Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, January 1, 2011

Security and Forensics Watch-List: GSD Linkfest Style

Posted on 1:32 PM by Unknown

It’s a sign of my busy-ness that most all the links for this first-of-the-year security and forensics linkfest post come from the tail-end of 2010.

I’m emptying all these out to clear the decks.  I’ve promised and need to deliver on the Xplico post that was mentioned some time ago.  These are the last bits that should empty out the “to-blog” hopper so I can turn all focus on that one.

Forensics and PenTest LiveCD News

Land Ahoy! DEFT 6 RC is OUT! - Stefano Fratepietro recently announced the “RC” release of the next DEFT iteration.  I’ve been playing with it and am very impressed with the polish and inclusions.  See his inclusions page to see what is loaded in, and check out the sexy-cool screenshot page for all the glamor and glitz.

CAINE 2.0 Live CD - “NewLight” Edition - Not to be outdone, the other highly-active LiveCD forensics distro CAINE had a final version release a while back.  Also highly updated with a “wax-on, wax-off” super-shine polish.  Check out this PDF version of Caine highlights as seen in Linux Magazine Online.

Katana 2.0 - A multi-boot “LiveUSB” distro from Hack from A Cave also got a November 2010 update. CAINE and Kon-Boot got added alone with some new Windows tools.  Maybe unknown to some, it also packs the Katana Tool Kit, based on a PortableApps launcher.  Like other distros, it provides a convenient manner to launch Windows-based tools from a nicely organized menu if using the tool in a Windows environment; rather than using one of the included distros to boot a system.

BackTrack Linux 4 R2 - The venerable penetration testing distribution packs a mean wallop!  You might want to look at both their Forensics page to find some features that might be useful. Also stop in on this SecurityOrb blog-post: BackTrack 4 Tutorials, Manuals and Howtos full of good resources.

Windows Forensic Environment Blog by Brett Shavers covers all things in the WinFE world.  Check out this wonderful post Updated video and other things to get a quick review on how the WinFE build it constructed.  Meanwhile we wait patiently for his magnum-opus WinBuilder based - WinFE creation tool to get released.

The Reading List

Windows Incident Response: Stuff - Great info on timeline thoughts from Harlan Carvey.

Reviewing Timelines with Excel - Journey Into Incident Response - Really great takeaway from Corey Harrell hopped to via Harlan’s post above.

Memory Analysis with Mandiant Memoryze - Digital Forensics How-To from the SANS Computer Forensics & Incident Response blog.  See also their post Persistence Registry keys.

The Digital Standard: The “Not So” Perfect Keylogger - cepogue has provided an interesting keylogger breakdown with lots of cross-response application.

JL’s stuff: Identifying Memory Images - In case you get an image with no clear information as to what system OS it was running under.

Open Source Digital Forensics - Bookmark this site to keep an eye on old and new tools in the Open Source forensic area.  Tools, paper, procedures and some test-image links available.

Derek Newton « Information Security Insights - Not really sure how I ended up exactly on Derek’s site but it is a gem.  Not only has he collected and organized some really nice Useful Links and Forensic Tools sub-pages, but his posts are always very educational.  For example, two recent posts:

  • Searching the Registry using PowerShell
  • Quick Tip: PowerShell Grep Equivalent

Finally, utility-building guru Nir Sofer offers all a Happy New Year To All NirSoft Users ! and then proceeds to tease us with some possible tools under development for the new year!  Awesome!

Wi-Fi Focus

A quick scan of the Wi-Fi surrounding the Valca home shows a total of 7 Wi-Fi networks with two of them wide-open and completely unsecured.  With really handy freeware tools such as the inSSIDer 2.0 Wi-Fi Scanner or NirSoft’s WirelessNetView or the eye-candy rich Xirrus Wi-Fi Inspector it is easy work finding and locating such things.

In his post How to capture data and passwords of unsecured wireless networks with SniffPass and SmartSniff, Nir Sofer shows just how easy it is to start grabbing data from unsecured networks.

I can’t recommend you test this on any network you don’t own or manage but if you are doing pentesting or an incident response involving a possible rogue Wi-Fi operation inside your network operations area, this could be a very valuable technique in some cases.

You might also find this MakeUseOf post 7 Completely Free VPN Services To Protect Your Privacy helpful.  Just saying…

“All-in-One” Forensic Tool?

At the risk of sounding like a fairly-recent Windows Phone 7 "Really?" TV Commercial (YouTube), I’m always very fascinated when I see a tool that honestly tries very hard to roll-up many “incident response” features into a single package. 

Like all such incident response tools, please understand and use the tools in a structured manner so as to not operate with a false sense of security…and potentially do more harm than good. Specifically, is use part of a larger and structured incident response plan, has the tool been seriously vetted, what key things does it NOT do that must be captured using alternative/supplemental tools?

Case in point just peruse this short-list of thoughts on the complexities of incident response from the pros:

  • WinFE and Triage - Brett Shavers WinFE Blog
  • Timelines - Harlan Carvey’s Windows Incident Response blog
  • Looking for "Bad Stuff", part I - Windows Incident Response blog
  • Summit Takeaways - Windows Incident Response blog
  • Why current IR models don’t work, part deux - Windows Incident Response blog
  • The need for IR training - Windows Incident Response blog

I ponder these things as I saw a new tool mentioned recently in the MakeUseOf site Investigate Or Troubleshoot Computer Systems With OSForensics [Windows]

It outlines a new (currently freeware) “many-in-one” forensic/digital-investigation tool by PassMark Software - OSForensics.

To PassMark’s credit, a look at the features shows it contains a very well rounded selection of components.  I’m not really fussing about the tool or its capabilities here.   I’m sure their target audience for the product are trained and harried professional incident-responder folks.  It is part of a number of tools offered by them, including ones to LiveCD boot a target system to capture an image as well as a tool mount the image file for processing with their OSForensics product.  So there is a unified structure to the tools.  Hopefully users will see these integrated parts and use them correctly in concert to process a system that preserves the integrity (ie, minimal/no write-back) to the target system.  PassMark has provided the toolset package.

I’m just curious how many untrained “incident responders” might jump on this tool based on its capabilities and convenience the first time someone hollers about a breach or incident and tosses this tool at the “live” target system. What will the aftermath be?

Of course, that situation probably occurs each and every day with any number of freely and publically available tools used by both “amateur” and certified professional incident responders alike.

That said, OSForensics rounds up quite a wide-range of useful tools and features into a very well organized and accessible package.  The interface is highly navigable.  I’m sure there are tools here for both the sysadmin-troubleshooter and the incident-responder alike to like and appreciate.  Of special note and appreciation is the offering of several “Hash Set” packages to add to OSForensics when scanning a system to rule-out known system files from suspect files worth closer inspection. It also include a “timeline view” function to provide understanding on system events and activity.

Did I mention that it is offered in both x32 and x64 bit versions? Nice!

