p>Using WebCase with Tor requires just installing Tor as described above. WebCase collects web –based evidence through Internet Explorer even when piped through the Tor Proxy. The collection times will be extended because of the way Tor functions and has nothing to do with WebCase.</p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=395</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Cyber-Investigator’s Introduction to IPv6</title>
		<link>http://veresoftware.com/blog/?p=392</link>
		<comments>http://veresoftware.com/blog/?p=392#comments</comments>
		<pubDate>Wed, 13 Jul 2011 17:20:06 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Legal & Policy Issues]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[IPv4]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Jonathan Abolins]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[Online investigation]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=392</guid>
		<description><![CDATA[This article is a guest post from Jonathan Abolins, who will be leading the next webinar in our Online Investigations Series: &#8220;Internationalised Domain Names, Foreign Language Websites, &#38; Investigations.&#8221; While the two topics are unrelated, they do have one thing in common: both present previously uncharted challenges for online investigators.
There’s no place like home.
There’s no [...]]]></description>
			<content:encoded><![CDATA[<p><em>This article is a guest post from <a href="http://veresoftware.com/index.php?page=webinar-guest-instructors#jon" target="_blank">Jonathan Abolins</a>, who will be leading the next webinar in our Online Investigations Series: &#8220;<a href="https://www1.gotomeeting.com/register/165327312" target="_blank">Internationalised Domain Names, Foreign Language Websites, &amp; Investigations</a>.&#8221; While the two topics are unrelated, they do have one thing in common: both present previously uncharted challenges for online investigators.</em></p>
<p>There’s no place like home.<br />
There’s no place like 127.0.0.1. (IPv4 version)<br />
There’s no place like ::1. (IPv6 version)</p>
<h2>Introduction</h2>
<p>The widely used Internet Protocol (Version 4) – IPv4 – was created approximately 30 years ago and it has served us well. But it’s also showing its age. Back in the early 1980s, it was almost impossible to anticipate the growth in the demand for IP addresses. Now we are running out of IPv4 addresses (&#8221;IPv4 address exhaustion&#8221;). Also various people have been seeing the need for various improvements in the Internet Protocol.</p>
<p>To address these issues, Internet Protocol (Version 6) – IPv6 – was proposed in the mid-1990s. IPv6 is not yet in wide use but it would be a big mistake to assume that IPv6 cannot affect our networks.</p>
<p>Most operating systems and systems now include IPv6 support by default. There is also the ability to tunnel IPv6 via IPv4 with Teredo, 6to4, etc. For those whose ISPs don’t provide IPv6 connections, there are services, such as Hurricane Electric Free IPv6 <a href="http://tunnelbroker.net/" target="_blank">Tunnel Broker1</a>, which allow people to tunnel with IPv4 to get to the service that will give them IPv6 connections.</p>
<div id="attachment_393" class="wp-caption aligncenter" style="width: 387px"><img class="size-full wp-image-393" title="win7_net_ipv6" src="http://veresoftware.com/blog/wp-content/uploads/2011/07/win7_net_ipv6.jpg" alt="win7_net_ipv6" width="377" height="474" /><p class="wp-caption-text">Example of IPv6 Support in Windows 7</p></div>
<p style="text-align: left;">IPv6 is going to become a bigger part of our networking and investigations in the near future. Will our tools and methods be able to handle the changes?</p>
<h2>IPv6 vs IPv4: A Few Key Points</h2>
<p>Without going into much detail, here are some of the key differences between IPv6 and IPv4:</p>
<h3>Number of bits and address space.</h3>
<ul>
<li>IPv4 has 32 bits, allowing just over 4 billion addresses. Not even enough to give a unique address to each human being on Earth.</li>
<li>IPv6 has 128 bits, allowing 340,282,366,920,938,000,000,000,000,000,000,000,000 unique addresses. This is roughly like giving 252 addresses for every star in the known universe. Not likely to run out of of IPv6 addresses.</li>
</ul>
<h3>Address notation.</h3>
<ul>
<li>IPv4 usually uses dotted decimal notation. E.g., 192.168.2.12.</li>
<li>IPv6 uses groups of 16-bit hexadecimal numbers separated by colons (“:”). E.g., 2001:04c0:0000:0000:0000:c5ef:0000:0231.</li>
<li>The IPv6 addresses can be compacted. So the above example becomes 2001:4c0::c5ef:0:0231.</li>
<li>In a mixed IPv4/IPv6, the IPv6 32 bit address can be incorporated into an IPv4 address. E.g., 2001:04c0::192.168.1.1 or ::126.143.54.107 (Note the switch from colon separators to dotted format.)</li>
</ul>
<h3>IP security (IPsec) is built into IPv6, the ability to cryptographically sign the packets.</h3>
<p>There are various IPv6 tools for defense (if we know how to use them).</p>
<p>This is barely scratching the surface. The Resources section (below) has IPv6 specifications and other documents for more in-depth information.</p>
<h2>Security, Forensics &amp; Investigations Issues for IPv6</h2>
<p>As mentioned above, IPv6 has some security features. Also, some IPv6 feature might be helpful in investigations. For example, IPv6 may give the source’s MAC address in some cases. But there are security problems raised by IPv6 and the current networking environments.</p>
<p><strong>The gigantic IPv6 address space means that scanning IPv6 networks with IPv4 methods where we can try each possible IP address is not going to work.</strong> It’s possible to scan the entire IPv4 address space this way in several days. Scanning the entire  IPv6 address space the same way would take billions of centuries. Even an IPv6 subnet could take over 145,000 years. So we need IPv6 methods, such as neighbour discovery, of finding systems at IPv6 addresses.</p>
<p><strong>Tools designed for IPv4 environments might not properly process IPv6 information.</strong> Some log processing applications truncate IPv6 addresses and many may not properly interpret IPv6 traits. Black listing tools may miss problem addresses because they cannot associate IPv6 with IPv4 or IPv4 within IPv6 notation. It is likely that some of the analysis tools for linking data such as IP address associated with crimes might have problems once IPv6 addresses come into play. What else might trip up with IPv6?</p>
<p>Keep in mind too that there are many tools available that can be used for attacking IPv6 systems or for using IPv6 to bypass security. Firewalls set up for IPv4 may ignore IPv6 connections and, thus, fail to protect the internal networks. Detection software may ignore the IPv6 or tunnelling.</p>
<p>Even many commonly used network tools can fail unless we have the right versions of the tools and suitable network connections. For example, here’s a part of a sample SMTP e-mail header with a reference to the IPv6 address of 2001:470:0:64::2:</p>
<p>From ipv6@he.net  Tue Nov 23 09:51:00 2010<br />
Return-Path:<br />
Received: from ipv6.he.net (ipv6.he.net [IPv6:2001:470:0:64::2])<br />
by Duncan-Server.duncan (8.14.3/8.14.3/Debian-9ubuntu1) with<br />
&lt;…&gt;</p>
<p>Try “ping 2001:470:0:64::2” and it will likely fail. If you have ping6, it might work but not if your network connection doesn’t support IPv6. Same for traceroute and various other tools. Nslookup, dig, and whois work better. (<a href="http://whois.arin.net/rest/net/NET6-2001-470-1/pft" target="_blank">Example of an IPv6 whois lookup via the ARIN Web site</a>) But they are not enough for our security &amp; forensics toolkit.</p>
<p><strong>The most critical security &amp; investigatory challenge is getting up to speed with IPv6.</strong></p>
<h2>Conclusion</h2>
<p>IPv6 has much to offer. It is also outpacing many of the tools and methods for securing IPv4 networks and investigating activities on the networks. Our tools, methods, and our understanding of IPv6 will need to adapt.</p>
<h2>Resources</h2>
<p>IETF,  RFC 2460 &#8211; <a href="http://tools.ietf.org/html/rfc2460" target="_blank">Internet Protocol, Version 6 (IPv6) Specifications.</a><br />
The Internet Society. <a href="http://www.isoc.org/internet/issues/ipv6.shtml" target="_blank">Internet Issue – Ipv6. </a><br />
Klein, Joe. <a href=" http://sites.google.com/site/ipv6security/" target="_blank">Collection of IPv6 Security presentations.</a> These presentations are an excellent resource for understanding the security issues with IPv6. Joe Klein is a great resource in this field.<br />
Leinwebe, James. <a href="https://mywebspace.wisc.edu/jeleinwe/web/ipv6/wacci/wacci_ipv6.pdf" target="_blank">IPv6 and the future of network forensics</a>. UW-Madison Information Security Team. June 6, 2011.<br />
Nikkel, Bruce J. <a href="http://www.digitalforensics.ch/nikkel07.pdf" target="_blank">An introduction to investigating IPv6 networks</a>. July 19, 2007 [Originally published by Elsevier in Digital Investigation: The International Journal of Digital Forensics and Incident Response,  Vol. 4, No. 2 (10.1016/j.diin.2007.06.001)]</p>
<p><strong> Wikipedia entries</strong><br />
<a href=" http://en.wikipedia.org/wiki/IPv6" target="_blank"> Ipv6</a><br />
<a href="http://en.wikipedia.org/wiki/IPv4_address_exhaustion" target="_blank"> IPv4 address exhaustion</a><br />
<a href="http://en.wikipedia.org/wiki/List_of_IPv6_tunnel_brokers" target="_blank"> List of IPv6 tunnel brokers</a></p>
<p>Wireshark Wiki. <a href="http://wiki.wireshark.org/SampleCaptures#IPv6_.28and_tunneling_mechanism.29" target="_blank">Sample PCAP Captures – Ipv6 and Tunneling</a>.</p>
<p><em>Acknowledgements: Many thanks to Joe Klein, Joshua Marpet, and Jeremy Duncan for their insights and help.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=392</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cell phones, the Internet and common evidence issues</title>
		<link>http://veresoftware.com/blog/?p=390</link>
		<comments>http://veresoftware.com/blog/?p=390#comments</comments>
		<pubDate>Wed, 06 Jul 2011 17:25:42 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Legal & Policy Issues]]></category>
		<category><![CDATA[cell phone forensics]]></category>
		<category><![CDATA[corroborating evidence]]></category>
		<category><![CDATA[Internet evidence]]></category>
		<category><![CDATA[mobile device forensics]]></category>
		<category><![CDATA[service providers]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[social networking sites]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=390</guid>
		<description><![CDATA[Our free webinar last week was on cell phones and the common apps used to connect them with the Internet.  Mike Harrington of Teel Technologies talked about some of the  items of evidence which those apps leave, both on the phones and on the Internet sites the apps lead to.
