<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>penoycentral.net &#187; Security</title>
	<atom:link href="http://www.penoycentral.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.penoycentral.net</link>
	<description>Misadventures of Penoy Internet tips tricks howtos reviews nonsense rants and fun</description>
	<lastBuildDate>Sat, 21 Aug 2010 10:54:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Phishing attack on bloggers</title>
		<link>http://www.penoycentral.net/security/phishing-attack-on-bloggers/</link>
		<comments>http://www.penoycentral.net/security/phishing-attack-on-bloggers/#comments</comments>
		<pubDate>Sun, 28 Feb 2010 10:33:14 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/uncategorized/phishing-attack-on-bloggers/</guid>
		<description><![CDATA[Last week i received an email asking if I&#8217;m in posting their ads. To check out their ADS Unit, i must click a Google Picasa Web album url. Curious, I clicked on the URL from the email and it forwarded me on a Google Account authentication page. Hmm smells fishy. Remember that my wife’s yahoo [...]]]></description>
			<content:encoded><![CDATA[<p>Last week i received an email asking if I&#8217;m in posting their ads. To check out their ADS Unit, i must click a Google Picasa Web album url. Curious, I clicked on the URL from the email and it forwarded me on a Google Account authentication page.</p>
<p><span id="more-418"></span></p>
<p>Hmm smells fishy. <a href="http://www.penoycentral.net/technology/yahoo-mail-account-hacked/">Remember that my wife’s yahoo account was hacked</a> after someone from her friend’s hacked YM asked her to check out the pictures on his flicker. In just a minute, her username and password was harvested by the hacker and we have to call Yahoo just to retrieve the credentials.</p>
<p>You wont notice that this is a bogus page.</p>
<p><a href="http://www.penoycentral.net/wp-content/uploads/2010/02/Capture2.jpg"><img style="display: inline; border-width: 0px;" title="Capture2" src="http://www.penoycentral.net/wp-content/uploads/2010/02/Capture2_thumb.jpg" border="0" alt="Capture2" width="493" height="246" /></a></p>
<p>http://picasaphotos21.t35.com/photoalbum.htm</p>
<p>hmmm, ok. Not your usual Google URL and looks like a subdomain of t35.com</p>
<p>Let’s check out www.t35.com</p>
<p><a href="http://www.penoycentral.net/wp-content/uploads/2010/02/Capture3.jpg"><img style="display: inline; border-width: 0px;" title="Capture3" src="http://www.penoycentral.net/wp-content/uploads/2010/02/Capture3_thumb.jpg" border="0" alt="Capture3" width="483" height="250" /></a></p>
<p>Boom!!! t35.com is a free website service. So the hacker uses a free web service to host his fake Google Picasa page. The minute you entered your Google Account username and password it will be harvested.</p>
<p>How will you identify if the page is bogus or not? Here are some of the basic steps that you can use:</p>
<p>1. Google always use webpage SSL certificates. You will notice that the URL starts with https://…. instead of http://… on its page authentication.</p>
<p>2. Update your internet browsers. New browsers are intelligent enough if the SSL certificates is fake or not.</p>
<p>3. Always check the URL of the page. Most of the hackers uses free web service hosting to host their bogus site.</p>
<p>Internet security awareness will always save your butt and your hard earned ADS payments.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/phishing-attack-on-bloggers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Yahoo Mail account: How did he do it??</title>
		<link>http://www.penoycentral.net/technology/hacking-yahoo-mail-account-how-did-he-do-it/</link>
		<comments>http://www.penoycentral.net/technology/hacking-yahoo-mail-account-how-did-he-do-it/#comments</comments>
		<pubDate>Sat, 25 Oct 2008 14:35:48 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/?p=150</guid>
		<description><![CDATA[After yesterday hacking incident on my gf&#8217;s yahoo mail account, we called and emailed yahoo customer service and answered all of the security question just to prove that she owns the yahoo id. Yahoo then emailed  us the new password and we were able to retrieve the account from the bastard. So how the hacker [...]]]></description>
			<content:encoded><![CDATA[<p>After yesterday <a href="http://lifeisfun1214.wordpress.com/2008/10/25/bewareyahoo-spammers-phishing-web-sites/">hacking incident on my gf&#8217;s yahoo mail account</a>, we called and emailed yahoo customer service and answered all of the security question just to prove that she owns the yahoo id. Yahoo then emailed  us the new password and we were able to retrieve the account from the bastard.</p>
<p><span id="more-150"></span></p>
<p>So how the hacker did it???? It was just a simple page that collects username and password. But he is skilled on &#8220;social engineering&#8221;. At first you will not notice anything because the flow of conversation is friendly.</p>
<p>The <a href="http://www.penoycentral.net/technology/yahoo-mail-account-hacked/">yahoo mail phishing webpage</a> was so simple. Last night i debug the page by using <a href="http://www.fiddler2.com/">fiddler2</a>, a free web debugging tool. So after the victim entered the username and password and clicked the fake Sign On button, the account information will be then be saved in a clear text file that the hacker then can retrieve and used to logon unto the victim&#8217;s account. After that he will change your password and 0wn your account.</p>
<p><a href="http://img389.imageshack.us/my.php?image=fiddlerof4.jpg" target="_blank"><img src="http://img389.imageshack.us/img389/3346/fiddlerof4.th.jpg" border="0" alt="Free Image Hosting at www.ImageShack.us" /></a></p>
<p>Debugging yahoo mail phishing page using Fiddler2</p>
<p><img src="http://img160.imageshack.us/img160/6899/fiddler2it5.jpg" alt="" width="513" height="121" /></p>
<p>Saves username and password on clear text</p>
<p>So if you are a victim of such incident, call Yahoo Customer Service, email them and never forget all information that you used during the creation of your account, alternate email, pet&#8217;s name, birthday, etc. War against cyber crime is true so always be on guard.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/technology/hacking-yahoo-mail-account-how-did-he-do-it/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Yahoo Mail Account hacked</title>
		<link>http://www.penoycentral.net/technology/yahoo-mail-account-hacked/</link>
		<comments>http://www.penoycentral.net/technology/yahoo-mail-account-hacked/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 13:00:09 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/?p=147</guid>