PassMark is very active in releasing updates to their beta product so development and improvement of the tool is clearly serious stuff here.

My one “gripe” at this point is the decision to require a full system install first, then from there create a OSForensics - Install OSForensics to a USB Flash Drive build.  I’d rather they take a tip from Piriform and just offer both the full-install or “standalone/zip” packages outright.  It would definitely save time and effort in the updating process considering the frequent update release.  Not a major issue, but something to consider.

Definitely PassMark has brought a handy toolset package to be added to your USB stick for all system admins and incident responders.  I’ve added to to my USB drive.

PassMark also offers some other freeware Tools for OSForensics tools that you may be interested in exploring which round out the full toolset for a response and review:

OSFClone - A freeware “LiveCD” tool to create a dd-based disk-image clone for use with PassMark’s tools (or other tools that support such image files).

OSFMount - Used to mount local disk image files to a drive letter. OSFMount has been released in both x32 and x64 bit versions. (Is it just me or does the drive-mount window look very similar to Olof Lagerkvist’s ImDisk freeware tool?)

image  versus  image.

So if you are comfortable using ImDisk you will be at home with OSFMount as well (if you don’t want to stick with ImDisk for some reason I guess…).

Update: A close reading of the “read-me” file included in the OFSMount package nicely does credit Olof’s ImDisk as the initial base for this utility, thereby explaining the similarity!

ImageUSB - freeware tool to create or write-back images to/from USB flash drives.

Check ‘em all out!  Just deploy wisely.

While looking at Olof Lagerkvist’s ImDisk freeware tool page making sure I wasn’t going crazy with the similarity in GUI, I see he is now offering a seriously updated Beta 1.4.0 version of ImDisk that was released on Dec 7th. Super sweet New Year bonus!

Per Olof’s Update description (bottom of list) for ImDisk Beta 1.4.0, I’m quoting below:

  • Beta release ImDisk Virtual Disk Driver version 1.4.0:
  • Corrected a serious bug that seems to have particularily caused blue screen crashes on 64 bit Windows versions on multi-processor computers. Thanks to Bruce Cran for helping the project with debugging on 64 bit architecture.
  • Graphical user interface, that is Control Panel applet and right-click menu option in Explorer now shows option to add MBR (Master Boot Record) while saving disk contents to image file.
  • Algorithm for selecting default virtual disk geometry (C/H/S geometry) for virtual hard disk volumes changed. From this version, driver will auto-select 255/63/512 geometry in most cases. Only exception from this is when virtual disk is smaller than about 2 GB in which case smaller tracks per cylinder size is choosen. User defined virtual geometry can still be manually selected using command line or API directly.
  • ImDisk source archive now contains a subdirectory called ImDiskNet. This is a .NET dll file which could be used from for example VB.NET or C# to create/modify/delete/save etc virtual disks. This dll also contains a class that can be used as a COM object from VB6 or VBScript etc. This dll is also available for direct download here.
  • 64 bit setup now installs 32 bit imdisk.cpl and imdisk.exe in addition to the usual 64 bit versions. This means that API calls and command line calls will work from 32 bit applications even on 64 bit Windows without tweaking with installing dlls manually in correct directories etc.
  • Updated "devio" tool. This version supports both reading and writing dynamic resizing .vhd files used by Microsoft Virtual PC, Virtual Server and Hyper-V. Earlier version had a serious bug that would corrupt disk image when mounted for both reading and writing.
  • Changed notification that is sent to other applications when a new virtual disk is created. ImDisk does no longer wait for all applications to process the notification. It however still waits for all applications to process the notification that is sent when a virtual disk is about to be deleted.

Did you catch that? Devio got updated as well. For more information see this old GSD post: Devio: Remote drive access and acquisition.

Maybe OSForensics can incorporate Devio in their forensic solution package(s) somehow as well in the future for “agent-based” capture of a remote system from within OSForensics?  Just another suggestion.

From Sweden with Love

Erik Hjelmvik, creator of the beloved NetworkMiner Network Forensic Analysis Tool (NFAT) and Packet Sniffer as well as the SplitCap - open source pcap file splitter also offers his SPID Statistical Protocol IDentification project also for Windows systems.

Erik also recently published an article recently titled Network Neutrality and Protocol Discrimination over at CIO.com that shows the application of his SPID tool.  Neat stuff.

Utils

Two more final utilities worth looking into:

USB Write-Blocker - Document Solutions, Inc.  Freeware tool you run-first before attaching a USB drive to look at.  It promises to prevent OS system write-back to the USB device once attached.  While certainly no substitute for a good, physical Forensic in-line USB WriteBlocker, once “proofed” for effectiveness on your analysis bench-system, it might be good software-based solution in a pinch.

BinPack: 2.0.1 Release - West Coast Hackers.  This “new” package release (actually back from August 2010) updates and rounds out a really cool pentest/security/response toolset manager.  Download the core files, then select, build and download the various independent software binaries from their developers and homepages.  Pick what you want; you can always go back and add/remove more later.

Happy hunting!

--Claus V.

Read More
Posted in boot-cd's, forensics, Link Fest, Linux, networking, security, software, utilities, Win FE | No comments

Quick-Tip : Blu-ray tip for Sony SDP-S360

Posted on 9:10 AM by Unknown

It’s been a long while, but we’ve been thoroughly tickled pink with our BDP-S360 Blu-ray™ Disc Player from Sony.

Quality has been awesome at full HD 1080p and it was a real steal at the price we paid to join the HD/Blu-ray crowd.

Only issue is that when I purchased and played the Blu-ray edition of Leap Year quite some time ago, when it reached a climactic scene near the end of the movie in the pub, I would experience extreme pixilation, playback freeze, and then a crash.  Mashing on the FF button usually kept it alive though the process but would jump to the end of the movie.

I kept looking for reports of bad-disk manufacturing error, but hadn’t found any.  The disk was clean and had no visible scratches or blemishes that might have interfered with play-back as far as I could tell.

So while researching another (unrelated) Blu-ray thing, it struck me that maybe the device codecs/DRM information might need to be updated on the Sony appliance.

I knew from the get-go that the unit came with a Ethernet port and could have the firmware updated either “on-line” or via manual burn & play of a firmware update CD.  When checked, it was sitting on version .002 as loaded at the factory.

I don’t keep it attached to the network so I had to temporarily string my super-long Cat-6 GeekSquad patch cord down the hall to plug in.

Following the on-line information on this Sony eSupport - BDP-S360-specific page, I

  • Checked the Current Firmware Version (yep was as .002 and Sony offering .008 as most current), then,
  • Followed the Network Upgrade Instructions

About 5-10 minutes later the system powered off after downloading and applying the firmware update.

With Alvis carefully shadowing me and providing additional guidance and encouragement, I powered it back on and re-tested my LeapYear Blu-ray disk and popped over to that chapter section of the disk that always caused the player to bork-out.