Todd has been talking [...]]]></description>
			<content:encoded><![CDATA[<p>Our free webinar last week was on cell phones and the common apps used to connect them with the Internet.  <a href="http://veresoftware.com/blog/?p=381" target="_blank">Mike Harrington of Teel Technologies talked</a> about some of the  items of evidence which those apps leave, both on the phones and on the Internet sites the apps lead to.</p>
<p>Todd has been talking for some time about how the normal crime scene has been changing over time and that investigators, both civil and criminal, need to be thinking of where there evidence is outside of the physical location they are at. The Internet, and the ability of most modern cell phones to connect to it, have greatly expanded our possible locations for evidence to be found – far beyond the physical crime scene. With this increase means of course more work. But with the additional locations for evidence, investigators can obtain a clearer picture of what occurred.</p>
<p>This means that evidence will be located at a minimum in the following places:</p>
<ol>
<li>The cell phone itself (forensic data extraction)</li>
<li>The social media site (accessed from the web and properly documented). Depending on the number of apps on the phone this could be numerous sites.</li>
</ol>
<p>Because we don’t generally let the cell phone access the web during data extraction (to prevent syncing and therefore data change), what is on the cell phone will undoubtedly be different then what is on the social media site.</p>
<p>This is particularly true if the user accesses the sites from places other than his cell phone, or his friends make posts to his wall (as themselves or even posing as him). So, to corroborate what they find on the phone, investigators should also plan to collect additional items through legal service (civil or criminal subpoena or search warrant):</p>
<ol>
<li>Cell phone/tower records from the provider</li>
<li>Social media site records from the social media site. Again, depending on the number of apps on the phone, this could be numerous sites.</li>
</ol>
<p>Each of these records contains a piece of the puzzle. Compiling all of them can give the investigator a more accurate picture of what occurred and when, but it all needs to be documented properly.</p>
<p>The investigator must also be prepared to investigate further when the two are inconsistent, and if necessary, explain the inconsistencies in court. For example, if phone artifacts have date/time stamps and content that are different from those found on social networking sites, investigators must question why. Likewise when a cell service provider&#8217;s records differ from phone or Internet evidence.</p>
<p>In short: none of this evidence – data on the cell phone, the social networking site, or in the cell or Internet service provider&#8217;s records – should be considered “nice to have.” With courts paying more attention to the authenticity and verifiability of digital evidence, gathering as much information as possible from as many sources as possible is a requirement to ensuring that victims and suspects alike get the due process they deserve.</p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=390</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Authenticating the inauthentic</title>
		<link>http://veresoftware.com/blog/?p=386</link>
		<comments>http://veresoftware.com/blog/?p=386#comments</comments>
		<pubDate>Tue, 28 Jun 2011 18:32:23 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Legal & Policy Issues]]></category>
		<category><![CDATA[Online Investigations in the News]]></category>
		<category><![CDATA[actionable intelligence]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[civil litigation]]></category>
		<category><![CDATA[cyberbullying]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Globe and Mail]]></category>
		<category><![CDATA[image forensics]]></category>
		<category><![CDATA[image metadata]]></category>
		<category><![CDATA[Law enforcement]]></category>
		<category><![CDATA[online evidence]]></category>
		<category><![CDATA[Photoshop]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[USAToday.com]]></category>
		<category><![CDATA[Vancouver riots]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=386</guid>
		<description><![CDATA[Last week, USAToday.com ran a story about the use of social media to investigate the Vancouver riots:
Vancouver police say they cannot keep up with the unprecedented number of tips and photos of people who torched cars, looted businesses and pounded on officers in a riot following the Canucks loss to Boston in the Stanley Cup [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_387" class="wp-caption alignright" style="width: 280px"><img class="size-medium wp-image-387 " title="photoshopping" src="http://veresoftware.com/blog/wp-content/uploads/2011/06/photoshopping-300x225.jpg" alt="How easy is it to tell if an image was manipulated?" width="270" height="203" /><p class="wp-caption-text">How easy is it to tell if an image was manipulated?</p></div>
<p>Last week, <a href="http://www.usatoday.com/tech/news/2011-06-22-facebook-vancouver-riots_n.htm" target="_blank">USAToday.com ran a story</a> about the use of social media to investigate the Vancouver riots:</p>
<blockquote><p>Vancouver police say they cannot keep up with the unprecedented number of tips and photos of people who torched cars, looted businesses and pounded on officers in a riot following the Canucks loss to Boston in the Stanley Cup finals&#8230;.</p>
<p>Police use of social media is exploding, and the Vancouver riot illustrates both unique opportunities and challenges for investigators.</p></blockquote>
<p><a href="http://veresoftware.com/index.php?page=executive-bios" target="_blank">Todd</a> was quoted as saying, “Law enforcement has to go where the people are, and the fact is, the people are online. The crime scene has expanded. It&#8217;s no longer just the physical world, but it&#8217;s that Internet cloud. There&#8217;s actionable information out there.&#8221;</p>
<h2>What if the information is inauthentic?</h2>
<p><a href="https://www.theglobeandmail.com/news/national/british-columbia/fake-vancouver-riot-photos-might-snarl-investigation/article2072026/?from=sec431" target="_blank">Another article posted</a> the previous day, however, notes:</p>
<blockquote><p>Social media have, in some ways, been a blessing for riot investigators, providing evidence that otherwise might never have seen the light of day. But it could also prove to be a curse, with police confirming they’re aware that images could be digitally altered, and social-media experts predicting the “That picture was photoshopped!” defence will be popular.</p></blockquote>
<p>The article goes on to note that some of the “photoshopping” is obvious; other instances, less so. The onus is on police to sift through the images to determine what is real, and what isn&#8217;t:</p>
<blockquote><p>Constable Jana McGuinness, a Vancouver police spokeswoman, wouldn’t confirm how many doctored images police have received, but said investigators are aware of the possibility of fraud.</p>
<p>“We have experts assisting the investigation that will validate the authenticity of all photographs and images that will be entered as evidence in future court proceedings,” she wrote in a statement.</p></blockquote>
<p>Photoshopped images are nothing new. More recent cases have been tried in which <a href="http://pinoytutorial.com/techtorial/dean-boland-photoshop-expert-for-fake-child-porn-busted/" target="_blank">defendants had photoshopped the faces of children</a> to make them appear to be engaged in sex, or gone even further in <a href="http://news.bbc.co.uk/2/hi/uk_news/england/tees/5327826.stm" target="_blank">manipulating images of women</a> to make them look like young girls.</p>
<p>As the Globe and Mail article notes, image metadata can help investigators authenticate the image, including creation  and modification date/time stamps. However, sites like Facebook strip the metadata. Investigators should therefore take pains to document both images and metadata, including their own observations about images&#8217; appearance. As in Vancouver, they should also have access to digital video experts.</p>
<h2>What does this mean for actual investigations?</h2>
<p>The evidence may not fit the original crime, but in some cases, it can lead to new charges, or lead to civil litigation. Interfering with a police investigation may be one charge leveled against those who actually alter the images (assuming the photo can be traced back to a source). Consider cyber-bullying cases, in which <a href="http://knowledgebase.findlaw.com/kb/2011/Jun/345844.html" target="_blank">children have created false profiles, complete with fake pictures</a>, to get their peers in trouble.</p>
<p>On the civil side, defamation suits might result from individuals falsely represented as having been involved in a crime or other illicit activity. Corporate espionage, intellectual property violations or even extramarital affairs can be falsified.</p>
<p>The more people become accustomed to using the internet and all it has to offer, the easier it will be for those with the wrong intentions to exploit the various tools. This complicates online investigations, but not insurmountably so.</p>
<h3>What wrinkles have you encountered in your online investigations, and how have you dealt with them?</h3>
