<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Shattered Dreams&#8230; and a welcome community</title>
	<atom:link href="http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/</link>
	<description>Bringing Fire To The Village: Your Source For Computer, Network &#38; Information Security News from Dave Lewis, Security Blogger</description>
	<lastBuildDate>Fri, 19 Mar 2010 16:45:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Claus Valca</title>
		<link>http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/comment-page-1/#comment-71633</link>
		<dc:creator>Claus Valca</dc:creator>
		<pubDate>Sun, 22 Mar 2009 01:51:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=5330#comment-71633</guid>
		<description>Hi James,

I finally found the time to do some testing on Windows FE builds to see if the claims against Windows FE not being &quot;forensically sound&quot; were true.

Posted the results here:

Windows FE: Forensically Sound? - http://grandstreamdreams.blogspot.com/2009/03/windows-fe-forensically-sound.html

Long post short: It seemed to check out just fine in my MD5 hashing tests of both a Windows system and a non-Windows system and matched the same MD5&#039;s generated by DEFT Linux forensics LiveCD results.

Felt duty-bound to do the work and share here after my previous comment.

Cheers.

--Claus V.</description>
		<content:encoded><![CDATA[<p>Hi James,</p>
<p>I finally found the time to do some testing on Windows FE builds to see if the claims against Windows FE not being &#8220;forensically sound&#8221; were true.</p>
<p>Posted the results here:</p>
<p>Windows FE: Forensically Sound? &#8211; <a href="http://grandstreamdreams.blogspot.com/2009/03/windows-fe-forensically-sound.html" rel="nofollow">http://grandstreamdreams.blogspot.com/2009/03/windows-fe-forensically-sound.html</a></p>
<p>Long post short: It seemed to check out just fine in my MD5 hashing tests of both a Windows system and a non-Windows system and matched the same MD5&#8217;s generated by DEFT Linux forensics LiveCD results.</p>
<p>Felt duty-bound to do the work and share here after my previous comment.</p>
<p>Cheers.</p>
<p>&#8211;Claus V.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Intern</title>
		<link>http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/comment-page-1/#comment-71615</link>
		<dc:creator>The Intern</dc:creator>
		<pubDate>Wed, 18 Mar 2009 11:55:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=5330#comment-71615</guid>
		<description>@Zach If you weren&#039;t so hawt, your bewbs wouldn&#039;t be news.</description>
		<content:encoded><![CDATA[<p>@Zach If you weren&#8217;t so hawt, your bewbs wouldn&#8217;t be news.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Claus Valca</title>
		<link>http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/comment-page-1/#comment-71607</link>
		<dc:creator>Claus Valca</dc:creator>
		<pubDate>Tue, 17 Mar 2009 03:17:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=5330#comment-71607</guid>
		<description>Hi James - great post.

I had been keeping an eye out for the next Helix release and was shocked when I landed on the new pages.  Puzzled it out myself like you did as well.  I see their side about wanting to make a buck or two, but it still seems like a loss.  Quite a large community had grown up around it.  I&#039;m going to have to guard my ISO files of it like gold and keep some masters squirreled away for safe keeping...

Fortunately, as you have shared others are hard at work keeping the forensics LiveCD field rich wth new life and projects.

One more active forensic LiveCD project you might want to take a look at (you may already know of it) is DEFT Linux - http://www.deftlinux.net

They seem to be actively working on updating and tweaking it.

I like the &quot;dual-nature&quot; of CAINE (Linux boot / Windows auto-run menu).  I do wonder if they might get into some &quot;redistribution issues&quot; by including some of the Windows-side utilities along with the CD ISO.  Some developers frown on that practice.  So I hope it survives that test.