Perfect playback.

So, lesson learned, if you have a Blu-ray player and it supports  updating of the firmware, and you are experiencing play-back issues with disks, seriously consider checking your firmware version and update if available.

It might really spare you unnecessary aggravation.

Cheers!

--Claus V.

Read More
Posted in hardware, movies, troubleshooting | No comments

New Year’s Day - First Post 2011

Posted on 8:47 AM by Unknown

Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over at ReadWriteWeb.  According to the study, blogging activity on-line has heavily dropped, while on-line content consumption has continued to grow.  Looking back at my side-bar, I have to confess that my raw content-generation post numbers have declined since my high-water mark in 2007.  However I would like to argue that while volume has decreased, quality has increased slightly.

Of course, the amount of leisure time I have available has also decreased which accounts for much of the decline in GSD posting.  At the same time, I could probably work on being more disciplined with some of my time.  Couple that with our “study” slowly turning into a laundry-room/super-closet of sorts and my blogging desk hidey-hole has disappeared. Yesterday I took down and stored away the Christmas decorations for another year (almost two-weeks early from my usual procrastinations).  This brought on a major re-setting of the living/family room area and I now have a micro-desk area set up there instead.  Maybe that will stimulate the blogging juices as well.

In the meantime, here is a getting-the-new-year started linkfest of new applications and neat utilities to jump-start the effort to push the GSD post-count for 2011 upward again.

FreeCommander XE Beta now public

FreeCommander remains my #1 top go-to dual-pane file manager.  I’ve tried tons of other file-managers and while there are many great options out there now, IMHO, none come close to the features and flexibility of FreeCommander.  It just works with the way I jockey files all day.

The developer, Marek Jasinski, was kind enough to give me private access to the alpha builds of the next generation of FreeCommander and I have been diligently putting them through the paces.

So it just in the last week or two that he posted the first publically available release of FreeCommander XE.  While it retains the same form and function of FreeCommander, the style has been seriously updated and the fine-tuning control is greatly enhanced.  You can get both the install version or a “portable” zip file version from that page.  Just be aware that it is still clearly a developmental “preview” release so while most of the features will work as planned, you might be a bit frustrated with what still does not if you are a power FreeCommander user.  I’m still not ready to replace the latest stable version of the “old” FreeCommander with this version just yet.  But it is a nice look at what is to come.

Other related tips that might be of use to you if you are both a FC user and a TeraCopy user.

  • Integrate in the TeraCopy freeCommander - Basskarre.de via Google Translate
  • FreeCommander Forum • View topic - Integrate TeraCopy ?

Run Command Links

When I am setting up special purpose XP systems, sometimes I have to make some tweaks to system settings.  Going the long way through menu systems to get to a particular windows is time consuming, so pulling it up via a run line is a big time-saver.  I’ve memorized many of them, but every now and then I can’t recall and Windows doesn’t make it easy to access the commands if you don’t know what they are to start.

Here are three bookmark-worthy resources for just when you need them most (XP/Win7).

  • 174 Run Commands For Windows XP - Very Useful - PCRunEasy
  • Run Commands for Windows 7 - Windows 7 Forums
  • Run Commands in Windows 7 (List) - Windows 7 Bits (included as though it has much the same content of the one above, the comments are filled with many more cool items.)

VirtualBox 4.0 Final

Oracle has now released the final public release of VirtualBox now sitting at 4.0 - Downloads - VirtualBox.

You can also get it via their ftp page: Index of /virtualbox/

Brett Shavers of WinFE Blog fame recently reminded me of the MobaLiveCD tool.  While not related to VirtualBox, it does provide a clever and portable Qemu package to run virtual sessions of LiveCD’s for down-n-dirty testing.  It worked on my rippin-fast Win7 x64 laptop, but was very, very slow in performance.  So while handy in a portable pinch, it probably isn’t useful for production-level virtualization work.

There is also vbox.me ‘s Portable-VirtualBox project.  As I understand it currently, while there is a v4.0.0 new release support out, Oracle has now required the developer to remove direct inclusions of VirtualBox items from the package, and it is now set up in a manner that first downloads the VBox binaries then unpacks them for the portable setup process. And USB support still is in works as well at the moment.  YMMV.  See also How To Make Portable VirtualBox 4.0 For Windows at addictivetips.com

Network Briefs

Always a great source of personal tippage, TinyApps passed on a lead to the Dualcomm Mini USB Powered 5-Port 10/100 Ethernet Switch TAP.  How cool is this at less than $100? They also offer this larger Dualcomm USB Powered Gigabit Ethernet Switch TAP at a $150 price point.  In both cases Port #1 is mirrored to Port #5.  See also this brief post by George Starcher » Review – DualComm – Ethernet Tap.

Speaking of taps, in a former GSD post on the subject I offered these references:

As such here are some related materials on that subject for future reference when needed.

…But first, read and review this brief TaoSecurity post on SPANs versus Taps: TaoSecurity: Expert Commentary on SPAN and RSPAN Weaknesses

It links to two MOST Excellent articles on the issues of using spanned switch ports for collecting your network capture data, both form Tim O’Neill:

  • SPAN Port or TAP? CSO Beware (by Tim O’Neill)
  • RSPAN … Friend or Foe? (by Tim O’Neill)

OK, now the linkage on SPAN’ing

  • Catalyst Switched Port Analyzer (SPAN) Configuration Example - Cisco Systems. A definitive resource.
  • Port Mirroring on a Cisco 3550 Switch -danielmiessler.com
  • Security Wizardry - Switch Port Mirroring
  • How to Configure Local SPAN Port on Cisco Catalyst Switch - ItsyourIP.com

And my oldies but goodies favorites:

CDP - What Switch Am I Connected To? and Monitoring Traffic with Span Ports – SynJunkie.  Two really great posts out of series of ones touching on network monitoring, and Cisco switch/router configuration techniques.  I’m singling these out in particular as they are of interest to sysadmin troubleshooting on the network as well as traffic captures.

And recently found this Wireshark Wiki article as well -- CaptureSetup/Ethernet.

Which is neat as I just ordered up some additional reference for the new year: Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide by Laura Chappell, Gerald Combs.  I sooo can’t wait for this one to arrive!

Finally, the Microsoft Network Monitor blog has this new post: Filtering On Timestamps which is good information to know if you prefer Network Monitor or NMcap (CLI) for your traffic capture handling.  Don’t miss the tip link to the online Date format converter page to assist in your conversion work.

Utility Roundup

Via the German blogger Caschy (through Google Translate magic), CopyTrans TuneSwift.  There are more than a few ways to move your iTunes stores from one system/location to another…though they all have their own quirks and shortcomings.

Check out either the CopyTrans Suite of tools or the CopyTrans specific utility as it may have a full-featured backup/transfer/restore solution you are looking for for iTunes/iPod management and recovery.  Currently CopyTrans is being offered for free, but will switch to a pay-version 03/15/2011.  You will need an unlock code so either use the one Caschy has provided on his page or the direct one on this CopyTrans page.