		<description><![CDATA[My gf yahoo mail account was hacked. A friend of her chatted thru yahoo messenger and asking for a load. At first you will not notice the scam because the chat was in Tagalog (native language in the Philippines). And after that the hacker asked her to check a URL for him. http://ymphotos.my3gb.com/yahoo.html The page [...]]]></description>
			<content:encoded><![CDATA[<p>My gf yahoo mail account was hacked. A friend of her chatted thru yahoo messenger and asking for a load. At first you will not notice the scam because the chat was in Tagalog (native language in the Philippines). And after that the hacker asked her to check a URL for him.<span id="more-147"></span></p>
<blockquote><p>http://ymphotos.my3gb.com/yahoo.html</p></blockquote>
<p><img src="http://img110.imageshack.us/img110/3192/yahooscamuc3.jpg" alt="Yahoo account scam" /></p>
<p>The page looks like a yahoo mail login page. She then mistakenly entered her username and password.. and boom, her account was hacked.</p>
<p>The hacker then used my gf&#8217;s yahoo account and chat her friends in yahoo messenger asking again for a load. After a series of conversation on one of her friends. A former officemate in Manila called her and asked if she were in the Philippines and if she is online on YM. They were puzzled why would she then asked for a cellphone load. Rachel notified me to check her Yahoo  but no avail, the hacker already changed the password.</p>
<p>I tried to reset the password but she forgot her alternate email. We called yahoo&#8217;s customer service but they are already closed for the day.</p>
<p>We spent the night changing all of our account&#8217;s password and calling friends not to chat her YM ID just to avert further damage.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/technology/yahoo-mail-account-hacked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>PuttyTabs: putty on tabs</title>
		<link>http://www.penoycentral.net/security/puttytabs-putty-on-tabs/</link>
		<comments>http://www.penoycentral.net/security/puttytabs-putty-on-tabs/#comments</comments>
		<pubDate>Fri, 28 Mar 2008 01:23:35 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/linuxnix/puttytabs-putty-on-tabs/</guid>
		<description><![CDATA[Tired of unorganized ssh putty sessions and don&#8217;t have the budget for SecureCRT??? Use PuttyTabs!!! PuttyTabs is a utility use to organize your ssh on tabs. It has its own docking window that you can hide in your desktop.]]></description>
			<content:encoded><![CDATA[<p>Tired of unorganized ssh <a href="http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html">putty</a> sessions and don&#8217;t have the budget for <a href="http://www.vandyke.com/products/securecrt/">SecureCRT</a>??? Use PuttyTabs!!! <a href="http://www.raisin.de/putty-tabs/putty-tabs.html">PuttyTabs</a> is a utility use to organize your <a href="http://en.wikipedia.org/wiki/Secure_Shell">ssh</a> on tabs.  It has its own docking window that  you can  hide  in your desktop.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/puttytabs-putty-on-tabs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EnCase® dv6 Computer Forensics I on June 2-5, 2008</title>
		<link>http://www.penoycentral.net/security/encase%c2%ae-dv6-computer-forensics-i-on-june-2-5-2008/</link>
		<comments>http://www.penoycentral.net/security/encase%c2%ae-dv6-computer-forensics-i-on-june-2-5-2008/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 12:10:15 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/security/encase%c2%ae-dv6-computer-forensics-i-on-june-2-5-2008/</guid>
		<description><![CDATA[First in the Philippines: EnCase® dv6 Computer Forensics I on June 2-5, 2008 Fee: Php56,000.00 (Inclusive of 12%VAT, Training Materials, Certificate and AM/PM Snack and Lunch) Venue: 25th Flr. Unit 2502b West Tower, Philippine Stock Exchange, Ortigas Center Pasig City CPE credits: 32 &#124; Level: Introductory &#124; Prerequisites: Basic computer skills. Advance preparation for this [...]]]></description>
			<content:encoded><![CDATA[<p><font style="color: #ff0000" size="6"><strong>First in the  Philippines:</strong></font>       <span><font size="-1"><strong><span style="font-size: 22pt; color: red"></span></strong></font></span><span><font size="-1"><strong><span style="font-size: 18pt; color: #548dd4">EnCase® dv6 Computer Forensics I  on June 2-5, 2008 </span></strong></font></span></p>
<p><span id="more-44"></span></p>
<p><font size="-1"><strong><span style="font-size: 16pt">Fee:  Php56,000.00</span></strong><span style="font-size: 16pt"> </span><strong>(Inclusive of  12%VAT, Training Materials, Certificate and AM/PM Snack and Lunch)</strong><span>  </span><span style="font-size: 14pt"></span></font></p>
<p><font size="-1"><strong><span style="font-size: 10pt">Venue:</span></strong><span>  25<sup>th</sup> Flr. Unit 2502b West Tower, <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_0">Philippine Stock Exchange</span>, Ortigas  Center Pasig City</span><span style="font-size: 14pt"></span></font></p>
<p><font size="-1"><strong><span style="font-size: 10pt">CPE credits</span></strong><span style="font-size: 10pt">: 32   | <strong>Level</strong>: Introductory   |  <strong>Prerequisites</strong>: Basic computer skills. Advance preparation for this course  is not required. </span></font></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt"><font size="-1">This hands-on course involves practical  exercises and real-life simulations. The class provides participants with an  understanding of the proper handling of digital evidence from the initial  seizure of the computer/media to acquisition, and then progresses to the  analysis of the data. It concludes with archiving and validating the data.  Delivery method: Group-Live.</font></span></p>
<p><font size="-1">Students attending this course will learn  the following: </font></p>
<ul type="disc">  <font size="-1"></p>
<li style="line-height: normal"><span>What constitutes digital evidence and    how computers work</span></li>
<li style="line-height: normal"><span>An overview of the EnCase Computer    Forensic Methodology</span></li>
<li style="line-height: normal"><span>Basic structures of the FAT and NTFS    file systems</span></li>
<li style="line-height: normal"><span>How to create a case and how to    preview/acquire media</span></li>
<li style="line-height: normal"><span>How to conduct basic keyword    searches</span></li>
<li style="line-height: normal"><span>How to analyze file signatures and view    files</span></li>
<li style="line-height: normal"><span>How to restore evidence</span></li>
<li style="line-height: normal"><span>How to archive files and data created    through the analysis process</span></li>