<p style="text-align: right;"><small><em>Image: <a href="http://www.flickr.com/photos/oskarssonfotos/2905756342/sizes/m/in/photostream/" target="_blank">oskarsson photography</a> via Flickr</em></small></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=386</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smartphones and the Internet: Finding evidence in 2 different places</title>
		<link>http://veresoftware.com/blog/?p=381</link>
		<comments>http://veresoftware.com/blog/?p=381#comments</comments>
		<pubDate>Wed, 22 Jun 2011 21:37:47 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Online Investigations in the News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[apps]]></category>
		<category><![CDATA[cloud services]]></category>
		<category><![CDATA[evidence collection]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Michael Harrington]]></category>
		<category><![CDATA[mobile browsers]]></category>
		<category><![CDATA[mobile devices]]></category>
		<category><![CDATA[mobile forensics]]></category>
		<category><![CDATA[Online investigation]]></category>
		<category><![CDATA[smartphones]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[Teel Technologies]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=381</guid>
		<description><![CDATA[On Thursday, June 30, we&#8217;ll be offering another webinar that is new to our series: Smartphones and the Internet, a discussion about how smart phones are changing the world of online investigations. Instructor Michael Harrington, Director of Training at Teel Technologies and a longtime expert in mobile device forensics, will cover the various apps and [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_382" class="wp-caption alignright" style="width: 310px"><img class="size-medium wp-image-382" title="facebook-phone" src="http://veresoftware.com/blog/wp-content/uploads/2011/06/facebook-phone-300x200.jpg" alt="How do Internet and mobile phone evidence support each other?" width="300" height="200" /><p class="wp-caption-text">How do Internet and mobile phone evidence support each other?</p></div>
<p>On Thursday, June 30, we&#8217;ll be offering another webinar that is new to our series: <a href="https://www1.gotomeeting.com/register/182329145" target="_blank">Smartphones and the Internet</a>, a discussion about how smart phones are changing the world of online investigations. Instructor <a href="https://mobileforensics.wordpress.com/bio/" target="_blank">Michael Harrington</a>, Director of Training at <a href="http://www.teeltech.com/tt3/" target="_blank">Teel Technologies</a> and a longtime expert in mobile device forensics, will cover the various apps and tools that tie smart phones to the Internet and the potential for evidence collection on both the phone and the websites tied to the apps.</p>
<p>We asked Mike for some more detail on what he&#8217;ll be talking about:</p>
<h3>VS: What are the major apps and platforms you&#8217;ll be covering in your webinar, and why are they especially relevant?</h3>
<p>MH: I&#8217;ll mostly be concentrating on iOS and Android and focusing attention on GPS, browser, cloud and social networking applications such as Facebook and Twitter. iOS and especially Android account for the vast majority of the consumer market. Android growth is particularly strong in emerging markets, and has arguably the number one market position.</p>
<p>I&#8217;ll be concentrating on social networking applications because research has shown that the vast majority of access to services such as Facebook and Twitter are done on mobile. Facebook in particular is relevant because of the recent controversies of underage access and of course <a href="http://www.miller-mccune.com/politics/the-cascading-effects-of-the-arab-spring-28575/" target="_blank">its role in the Arab Spring</a>. Twitter has also made the news with Weinergate, and controversy over ill-thought tweets by such people as Roger Ebert.</p>
<p>The ability to access cloud based services from smart phones (<a href="https://www.evernote.com/" target="_blank">Evernote</a>, <a href="https://secure.logmein.com/" target="_blank">logmein</a> and the like) as well as the <a href="http://itsalltech.com/2011/04/22/google-captures-same-location-data-from-smartphones-as-apple-does/" target="_blank">smartphones capturing of location information not just overtly</a> through GPS applications makes discussion of the platforms relevant.</p>
<h3>VS: How do online evidence and mobile evidence work in conjunction? What if one doesn&#8217;t match the other?</h3>
<p>Online evidence and mobile evidence should be used to validate each other. They <em>should</em> match each other regarding similar data such as IP address. In some instances online evidence may contain more information and vice versa. If they don&#8217;t match further investigation and explanation is needed to account for differences.</p>
<h3>VS: How deep should investigators dive when collecting evidence from the Internet and from a mobile device? How can they make the decision about how far to go?</h3>
<p>I think these questions are tied together inextricably. The decision on how far to dive depends on the severity of the crime. In most instances a simple download of the logical data on the phone will be sufficient to corroborate online evidence or to gather additional evidence to support that gathered online. In some instances it may be necessary to try to recover deleted data off a mobile &#8212; this may require specialist equipment and certainly more time and training.</p>
<h3>VS: Not all mobile examiners will collect online evidence, and not all online investigators will collect mobile evidence. What&#8217;s the best way for them to come together to work out case building?</h3>
<p>Since most people on the planet carry mobile phones and the usage of smart phones to access more services is expected to rise by 55% in 2011 it is absolute folly not to look for evidence on mobile devices. I would recommend that a [standard operating procedure] be worked out that if mobile devices are seized, and the particular type of case being worked suggests that a device may be used to access online services where evidence could be collected &#8212; or the like is found on mobile devices &#8212; that [all] those leads are chased down.</p>
<p>Investigators have to aware of all ways in which criminals and victims access the online world. More and more it&#8217;s through their mobile devices.</p>
<h3>VS: Anything else webinar attendees should know in advance?</h3>
<p>Maybe some stats on the smartphone market. Here is an excerpt from the first chapter of the Android book (<a href="http://www.apress.com/" target="_blank">Apress</a>, expected pub date December 2011) I&#8217;m working on:</p>
<p>The growth of the global smart phone market has been nothing short of explosive. According to the International Data Corporation (IDC), a leader in market research,  <a href="http://news.yahoo.com/s/nm/20110609/tc_nm/us_smartphones_forecast" target="_blank">the world wide smartphone market is expected to grow 55% in 2011</a>, fueled by consumers eager to exchange their feature mobile phones for advanced devices with more features, and most importantly, apps.</p>
<p>The sheer number of devices being shipped is staggering. Again according to the IDC’s Worldwide Quarterly Mobile Phone Tracker there will be a total of 472 million smart phones shipped in 2011 up from 305 in 2010. Furthermore, this is expected to almost double to an unbelievable 982 million by the end of 2015.</p>
<p>The growth rate is over four times the rate of the overall mobile phone market due to the accessibility of devices to a wide range of users, and helped by falling prices, functionality and low cost data plans.</p>
<p>The growth is most pronounced in markets that are emerging and where the adoption of these devices is still in early days &#8211; the IDC predicts that the most stunning growth will be in the Asia/Pacific region and in Latin America.</p>
<p><strong><a href="https://www1.gotomeeting.com/register/182329145" target="_blank">Join us on Thursday, June 30 from 11am-12pm Pacific</a>, and bring any questions you have for Mike!</strong></p>
<p style="text-align: right;"><em><small>Image: <a href="http://www.flickr.com/photos/johanl/4859806074/sizes/z/in/photostream/" target="_blank">Johann Larsson</a> via Flickr</small></em></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=381</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Examining video file metadata</title>
		<link>http://veresoftware.com/blog/?p=364</link>
		<comments>http://veresoftware.com/blog/?p=364#comments</comments>
		<pubDate>Wed, 25 May 2011 15:30:31 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[Advanced Systems Format]]></category>
		<category><![CDATA[ASF]]></category>
		<category><![CDATA[Dublin Core Metadata Element Set]]></category>
		<category><![CDATA[EXIF data]]></category>
		<category><![CDATA[Gspot]]></category>
		<category><![CDATA[Internet investigations]]></category>
		<category><![CDATA[MediaInfo]]></category>
		<category><![CDATA[Resource Interchange File Format]]></category>
		<category><![CDATA[RIFF]]></category>
		<category><![CDATA[search engines]]></category>
		<category><![CDATA[video file metadata]]></category>
		<category><![CDATA[Video Inspector]]></category>
		<category><![CDATA[Wikicafe]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=364</guid>
		<description><![CDATA[Digital forensics examiners are very aware of the benefits of identifying metadata in files from word processing documents to image files. The metadata in image files, referred to as Exif  (Exchangeable image file format), has been a source of information in forensic examinations for some time.  Many files, including video files, have metadata.