Because I never can remember the conversion rates for bps to Bps to Mbps as I deal with various network bandwidth graphs I’ve settled on Converber Portable over at PortableApps.com to prove me a super-handy tool for all my IT figure conversion needs.  Tip: While it can do so much more, just set the “Category” field to “Computer” to filter down the list of over 1324 various units of measure in 38 categories to just those used in the IT field.  It’s much less overwhelming that way!

ImageX GUI (GImageX) still remains my fav ImageX CLI Gui-based tool for super-fast WIM management.  However, 4SYSOPS recently posted about an alternative ImageX gui manager GDism ELDI v3.0.2. As Michael Pietroforte points out, the strongest feature/drawback might be the fact that it is a Java application so depending on your viewpoint on Java, that may or may not be a good thing.  That said it is a nice alternative. (Note: the CGI ‘avatar’ figure displayed on the ELDI page might be a bit racy for some so depending on policy standards, you may want to check the page out at home first before hitting it from work…just to be safe.)

First there was Orca for picking apart and manipulating MSI packages. Then came InstEd It! which seriously seemed to expand the options available.  Then I really fell in love with the light but perfectly handy (for me) lessmsi tool (still alive and cool). Now comes wind from Kurt Shintaku via his blog post RELEASE: MSI Explorer – Inspection Tool for .MSI installation packages of yet another MSI package inspection/change tool; MSI Explorer coded by Sateesh Arveti.

Ryan at CyberNet News seems to have slowed down on the blogging as well, but his post Stress Test a PC with HeavyLoad offers an additional (portable) freeware tool that can be used to put the heavy on a system for load-testing and performance monitoring.  Don’t forget other beefier tools such as the Phoronix Test Suite and Inquisitor. MakeUseOf blog also offered a while back The 5 Best Free Benchmark Programs for Windows.

See also the JAM Software - FileList CLI tool (freeware) for generating file-lists in a given directory.  Check out the ReadMe for additional CLI arguments.

What the Web Says…

Sometimes you have to go to the Web to find out just what is what and where stuff is ranked.  These were pretty cool finds this past week.

Browserscope - From the web-page “Browserscope is a community-driven project for profiling web browsers. The goals are to foster innovation by tracking browser functionality and to be a resource for web developers.”

namebench - From the project page “It hunts down the fastest DNS servers available for your computer to use. namebench runs a fair and thorough benchmark using your web browser history, tcpdump output, or standardized datasets in order to provide an individualized recommendation.”

See also the super-tiny, fully portable GRC’s DNS Nameserver Performance Benchmark utility for a no-install alternative.

Finally, got an Intel chip-based Windows system? You might want to hop over and try the Intel Driver Update Utility.  Ed Bott gets the hat-tip and has more information on his How to update Intel drivers automatically blog post.  I found a very new wired Ethernet port driver update for my new Laptop.  Please carefully note this one item from the Intel page easily overlooked:

Intel® Wired Networking note: If the Intel Driver Update Utility shows your Intel wired networking product ending in '(OEM)', Intel recommends you use the networking software provided by your computer manufacturer. OEMs may have optimized the drivers for your system.

Happy New Year!

Claus V.

Read More
Posted in blogging, command-line interface, hardware, imagex, iPod, iTunes, Link Fest, networking, utilities, virtualization, Windows 7, XP | No comments

Thursday, December 16, 2010

Worn Down and Rusted Out Linkfest Edition

Posted on 6:19 PM by Unknown

worn-down-rusted-out

cc attribution: 14. An Antique Truck by Jinx! on flickr

Thanks for the messages of kindness checking on me that a few GSD faithful have sent in over the past few weeks.

I’m pleased to say that Claus V. is still alive and kicking…just worn down and rusted out a bit.  As many of you have correctly surmised, work assignments have pretty much overwhelmed me and left me with little energy left except for watching Phineas and Ferb, iCarly, and Bones with the ladies off the DVR on the few free hours when I drag home at night as well as wearily wake up on the weekends.  Everyone has had to really crank up the productivity (already red-lined) due to economy pressures with more special-projects in the pipes.

I even got some time off today to catch the Disney movie “Tangled” with Alvis this afternoon.  I’m a sucker for princess movies!  I can’t wait to put the Blu-ray version of this one next to my “Enchanted” disk set.  Good family movie for all ages!

Anyway, the positive news from this unplanned blogging hiatus is that I have really been able to focus on applying many of the security/forensics tools and techniques in a myriad of very unusual incidents so while I am still exhausted to the frame-rails, it’s been a fun trip along the way.   Look for some neat stuff soon from that camp.

Nor have I been taking a “Net-free” sabbatical.  The RSS-feed collector has been diligently at work as well and I’ve been distilling the results to some of the most interesting and helpful links of all that survived the winnowing process.

So, without more ado, sit down, strap in, and hang on tight.  The Linkfest begins!

Microsoft Security Essentials 2.0 ?

Microsoft Security Essentials 2.0 looks like it may have been released.

Microsoft Security Essentials - Microsoft Download Center. Publish date 12/16/2010  (Note: as of this post, that link still shows a version number of “1”.)

I've been running the Beta MSE 2.0 versions on our Windows 7 x64 & x32 systems for some time and have been pleased. Love the inclusion of a right-click context menu "scan with MSE" menu item now.MSSE2.0.6.57.0

This morning my Beta MSE version was 2.0.522.0

After downloading and over-installing the new setup file version downloaded from that page, it now checks in at 2.0.657.0

Some more info on what the new edition offers over at this Security Essentials 2.0 releasing tomorrow mynetx post.

I assume patient users of MSE already will eventually get a push/Windows Update to bump it.

Meta data in the setup file (x64 version) I downloaded and used did report it was a 2.0 version as well…so maybe MS hasn’t updated the version number on the page until an official release announcement…or it could be one last final beta bump before the final release?  I’m not certain.

Spotted over at the (German) Caschys Blog post:  Microsoft veröffentlicht kostenlose Sicherheitslösung Security Essentials 2.0

i-odd Firmware updates and other multi-boot/formatting toys 

I-Odd has released some firmware updates.  If you don’t recall the iodd : Multi-boot madness! post, the i-odd is an external USB2.0/eSATA drive enclosure that allows you to store boot-disks in ISO format and then boot a system with any of them via the selector toggle.  It is wicked cool.

The US i-odd site is offering Firmware Version 1.42.48 (ISO) that supports either FAT32, EXFAT or NTFS partition handling for loading disk images.  Until recently only FAT was supported.

The Korean manufacture's i-odd site actually is serving an even newer firmware version at 1.42.53.

Take your pick.

FAT/FAT32 formatting limitations typically have restricted partition sizes so you have had to use alternative formatting tools to get around those limits if you wanted a really big FAT32 partition to store your ISO’s on.