<li style="line-height: normal"><span>How to prepare evidence for presentation    in court</span></li>
<li style="line-height: normal"><span>How to verify the evidence file</span></li>
<p></font></ul>
<p style="margin-bottom: 0pt; line-height: normal"><font size="-1"><strong><span style="font-size: 10pt">WHO SHOULD ATTEND</span></strong><span style="font-size: 10pt"> </span></font></p>
<p style="line-height: normal"><span style="font-size: 10pt"><font size="-1">This  course is intended for IT security professionals, litigation support and  forensic investigators Participants may have minimal computer skills and may be  new to the field of computer forensics.</font></span></p>
<p align="left">&nbsp;</p>
<p align="center">
<table style="border: medium none ; border-collapse: collapse" border="1" cellpadding="0" cellspacing="0" height="1273" width="426">
<tr>
<td style="border: 1pt solid black; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 306.75pt" width="409">
<p align="left">&nbsp;</p>
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="left"><strong><span style="font-size: 10pt">DAY 1      OUTLINE</span></strong></p>
</td>
<td style="border-style: solid solid solid none; border-color: black; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 297pt" width="396">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 2      OUTLINE</span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 306.75pt" valign="top" width="409">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">EnCase        Concepts</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Case File</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Evidence  File</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Case File        Backup</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Configuration        Files</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">What        constitutes Digital Evidence</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Computers as an        instrumentality of the crime</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Computers as a        repository of evidence</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Examples of mediums of        storing digital evidence </span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">How Computer        Works</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Power        Sequence</span></p>
<p style="margin: 0in 0in 0pt 49.5pt; line-height: normal"><span style="font-size: 10pt"><span>o<span>           </span></span></span><span style="font-size: 10pt">BIOS</span></p>
<p style="margin: 0in 0in 0pt 49.5pt; line-height: normal"><span style="font-size: 10pt"><span>o<span>           </span></span></span><span style="font-size: 10pt">POST</span></p>
<p style="margin: 0in 0in 0pt 49.5pt; line-height: normal"><span style="font-size: 10pt"><span>o<span>           </span></span></span><span style="font-size: 10pt">Etc.</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Bits/Bytes/Hex/Binary</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Encase        Navigation</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Diskette        Preview / Acquisition</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Create Case</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Options</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt">Day one provides an understanding of the proper        handling of digital evidence from seizure to acquisition. Students receive        a basic overview of how computers function, as well as the constitutes        digital evidence</span></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 297pt" valign="top" width="396">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 12pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">NTFS/FAT File        Systems</span></strong><strong><span style="font-size: 12pt; color: #0070c0"></span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">How these file systems        track data</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">What happens when a        file is created</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">What happens when a        file is deleted</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Creating a        Boot Disk</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Why a forensically        sound boot disk is needed</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Components of a        forensically sound boot disk</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Hard Drive        Preview and Acquisitions</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Physical disk versus        logical drive</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Fastbloc</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">DOS based via disk to        disk</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">DOS based via crossover        cable</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Creation of        Keywords and Searching</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Global versus Case        Specific</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Selecting        Keywords</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Selecting where/what to        search</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Viewing        results</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="color: #0070c0">Bookmarking/Preserving        Findings</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Highlighting sections        of data</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Pointing to        file(s)</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt">Day two begins with a discussion of the FAT file        systems as well as an overview of the NT file system. Hard disk        acquisition is covered, using both a forensically sound boot diskette, as        well as a hardware write blocking device. Attendees will learn how to        properly preview a computer system prior to acquisition, as well as        explore keyword searching and bookmarking of relevant data.