I&#039;ve not independently confirmed it myself, but I&#039;ve read that WinFE might in fact somehow change disk media anyway.  There are reports that it may not be forensically sound.  Some comments are that if you take a hash of a drive before using it (using another forensics tool) then boot a system with Win FE and then take a 2nd hash when done using the original tool, the hash is different.  Don&#039;t know more than those details and they might not bear out to be factual...I hesitated to even mention it, but it might be worth validating before using in a &quot;live-fire&quot; response with it.  Could be limited to specific storage devices.  I&#039;ve got some homework to do on this one.  I&#039;ve been doing a lot of Win PE building so I am curious in particular with Windows FE behaviour as it is based on Windows PE, but with two registry tweaks: Windows FE – Details Teased out of the Web - http://grandstreamdreams.blogspot.com/2009/02/windows-fe-details-teased-out-of-web.html

John Sawyer posted a followup article to the Windows FE one you linked to posing that very question:

Tool Validation: Trust, But Verify - http://darkreading.com/blog/archives/2009/02/tool_validation.html

Anyway, great blog and I am enjoying your perspective on things.

Cheers.

--Claus V.</description>
		<content:encoded><![CDATA[<p>Hi James &#8211; great post.</p>
<p>I had been keeping an eye out for the next Helix release and was shocked when I landed on the new pages.  Puzzled it out myself like you did as well.  I see their side about wanting to make a buck or two, but it still seems like a loss.  Quite a large community had grown up around it.  I&#8217;m going to have to guard my ISO files of it like gold and keep some masters squirreled away for safe keeping&#8230;</p>
<p>Fortunately, as you have shared others are hard at work keeping the forensics LiveCD field rich wth new life and projects.</p>
<p>One more active forensic LiveCD project you might want to take a look at (you may already know of it) is DEFT Linux &#8211; <a href="http://www.deftlinux.net" rel="nofollow">http://www.deftlinux.net</a></p>
<p>They seem to be actively working on updating and tweaking it.</p>
<p>I like the &#8220;dual-nature&#8221; of CAINE (Linux boot / Windows auto-run menu).  I do wonder if they might get into some &#8220;redistribution issues&#8221; by including some of the Windows-side utilities along with the CD ISO.  Some developers frown on that practice.  So I hope it survives that test.</p>
<p>I&#8217;ve not independently confirmed it myself, but I&#8217;ve read that WinFE might in fact somehow change disk media anyway.  There are reports that it may not be forensically sound.  Some comments are that if you take a hash of a drive before using it (using another forensics tool) then boot a system with Win FE and then take a 2nd hash when done using the original tool, the hash is different.  Don&#8217;t know more than those details and they might not bear out to be factual&#8230;I hesitated to even mention it, but it might be worth validating before using in a &#8220;live-fire&#8221; response with it.  Could be limited to specific storage devices.  I&#8217;ve got some homework to do on this one.  I&#8217;ve been doing a lot of Win PE building so I am curious in particular with Windows FE behaviour as it is based on Windows PE, but with two registry tweaks: Windows FE – Details Teased out of the Web &#8211; <a href="http://grandstreamdreams.blogspot.com/2009/02/windows-fe-details-teased-out-of-web.html" rel="nofollow">http://grandstreamdreams.blogspot.com/2009/02/windows-fe-details-teased-out-of-web.html</a></p>
<p>John Sawyer posted a followup article to the Windows FE one you linked to posing that very question:</p>
<p>Tool Validation: Trust, But Verify &#8211; <a href="http://darkreading.com/blog/archives/2009/02/tool_validation.html" rel="nofollow">http://darkreading.com/blog/archives/2009/02/tool_validation.html</a></p>
<p>Anyway, great blog and I am enjoying your perspective on things.</p>
<p>Cheers.</p>
<p>&#8211;Claus V.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zach</title>
		<link>http://www.liquidmatrix.org/blog/2009/03/16/shattered_dreams/comment-page-1/#comment-71606</link>
		<dc:creator>Zach</dc:creator>
		<pubDate>Tue, 17 Mar 2009 01:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/?p=5330#comment-71606</guid>
		<description>Eh. My bewbs are making the rounds right now. No worries. :)</description>
		<content:encoded><![CDATA[<p>Eh. My bewbs are making the rounds right now. No worries. <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