TinyApps.Org Blog recommended the FAT 32 Formatter from Ridgecrop Consultants Ltd.  If that CLI version isn’t to your speed, they also offer a Windows GUI version of fat32format.  Miles’ recommendations are always golden so that’s the tool I still use.

I recently found mention Fat32Formatter which has a slightly different GUI.

That was picked out from RMPrepUSB HomePage which has an interesting tool to partition/format USB drives and make them bootable for SysLinux or grub4dos bootloaders. 

That was found via this XBOOT vs 1.0.0 beta4 - reboot project that is working to aid in the creation of a multi-boot USB builder.

All this is still very interesting, but TinyApps’s find of the i-odd device makes all these exercises almost academic.  Get the enclosure, buy a 2.5” drive to stick in it, update the firmware, and copy your boot ISO images over to your heart’s content.  Then just toggle to the ISO you want to boot with, select it, and boot away.

One last TinyApps mention: check out his amazing documentation work TinyApps.Org : Mounting disk image partitions.  He sent the link to me some time ago but I’ve been swamped and only had time to do very limited Linux-based work at work so I haven’t been able to give it its true due.

Secunia PSI 2.0 Beta Available 

Security company Secunia announced in September the release of the PSI 2.0 Beta.

Auto Update your Programs - Secunia PSI 2.0 Public Beta - Secunia Blog

From the blog post, the engine remains the same but the user interfaces, the auto-updates, and reporting have all been revamped. Secunia PSI changelog

While I and everyone else can continue to benefit from the cloud-based Online Software Inspector (OSI) version, having a localized Personal Software Inspector (PSI) on your Windows system can go a very long way to ensuring your applications are able to be kept current without much mess or fuss.

Adobe Advances

The Adobe folks have been hard at work revamping and prepping a number of products that are often found on many enterprise and consumer Windows systems.

Adobe Labs - Adobe Flash Player 10.2 beta - This is the latest “mainstream” Flash beta version.  It includes enhanced support for IE 9.0 releases and full screen mode support for users with multiple monitors.  However it only comes in a x32 bit release version.

Adobe Labs Download: Flash Player 10.2 Beta Release

Adobe Labs - Adobe Flash Player "Square" is also available and does include x64 bit support for Windows, Mac OS, and Linux.  I’ve been running this one on my x64 Windows 7 system with no issues at all.

Adobe Labs Download: Adobe Flash Player "Square" Preview Release

Related: How-to: Disable Chrome’s built-in Flash to use a Flash beta release. DownloadSquad

You may also have heard Adobe released version 10 (a.k.a “X”) of the Adobe Reader.

Adobe Reader X is Here! « Adobe Secure Software Engineering Team (ASSET) Blog

Adobe - Adobe Reader download

PDF security guru Didier Stevens has some initial thoughts: Quickpost: Adobe Reader X and provided a wicked-helpful link to Adobe’s FTP server. The en_US FTP folder contains both msi and exe based installer versions!

To add to the helpfulness, Aaron Parker at StealthPuppy has a number of great Adobe Reader deployment tips and tricks postings.

Deploying Adobe Reader X | Aaron Parker

Uninstalling Adobe Reader | Aaron Parker

…including a tip-out to the Customization wizard for pre-deployment installer tweaking; note you can get the 10.x version from the FTP site.

Network Nuggets!

One of the duties that has required a lot of my time has been network monitoring and traffic analysis.  I continue to make good progress with Microsoft’s Network Monitor 3.4; specifically the nmcap.exe CLI tool.  I’ve not had a dropped packet yet during a capture session.

Marking Frames with Network Monitor 3.4 - Network Monitor Blog

Network Monitor Freezes While Loading Capture - Network Monitor Blog

CodePlex Parser Site - Check for the latest Network Monitor parser sets here.

In case I haven’t mentioned it recently (it’s been a while) inSSIDer Wi-Fi Scanner over at MetaGeek is now out at version 2.0.  It was a great help tracking down a network tap some time ago.

And despite my comfort and pleasure with Network Monitor 3.4, I am now trying to transition back to Wireshark.  NM3.4 only seems to output in “cap” format, not pcap.  That’s no big issue but I then have to do an extra step of “editcap -F libpcap infile.cap outfile.pcap” to convert things.  This has been quite fast, but it is a step I shouldn’t have to be taking. 

My biggest complaint to date with Wireshark (and it’s a noobie one) is that I kept getting occasional crashes during capture in the Wireshark GUI mode.

However since I’ve gotten comfortable working in the NMcap CLI tool mode, I’ve started flirting around the the TShark CLI utility for captures as well.  It seems to be more stable for longer-run capture sessions.

Along those lines I’ve been collecting resource links on TShark:

Tshark examples: howto capture and dissect network traffic - CodeAlias

tshark filters - PacketLevel

tshark examples - random notes

TShark Packet Filtering - TheSprawl

Wireshark/TShark Utilities - TheSprawl

Pcap format is essential as I continue to use the NetworkMiner Network Forensic Analysis Tool (NFAT) and Packet Sniffer for much of my post-capture analysis work.  Unfortunately, it doesn’t handle NM “cap” format files, thus the conversion to pcap first in editcap.  So capturing in pcap native files is a time-saver.

You may also recall that I’ve been restricted to using an older .88 version of NetworkMiner as some packet captures end up forcing a premature shutdown in versions up to the current .92.  I actually was able to engage developer Erik Hjelmvik in this Topic: Versions past .88 prematurely exit discussion.  He was awesomely kind and patient.  We eventually took the discussion off-line and with his gentle guidance I was eventually able to provide him some helpful data that explained the issue.  He thinks that the issue “…could occur when there are partially overlapping TCP segments at the same time as the TCP packets arrive out-of-order.”

A future version of Network Miner should address this issue, and bring many more enhancements.  Hopefully Erik will release an updated version soon!

It was really challenging but really rewarding having the opportunity to work with Erik on this issue.  He is a really great guy for kindly providing that level of support to me on a free-to-the-community project.

Microsoft Tips, Tricks, and Treats

Download details: The Windows® Automated Installation Kit (AIK) for Windows® 7 - Released in mid-November under version 2.0.

The Case of the Slow Project File Opens - Mark’s Blog; troubleshooting awesomeness!

The Windows 7 Guide: From Newbies To Pros [FREE EBOOK] - MakeUseOf - Nice resource for you all who are planning on handing out Windows 7 systems as gift to current XP users.

Enhanced Event Viewer for Windows 7 released - The Windows Club is a fancier version to view and search event logs.  Pick it up over at the sateesh-arveti - Site Home  on TechNet Blogs

Tenniswood Blog has an update tip on How to enable Remote Desktop in Windows 7 Home Premium.  Follow his links to grab the new and improved bits.  Me?  I’ve still got this around on our home systems as a “just in case” but am really loving the TightVNC 2.0 application even more.