</span><strong><span style="font-size: 12pt; color: #0070c0"></span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 306.75pt" valign="top" width="409">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 3</span></strong></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 297pt" valign="top" width="396">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 4</span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 306.75pt" valign="top" width="409">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">File Types</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Icons</span><span style="font-size: 9pt">/Description column</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Bookmarking        Techniques</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Pointing to        file(s)</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Comments</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Organizing</span><span style="font-size: 9pt"> Report</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Signature        Analysis</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Search  Button</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">All or        Selected</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Compares Extension to        Header</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Interpreting</span><span style="font-size: 9pt">        results</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Installing External        Viewers</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Link Application to        EnCase</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Can link file        extensions to Application</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Copy/Unerase        Options</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Restoring        Evidence</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Reacquiring an Evidence        File</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Don&#8217;t need original        hardware to change options</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Quick        Reacquisition</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Day three includes more complex bookmarking of        data, and examination of file signatures to accurately identify file        types. Attendees will install external viewers within EnCase and learn how        to copy data from within an evidence file. Students learn how  to</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">restore an evidence file back to physical media and        reacquire an evidence file with different options.</span><span style="font-size: 10pt"></span></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 297pt" valign="top" width="396">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Archiving/Reopening an        Archived Case</span></strong><strong><span style="color: #0070c0"></span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 9pt">What </span><span style="font-size: 10pt">to archive</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Spec</span><span style="font-size: 9pt">ify path to EnCase of Evidence file to reopen        case</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Verification of Evidence        File</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Change 1 bit; EnCase        detects change</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Ma</span><span style="font-size: 9pt">nually re-verify at any time</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Timeline</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Define</span><span style="font-size: 9pt"> four Date/Time stamps</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Windows        Artifacts</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">User  Accounts</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Recently Accessed        Files</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Internet        Cache</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Desktop</span><span style="font-size: 9pt">/My Documents</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Searching Unallocated        Space</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Use file header for        image</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Display</span><span style="font-size: 9pt"> image</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 9pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Day four explores how to archive a completed case,        as well as how</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">to reopen this case if needed in the future.        Attendees will observe</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">how EnCase can detect and identify any changes to        the content</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">of an evidence file, as well as take a detailed        look at the Timeline</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">view within EnCase. Pertinent areas of interest        within the Windows</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">operating system and user accounts are explored as        well as locating</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">data in unallocated space.</span><span style="font-size: 10pt"></span></p>
</td>
</tr>
</table>
<p><span style="font-size: 10pt; line-height: 115%"></span></p>
<p><span style="font-size: 10pt; line-height: 115%"><font size="-1"><br clear="all" /></font></span><span style="font-size: 10pt; line-height: 115%"></span></p>
<p><span><font size="-1"><strong><span style="font-size: 18pt; color: #548dd4">EnCase® v6 Computer Forensics II  on June 16-19, 2008</span></strong></font></span><span><font size="-1"><strong><span style="font-size: 18pt; color: #548dd4"></span></strong></font></span></p>
<p><font size="-1"><strong><span style="font-size: 16pt">Fee:  Php56,000.00</span></strong><span style="font-size: 16pt"> </span><strong>(Inclusive of  12%VAT, Training Materials, Certificate and AM/PM Snack and Lunch)</strong><span><br />
Venue: 25<sup>th</sup> Flr. Unit 2502b West Tower, <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_1">Philippine Stock  Exchange</span>, <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_2">Ortigas Center</span> Pasig City<br />
</span><strong><span style="font-size: 10pt">CPE credits</span></strong><span style="font-size: 10pt">:  <em>32 </em>  |  <strong>Level</strong>: <em>Intermediate </em>  |   <strong>Prerequisites</strong>: </span><a href="http://www.guidancesoftware.com/training/courses/computerforensics_i_private.aspx" rel="nofollow" target="_blank"><em><span style="font-size: 10pt">EnCase® Computer Forensics  I</span></em></a><em><span style="font-size: 10pt">. Advance preparation for this  course is not required. </span></em><span style="font-size: 10pt"></span></font></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt"><font size="-1">This hands-on course is designed for  investigators with strong computer skills, prior computer forensics training,  and experience using the EnCase forensic software. This course builds upon the  skills covered in the EnCase Computer Forensics I course and enhances the  examiner&#8217;s ability to work efficiently through the use of the unique features of  EnCase.<br />
