<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>OS issues windows and Linux by Daniel Nazri</title>
      <link>https://padlet.com/danielfskik/knlmuu27romns8e8</link>
      <description>Made with the strength to succeed</description>
      <language>en-us</language>
      <pubDate>2020-04-09 02:11:45 UTC</pubDate>
      <lastBuildDate>2020-04-09 04:14:07 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Window does not freeze/disable last modified file.</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499760928</link>
         <description><![CDATA[<div>By default, Windows does show last modified file which are will destroy the evidence. If the investigator accidentally open or edit without having a full backup, the evidence will not be acceptable. In this case, the investigator need to use external hardware  called write blocker that need to be connected to USB drive or edit using REGISTRY EDITOR. The investigator also needs to have a full backup of the entire drive and edit the file on the backup file but not the real drive.</div><div><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 02:20:27 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499760928</guid>
      </item>
      <item>
         <title>The running process is being remove on shutdown</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499770426</link>
         <description><![CDATA[<div>If the computer/desktop is running, Investigator cannot simply shut down the computer or the background process will be removed from RAM. The backgroud process is also a evidence that need to bring to the lab. So, the right way to do before bring the evidence to lab, investigator need to plug off the machine on power supply.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 02:34:24 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499770426</guid>
      </item>
      <item>
         <title>Start the machine will update some windows configuration</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499773670</link>
         <description><![CDATA[<div>If the machine is in the shutdown mode, investigator cannot simply turned on the machine, because it will messed up with BIOS configuration .</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 02:39:29 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499773670</guid>
      </item>
      <item>
         <title>(Linux)Failure to properly write protect</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499784892</link>
         <description><![CDATA[<div>Some Linux distributions rely on device blocking scripts to set the underlying blocking devices of file systems to read only mode. However, there are certain downfalls to this approach, as read-only mode will only protect the filesystems memory from the process running under user space, but the driver code running under kernel space can still modify the filesystem memory.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 02:53:07 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499784892</guid>
      </item>
      <item>
         <title>(Linux)Journaling file system may be tempered.</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499785564</link>
         <description><![CDATA[<div>For some machine, the user may install auto cleanup machine such as CCleaner, Wise Disk Cleaner and Clean Master. These application have feature that will clear all browsing history, temp file and cache of the machine on next reboot. This will destroy the evidence when the investigator trying to reboot the machine. To solve this problem, investigator might consider the safe mode option which will disable the unnecessary process. </div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 02:54:01 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499785564</guid>
      </item>
      <item>
         <title>(Linux)Auto mount of block devices</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499795341</link>
         <description><![CDATA[<div>When booting an evidence system from a Live CD, a number of initrd scripts gets executed in order to create a temporary root file system. However, this will also result in several writes to the filesystem resulting in tampering of evidence data. This can occur for several reasons such as execution of hardware detection scripts during boot time, mounting file system in read-only mode while creating a temporary root file system etc.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 03:08:40 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499795341</guid>
      </item>
      <item>
         <title>NTFS read Only for Windows</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499797923</link>
         <description><![CDATA[<div>Linux cannot read the NTFS drive. If the investigator using Linux as Main OS, it cannot read the NTFS drive which may be an evidence of the cases. Any attempt to convert NTFS to FAT format will tempering the evidence.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 03:12:22 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499797923</guid>
      </item>
      <item>
         <title>Auto cleanup software</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499808783</link>
         <description><![CDATA[<div>For some machine, the user may install auto cleanup machine such as CCleaner, Wise Disk Cleaner and Clean Master. These application have feature that will clear all browsing history, temp file and cache of the machine on next reboot. This will destroy the evidence when the investigator trying to reboot the machine. To solve this problem, investigator might consider the safe mode option which will disable the unnecessary process. </div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 03:28:53 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499808783</guid>
      </item>
      <item>
         <title>Some forensic tool does not suitable for Linux os</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499831798</link>
         <description><![CDATA[<div>Investigator can only use specific tool or software in order to show the evidence result to court. As some software are OS dependent,  it will cause trouble to the investigator to investigate the evidence.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 04:04:23 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499831798</guid>
      </item>
      <item>
         <title>Registry editor for Linux.</title>
         <author>danielfskik</author>
         <link>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499836363</link>
         <description><![CDATA[<div>Window have registry database that collect all registry to one software call 'registry editor'. Linux does not have the registry database that can show the registry files on it. It may difficult the investigator to investigate the evident like showing the last modified file of the system.</div>]]></description>
         <enclosure url="" />
         <pubDate>2020-04-09 04:09:58 UTC</pubDate>
         <guid>https://padlet.com/danielfskik/knlmuu27romns8e8/wish/499836363</guid>
      </item>
   </channel>
</rss>