While we are still on the subject, MakeUseOf blog has a really interesting Control Your Computer Remotely Using HTML5 With ThinVNC post worth checking out.

The Best Ways To Customize The Welcome Screen In Windows 7 by Simon Slagen on MakeUseOf has a trio of ways to modify your Windows 7 login screen ranging from the very simple to the very complex. Of them, I agree with the post and found that for most users the Logon Screen For Windows 7 tool by DanielNET software was the easiest to use.  That said I’m surprised my first utility to encounter in this class, Windows 7 Logon Background Changer didn’t get included.  It hasn’t let me down yet.

Image is Everything

TOOL: Image Resizer 2.11 for Windows 7/Vista  - Kurt Shintaku’s Blog is a dead-simple, integrated way to let anyone quickly and easily resize their images fast.  It’s a must add.

Freemake Video Converter updated with cool new features - freewaregenius.com is yet another great and very full featured video converter.

Lightworks - Open Source highly complex but wonderfully approachable video editor is out in a public beta.  I’ve been waiting for this one for some time and am amazed it is sitting on my desktop.  The GUI is very well designed but start digging under the hood and I think this tool has the stuff to leave the other freeware/open-source video editors in the dust.  For a Windows platform, this must be seen.  I’m itching to get a new video-production project to toss at it.  This is not for casual users who might find Windows Live Movie Maker 2011 or another similar non-MS product easier to get started with.  Registration (easy and free) with Lightworks required to get the download bits.  Lots of documentation in PDF form is a happy bonus.  Requires download of third-party “Matrox VFW” codecs.

For other options and software tools in video editing see this GSD Blog Video-Editing Resource Roundup.

Finance Planning Tools 

Things have been very tight around the Valca home.  For almost the past two years we have had to painfully downsize to a single-income family lifestyle.  It has been almost that long since Lavie was able to work.  However thanks to discipline and the kindness of family and friends, we have weathered the belt-tightening fairly well.  Hopefully the new year will bring new riches both in terms of our family employment outlook as well as the bank account.

We continue to benefit from the use of Microsoft’s free “Sunset” edition of Microsoft Money Plus.  I’m using the Money Plus Sunset Deluxe version but there is also the Money Plus Sunset Home and Business. 

However, if you trust and and are looking for a cloud-based financial planning tool, check out the following finds:

Sprouty - Simple and easy budgeting

Mint.com

Either of these along with some healthy Finance & Family encouragements from zenhabits, those (by choice or circumstance) living in the “simple life” may find some great tools and resources to help them breath.

More Utilities

These didn’t seem to fit in other categories, so here they reside:

CSV file editor, for Windows - CSVed is now updated to version 2.1.3.  This freeware tool has saved my rear lots of times for complex pre-editing of tricky CSV files before dumping into Access or Excel.

BulletsPassView - NirSoft’s new build to view the passwords stored behind the bullets in Windows / IE.  Doesn’t work for everything but is super-useful in a pinch. May set off AV as “hackware” or PUP.  That’s a AV thing nothing wrong with the tool in the right hands.

6 Must-Have Apps For Computer Repair Technicians - MakeUseOf blog.  Interesting roundup. Not what I would pick for my “must have 6” list, but they are worthy to add to your toolbox.

FOG-ing the Future?

With only a literary nod to JKR, the FOG project is one really neat looking project.

fogproject.org

FOG allows for Windows system imaging capture/deployments from a Linux OS.  It is very cool looking and very neat, particularly with an almost turn-key PXE-based capture/deployment solution.

Windows Image Deployment with FOG - Petri.co

Lifting the Fog - Compendium IT

Cloning Windows 7 VMs Using FOG - The Horrendous World of IT

FOG - Computer Cloning/Imaging solution Server (0.27) - VMware Virtual Appliance Marketplace

See also these FOG Project Video Tutorials

There is a lot of documentation and YouTube video resources and it looks to be a very mature (and still developing) project.

If you haven’t heard of FOG yet, it’s worth checking out, particularly if you are an imaging guy.

That said, I still like working with Microsoft ImageX WIM file images and deploying them in PE-based methods in our environment.  Being able to off-line mount and service image files has helped me lots of times.

Virtualizations

In the “Lifting the Fog” link above, the author incorrectly states that the virtual version of FOG uses Oracle’s VM VirtualBox.    That isn’t correct.  It is a VMware appliance version, not VirtualBox.  I guess it is easy to get them mixed up by name alone.  I currently have Windows VirtualPC, Oracle’s VirtualBox, and VMware’s VMware Player all installed on my system!

VMware Player still is getting updated (and remains free).  If you don’t want to register to get the bits from VMware, try this Download VMware Player 3.1.3 link via FileHippo.com.

Think the VMware Player will trap you into using only pre-configured VMware appliances?  Check out the free VMware resources by developer DEVFarm Software such as the really cool VMX Builder. One of may cool tools at VMXBuilder.com

VirtualBox fans may be surprised (or not) to learn that while the public build of VirtualBox is at 3.2.12, if you dig around you can find and use VirtualBox 4.0 beta builds.  I’ve been using these for a while and they are really nice!  I really find the GUI interface improvements particularly enjoyable…not to mention all the under-the-hood updates!

Download VirtualBox 4.0.0 Beta 3 - Change Log - FileHippo.com

Index of /virtualbox/ - Oracle’s FTP site for direct VirtualBox bits including the [DIR] 4.0.0_BETA3/

Whew!

Hope you found something here enjoyable and I appreciate the GSD fans who have been waiting for a new post.

Check back again soon for the forensics and security linkfest followup.

Even more goodies await!

Cheers!

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, family, forensics, graphics, imagex, Link Fest, Microsoft, networking, PDF's, Remote Support, security, utilities, video, Virtual PC, virtualization, Windows 7 | No comments

Sunday, October 17, 2010

Books, Networks, Security, and Forensics

Posted on 2:14 PM by Unknown

The little-brother endowment for big-brother improvement has allowed for the recent expansion of my technical library by three more volumes.

I have just ordered the following books after a long wait in my wish-list pile:

  • Network Warrior: Everything you need to know that wasn’t on the CCNA exam by Gary A. Donahue (Amazon.com)
  • Mastering Windows Network Forensics and Investigation by Steven Anson, Steve Bunting (Amazon.com), and
  • Windows Forensic Analysis DVD Toolkit, Second Edition by Harlan Carvey (Amazon.com)

I had flirted with also picking up the Wireshark Network Analysis: The Official Wireshark Certified Network Analyst Study Guide by Laura Chappell, Gerald Combs (Amazon.com) but decided instead to invest in a Canon Speedlite 270EX Flash (Amazon.com) for our Canon Rebel DSLR as all work and no play makes Claus a cranky boy.

The first two selections reflect an expansion and recognition that understanding and analyzing network traffic can not only complement Windows systems forensics and incident response, but in some cases be the canary in the mine that signals something much larger is going on worthy of focused investigation at the machine level.