*Students must understand evidence handling; the structure of the  evidence file; creating and using case files; data acquisition methods including  DOS based, hardware write protected, crossover cable and disk to disk;  recovering deleted files and folders in a FAT environment; keyword searches  across logical and physical media; creating and using EnCase bookmarks; file  signatures and signature analysis; and locating and understanding Windows®  artifacts. Delivery method: Group-Live.<br />
</font></span><span><font size="-1"><br />
</font></span><span style="font-size: 10pt"><font size="-1">Focusing  on investigations common to the private sector, students will learn about the  following:</font></span></p>
<ul type="disc">  <font size="-1"></p>
<li style="line-height: normal"><span style="font-size: 10pt">How to create    and use of logical evidence files</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to locate    and recover deleted partitions and folders</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to conduct    keyword searches and advanced searches using GREP</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">Students will    gain an understanding of the EnCase Virtual File System (VFS) and Physical    Disk Emulator (PDE)</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">Students will    learn about the Windows® Registry</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">Students will    learn how to deal with compound file types</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to export    files, directories and entire volumes</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to identify    files using hash values and building hash libraries</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to identify    <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_3">Windows XP operating system</span> artifacts such as link files, recycle bin, and    user folders</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to prepare    reports and evidence for presentation in court</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to recover    artifacts such as swap files, file slack, and spooler files</span></li>
<li style="line-height: normal"><span style="font-size: 10pt">How to recover    printed and faxed pages</span></li>
<p></font></ul>
<p style="margin-bottom: 0pt; line-height: normal"><font size="-1"><strong><span>WHO  SHOULD ATTEND</span></strong><span> </span></font></p>
<p style="line-height: normal"><span><font size="-1">This course is intended for  IT security professionals, litigation support and forensic investigators.  Participants should have attended the EnCase Computer Forensics I.  </font></span></p>
<p align="center">
<table style="border: medium none ; border-collapse: collapse" border="1" cellpadding="0" cellspacing="0" height="908" width="489">
<tr>
<td style="border: 1pt solid black; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 314.35pt" width="419">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 1</span></strong></p>
</td>
<td style="border-style: solid solid solid none; border-color: black; border-width: 1pt 1pt 1pt medium; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 3.7in" width="355">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 2</span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 314.35pt" valign="top" width="419">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">How the EnCase Evidence File        is Stored and Verified</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Encase Forensic Edition        Overview</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Data flow</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Navigating        EnCase</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Logical Evidence        Files</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">What are        they?</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Why would I use        them?</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">How to create        them</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Single Evidence        Files</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">What are        they?</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Why would I use        them?</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">How to create        them</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Software Write        Protection</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Fast Bloc SE</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Introduction to        NTFS</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Understanding the        Windows® New Technology File System</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Handling Formatted or        Repartitioned Media</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Partition        recovery</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Folder        Recovery</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Day one provides an understanding of EnCase        concepts. Students will learn how an evidence file is acquired, verified,        added to a case, and stored. They will learn how to create and use logical        evidence files and single evidence files. Students will receive hands-on        imaging training using FastBloc SE.</span><span style="font-size: 10pt"></span></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 3.7in" valign="top" width="355">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Hash Analysis</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Using file hashes to        improve accuracy and efficiency</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Compound  files</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">An overview of compound        files</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Mounting compound        files</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Searching compound file        types</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">- Windows        Registry</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Appropriate        keywords</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">How EnCase searches the        evidence file</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">VFS / PDE</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Using Virtual File        System</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Using Physical Disk        Emulator</span></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Using GREP to focus        searches. GREP allows the examiner to create concise keywords using        control characters, reducing false positives and increasing        efficiency.