If [...]]]></description>
			<content:encoded><![CDATA[<p>Digital forensics examiners are very aware of the benefits of identifying metadata in files from word processing documents to image files. The metadata in image files, referred to as Exif  (Exchangeable image file format), has been a source of information in forensic examinations for some time.  Many files, including video files, have metadata.</p>
<p>If metadata is important in other investigations, can video metadata be a similar potential treasure trove?  In <a href="http://veresoftware.com/index.php?page=cybercrime-survival-basic" target="_blank">our basic course</a> I have extolled the examination of metadata during internet investigations, because in online documents or images, metadata can be incredibly damaging evidence.</p>
<p>For example, recently I was asked to examine a website set up on a &#8220;free&#8221; domain to find out who the the owner might be. Examination of the website failed to ascertain anything until I downloaded the files embedded in the site. A quick look at the files&#8217; metadata ascertained their author – who was well known to the plaintiff.</p>
<h2>Two types of video metadata</h2>
<p>So video metadata does exist, and it is important. To deal with video metadata, we have to understand where it comes from.  There are  two sources, which <a href="http://www.masternewmedia.org/video-metadata-key-strategic-importance-for-online-video-publishers-part-1/" target="_blank">one article describes</a> as:</p>
<blockquote><p>a) Operational, automatically gathered video metadata, which is typically a set of information about the content you produce, such as the equipment you used, the software you employed, the date you created your video, GPS coordinates of shooting location, and more.</p>
<p>b) Human-authored video metadata, which can be created to provide more search engine visibility, audience engagement, and better advertising opportunities for online video publishers.</p></blockquote>
<p>Most of what we are currently dealing with in metadata examination is the &#8220;operational&#8221; metadata. However, human-authored metadata may become more important.</p>
<p>Interestingly enough, video metadata is getting some heavy discussion from a marketing point of view. Online video providers are looking at the use of video metadata to describe the video better for two reasons: first, better coverage in the search engines, and second, so end users have more descriptive information about the video.</p>
<p>Additionally, video-sharing sites seek to make videos more “social” by enabling users to add metadata to the videos they host. For instance, Metacafe&#8217;s <a href="http://www.metacafe.com/wikicafe/" target="_blank">Wikicafe</a> section allows all its users to add &#8220;human authored&#8221; comments to video metadata.</p>
<p>Although few standards currently exist for video metadata, this is changing as video delivery becomes more important. Acceptance of standards such as the <a href="http://dublincore.org/documents/dces/" target="_blank">Dublin Core Metadata Element Set</a> are becoming common. With standards in the metadata, investigators will have an ability to look for common items of information in the file.</p>
<p>Standard metadata also makes it easier to build tools to extract this data. The continuing conversation, and the acceptance of <a href="http://www.telestream.net/pdfs/whitepapers/wp-preparing-video-metadata.pdf" target="_blank">&#8220;human authored&#8221;</a> metadata, will undoubtedly provide investigators with additional information regarding videos they find on the internet during investigations.</p>
<h2>File formats and what they contain</h2>
<p>Search Google for &#8220;video metadata forensics&#8221;, and you won&#8217;t find much of anything useful. It is mentioned in some places that video has metadata, but little describes the metadata in depth. However, search for RIFF (Resource Interchange File Format) and you will find a lot more. Riff, the term similar in usage to Exif data,  is the format that describes the usage of metadata in many video and audio files.</p>
<p>Riff data can include:</p>
<p><img class="alignnone size-full wp-image-365" title="riff-data" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/riff-data.png" alt="riff-data" width="362" height="248" /></p>
<p>The amount of Riff data  available depends on the file format. Riff data is a proprietary format originally developed by Microsoft and IBM for Windows 3.1.  The format was released in the 1991 in the Windows Multimedia Programmer&#8217;s Reference. Riff was never adopted as a standard and few new video formats have adopted the file format since the 1990&#8217;s. Common files formats still in use that use Riff include .wav and .avi. Microsoft has since 2004 been using the ASF format (Advanced Systems Format) since 2004 in its .wma files.</p>
<p>From the Microsoft Advanced Systems Format specifications, we can find that the ASF file can contain potentially valuable information.</p>
<p><img class="alignnone size-full wp-image-366" title="asf-file" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/asf-file.png" alt="asf-file" width="565" height="380" /></p>
<p>And,</p>
<p><img class="alignnone size-full wp-image-367" title="asf-file-2" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/asf-file-2.png" alt="asf-file-2" width="556" height="297" /></p>
<p>Okay….so we have looked at the underlying  structure for the metadata present in video. The question now becomes, how do we look at that data?  There are a few free tools out there to assist you. Let&#8217;s talk about three:</p>
<h2>Gspot</h2>
<p><a href="http://gspot.headbands.com/" target="_blank">Gspot</a> has been the heavy lifter for most investigators looking at metadata in video files. It provides a single screen view of the available data in a video file (of the files it can translate). Most of the data is &#8220;operational&#8221; data found in the file, but it does provide you with the &#8220;human authored&#8221; data if it is present. Gspot has an export function to allow the user to save the metadata information for inclusion in a report or to add to WebCase. Gspot&#8217;s failing is that it has had no recent updates since 2007.</p>
<p><img class="alignnone size-full wp-image-368" title="gspot-interface" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/gspot-interface.png" alt="gspot-interface" width="560" height="560" /></p>
<p><strong>The Gspot report looks like this:</strong></p>
<p><img class="alignnone size-full wp-image-369" title="gspot-report" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/gspot-report.png" alt="gspot-report" width="1316" height="1170" /></p>
<h2>MediaInfo</h2>
<p>To me, <a href="http://mediainfo.sourceforge.net/en" target="_blank">MediaInfo</a> is a newer tool. Its basic view is much simpler than Gspot&#8217;s, but it offers several different views of the data that allow you to determine what metadata is present.  I personally like the &#8220;tree&#8221; view as it lays out all of the metadata present in an easy to view screen. The export options for reporting also allow the user to quickly make reports in a text or html format for inclusion in their reports or to add to WebCase.  MediaInfo also adds during installation a right click function to Windows Explorer to easily access the tool.</p>
<p><img class="alignnone size-full wp-image-370" title="mediainfo-interface" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/mediainfo-interface.png" alt="mediainfo-interface" width="700" height="392" /></p>
<p><strong>Media Info report (txt, html, or CSV) looks like:</strong></p>