A recent series of events have driven both these points home to me in a very powerful way.  So I really am excited waiting for their arrival.

As for Harlan’s book, it really is one of the cornerstone books of Windows forensics and I’ve really felt weaker for not having read it yet.  I’m truly honored and stoked to be adding it to my bookshelf.

The nature of my work demands that I approach things from an holistic approach and I really hope that the combination of these materials gives me a sharper edge in analysis as well as how all the parts can better fit together.

In the News:

(IN)SECURE Magazine issue 27 released - Great security and risk-management articles in portable PDF reading format.  I’m always waiting for the next edition!

Hiberfil Xpress and FTK Imager 3 posts - Forensics from the sausage factory.  DC1743 tears into the Hiberfil and touches on it’s compression as well as new support (script) for examination via EnCase.  The second post points out the awesome and free forensic image capture tool (and then some!) FTK Imager 3 is now out from AccessData.  This newest version does require a system-install, but they have also released a bumped version of their free/portable “Lite” version to 2.9.0. Go get’em!  AccessData Product Downloads

CAINE 2.0 Live CD - “NewLight” computer forensics digital forensics - LiveCD Distro - I was unexpectedly surprised to discover CAINE 2.0 “NewLight” was released in the past few weeks.  CAINE and DEFT both are my current favorites for Linux-based “LiveCD” distros and are jam-packed with complimentary toolsets.  CAINE 2.0 has a fresh look and updated features all the way around.  I’ll save post-space here by not posting a list of all the new and updated feature-sets, but suffice it to say, it really  is super-slick and just like mighty-mouse, lots of power in a small size!

Gift Card FAIL: What do sequential numbers and shopping sprees have in common? - PaulDotCom - Yeah…worrying.  Besides the obvious issues, what really stands out to me is that I’m not the only one who can’t seem to turn their brain off from security/incident response musings…even when off-the-clock.  Every situation and every place presents opportunities for mental security pushup work.

Asset Tags For Dummies - Liquidmatrix Security Digest.  Part II from the theme above.  Really, we also stick honking-big asset tag stickers prominently on our equipment that can be read from 10 yards or greater away, with enterprise name and everything.  Plus the brand of our whole-disk encryption provider on a separate sticker.  “So we can tell which systems are whole-disk-encrypted” easily by just looking at the case.  At least that was the justification provided.  Really?  Can we?

Memory forensics on Windows 7 (x86 and x64) and Windows 2008 x64 and Avoid the Knee Jerk Reaction -M-unition Blog.  Two great posts from the MANDIANT gang including the announcement of the release of Memoryze 1.4.2900 which has added support for Windows 7 64-bit, Windows 7 32-bit, and Windows 2008 64-bit along with the previously supported platforms.

Free Malicious PDF Analysis E-book - Didier Stevens.  Go grab it now!

FireMaster : The Firefox Master Password Recovery Tool - SecurityXploded.  Free tool to recover the master password from Firefox.

Symantec’s w32_stuxnet_dossier (PDF) is a perfect model of how a incident/threat analysis report should be written.  It seems to set a new gold-standard for informative analysis and technical writing for malware/threats.  Wow!

Tshark/Wireshark SSL Decryption - Lessons Learned - PaulDotCom - Mark Baggett has written a great tutorial on how to configure Wireshark to decrypt SSL packets.  Great stuff.

PrefetchForensics v1.0.3 : woanware - Mark Woan has made some improvements to this free Windows Prefetch file analysis tool.  Update your copy now!

Forensic analysis of "Frozen" hard drive using Deep Freeze - Computer Forensics, Malware Analysis & Digital Investigations.  Deep Freeze is one of several “steady-state” system solutions that “restore” a Windows system back to a predefined configuration when the user’s session is over.  In theory this should erase all tracks, but as all good forensicators know, there’s gold in in the streambed one you dig just under the surface a bit!

Xplico » Xplico 0.6.0 - Just released!  Xplico is a Linux-based tool that allows for reassembly of network traffic browsing sessions.  I’ve been having to use it quite a bit lately and find as I get to know its capabilities better, I am floored by the power and benefit having this tool in my arsenal brings me.  I’m planning a followup post on Xplico very soon here at GSD.  Stay tuned!

Happy Digging!

--Claus V.

Read More
Posted in books, boot-cd's, browsers, Firefox, forensics, security, utilities, Windows 7 | No comments

Mostly Minor Network Notes

Posted on 12:55 PM by Unknown

Here are some minor tweaks and features, mostly of a network nature.

Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- because sometimes the uninstaller just doesn’t work, and the new installer won’t put it on, particularly with that stubborn Deterministic Networks package present.

Get the Classic Style Network Activity Indicator Back in Windows 7 - How-To Geek.  I’ve not been impressed with the lack of network activity indication on Windows 7.  Sure, it is a very weak and basic way to see if and when you are having network issues, but it can be a good first warning.  This Network Activity Indicator for Windows 7 via IT Samples is a very good approximation to the XP system tray indicator.

How to Optimize Network Connections in Windows XP - Windows Networking - On my XP system at work, I’ve got several network connections available, though some are used more regularly than others, and within them, some bindings will not be used ever.  So it seemed to me that it would be nice to rearrange the preferred order of the network connections, and disable any unneeded bindings for good measure.  This article was perfect.  In no time I had resorted and tweaked them.  Subjectively I think it helped a bit, but I didn’t actually benchmark before/after performance.

While useful at work and easy to do on the XP systems, before long I was wondering if I could do this same thing on my home Windows 7 laptop.  For my own system, depending on where I am sitting in the house and what I am doing, I may prefer to hook up via a wired Ethernet cable rather than using wireless…watching videos or downloading mega-files (Windows Updates, software packages, virtual appliances, Live CD ISO’s, etc.).  However, I was getting frustrated as despite plugging in the network cable pre-boot, I always seemed to be defaulting to my wireless connection instead!

So I had been manually disabling the Wi-Fi then forcing it to go to the Ethernet cable.  But that just didn’t seem right.

I already knew I set a preferred order for network devices in XP, but I just couldn’t find it in Windows 7 as easily.

Then I found this.

How to Change the Priority of Wired/Wireless Network Cards in Windows - How-To Geek

Better, and interesting.   But what about GUI only lovers?

Change Wireless Network Priority to Make Windows 7 Choose the Right Network First - How-To Geek.

Making progress but this is for prioritizing your Wi-Fi network connections, not for juggling both your wired/wired network connections.

So I ended up pulling all the pieces together for a Windows 7 system; and using the “XP” method noted earlier.

Start/Control Panel --> Network and Sharing Center.

On the left side-bar, select “Change adapter settings”

image

On the menu-bar, choose, “Advanced” and from the drop-down menu “Advanced settings”

image

Then in the resulting dialog window, select the network connection(s) and using the green arrow on the right, change them in order up or down accordingly.  Save your changes when done.

image

In my case, I have the Local Area Connection (my wired Ethernet port) set at the top as my preferred item, then my home Wireless Network Connection second.