</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><strong><span style="font-size: 9pt; color: #0070c0"></span></strong></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Day two introduces the students to the process of        analyzing the evidence. The hashing of files both as a means of        identification and as a tool to speed up the searching process is        covered.</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Students also take a first look into the Windows        Registry and learn how, why and when to use VFS and PDE. We continue to        build on the students&#8217; skill sets, moving from general keyword</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">searches and file type analysis to advanced keyword        searches using GREP.</span><span style="font-size: 10pt"></span></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 314.35pt" width="419">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 3</span></strong></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; background: #548dd4 none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; width: 3.7in" width="355">
<p style="margin-bottom: 0pt; line-height: normal; text-align: center" align="center"><strong><span style="font-size: 10pt">DAY 4</span></strong></p>
</td>
</tr>
<tr>
<td style="border-style: none solid solid; border-width: medium 1pt 1pt; padding: 0in 5.4pt; width: 314.35pt" valign="top" width="419">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Quickly locating file system        artifacts unique to the NTFS file system</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">De-constructing link files        to reveal artifacts that indicate the who, what, when and where of file        manipulation.</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">E-mail recovery and        examinations including <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_4">Microsoft Outlook</span>, Outlook Express        and</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">web based        e-mail.</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Recovering and analyzing        e-mail attachments</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Internet history concepts        and analysis using Internet Explorer</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Understanding and recovering        documents that have been printed</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Recycle Bin analysis to        reveal important information about deleted files</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><strong><span style="font-size: 9pt; color: #0070c0"></span></strong></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">Day three moves to specific analysis of common        artifacts that cannot normally be locatedthrough keyword searches. This        analysis can often provide vital information to investigations        by</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 9pt">revealing data that can provide a clear indication        of a user&#8217;s activities. We look at how EnCase handles common e-mail files        and Internet history.</span><span style="font-size: 10pt"></span></p>
</td>
<td style="border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0in 5.4pt; width: 3.7in" valign="top" width="355">
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Handling and acquiring Flash        Memory and artifacts</span></strong></p>
<p style="margin: 0in 0in 0pt 0.25in; line-height: normal"><span style="font-size: 9pt; color: #0070c0; font-family: Wingdings"><span>Ø<span>         </span></span></span><strong><span style="font-size: 9pt; color: #0070c0">Reporting</span></strong></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">How and what to report        after the investigation is completed</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Using bookmarks we        created to prepare a written report within the EnCase interface</span></p>
<p style="margin: 0in 0in 0pt 27pt; line-height: normal"><span style="font-size: 10pt; font-family: Symbol"><span>·<span>                </span></span></span><span style="font-size: 10pt">Exporting the report in        an HTML or other format</span></p>
<p style="margin: 0in 0in 0pt 9pt; line-height: normal"><span style="font-size: 10pt"></span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt">On day four students learn how to utilize all of        the techniques from the previous days to create a</span></p>
<p style="margin-bottom: 0pt; line-height: normal"><span style="font-size: 10pt">readable, coherent report using      EnCase.</span></p>
</td>
</tr>
</table>
<p style="text-align: center" align="center"><span style="font-size: 20pt; color: red; line-height: 115%"><font size="-1">ENROLL  NOW!</font></span></p>
<p><span style="font-size: 20pt; color: #00b050; line-height: 115%"><font size="-1">GLOBALKNOWLEDGE <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_5">PHILIPPINES</span>, INC.</font></span><br />
<span style="font-size: 20pt; color: #00b050; line-height: 115%"></span><span style="font-size: 10pt; line-height: 115%"><font size="-1">2502B West Tower, PSE Bldg. Exchange Road, <span style="border-bottom: 1px dashed #0066cc; cursor: pointer" class="yshortcuts" id="lw_1206533282_6">Ortigas Center</span>, Pasig City,  Philippines 1600</font></span><br />
<span style="font-size: 10pt; line-height: 115%"><font size="-1">Tel. Nos. (632)  683-0969; 637-3657; 0920-709-8298</font></span><br />
<span style="font-size: 10pt; line-height: 115%"><font size="-1">Email:  </font></span><font size="-1"><a href="http://us.f527.mail.yahoo.com/ym/Compose?To=Sandra@globalknowledgeph.com" rel="nofollow" ymailto="mailto:Sandra@globalknowledgeph.com" target="_blank"><span style="font-size: 10pt; line-height: 115%">Sandra@globalknowledgeph.com</span></a><span style="font-size: 10pt; line-height: 115%"> YM: </span><a href="http://us.f527.mail.yahoo.com/ym/Compose?To=Sandra_medalla@yahoo.com" rel="nofollow" ymailto="mailto:Sandra_medalla@yahoo.com" target="_blank"><span style="font-size: 10pt; line-height: 115%">Sandra_medalla@yahoo.com</span></a></font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/encase%c2%ae-dv6-computer-forensics-i-on-june-2-5-2008/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Installing Security Auditor&#8217;s Research Assistant(SARA) in backtrack linux</title>
		<link>http://www.penoycentral.net/security/installing-security-auditors-research-assistantsara-in-backtrack-linux/</link>
		<comments>http://www.penoycentral.net/security/installing-security-auditors-research-assistantsara-in-backtrack-linux/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 14:10:39 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Linux/Nix]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/security/installing-security-auditors-research-assistantsara-in-backtrack-linux/</guid>
		<description><![CDATA[Installing Security Auditor&#8217;s Research Assistant(SARA) in backtrack linux  Install tcsh. Perl needs the csh shell to execute SARA #wget http://mirror.muntinternet.net/pub/slackware/slackware_source/a/tcsh/tcsh-6.15.00.tar.bz2 #bunzip2 tcsh-6.15.00.tar.bz2 #tar xvf tcsh-6.15.00.tar #cd tcsh-6.15.00 #./configure #make #make install #ln -sf /usr/local/bin/tcsh /bin/csh Download and install SARA #wget http://www-arc.com/sara/downloads/sara-7.5.2.tgz #tar xvzf sara-7.5.2.tgz #cd sara-7.5.2 #./configure #make #make install Add sara user ./add_user Scan [...]]]></description>
			<content:encoded><![CDATA[<p>Installing Security Auditor&#8217;s Research Assistant(SARA) in <a href="http://www.remote-exploit.org/">backtrack linux </a></p>
<p><span id="more-43"></span></p>
<p>Install tcsh. Perl needs the csh shell to execute <a href="http://www-arc.com/sara/">SARA</a><br />
<em>#wget http://mirror.muntinternet.net/pub/slackware/slackware_source/a/tcsh/tcsh-6.15.00.tar.bz2<br />
#bunzip2 tcsh-6.15.00.tar.bz2<br />
#tar xvf tcsh-6.15.00.tar<br />
#cd tcsh-6.15.00<br />
#./configure<br />
#make<br />
#make install<br />
#ln -sf /usr/local/bin/tcsh /bin/csh</em></p>
<p>Download and install SARA<br />
<em>#wget http://www-arc.com/sara/downloads/sara-7.5.2.tgz<br />
#tar xvzf sara-7.5.2.tgz<br />
#cd sara-7.5.2<br />
#./configure<br />
#make<br />
#make install</em></p>
<p>Add sara user<br />
<em>./add_user</em></p>
<p>Scan a host<br />
<em>./sara -a4 &lt;ip.address&gt;</em></p>
<p>Run SARA in daemon mode<br />
<em>./sara -D</em></p>
<p>Now browse to <strong>http://localhost:666</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/installing-security-auditors-research-assistantsara-in-backtrack-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should i Perl or Python now</title>
		<link>http://www.penoycentral.net/security/should-i-perl-or-python-now/</link>
		<comments>http://www.penoycentral.net/security/should-i-perl-or-python-now/#comments</comments>
		<pubDate>Tue, 25 Mar 2008 08:55:12 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/security/should-i-perl-or-python-now/</guid>
		<description><![CDATA[my 30 days lab access ended last February for the security course that im attending. Im still waiting for a May slot and extend another 30 days access. For the meantime, im struggling to learn perl and python programming needed in some of the course lab exercises.]]></description>
			<content:encoded><![CDATA[<p>my 30 days lab access ended last February for the security course that im attending. Im still waiting for a May slot and extend another 30 days access. For the meantime, im struggling to learn perl and python programming needed in some of the course lab exercises.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/should-i-perl-or-python-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PostgreSQL</title>
		<link>http://www.penoycentral.net/security/postgresql/</link>
		<comments>http://www.penoycentral.net/security/postgresql/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 03:42:16 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Linux/Nix]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/security/postgresql/</guid>
		<description><![CDATA[[root@localhost]# postgres &#8220;root&#8221; execution of the PostgreSQL server is not permitted. The server must be started under an unprivileged user ID to prevent possible system security compromise.  See the documentation for more information on how to properly start the server. [root@localhost]# im starting to like PostgreSql&#8230;]]></description>
			<content:encoded><![CDATA[<p>[root@localhost]# postgres<br />
&#8220;root&#8221; execution of the PostgreSQL server is not permitted.<br />
The server must be started under an unprivileged user ID to prevent<br />
possible <strong>system security compromise</strong>.  See the documentation for<br />
more information on how to properly start the server.<br />
[root@localhost]#</p>
<p><span id="more-34"></span></p>
<p>im starting to like <a href="http://www.postgresql.org/">PostgreSql</a>&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/postgresql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Backtrack V3 in Toshiba Satellite M50</title>
		<link>http://www.penoycentral.net/technology/backtrack-v3-in-toshiba-satellite-m50/</link>
		<comments>http://www.penoycentral.net/technology/backtrack-v3-in-toshiba-satellite-m50/#comments</comments>
		<pubDate>Sun, 17 Feb 2008 13:46:01 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Linux/Nix]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/technology/backtrack-v3-in-toshiba-satellite-m50/</guid>
		<description><![CDATA[&#160; My Toshiba Satellite M50 laptop now runs Backtrack v3 Linux!!!! The installation manual was straightforward although i have to mess around with lilo bootloader and the computer&#8217;s mbr. Copying the livecd&#8217;s xorg.conf to my HD installed xorg.conf fixed the LCDs resolution]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img src="http://img261.imageshack.us/img261/3116/picture38bm1.jpg" alt="Toshiba M50 Backtrack 3 Linux" height="240" width="320" /></p>
<p><span id="more-31"></span></p>
<p style="text-align: center">&nbsp;</p>
<p style="text-align: left" align="left">My <a href="http://www.zdnet.com.au/reviews/hardware/laptops/soa/Toshiba-Satellite-M50-14-inch-1-4GHz-/0,2000065761,139235551,00.htm">Toshiba Satellite M50</a> laptop now runs <a href="http://www.remote-exploit.org">Backtrack v3</a> Linux!!!! The <a href="http://www.offensive-security.com/movies/dualboot/dualboot.html">installation manual </a>was straightforward although i have to mess around with lilo bootloader and the computer&#8217;s mbr. Copying the livecd&#8217;s xorg.conf to my HD installed xorg.conf fixed the LCDs resolution <img src='http://www.penoycentral.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/technology/backtrack-v3-in-toshiba-satellite-m50/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Installing Nessus Vulnerability Scanner in CentOS Enterprise Linux 5</title>
		<link>http://www.penoycentral.net/security/installing-nessus-vulnerability-scanner-in-centos-enterprise-linux-5/</link>
		<comments>http://www.penoycentral.net/security/installing-nessus-vulnerability-scanner-in-centos-enterprise-linux-5/#comments</comments>
		<pubDate>Wed, 16 Jan 2008 01:35:50 +0000</pubDate>
		<dc:creator>penoycentral</dc:creator>
				<category><![CDATA[Linux/Nix]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.penoycentral.net/security/installing-nessus-vulnerability-scanner-in-centos-enterprise-linux-5/</guid>
		<description><![CDATA[Nessus is a free, up to date and easy to use vulnerability scanner. You can find the official documentation of how to install Nessus here. Download and install Nessus rpm package from the Nessus download page [root@nessus chris]# rpm -ivh Nessus-3.0.6-es5.i386.rpm Preparing&#8230; ########################################### [100%] 1:Nessus ########################################### [100%] nessusd (Nessus) 3.0.6. for Linux (C) 1998 &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><o:p> </o:p><a href="http://en.wikipedia.org/wiki/Nessus_(software)">Nessus</a> is a free, up to date and easy to use vulnerability scanner. You can find the <a href="http://www.nessus.org/download/index.php">official documentation</a> of how to install Nessus here.</p>
<p><span id="more-22"></span></p>
<p class="MsoNormal">
<o:p> </o:p>Download and install Nessus rpm package from the <a href="http://www.nessus.org/download/">Nessus download</a> page</p>
<blockquote>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><o:p> </o:p><strong><span style="font-size: 10pt; font-family: Arial">[root@nessus chris]# rpm -ivh Nessus-3.0.6-es5.i386.rpm<o:p></o:p><br />
Preparing&#8230;<span>                </span>########################################### [100%]<o:p></o:p><br />
<span></span>1:Nessus<span>                 </span>########################################### [100%]<o:p></o:p><br />
nessusd (Nessus) 3.0.6. for Linux<o:p></o:p><br />
(C) 1998 &#8211; 2007 Tenable Network Security, Inc.<o:p></o:p><br />
Processing the Nessus plugins&#8230;<o:p></o:p><br />
[##################################################]<o:p></o:p><br />
All plugins loaded<o:p></o:p><br />
<span></span>- Please run /opt/nessus//sbin/nessus-add-first-user to add an admin user<o:p></o:p><br />
<span></span>- Register your Nessus scanner at http://www.nessus.org/register/ to obtain<o:p></o:p><br />
<span></span>all the newest plugins<o:p></o:p><br />
<span></span>- You can start nessusd by typing /sbin/service nessusd start<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><strong>[root@nessus chris]#</strong><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</blockquote>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Add the first Nessus user, it will be the admin account</p>
<p class="MsoNormal"><o:p> </o:p></p>
<blockquote>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">[root@nessus chris]# /opt/nessus/sbin/nessus-add-first-user<o:p></o:p><br />
Using /var/tmp as a temporary file holder<o:p></o:p><br />
Add a new nessusd user<o:p></o:p><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">Login : admin<o:p></o:p><br />
Authentication (pass/cert) [pass] :<o:p></o:p><br />
Login password :<o:p></o:p><br />
Login password (again) :<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">User rules<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">&#8212;&#8212;&#8212;-<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">nessusd has a rules system which allows you to restrict the hosts<o:p></o:p><br />
that admin has the right to test. For instance, you may want<o:p></o:p><br />
him to be able to scan his own host only.<o:p></o:p><br />
Please see the nessus-adduser(8) man page for the rules syntax<o:p></o:p><br />
Enter the rules for this user, and hit ctrl-D once you are done :<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">(the user can have an empty rules set)<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">Login<span>  </span><span>           </span>: admin<o:p></o:p><br />
Password<span>          </span>: ***********<o:p></o:p><br />
DN<span>                </span>:<o:p></o:p><br />
Rules<span>             </span>:<o:p></o:p><br />
Is that ok ? (y/n) [y] y<o:p></o:p><br />
user added.<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">Thank you. You can now start Nessus by typing :<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><strong>/opt/nessus//sbin/nessusd -D</strong><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></p>
</blockquote>
<p class="MsoNormal">Start Nessus service daemon</p>
<p class="MsoNormal"><o:p> </o:p></p>
<blockquote>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">[root@nessus chris]# /opt/nessus/sbin/nessusd -D &amp;<o:p></o:p><br />
[2] 1454<o:p></o:p><br />
[root@nessus chris]# nessusd (Nessus) 3.0.6. for Linux<o:p></o:p><br />
(C) 1998 &#8211; 2007 Tenable Network Security, Inc.<o:p></o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial"><o:p> </o:p></span></strong></p>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">Processing the Nessus plugins&#8230;<o:p></o:p><br />
[##################################################]<o:p></o:p><br />
All plugins loaded<o:p></o:p><br />
[2]-<span>  </span>Done<span>                    </span>/opt/nessus/sbin/nessusd -D<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><strong>[root@nessus chris]#</strong><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</blockquote>
<p class="MsoNormal">Obtain your Nessus registration code in the Nessus website and register your nessus installation.</p>
<p class="MsoNormal"><o:p> </o:p></p>
<blockquote>
<p class="MsoNormal"><strong><span style="font-size: 10pt; font-family: Arial">[root@nessus chris]# /opt/nessus/bin/nessus-fetch &#8211;register <em>putyourregcodehere</em><o:p></o:p><br />
Your activation code has been registered properly &#8211; thank you.<o:p></o:p><br />
Now fetching the newest plugin set from plugins.nessus.org&#8230;<o:p></o:p><br />
Your Nessus installation is now up-to-date.<o:p></o:p><br />
If auto_update is set to &#8216;yes&#8217; in nessusd.conf, Nessus will<o:p></o:p><br />
update the plugins by itself.<o:p></o:p></span></strong></p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial"><strong>[root@nessus chris]#</strong><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</blockquote>
<p class="MsoNormal">If you want a Windows-based Nessus admin console. Download and install <a href="http://www.idealogica.com/?f=products/nessconnect.html">Nessconnect</a></p>
<p class="MsoNormal" align="center"><o:p> </o:p><img src="http://img150.imageshack.us/img150/8867/nessus1aa9.png" alt="NessConnect Nessus Vulnerability Scanner" align="left" height="412" width="693" /></p>
<p class="MsoNormal"><o:p> </o:p></p>
]]></content:encoded>
			<wfw:commentRss>http://www.penoycentral.net/security/installing-nessus-vulnerability-scanner-in-centos-enterprise-linux-5/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