<p><img class="alignnone size-full wp-image-371" title="mediainfo-report" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/mediainfo-report.png" alt="mediainfo-report" width="1316" height="914" /></p>
<h2>Video Inspector</h2>
<p>A very basic tool, <a href="http://www.kcsoftwares.com/?vtb#help" target="_blank">Video Inspector</a> provides the user with the essential metadata present in the video file.  The export function allows for exporting a text document with the metadata it finds, but it is limited. The tool was designed to assist the user in identifying missing codecs required to play the video, so reading all the available metadata is not its main function.</p>
<p><img class="alignnone size-full wp-image-372" title="videoinspector" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/videoinspector.png" alt="videoinspector" width="505" height="483" /></p>
<p><strong>Video Inspector Report looks like:</strong></p>
<p><img class="alignnone size-full wp-image-373" title="videoinspector-report" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/videoinspector-report.png" alt="videoinspector-report" width="1316" height="530" /></p>
<p>In comparing the tools I used a video that I know had &#8220;operational&#8221; metadata in it to determine whether each program reported the data. Gspot and MediaInfo both located and reported the data. MediaInfo included the &#8220;Master date&#8221; which could either be the date the video was &#8220;mastered&#8221; or possibly the date it was uploaded to the site (I have to do some more research on that date and time stamp).</p>
<p><img class="alignnone size-full wp-image-375" title="gspot-metadata" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/gspot-metadata.png" alt="gspot-metadata" width="560" height="560" /></p>
<p><img class="alignnone size-full wp-image-376" title="mediainfo-metadata" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/mediainfo-metadata.png" alt="mediainfo-metadata" width="700" height="392" /></p>
<p><img class="alignnone size-full wp-image-377" title="vi-metadata" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/vi-metadata.png" alt="vi-metadata" width="505" height="483" /></p>
<p>So there is some usefulness in reviewing video files for metadata. Something to remember is that some sites may strip the metadata when posted on line. Also, other tools used to download videos from the Internet, like <a href="http://savevid.com" target="_blank">savevid.com</a>, save the video in flash and not the original file format containing the original metadata . Investigators need to find the original video uploaded to get to the metadata.</p>
<p>Additionally, as previously discussed, investigators may encounter challenges in the form of social media. For example: Metacafe&#8217;s attempt to add metadata to videos it hosts. Its <a href="http://www.metacafe.com/wikicafe/" target="_blank">Wikicafe section</a> allows all its users to add &#8220;human authored&#8221; comments to video metadata.</p>
<p>If you are more interested in reading about metadata in video files here are some resources:</p>
<p><strong>Riff Info</strong></p>
<p><strong></strong><a href="http://www.digitalpreservation.gov/formats/fdd/fdd000025.shtml" target="_blank">http://www.digitalpreservation.gov/formats/fdd/fdd000025.shtml</a></p>
<p><a href="http://en.wikipedia.org/wiki/Resource_Interchange_File_Format" target="_blank">http://en.wikipedia.org/wiki/Resource_Interchange_File_Format</a></p>
<p><a href="http://www.blitzbasic.com/codearcs/codearcs.php?code=2582" target="_blank">http://www.blitzbasic.com/codearcs/codearcs.php?code=2582</a></p>
<p><a href="http://code.google.com/speed/webp/docs/riff_container.html" target="_blank">http://code.google.com/speed/webp/docs/riff_container.html</a></p>
<p><strong>ASF File Format</strong></p>
<p><a href="http://www.digitalpreservation.gov/formats/fdd/fdd000067.shtml" target="_blank">http://www.digitalpreservation.gov/formats/fdd/fdd000067.shtml</a></p>
<p><strong>What experiences have you had collecting video file metadata? Comment below!</strong></p>
<p><em><a style="color: #114477; text-decoration: underline;" href="http://veresoftware.com/index.php?page=executive-bios" target="_blank">Todd Shipley is Vere Software’s president and CEO</a></em><em>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=364</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Dissecting a MySpace cookie</title>
		<link>http://veresoftware.com/blog/?p=354</link>
		<comments>http://veresoftware.com/blog/?p=354#comments</comments>
		<pubDate>Wed, 18 May 2011 17:00:48 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[Google Analytics]]></category>
		<category><![CDATA[MySpace cookies]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=354</guid>
		<description><![CDATA[I previously looked at the MySpace source code and as an aside, I decided to look at the MySpace cookie placed on my computer through Internet Explorer. I need to spend some more time with it, but I found one tidbit of interest. Here are the contents of that cookie:
MSCulture
IP=76.232.69.187&#38;IPCulture=en-US&#38;PreferredCulture=en-US&#38;Country=VVM%3D&#38;ForcedExpiration=0&#38;timeZone=-7&#38;USRLOC=QXJlYUNvZGU9Nzc1JkNpdHk9UmVubyZDb3VudHJ5Q29kZT1VUyZDb3
VudHJ5TmFtZT1Vbml0ZWQgU3RhdGVzJkRtYUNvZGU9ODExJkxhdGl0dWRlPTM
5LjU1NDUmTG9uZ2l0dWRlPS0xMTkuODA2MiZQb3N0YWxDb2RlPSZSZWdpb25
OYW1lPU5WJkxvY2F0aW9uSWQ9MA
myspace.com/
1600
1450779520
30110255
767532288
30108847*
SessionDDF2
WecgMpqrHOI4tePW304hLLYkIoD8e+hqZQakpBfhu0bf+3YNd9a3gLJAKgrhd57+klMP1U9u
DlEKYfXnDvXE8w==
myspace.com/
1536
2677308160
31578165
1536619600
30108650
*__utma
102911388.576917061.1287093264.1287098574.1287177795.3
myspace.com/
1600
522347392
30255698
765392288
30108847
*
__utmz
102911388.1287093264.1.1.utmcsr=(direct)&#124;utmccn=(direct)&#124;utmcmd=(none)
myspace.com/
1600
428951552
30145363
1564109600
30108650
*__utmb
102911388.0.10.1287177795
myspace.com/
1600
1584863104
30108851
765392288
30108847
*
__unam
7639673-12bb1c67c3e-6a4aaea5-1
myspace.com/
1600
3491813376
30163644
781442288
30108847
*
Here is an interesting part in [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-358" title="myspace_logo" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/myspace_logo-273x300.png" alt="myspace_logo" width="218" height="240" />I <a href="http://veresoftware.com/blog/?p=335" target="blank">previously looked at the MySpace source code</a> and as an aside, I decided to look at the MySpace cookie placed on my computer through Internet Explorer. I need to spend some more time with it, but I found one tidbit of interest. Here are the contents of that cookie:</p>
<p>MSCulture<br />
IP=76.232.69.187&amp;IPCulture=en-US&amp;PreferredCulture=en-US&amp;Country=VVM%3D&amp;ForcedExpiration=0&amp;timeZone=-7&amp;USRLOC=<strong>QXJlYUNvZGU9Nzc1JkNpdHk9UmVubyZDb3VudHJ5Q29kZT1VUyZDb3<br />
VudHJ5TmFtZT1Vbml0ZWQgU3RhdGVzJkRtYUNvZGU9ODExJkxhdGl0dWRlPTM<br />
5LjU1NDUmTG9uZ2l0dWRlPS0xMTkuODA2MiZQb3N0YWxDb2RlPSZSZWdpb25<br />
OYW1lPU5WJkxvY2F0aW9uSWQ9MA</strong><br />
myspace.com/<br />
1600<br />
1450779520<br />
30110255<br />
767532288<br />
30108847*<br />
SessionDDF2<br />
WecgMpqrHOI4tePW304hLLYkIoD8e+hqZQakpBfhu0bf+3YNd9a3gLJAKgrhd57+klMP1U9u<br />
DlEKYfXnDvXE8w==<br />
myspace.com/<br />
1536<br />
2677308160<br />
31578165<br />
1536619600<br />
30108650<br />
*__utma<br />
102911388.576917061.1287093264.1287098574.1287177795.3<br />
myspace.com/<br />
1600<br />
522347392<br />
30255698<br />
765392288<br />
30108847<br />
*<br />
__utmz<br />
102911388.1287093264.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)<br />
myspace.com/<br />
1600<br />
428951552<br />
30145363<br />
1564109600<br />
30108650<br />
*__utmb<br />
102911388.0.10.1287177795<br />
myspace.com/<br />
1600<br />
1584863104<br />
30108851<br />
765392288<br />
30108847<br />
*<br />
__unam<br />
7639673-12bb1c67c3e-6a4aaea5-1<br />
myspace.com/<br />
1600<br />
3491813376<br />
30163644<br />
781442288<br />
30108847<br />
*</p>
<p>Here is an interesting part in Base64:</p>
<p><strong>QXJlYUNvZGU9Nzc1JkNpdHk9UmVubyZDb3VudHJ5Q29kZT1VUyZDb3VudHJ5<br />
TmFtZT1Vbml0ZWQgU3RhdGVzJkRtYUNvZGU9ODExJkxhdGl0dWRlPTM5LjU1NDUmT<br />
G9uZ2l0dWRlPS0xMTkuODA2MiZQb3N0YWxDb2RlPSZSZWdpb25OYW1lPU5W<br />
JkxvY2F0aW9uSWQ9MA</strong></p>
<p>Here is the Base 64 Translation:</p>
<p>USRLOC=AreaCode=775&amp;City=<strong>Reno</strong>&amp;CountryCode=US&amp;CountryName=<strong>United States</strong>&amp;DmaCode=811&amp;<strong>Latitude=39.5545</strong>&amp;<strong>Longitude=-119.8062</strong>&amp;PostalCode=&amp;RegionName=<strong>NV</strong>&amp;LocationId=0</p>
<p>The investigator should be aware that the latitude and longitude is generally based on the IP address geolocation. Again this is something you are revealing to the website when you visit it. The website automatically geolocates the IP address for general marketing purposes. As an investigator you need to be aware that you are exposing this information to the websites you surf. I’ll comment more on geolocation in another post.</p>
<p>Not that we all did not know that companies use tracking codes to identify us, but here is the type of information that might be on a suspect&#8217;s system if you go looking for it in his cookies. It also shows how much MySpace is tracking about you during an investigation and collecting about you when you go to a suspect&#8217;s MySpace page. I found a nice article at <a href="http://helpful.knobs-dials.com/index.php/Utma,_utmb,_utmz_cookies" target="_blank">http://helpful.knobs-dials.com/index.php/Utma,_utmb,_utmz_cookies</a> describing some of the cookie&#8217;s contents of the cookie.</p>
<p>The cookies named __utma through __utmz are part of Google Analytics, originally by the <a href="http://www.google-analytics.com/urchin.js" target="_blank">urchin</a> tracking module, also by the newer <a href="http://www.google-analytics.com/ga.js" target="_blank">ga.js</a>.  These cookies track usage on sites that use Google Analytics.”</p>
<p>The article goes on to describe the various pieces of the cookie.</p>
<p><strong>__utma</strong> tracks each user&#8217;s amount of visits, first, last visit.<br />
<strong>__utmz</strong> tracks where a visitor came from (search engine, search keyword, link)<br />
<strong>__utmb</strong> and <strong>__utmc</strong> are used to track when a visit starts and approximately ends (c 	expires quickly).<br />
<strong>__utmv</strong> is used for user-custom variables in Analytics<br />
<strong>__utmk</strong> &#8211; digest hashes of utm values<br />
<strong>__utmx</strong> is used by <a href="http://www.google.com/websiteoptimizer" target="blank">Website 	Optimizer</a>, when it is being used</p>
<p>Another good description of the Google Analytic cookies and their contents can be found at <a href="http://www.morevisibility.com/analyticsblog/from-__utma-to-__utmz-google-analytics-cookies.html" target="_blank">MoreVisibility</a> (A marketing website). There are many other sites that collect similar information such as <a href="http://news.netcraft.com/" target="_blank">Netcraft</a>, <a href="http://www.alexa.com/" target="_blank">Alexa</a>, and <a href="http://www.wmtips.com/tools/info/" target="_blank">WMtips</a> (each of these can be accessed from our free <a href="http://veresoftware.com/index.php?page=downloads#toolbar" target="_blank">Internet Investigators Toolbar</a>.</p>
<p>The __utma cookie appears to be a string with six fields, delimited by a &#8220;.&#8221;. The last field is a single integer which records the number of sessions during the cookie lifetime</p>
<p>Here are the various pieces of the cookie with the date and times translated:</p>
<table border="1" cellspacing="0" cellpadding="7" width="540" bordercolor="#000000">
<colgroup>
<col width="270"></col>
<col width="270"></col>
</colgroup>
<tbody>
<tr valign="TOP">
<td width="270" bgcolor="#d9d9d9"><strong>Cookie Code Section</strong></td>
<td width="270" bgcolor="#d9d9d9"><strong>Date and Time Translation*</strong></td>
</tr>
<tr valign="TOP">
<td width="270">myspace.com/<br />
1600<br />
1450779520<br />
30110255<br />
767532288<br />
30108847</td>
<td width="270">1450779520,30110255<br />
Fri, 22 October 2010 13:23:15 -0800<br />
767532288,30108847<br />
Fri, 15 October 2010 13:23:15 -0800</td>
</tr>
<tr valign="TOP">
<td width="270">SessionDDF2<br />
WecgMpqrHOI4tePW304hLLYkIo<br />
D8e+hqZQakpBfhu0bf+3YNd9a3g<br />
LJAKgrhd57+klMP1U9uDlEKYfXn<br />
DvXE8w==<br />
myspace.com/<br />
1536<br />
2677308160<br />
31578165<br />
1536619600<br />
30108650</td>
<td width="270">2677308160,31578165<br />
Mon, 14 October 2030 13:54:22 -0800<br />
153661960,30108650<br />
Thu, 14 October 2010 13:52:03 -0800</td>
</tr>
<tr valign="TOP">
<td width="270"><strong>__utma</strong><br />
102911388.576917061.1287093264.<br />
1287098574.1287177795.3<br />
myspace.com/<br />
1600<br />
522347392<br />
30255698<br />
765392288<br />
30108847</td>
<td width="270">522347392,30255698<br />
Sun, 14 October 2012 13:23:15 -0800<br />
765392288,30108847<br />
Fri, 15 October 2010 13:23:15 -0800</td>
</tr>
<tr valign="TOP">
<td width="270"><strong>__utmz</strong><br />
102911388.1287093264.1.1.utmcsr=<br />
(direct)|utmccn=(direct)|utmcmd=(none)<br />
myspace.com/<br />
1600<br />
428951552<br />
30145363<br />
1564109600<br />
30108650</td>
<td width="270">428951552,30145363<br />
Fri, 15 April 2011 01:54:24 -0800<br />
1564109600,30108650<br />
Thu, 14 October 2010 13:54:24 -0800</td>
</tr>
<tr valign="TOP">
<td width="270"><strong>__utmb</strong><br />
102911388.0.10.1287177795<br />
myspace.com/<br />
1600<br />
1584863104<br />
30108851<br />
765392288<br />
30108847</td>
<td width="270">1584863104,30108851<br />
Fri, 15 October 2010 13:53:15 -0800<br />
765392288,30108847<br />
Fri, 15 October 2010 13:23:15 -0800</td>
</tr>
<tr valign="TOP">
<td width="270"><strong>__unam</strong><br />
7639673-12bb1c67c3e-6a4aaea5-1<br />
myspace.com/<br />
1600<br />
3491813376<br />
30163644<br />
781442288<br />
30108847</td>
<td width="270">3491813376,30163644<br />
Thu, 14 July 2011 23:00:00 -0800<br />
781442288,30108847<br />
Fri, 15 October 2010 13:23:16 -0800</td>
</tr>
</tbody>
</table>
<p>*Decoding of the dates and times are thanks to the free “Dcode” tool by <a href="http://www.digital-detective.co.uk/" target="_blank">Digital Detective</a>.</p>
<p><em><a style="color: #0066cc; text-decoration: none;" href="http://veresoftware.com/index.php?page=executive-bios" target="_blank">Todd Shipley is Vere Software’s president and CEO</a></em><em>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=354</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dissecting a MySpace page</title>
		<link>http://veresoftware.com/blog/?p=335</link>
		<comments>http://veresoftware.com/blog/?p=335#comments</comments>
		<pubDate>Tue, 17 May 2011 20:27:15 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Investigative Techniques]]></category>
		<category><![CDATA[embedded images]]></category>
		<category><![CDATA[embedded videos]]></category>
		<category><![CDATA[MySpace FriendID]]></category>
		<category><![CDATA[MySpace pages]]></category>
		<category><![CDATA[MySpace source code]]></category>
		<category><![CDATA[MySpace.BeaconData]]></category>
		<category><![CDATA[tracking code]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=335</guid>
		<description><![CDATA[Having not seen this done anywhere else, I decided to look at some basic MySpace pages at random and determine if I could find anything in the source code that might be of any investigative interest.
In general, the source code of a MySpace page has lots of HTML code, but much of it is of [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-347" title="myspace-300x81" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/myspace-300x81.jpg" alt="myspace-300x81" width="300" height="81" />Having not seen this done anywhere else, I decided to look at some basic MySpace pages at random and determine if I could find anything in the source code that might be of any investigative interest.</p>
<p>In general, the source code of a MySpace page has lots of HTML code, but much of it is of no use to the investigator because it does not identify the user or provide investigative leads. There are, however, a couple of interesting things to be found if you look for them.</p>
<h2>The actual server location of an image file</h2>
<p>Images on a MySpace main page are not embedded in the page. They are linked to a separate web address at <a href="www.msplinks.com" target="_blank">www.msplinks.com</a>. Here is a real example randomly gathered from a MySpace page of an image that was on the page:</p>
<blockquote><p>href=&#8221;http://www.msplinks.com/MDFodHRwOi8vdmlld21vcmVwaWNzLm15c3BhY2<br />
UuY29tL2luZGV4LmNmbT9mdXNlYWN0aW9uPXZpZXdJbWFnZSZmcmllbmRJRD0y<br />
ODYzNDc4JmFsYnVtSUQ9MjExNDE2NSZpbWFnZUlEPTQ0OTU4MTY2&#8243;&gt;</p></blockquote>
<p>This highlighted portion of the code which is obfuscated and is actually encoded in Base64:</p>
<blockquote><p>MDFodHRwOi8vdmlld21vcmVwaWNzLm15c3BhY2UuY29tL2luZGV4LmNmbT9mdXNl<br />
YWN0aW9uPXZpZXdJbWFnZSZmcmllbmRJRD0yODYzNDc4JmFsYnVtSUQ9MjExNDE<br />
2NSZpbWFnZUlEPTQ0OTU4MTY2</p></blockquote>
<p>The Base64 translation of this portion of the code is:</p>
<blockquote><p>01http://viewmorepics.myspace.com/index.cfm?fuseaction=viewImage&amp;friendID=2863478&amp;albumID=2114165&amp;imageID=44958166</p></blockquote>
<p>The Base64 translated link contains the friendID of the page it is from and what appears to be a uniquely assigned imageID.</p>
<p>The www.msplinks.com address is just a white page when you go there. However, when you look at the source code for this page you see some &#8220;old school letters&#8221; spelling out myspace.com:</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-336" title="myspace" src="http://veresoftware.com/blog/wp-content/uploads/2011/05/myspace-300x115.jpg" alt="myspace" width="300" height="115" /></p>
<h2>Embedded video files and their original location</h2>
<p>If you right click on an embedded video and select &#8220;copy embedded HTML&#8221; and paste that into a separate document, you can review the code and find the video location.</p>
<p>Actual example of an embedded video from a random MySpace page:</p>
<blockquote><p>&lt;imgsrc=&#8221;&lt;object width=&#8221;640&#8243; height=&#8221;390&#8243;&gt;&lt;param name=&#8221;movie&#8221; value=&#8221;http://www.youtube.com/v/Xz2MWedTbP0&amp;hl=en_US&amp;feature=<br />
player_embedded&amp;version=3&#8243;&gt;&lt;/param&gt;&lt;param name=&#8221;allowFullScreen&#8221; value=&#8221;true&#8221;&gt;&lt;/param&gt;&lt;param name=&#8221;allowScriptAccess&#8221; value=&#8221;always&#8221;&gt;&lt;/param&gt;&lt;embed src=&#8221;http://www.youtube.com/v/Xz2MWedTbP0&amp;hl=en_US&amp;feature=<br />
player_embedded&amp;version=3&#8243; type=&#8221;application/x-shockwave-flash&#8221; allowfullscreen=&#8221;true&#8221; allowScriptAccess=&#8221;always&#8221; width=&#8221;640&#8243; height=&#8221;390&#8243;&gt;&lt;/embed&gt;&lt;/object&gt;</p></blockquote>
<p>The actual page location on YouTube of the embedded video from above example:</p>
<blockquote><p>http://www.youtube.com/v/Xz2MWedTbP0</p></blockquote>
<h2>Finding the FriendID</h2>
<p>I also found the MySpace FriendID in several different locations in the pages source code. A simple search for “FriendID” will find the numerical Friend ID used by MySpace.</p>
<p>Here is a random example of a FriendID found in MySpace source code:</p>
<blockquote><p>var MySpaceClientContext = {&#8221;UserId&#8221;:-1,&#8221;DisplayFriendId&#8221;:281346014,&#8221;IsLoggedIn&#8221;:false,&#8221;FunctionalContext&#8221;:<br />
&#8220;UserViewProfile&#8221;,&#8221;UserType&#8221;:1};</p></blockquote>
<p>This is the Myspace ID # that corresponds with the MySpace user name:</p>
<blockquote><p>DisplayFriendId&#8221;:281346014</p></blockquote>
<p>Add the Friend ID to the MySpace URL and it will take you to that friend&#8217;s page.</p>
<blockquote><p>http://www.myspace.com/281346014</p></blockquote>
<h2>Tracking Code</h2>
<p>I also found something of interest to the investigator and a good reason not to use your agency/company computer network to look at a MySpace page. Without much effort I found the code for MixMap. MixMap is tracking code that can be used to identify the IP addresses of anyone viewing a MySpace page.  You can register at <a href="www.mixmap.com" target="_blank">www.mixmap.com</a> for access to your account and to prepare unique code for insertion on your MySpace page.</p>
<p>In a real example I found the following tracking code located in the MySpace page&#8217;s source code:</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 1327px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">&lt;a href=&#8221;http://www.msplinks.com/MDFodHRwOi8vd3d3Lm1peG1hcC5jb20v&#8221;<br />
target=&#8221;_new&#8221; title=&#8221;MySpace Tracker&#8221;&gt;</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 1327px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">&lt;img src=&#8221;http://www.mixmap.com/661165/no_image_tracker_strict.jpg&#8221; border=&#8221;0&#8243; height=&#8221;1&#8243; width=&#8221;1&#8243; style=&#8221;visibility:hidden;&#8221; alt=&#8221;MySpace Tracker&#8221; /&gt;&lt;/a&gt;&lt;/style&gt;&lt;/span&gt;</div>
<blockquote><p>&lt;a href=&#8221;http://www.msplinks.com/<strong>MDFodHRwOi8vd3d3Lm1peG1hcC5jb20v</strong>&#8221; target=&#8221;_new&#8221; title=&#8221;MySpace Tracker&#8221;&gt;&lt;img src=&#8221;http://www.mixmap.com/661165/no_image_tracker_strict.jpg&#8221; border=&#8221;0&#8243; height=&#8221;1&#8243; width=&#8221;1&#8243; style=&#8221;visibility:hidden;&#8221; alt=&#8221;MySpace Tracker&#8221; /&gt;&lt;/a&gt;&lt;/style&gt;&lt;/span&gt;</p></blockquote>
<p>This portion of the code is actually encoded in Base64:</p>
<blockquote><p>MDFodHRwOi8vd3d3Lm1peG1hcC5jb20v</p></blockquote>
<p>The Base64 translation of this portion of the code is:</p>
<blockquote><p>01http://www.mixmap.com/</p></blockquote>
<h2>MySpace beacon data</h2>
<p>Another thing I found a little disturbing about MySpace was what it is collecting on its pages. I located the following code labeled MySpace.BeaconData, which indicates that MySpace appears to be tracking persons viewing MySpace pages.  Not that this is unusual from a marketing point of view. But the investigator should be aware that s/he is being tracked.</p>
<p>In the abbreviated random example below, you can see in the bolded portions the city, state and country I am coming from, as well as my computer&#8217;s operating system and the version of Internet Explorer I was using.</p>
<blockquote><p>MySpace.BeaconData={&#8221;dsid&#8221;:&#8221;2&#8243;,&#8221;dsv&#8221;:&#8221;1&#8243;,&#8221;rd&#8221;:&#8221;browseusers.myspace.com&#8221;,&#8221;rqs&#8221;:&#8221;",&#8221;refpg&#8221;:<br />
&#8220;/Browse/Browse.aspx&#8221;,&#8221;rpf&#8221;:&#8221;Browse&#8221;,&#8221;d&#8221;:&#8221;www.myspace.com&#8221;,&#8221;qs&#8221;:<br />
&#8220;friendID=2863478&#8243;,&#8221;pf&#8221;:&#8221;UserViewProfile&#8221;,&#8221;fa&#8221;:&#8221;",&#8221;pgnm&#8221;:<br />
&#8220;/Modules/Profiles/Pages/Display/Profile.aspx&#8221;,&#8221;cip&#8221;:&#8221;1290290619&#8243;,&#8221;pc&#8221;:&#8221;en-US&#8221;,&#8221;pid&#8221;:&#8221;405384887825081977&#8243;,&#8221;pidf&#8221;:&#8221;0&#8243;,&#8221;ABtd&#8221;:&#8221;0&#8243;,&#8221;t&#8221;:<br />
&#8220;1287086098069&#8243;,&#8221;ct&#8221;:&#8221;1287086098069&#8243;,&#8221;ci&#8221;:&#8221;<strong>Reno</strong>&#8220;,&#8221;st&#8221;:&#8221;<strong>NV</strong>&#8220;,&#8221;co&#8221;:&#8221;<strong>US</strong>&#8220;,<br />
&#8220;dmac&#8221;:&#8221;811&#8243;,&#8221;uff&#8221;:&#8221;0&#8243;,&#8221;uatv&#8221;:&#8221;br=<strong>MSIE 8.0</strong>&amp;os=<strong>Windows NT 6.1</strong>&#8220;,&#8221;sip&#8221;:&#8221;170659174&#8243;,&#8221;uid&#8221;:&#8221;-2&#8243;,&#8221;pggd&#8221;:<br />
&#8220;e327762c-2571-4e8f-b47f-d5fb46a670e5&#8243;,&#8221;prid&#8221;:&#8221;2863478&#8243;,&#8221;ili&#8221;:&#8221;0&#8243;,&#8221;at&#8221;:&#8221;1&#8243;,&#8221;cfv&#8221;:&#8221;0:0:0&#8243;,&#8221;cef&#8221;:<br />
&#8220;0&#8243;,&#8221;sliu&#8221;:&#8221;0&#8243;,&#8221;pref&#8221;:&#8221;0&#8243;,&#8221;kvp&#8221;:&#8221;bt=0</p></blockquote>
<p>In the following abbreviated random example I used the Tor network to hide myself, and you can still see (in the bolded portions) the city, state and country the Tor exit node was located:</p>
<blockquote><p>MySpace.BeaconData={&#8221;dsid&#8221;:&#8221;2&#8243;,&#8221;dsv&#8221;:&#8221;1&#8243;,&#8221;rd&#8221;:&#8221;",&#8221;rqs&#8221;:&#8221;",&#8221;refpg&#8221;:&#8221;",&#8221;rpf&#8221;:&#8221;",&#8221;d&#8221;:&#8221;www.myspace.com&#8221;,<br />
&#8220;qs&#8221;:&#8221;friendID=542455573&#8243;,&#8221;pf&#8221;:&#8221;UserViewProfile&#8221;,&#8221;fa&#8221;:&#8221;",&#8221;pgnm&#8221;:<br />
&#8220;/Modules/Profiles/Pages/Display/Profile.aspx&#8221;,&#8221;cip&#8221;:&#8221;3493170727&#8243;,&#8221;pc&#8221;:&#8221;en-US&#8221;,&#8221;pid&#8221;:&#8221;405384887825081977&#8243;,&#8221;pidf&#8221;:&#8221;0&#8243;,&#8221;ABtd&#8221;:&#8221;0&#8243;,&#8221;t&#8221;:&#8221;1287100961997&#8243;,&#8221;ct&#8221;:<br />
&#8220;1287100961997&#8243;,&#8221;ci&#8221;:&#8221;<strong>Woodstock</strong>&#8220;,&#8221;st&#8221;:&#8221;<strong>IL</strong>&#8220;,&#8221;co&#8221;:&#8221;<strong>US</strong>&#8220;,&#8221;dmac&#8221;:&#8221;602&#8243;,&#8221;uff&#8221;:<br />
&#8220;0&#8243;,&#8221;uatv&#8221;:&#8221;br=<strong>MSIE 8.0</strong>&amp;os=<strong>Windows NT<br />
6.1</strong>&#8220;,&#8221;sip&#8221;:&#8221;170663537&#8243;,&#8221;uid&#8221;:&#8221;281346014&#8243;,&#8221;pggd&#8221;:&#8221;c1834a83-d897-44a8-adfe-<br />
93e8f959c60e&#8221;,&#8221;prid&#8221;:<br />
&#8220;542455573&#8243;,&#8221;ili&#8221;:&#8221;0&#8243;,&#8221;at&#8221;:&#8221;2&#8243;,&#8221;cfv&#8221;:&#8221;0:0:0&#8243;,&#8221;cef&#8221;:&#8221;0&#8243;,&#8221;sliu&#8221;:&#8221;0&#8243;,&#8221;pref&#8221;:&#8221;0&#8243;,&#8221;</p></blockquote>
<p>In this example the Tor exit node just happened to be in Illinois. From an investigative standpoint, the investigator should know what s/he is exposing to the target website.</p>
<p>I’ll continue to review pages and comment as I find anything interesting.  If anyone else has any good tidbits about MySpace or any other social networking sites let me know in comments.</p>
<p><em><a href="http://veresoftware.com/index.php?page=executive-bios" target="_blank">Todd Shipley is Vere Software&#8217;s president and CEO</a></em><em>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=335</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where&#8217;s the WebCase 30-day demo?</title>
		<link>http://veresoftware.com/blog/?p=330</link>
		<comments>http://veresoftware.com/blog/?p=330#comments</comments>
		<pubDate>Thu, 21 Apr 2011 15:00:59 +0000</pubDate>
		<dc:creator>cmiller</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[WebCase]]></category>
		<category><![CDATA[WebCase 30-day demo]]></category>
		<category><![CDATA[WebCase webinars]]></category>

		<guid isPermaLink="false">http://veresoftware.com/blog/?p=330</guid>
		<description><![CDATA[In recent weeks, we&#8217;ve gotten a number of questions about why our 30-day demo is no longer available for download, and how investigators can get to know WebCase without it.
To answer the second part first: we found that our customers had a much better experience with WebCase when they used it after a walk-through. That&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-331" title="3" src="http://veresoftware.com/blog/wp-content/uploads/2011/04/dvdcase.jpg" alt="3" width="174" height="250" />In recent weeks, we&#8217;ve gotten a number of questions about why our 30-day demo is no longer available for download, and how investigators can get to know WebCase without it.</p>
<p>To answer the second part first: we found that our customers had a much better experience with WebCase when they used it after a walk-through. That&#8217;s why we take you through a <a href="http://veresoftware.com/index.php?page=webinars" target="_blank">one-hour webinar</a> &#8212; you can either register for one of our monthly demos, or contact us to set up a time that is convenient for you and your team.</p>
<p>As for the software demo itself, we&#8217;ve recently made changes to WebCase that necessitated our retooling the demo. We don&#8217;t have a firm launch date, but we&#8217;ll let you know when we do.</p>
<p>Meanwhile, please do <a href="http://veresoftware.com/index.php?page=webinars" target="_blank">register for a webinar demo</a> (be sure it&#8217;s a WebCase demo, though we&#8217;d love to see you for our Online Investigation Series too), and be sure to <a href="http://veresoftware.com/index.php?page=contact-us" target="_blank">ask us</a> if you have any further questions for us!</p>
]]></content:encoded>
			<wfw:commentRss>http://veresoftware.com/blog/?feed=rss2&amp;p=330</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