This way, if I plug in and boot, the LAC takes precedence and connection gets established before Wi-Fi.  If it isn’t plugged in, then the Wi-Fi connection takes over.

Non-Network Tweaks

One of the remaining pet-peeves I’ve had with Tatiana, my new Dell Studio 15 laptop, has been the sensitivity of the touch-pad.  I’ve had to put with with automatic text zooming when I brush against it or hover my thumb over it.  Touching the side/bottom scroll zones on the touch-pad sent web-pages flying up/down & left/right.  It was like trying to manage the throttle of a Mustang 5.0 on a slippery-as-glass wet roadway!

Fortunately, I’m not the first who has found this default Dell touchpad behavior, really, really annoying.

How do I change my Dell Touchpad settings and preferences?  -- Ask Dave Taylor!

Turns out Dell has an embedded “Dell Touchpad” management utility tab embedded in the mouse settings.

Poking around in there, I set the pad sensitivity from “hair-trigger” down closer to heavier touch, I disabled the text-zooming feature, and set the scroll-zones on the touch-pad to be much narrower than default.

A few more fine tuning tests and the touchpad is now no longer a bad-actor but well groomed thespian.

Finally, I added a System Restore Point Shortcut - Windows 7 Forums - great tips on how to make a shortcut to fire off an System Restore Point rather than the longer method.

Cheers!

--Claus V.

Read More
Posted in hardware, networking, troubleshooting, utilities, Windows 7, XP mods | No comments

Sunday, October 3, 2010

Just a Note or Two and some SteamPunk

Posted on 2:21 PM by Unknown

image

cc attribution: Notebooks by See-ming Lee 李思明 via flickr

Wow.  Can’t believe it has been this long since the last post!  What’s sad is that very little of it has been spent on the new laptop.

Mostly bad-crazy work stuff leading me to be exhausted by the time I get home from work. Then honoring time and family commitments on the weekends.  So much to post…so little time.

On the plus-side I’ve been able to really put some of the tools and techniques I blog about into incident response action lately.  While it is never a “fun” thing to have to do, it is pretty cool when you get to apply your knowledgebase in extreme situations.  While (unfortunately) it’s very doubtful I will share any information at all, I do expect to share some more information on tools and techniques I found valuable in the process.

I’m taking a break at the moment from technology posts to go a bit “old-school”.

While I generally use QCC’s freeware tool CaseNotes to document my incident response activities, and find it really does an excellent job fitting my needs I almost always keep a pen and micro-sized paper notebook on my person as well.  Beats writing on my hand and is great for jotting down phone numbers, bits of data, field observations, quotes, URL links, etc.

I’ve been thinking of this lately as I saw some Moleskine mini-notebooks a few weeks ago when visiting the bookstore with mom.  I didn’t pick any up but they did catch my attention.

Then The Art of Manliness blog ran a series of articles that really encouraged me to use them that much more:

  • Pocket Notebooks: A Brief History
  • The Pocket Notebooks of 20 Famous Men

The comments in the first post were a treasure-trove of links and materials for the notebook carrying fan.  I found a number of great sources for fun and functional mini-notebooks.

Field Notes - Seemed to be one of the most popular sources for no-frills “common-man” notebooks.

Rite in the Rain - Was praised by field workers, outdoorsmen, military/LE, and other extreme environment folks.

Moleskine - This brand seems to have splashed onto the market with much fan-fare.  The quality and variety seems to make them very popular with note-takers and artists alike.

Right now, I am using these Top Flight Sewn Mini-Marble Composition Books (Amazon.com) that Alvis tossed my way.  They fit unobtrusively in my front pocket and are surprisingly durable.  They are very cheap…so I tend to toss them when all the note taking is over and they are filled up.  Not really archival material.

I had been using these Mead Wirebound Memo Books (Amazon.com) but the wire ring would get crushed after a few days in my pocket and the pages tore out too easily.  So I just keep one in my car only for quick notes but that’s it.  It will likely be replaced soon.

These Writersblok Bamboo Mini Notebooks looked like a cheap and nice alternative to my current notebook fare. Made by K I K K E R L A N D, they seem high quality and fit the quirky and fun other products offered by them.

Turns out there is a whole fan-following of notebook bearers!

I’ve scored a few new RSS links for some sites that live and breath all things creative and useful with notetaking and notebooks.

  • moleskinerie - a  bit spare in style but I think that’s the point.
  • Notebook Stories: A Blog About Notebooks, Journals, Moleskines, Blank Books, Sketchbooks, Diaries and More - definitely worth saving and checking in on.
  • Rhodia Drive - That little orange notebook.  I like the detective-style hard flip cover.
  • The Notebook Addict - Reviews and perspectives.
  • The Well-Appointed Desk - Writing and Work Desk candy.
  • ’skine.art - Moleskine Art - I sooo wish I could do this.
  • notebookism - tips, leads, hacks, and the smell of fresh paper and bindings…
  • Trains, pens and planners - thoughtful thoughts on notes, life, and mono-no-aware.
  • Museum of Notebooks - Notebooks from around the world.
  • Urban Sketchers - I so really need to dig out my sketchbook an ink-pen set……

The Little Black Book by Pad&Quill - This was pretty clever…and inspired me.  I’m overwhelmed at the moment with ballistic nylon carrying cases for all my portable hard drives and gizmos.  After looking at this, I was struck with how easy it would be to stop by ye-old/used-bookstore and pick up some tomes that had outward character to their binding and cover.  Then hollow them out to make carry-cases for the portable USB HDD I carry.  Some glue and some tiny metal/magnets to hold the lid shut and bam--pretty neat carry-case!

SteamPunk Resources

As a Sherlock Holmes fan, I appreciate the romantic notion of the Victorian era (but accept the Dickensian reality).  Add to that the fact that Last Exile is based heavily on a “SteamPunk” styling and my artistic eye is smitten.

Turns out there is a whole fan-base devoted to making and living SteamPunk style.

Steampunk Wallpaper is a very recent find that has provided a ton of awesome high-quality desktop wallpapers in the SteamPunk/grungish style.  Really stunning work here by the artists.  Even if you aren’t a fan, you are bound to find something appealing.

The Steampunk Workshop | Technology & Romance - Fashion, Style, & Science - Ongoing web-site filled with the very best examples and guides to SteamPunk hardware and software.

The Steampunk Home - Neat ways to add that anachronistic touch of class to your home; many with commonly available materials repurposed.

SteamPunk Magazine » Downloads - Free PDF downloads of SteamPunk Magazine.   Very interesting articles and perspecitves…to say the least!

Happy notetaking and jotting!

--Claus V.

Read More
Posted in blogging, books, crafts, For the Gentleman, Link Fest, writing | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile