<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Into The Boxes</title>
	<atom:link href="http://intotheboxes.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://intotheboxes.wordpress.com</link>
	<description>Digital Forensics and Incident Response Magazine</description>
	<lastBuildDate>Mon, 16 Apr 2012 18:56:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='intotheboxes.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Into The Boxes</title>
		<link>http://intotheboxes.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://intotheboxes.wordpress.com/osd.xml" title="Into The Boxes" />
	<atom:link rel='hub' href='http://intotheboxes.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Into The Boxes: Call for Collaboration 0×02 &#8211; Second Try</title>
		<link>http://intotheboxes.wordpress.com/2012/04/16/into-the-boxes-call-for-collaboration-0%c3%9702-second-try/</link>
		<comments>http://intotheboxes.wordpress.com/2012/04/16/into-the-boxes-call-for-collaboration-0%c3%9702-second-try/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 14:26:58 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=133</guid>
		<description><![CDATA[Okay, the first Call for Collaboration for edition 0&#215;02 did not work out as well as I would have hoped. I did not get any input and I just got busy with work and home. But, there has been recent interest and we (Harlan Carvey and myself) have never given up hope. We are shooting [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=133&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Okay, the first Call for Collaboration for edition 0&#215;02 did not work out as well as I would have hoped. I did not get any input and I just got busy with work and home. But, there has been recent interest and we (<a title="@keydet89" href="https://twitter.com/#!/keydet89">Harlan Carvey </a>and <a title="@cutaway" href="https://twitter.com/#!/cutaway">myself</a>) have never given up hope. We are shooting for issue 0&#215;02 to be published in May or June of 2012.  Of course this will depend on the community.  Your input is necessary to our success.</p>
<p>Therefore this is another call for collaboration.  Please use the <a title="Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_blank">Call Box</a> to provide us with details about issues and topics within digital forensics and incident response that interest you and your colleagues.  We look forward to your submissions and recommendations.</p>
<p>Go forth and do good things,</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/information/'>Information</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/133/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=133&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2012/04/16/into-the-boxes-call-for-collaboration-0%c3%9702-second-try/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>Into The Boxes: Call for Collaboration 0&#215;02</title>
		<link>http://intotheboxes.wordpress.com/2010/07/25/into-the-boxes-call-for-collaboration-0x02/</link>
		<comments>http://intotheboxes.wordpress.com/2010/07/25/into-the-boxes-call-for-collaboration-0x02/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 19:17:02 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=121</guid>
		<description><![CDATA[In case you were wondering, Into The Boxes is still an active project.  Work load and professional changes have caused us to skip a quarter.  This will not deter our efforts and we are shooting for issue 0&#215;02 to be published in September 2010.  Of course this will depend on the community.  Your input is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=121&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>In case you were wondering, <strong>Into The Boxes</strong> is still an active project.  Work load and professional changes have caused us to skip a quarter.  This will not deter our efforts and we are shooting for issue 0&#215;02 to be published in September 2010.  Of course this will depend on the community.  Your input is necessary to our success.</p>
<p>Therefore this is another call for collaboration.  Please use the <a title="Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_blank">Call Box</a> to provide us with details about issues and topics within digital forensics and incident response that interest you and your colleagues.  We look forward to your submissions and recommendations.  Anybody who has already contacted us we will be getting back to you within the next week or two about moving forward with your ideas.</p>
<p>For those of you attending Def Con, be sure to find me and talk to me about this or any other topics.  I will be busy working on the Mystery Challenge again, but there will be plenty of extra time to converse and have a beer or three.  See you there.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/information/'>Information</a> Tagged: <a href='http://intotheboxes.wordpress.com/tag/digital-forensics/'>Digital Forensics</a>, <a href='http://intotheboxes.wordpress.com/tag/incident-response/'>Incident Response</a>, <a href='http://intotheboxes.wordpress.com/tag/into-the-boxes/'>Into The Boxes</a>, <a href='http://intotheboxes.wordpress.com/tag/itb/'>ITB</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/121/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/121/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=121&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/07/25/into-the-boxes-call-for-collaboration-0x02/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>Registry Analysis and Geolocation Scripts Released</title>
		<link>http://intotheboxes.wordpress.com/2010/04/07/registry-analysis-and-geolocation-scripts-released/</link>
		<comments>http://intotheboxes.wordpress.com/2010/04/07/registry-analysis-and-geolocation-scripts-released/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 06:22:26 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Harlan Carvey]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>
		<category><![CDATA[RegRipper]]></category>
		<category><![CDATA[Win4n6]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=117</guid>
		<description><![CDATA[Harlan has released the scripts he used in the &#8220;Registry Analysis and Geolocation&#8221; article.  These scripts are available to members of the Win4n6 forum and can be downloaded from the &#8220;Files&#8221; directory.  Just look for the file named itb0x1.zip.  This zip file contains the following perl scripts which are to used with RegRipper: ssid.pl, networklist.pl, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=117&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Harlan has released the scripts he used in the &#8220;Registry Analysis and Geolocation&#8221; article.  These scripts are available to members of the Win4n6 forum and can be downloaded from the &#8220;Files&#8221; directory.  Just look for the file named itb0x1.zip.  This zip file contains the following perl scripts which are to used with RegRipper:</p>
<ul>
<li>ssid.pl,</li>
<li>networklist.pl, and</li>
<li>maclookup.pl.</li>
</ul>
<p>Be sure to read the &#8220;readme.first&#8221; file as there are some requirements associated with the maclookup plugin.</p>
<p>Enjoy,</p>
<p>Don C. Weber</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/information/'>Information</a> Tagged: <a href='http://intotheboxes.wordpress.com/tag/harlan-carvey/'>Harlan Carvey</a>, <a href='http://intotheboxes.wordpress.com/tag/into-the-boxes/'>Into The Boxes</a>, <a href='http://intotheboxes.wordpress.com/tag/itb/'>ITB</a>, <a href='http://intotheboxes.wordpress.com/tag/regripper/'>RegRipper</a>, <a href='http://intotheboxes.wordpress.com/tag/win4n6/'>Win4n6</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/117/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/117/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=117&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/04/07/registry-analysis-and-geolocation-scripts-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>Into The Boxes: Issue 0&#215;1</title>
		<link>http://intotheboxes.wordpress.com/2010/04/05/into-the-boxes-issue-0x1/</link>
		<comments>http://intotheboxes.wordpress.com/2010/04/05/into-the-boxes-issue-0x1/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 12:01:33 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[Chris Pogue]]></category>
		<category><![CDATA[Don C. Weber]]></category>
		<category><![CDATA[Harlan Carvey]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>
		<category><![CDATA[OSX]]></category>
		<category><![CDATA[plist]]></category>
		<category><![CDATA[Scott Burkhart]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[Super DriveLock]]></category>
		<category><![CDATA[The Digital Standard]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Windows Incident Response]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=110</guid>
		<description><![CDATA[It is time for the second edition of Into The Boxes - Digital Forensics and Incident Response Magazine.

Into The Boxes: Issue 0x1

This time we have contributions from Scott Burkhart and Chris Pogue.  This is another diverse issue covering a wide range of digital forensic and incident response topics. <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=110&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>It is time for the second edition  of Into The Boxes &#8211; Digital Forensics and Incident Response Magazine.</p>
<p><a title="Into The Boxes: Issue 0x0" href="http://intotheboxes.files.wordpress.com/2010/04/intotheboxes_2010_q2.pdf" target="_self">Into The Boxes: Issue 0&#215;1</a></p>
<p>This time we have contributions from Scott Burkhart and <a title="The Digital Standard" href="http://thedigitalstandard.blogspot.com/" target="_blank">Chris Pogue</a>.  This is another diverse issue covering a wide range of digital forensic and incident response topics.  More specifically:</p>
<p>MAC Box: Introduction to Plist Files by Scott Burkhart</p>
<blockquote><p>Want to know how OSX maintains its configurations?  Scott Burkhart breaks down the .plist configuration files and how they can be used during data analysis.</p></blockquote>
<p>Squawk Box: The Simple Truth &#8211; <a title="The Digital Standard" href="http://thedigitalstandard.blogspot.com/" target="_blank">Chris  Pogue</a></p>
<blockquote><p><a title="The Digital Standard" href="http://thedigitalstandard.blogspot.com/" target="_blank">Chris   Pogue</a> provides us some insights into the world of PCI breach incident response.</p></blockquote>
<p>Software Box: Poorcase: Split Image Reconstruction &#8211; <a title="Security Ripcord" href="http://securityripcord.com" target="_blank">Don C. Weber</a></p>
<blockquote><p><a title="Poorcase" href="http://code.google.com/p/poorcase/" target="_blank">Richard Harman</a> has released a new tool for combining split images for data analysis with tools that cannot inherently handle split images.</p></blockquote>
<p>Windows Box: Registry Analysis and Geolocation &#8211; <a title="Windows Incident  Response" href="http://windowsir.blogspot.com/" target="_blank">Harlan Carvey</a></p>
<blockquote><p><a title="Windows Incident  Response" href="http://windowsir.blogspot.com/" target="_blank">Harlan Carvey</a> explains how Windows Registry analysis can be leveraged to perform geolocation and establish information about the different physical locations a system has been used.</p></blockquote>
<p>Hardware Box: Super DriveLock Review &#8211; <a title="Security Ripcord" href="http://securityripcord.com" target="_blank">Don C. Weber</a></p>
<blockquote><p><a title="Security Ripcord" href="http://securityripcord.com/" target="_blank">Don C. Weber</a> reviews Intelligent Computer Solutions&#8217; Super DriveLock, a multi-interface write blocker which can be used in a digital forensic tower or taken on the road.</p></blockquote>
<p>As always, please let us know how you feel and provide us with  recommendations and article submittals for future ITB efforts.  We look  forward to your comments and blog posts about these subjects.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/releases/'>Releases</a> Tagged: <a href='http://intotheboxes.wordpress.com/tag/chris-pogue/'>Chris Pogue</a>, <a href='http://intotheboxes.wordpress.com/tag/don-c-weber/'>Don C. Weber</a>, <a href='http://intotheboxes.wordpress.com/tag/harlan-carvey/'>Harlan Carvey</a>, <a href='http://intotheboxes.wordpress.com/tag/into-the-boxes/'>Into The Boxes</a>, <a href='http://intotheboxes.wordpress.com/tag/itb/'>ITB</a>, <a href='http://intotheboxes.wordpress.com/tag/osx/'>OSX</a>, <a href='http://intotheboxes.wordpress.com/tag/plist/'>plist</a>, <a href='http://intotheboxes.wordpress.com/tag/scott-burkhart/'>Scott Burkhart</a>, <a href='http://intotheboxes.wordpress.com/tag/security-ripcord/'>Security Ripcord</a>, <a href='http://intotheboxes.wordpress.com/tag/super-drivelock/'>Super DriveLock</a>, <a href='http://intotheboxes.wordpress.com/tag/the-digital-standard/'>The Digital Standard</a>, <a href='http://intotheboxes.wordpress.com/tag/windows/'>Windows</a>, <a href='http://intotheboxes.wordpress.com/tag/windows-incident-response/'>Windows Incident Response</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/110/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=110&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/04/05/into-the-boxes-issue-0x1/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>ITB Issue 0&#215;1 &#8211; Call For Collaboration</title>
		<link>http://intotheboxes.wordpress.com/2010/02/07/itb-issue-0x1-call-for-collaboration/</link>
		<comments>http://intotheboxes.wordpress.com/2010/02/07/itb-issue-0x1-call-for-collaboration/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 16:51:32 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=98</guid>
		<description><![CDATA[The success of Into The Boxes Issue 0&#215;0 was only possible because of the collaboration provided by members of the Digital Forensics and Incident Response community.  In order for this publication to continue we need more people to step up and provide their input.  As you can see from the first issue we are looking [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=98&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>The success of <strong>Into The Boxes</strong> <a title="ITB Issue 0x0" href="http://intotheboxes.files.wordpress.com/2009/12/intotheboxes_q12009.pdf" target="_blank">Issue 0&#215;0</a> was only possible because of the collaboration provided by members of the Digital Forensics and Incident Response community.  In order for this publication to continue we need more people to step up and provide their input.  As you can see from the first issue we are looking for input that can be implemented by people in the DF/IR fields.  This input can be in the form of detailed articles or quick tips.  All input will be given serious consideration.  The <strong>ITB</strong> editors will provide authors with recommendations to strengthen their write-ups to ensure the best value to the community and help the authors develop as DF/IR professionals and writers.</p>
<p>Please help <strong>ITB</strong> by providing your submissions or letting us know about your intent to submit via the <a title="ITB Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_blank">ITB Call Box</a>.  We are also looking for article recommendations which we will place in the <a title="ITB Research Box" href="http://intotheboxes.wordpress.com/research-box/" target="_blank">ITB Research Box</a> so that others have good ideas as to what will help the DF/IR Community.  Obviously, if you would like to contribute but do not know what to write about, check out the <a title="ITB Research Box" href="http://intotheboxes.wordpress.com/research-box/" target="_blank">ITB Research Box</a> for recommendations.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/information/'>Information</a> Tagged: <a href='http://intotheboxes.wordpress.com/tag/digital-forensics/'>Digital Forensics</a>, <a href='http://intotheboxes.wordpress.com/tag/incident-response/'>Incident Response</a>, <a href='http://intotheboxes.wordpress.com/tag/into-the-boxes/'>Into The Boxes</a>, <a href='http://intotheboxes.wordpress.com/tag/itb/'>ITB</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/98/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/98/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=98&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/02/07/itb-issue-0x1-call-for-collaboration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>ITB DF/IR Tip Contest</title>
		<link>http://intotheboxes.wordpress.com/2010/02/05/itb-dfir-tip-contest-2/</link>
		<comments>http://intotheboxes.wordpress.com/2010/02/05/itb-dfir-tip-contest-2/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 04:20:18 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Harlan Carvey]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>
		<category><![CDATA[John McCash]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[Windows Incident Response]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=87</guid>
		<description><![CDATA[This has been a long time coming.  The winner of the first Into The Boxes DF/IR Tip Contest is John McCash with the one and only entry for this contest: Windows &#8216;Default User&#8217; Browser History may be left by anything that uses the WinInet APIs &#38; runs as System, including wget.exe. To clarify John points [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=87&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This has been a long time coming.  The winner of the first <strong>Into The Boxes DF/IR Tip Contest</strong> is <a title="Some articles by John McCash" href="http://blogs.sans.org/computer-forensics/author/johnmccash/" target="_blank">John McCash</a> with the one and only entry for this contest:</p>
<blockquote><p>Windows &#8216;Default User&#8217; Browser History may be left by anything that uses the WinInet APIs &amp; runs as System, including wget.exe.</p></blockquote>
<p>To clarify John points us to a post on Harlan&#8217;s blog: <a title="Windows Incident Response" href="http://windowsir.blogspot.com/2009/06/case-of-default-user.html" target="_blank">The Case of the &#8220;Default User&#8221;</a> and Robert Hensing&#8217;s Blog post <a title="Robert Hensing" href="http://blogs.technet.com/robert_hensing/archive/2006/11/15/ever-found-malware-hiding-in-the-all-users-profile-on-windows-ever-wonder-how-it-got-there-or-why-it-was-there.aspx" target="_blank">&#8220;Ever found malware hiding in the &#8220;Default User&#8221; profile on Windows? Ever wonder how it got there or why it was there?&#8221;</a></p>
<p>John wins a signed first edition of <strong>ITB</strong>.  If we had more staff this would have already been taken care of earlier last month.  However, we have leaned on John&#8217;s patience a little and we will be getting this out to him as soon as possible.</p>
<p>Now, stay tuned for more information about future <strong>ITB</strong> events.  We will be putting out the call for new articles very shortly and we hope that many of you will help us follow up with a second edition that matches the first.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Filed under: <a href='http://intotheboxes.wordpress.com/category/information/'>Information</a> Tagged: <a href='http://intotheboxes.wordpress.com/tag/harlan-carvey/'>Harlan Carvey</a>, <a href='http://intotheboxes.wordpress.com/tag/into-the-boxes/'>Into The Boxes</a>, <a href='http://intotheboxes.wordpress.com/tag/itb/'>ITB</a>, <a href='http://intotheboxes.wordpress.com/tag/john-mccash/'>John McCash</a>, <a href='http://intotheboxes.wordpress.com/tag/security-ripcord/'>Security Ripcord</a>, <a href='http://intotheboxes.wordpress.com/tag/windows-incident-response/'>Windows Incident Response</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=87&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/02/05/itb-dfir-tip-contest-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>Into The Boxes: Issue 0&#215;0</title>
		<link>http://intotheboxes.wordpress.com/2010/01/01/into-the-boxes-issue-0x0/</link>
		<comments>http://intotheboxes.wordpress.com/2010/01/01/into-the-boxes-issue-0x0/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 14:09:16 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[Didier Stevens]]></category>
		<category><![CDATA[Don C. Weber]]></category>
		<category><![CDATA[Harlan Carvey]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>
		<category><![CDATA[Jamie Levy]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[Windows Incident Response]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=77</guid>
		<description><![CDATA[It is official.  Harlan and I are proud to announce the first edition of Into The Boxes - Digital Forensics and Incident Response Magazine.
Into The Boxes: Issue 0x0<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=77&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>It is official.  Harlan and I are proud to announce the first edition of Into The Boxes &#8211; Digital Forensics and Incident Response Magazine.</p>
<p><a title="Into The Boxes: Issue 0x0" href="http://intotheboxes.files.wordpress.com/2010/04/intotheboxes_2010_q1.pdf" target="_self">Into The Boxes: Issue 0&#215;0</a></p>
<p>Of course this release would not have been possible if it were not for the contributions of <a title="Didier Stevens" href="http://blog.didierstevens.com/" target="_blank">Didier Stevens</a> and <a title="Jamie Levy" href="http://gleeda.blogspot.com/" target="_blank">Jamie Levy</a>.  These two produced, in our opinion, two very good articles that will benefit your analysis efforts and overall education.  We all owe these two a big thank you for helping us get this effort moving forward.  There were several others who also provided us various forms of encouragement and article submittals but, for various reasons, were not able to provide contend for this publications.  Harlan and I would also like to thank these people as well and let them know we are looking forward to their submittals for Issue 0&#215;1 in addition to their continued verbal support.</p>
<p>This issue contains four specific articles that cover a variety of digital forensic and incident response issues.  More specifically:</p>
<p>Windows Box: Windows 7 UserAssist Registry Keys by <a title="Didier Stevens" href="http://blog.didierstevens.com/" target="_blank">Didier Stevens</a>.</p>
<blockquote><p>This is an analysis of the new UserAssist registry keys binary data format used in Windows 7 and Windows 2008 R2.</p></blockquote>
<p>*nix Box: Red Hat Crash Memory Forensics &#8211; <a title="Jamie Levy" href="http://gleeda.blogspot.com/" target="_blank">Jamie Levy</a></p>
<blockquote><p>This article covers the installation and use of Redhat Crash Utility for Linux memory forensics.</p></blockquote>
<p>Software Box: Beware The Preview Pane &#8211; <a title="Security Ripcord" href="http://securityripcord.com" target="_blank">Don C. Weber</a></p>
<blockquote><p>A quick dip into the preview pane functionality provided by AccessData&#8217;s FTK Imager and FTK Imager Lite.</p></blockquote>
<p>Squawk Box: PCI Interview with <a title="Windows Incident Response" href="http://windowsir.blogspot.com/" target="_blank">Harlan Carvey</a></p>
<blockquote><p>An interview about digital forensics and incident response as it pertains to Payment Card Industry-related investigations.</p></blockquote>
<p>As always, please let us know how you feel and provide us with recommendations and article submittals for future ITB efforts.  We look forward to your comments and blog posts about these subjects.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Posted in Releases Tagged: Didier Stevens, Don C. Weber, Harlan Carvey, Into The Boxes, ITB, Jamie Levy, Security Ripcord, Windows Incident Response <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/77/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=77&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2010/01/01/into-the-boxes-issue-0x0/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>ITB DF/IR Tip Contest &#8211; Update</title>
		<link>http://intotheboxes.wordpress.com/2009/12/05/itb-dfir-tip-contest-update/</link>
		<comments>http://intotheboxes.wordpress.com/2009/12/05/itb-dfir-tip-contest-update/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 13:23:17 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=68</guid>
		<description><![CDATA[Okay, the ITB DF/IR Tip Contest went off without a hitch.  Well, actually there was one hitch.  I have only found one entry.  Harlan and I have been very busy generating content, getting ITB ready for the January release, and working our day jobs, but I did have time to search for entries using Twitter [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=68&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Okay, the <a title="ITB DF/IR Tip Contest" href="http://intotheboxes.wordpress.com/2009/11/05/itb-dfir-tip-contest/" target="_self">ITB DF/IR Tip Contest</a> went off without a hitch.  Well, actually there was one hitch.  I have only found one entry.  <a title="Windows Incident Response" href="http://windowsir.blogspot.com/" target="_blank">Harlan</a> and <a title="Security Ripcord" href="http://www.cutawaysecurity.com/blog" target="_blank">I</a> have been very busy generating content, getting ITB ready for the January release, and working our day jobs, but I did have time to search for entries using <a title="Twitter Search" href="http://search.twitter.com/" target="_blank">Twitter Search</a>.  I never found any hits with #ITBTIP tag.  But, before I jump to any conclusions I am going to give you a week (till December 12, 2009) to point me to your DF/IR awareness tip.  This tip must have been submitted during the contest timeframe.  So, if you did submit a DF/IR awareness tip for the contest, please use the <a title="ITB: Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_self">ITB Call Box</a> and point us to your submittal.  I will be glad to review your twitter history but please be sure to at least include a date and time to help narrow down the search.</p>
<p>Barring that I guess the one submittal will be the best submitted (it is pretty good anyway).  As to the one person who submitted the lone, he did so via the <a title="ITB: Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_self">ITB Call Box</a>, so you will just have to await to see his entry.  I would, however, like to thank him for participating.</p>
<p>Have a great holiday season,</p>
<p>Don C. Weber</p>
<br />Posted in Uncategorized  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=68&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2009/12/05/itb-dfir-tip-contest-update/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>ITB DF/IR Tip Contest</title>
		<link>http://intotheboxes.wordpress.com/2009/11/05/itb-dfir-tip-contest/</link>
		<comments>http://intotheboxes.wordpress.com/2009/11/05/itb-dfir-tip-contest/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 14:46:06 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Contest]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Into The Boxes]]></category>
		<category><![CDATA[ITB]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=56</guid>
		<description><![CDATA[To help raise awareness about  Into The Boxes (ITB), digital forensics, and incident response, ITB will be holding a competition via Twitter.  This contest will also help  show the community how easy it is to collaborate and contribute to the ITB effort.  The basis of this competition are Digital Forensic and Incident Response (DF/IR) tips [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=56&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>To help raise awareness about  <em><strong>Into The Boxes</strong></em> (<em><strong>ITB</strong></em>), digital forensics, and incident response, <em><strong>ITB</strong></em> will be holding a competition via <a title="Twitter" href="http://twitter.com" target="_blank">Twitter</a>.  This contest will also help  show the community how easy it is to collaborate and contribute to the <em><strong>ITB</strong></em> effort.  The basis of this competition are Digital Forensic and Incident Response (DF/IR) tips that can be placed in the space allowed by the <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> &#8220;What are you doing?&#8221; textbox.  To help <strong><em>ITB</em></strong> Staff identify entries each tip entry will need to start with &#8220;#ITBTIP: &#8220;.   This leaves each contestant 131 characters to work with when creating a DF/IR tip.  Links are allowed but they will only be taken in context of the DF/IR tip and not followed.  Here is an example:</p>
<blockquote><p>#ITBTIP: Wipe drive with known pattern &#8211; # sudo dcfldd textpattern=IntoTheBoxes of=/dev/&lt;drive&gt;</p></blockquote>
<p>Size doesn&#8217;t matter as long as the tip is less than or equal to 140 characters including the header.  Tips do not have to be technical.  DF/IR managerial statements are sometimes just as important as the data acquisition and analysis and are good for elevator/water cooler comments and are the basis for more in-depth recommendations that can be used in Lessons Learned and Final Reports stemming from an incident response effort.  Here is another example.</p>
<blockquote><p>#ITBTIP: Centralized logging provides us valuable IT security information while reducing the cost required to review and alert on incidents.</p></blockquote>
<p>All entries will be judged by the <em><strong>ITB</strong></em> staff.  The results will be posted here and the top five will be included in the January 2010 release of  <strong><em>ITB</em></strong>.   Tips will also be reused, periodically, by <strong><em>ITB</em></strong> to promote DF/IR awareness.  If you do not have a Twitter account but would still like to participate in the contest just drop us your tip, which must still follow the contest guidelines, using the <a title="Into The Boxes - Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_blank"><em><strong>ITB</strong></em> Call Box</a>.</p>
<p>This contest will end on November 22nd, 2009.  So you have a little time to think about what you want to do.  To be fair only five submissions per person are permitted and only one of those will be allowed into the top five category.  The first prize winner of this contest will receive a hard copy version of the <strong><em>ITB</em></strong> inaugural edition signed by the <strong><em>ITB</em></strong> Staff.  Not much, but it is all we have right now.  There will only be three hard copies made of this first edition, so this will be a limited edition.</p>
<p>While you are at it, you can follow <em><strong>ITB</strong></em> events by <a title="Into The Boxes on Twitter" href="http://twitter.com/IntoTheBoxes" target="_blank">following us on Twitter </a>or <a title="Into The Boxes - Feed Box" href="http://intotheboxes.wordpress.com/feed/" target="_blank">subscribing to our feed</a>.</p>
<p>So, here is a list of those rules again.  These may change a little if somebody points out something glaringly obvious, so check back and watch our Tweets.</p>
<ul>
<li>All tips can only be 140 characters and must use the header &#8220;#ITBTIP: &#8221; (so you only get 131 characters).</li>
<li>Links are allowed but they will only be taken in context of the DF/IR tip and not followed.</li>
<li>Contest ends at <a title="CST Time Zone" href="http://www.time.gov/timezone.cgi?Central/d/-6" target="_blank">00:00:00 CST</a> on November 22nd, 2009 the winner will be announced on November 29th, 2009.</li>
<li>Five entries per person and only one can be in the top five.</li>
<li>All entries will be judged by <em><strong>ITB</strong></em> Staff.</li>
<li>Tips can be submitted via Twitter or the <a title="Into The Boxes - Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_blank"><em><strong>ITB</strong></em> Call Box</a>.</li>
<li>All participants agree that their tips can be reused on the <em><strong>Into The Boxes</strong></em> website and in future <em><strong>Into The Boxes</strong></em> publications.  All copyrights, outside of these limited publishing rights for <strong><em>Into The Boxes</em></strong>, will remain with the author of the <em><strong>ITB</strong></em> Tip.</li>
</ul>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<div id="_mcePaste" style="overflow:hidden;position:absolute;left:-10000px;top:14px;width:1px;height:1px;"><strong>inaugural</strong></div>
<br />Posted in Information Tagged: Contest, Digital Forensics, Incident Response, Into The Boxes, ITB, Twitter <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=56&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2009/11/05/itb-dfir-tip-contest/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
		<item>
		<title>Contributing to Into The Boxes</title>
		<link>http://intotheboxes.wordpress.com/2009/11/03/contributing-to-into-the-boxes/</link>
		<comments>http://intotheboxes.wordpress.com/2009/11/03/contributing-to-into-the-boxes/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 13:31:33 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Information]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Into The Boxes]]></category>

		<guid isPermaLink="false">http://intotheboxes.wordpress.com/?p=46</guid>
		<description><![CDATA[The staff of Into The Boxes have tried to make contributing to this resource as easy as possible.  You can find most of the information you need right here.  Just look to the right sidebar and you will find links to all of the following information. Into The Boxes &#8211; Main page that will change very [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=46&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>The staff of <em><strong>Into The Boxes</strong></em> have tried to make contributing to this resource as easy as possible.  You can find most of the information you need right here.  Just look to the right sidebar and you will find links to all of the following information.</p>
<ul>
<li><a title="Into The Boxes" href="http://intotheboxes.wordpress.com/" target="_self">Into The Boxes</a> &#8211; Main page that will change very little but does contain useful information about the next release.</li>
<li><a title="ITB: Blog Box" href="http://intotheboxes.wordpress.com/blog-box/" target="_self">Blog Box </a>- You are here. Enjoy and come back often.</li>
<li><a title="ITB: Collaboration Box" href="http://intotheboxes.wordpress.com/author-guidelines/" target="_blank">Collaboration Box</a> &#8211; Guidelines to help people understand how to collaborate and get articles published in this e-magazine.</li>
<li><a title="ITB: Research Box" href="http://intotheboxes.wordpress.com/research-box/" target="_blank">Research Box </a>- A list of topics to help authors who are looking for inspiration.  We are accepting requests for articles and these requests will be posted here for us and others to consider as topics for future articles.  Use the<a title="Call Box" href="../call-box/"> </a><a title="ITB: Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_self">Call Box</a> to get us you request or let us know you are working an a particular topic.</li>
<li><a title="ITB: Mission Box" href="http://intotheboxes.wordpress.com/mission/" target="_self">Mission Box</a> &#8211; the mission statement which guides <em><strong>Into The Boxes.<br />
</strong></em></li>
<li><a title="ITB: Call Box" href="http://intotheboxes.wordpress.com/call-box/" target="_self">Call Box</a> &#8211; when you need to contact the staff of <em><strong>Into The Boxes</strong></em> use this web form.  This will notify the proper personnel and we will get to your request as quickly as possible.</li>
</ul>
<p>Obviously as we move forward we will have more pages with more information.  Starting in the first week of January 2010, with the release of <strong><em>Into The Boxes</em></strong>&#8216; first issue, we will have pages for curent and previous issues of the e-magazine.  For now, however, simple is better.</p>
<p>Do not forget to <a title="Into The Boxes - Feed" href="http://intotheboxes.wordpress.com/feed/" target="_blank">subscribe to the <em><strong>Into The Boxes</strong></em> feed</a> so that you are up-to-date with new information about Into The Boxes.  You can also get information about the e-magazine on <a title="Twitter" href="http://twitter.com/" target="_blank">Twitter</a> by following <a title="Follow Into The Boxes" href="https://twitter.com/IntoTheBoxes" target="_blank">IntoTheBoxes</a>.</p>
<p>Please let us know if something is missing or needs clarification.  The staff of <em><strong>Into The Boxes</strong></em> will get to your input as quickly as possible.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
<br />Posted in Information Tagged: Digital Forensics, Incident Response, Into The Boxes <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/intotheboxes.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/intotheboxes.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=intotheboxes.wordpress.com&#038;blog=10029289&#038;post=46&#038;subd=intotheboxes&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://intotheboxes.wordpress.com/2009/11/03/contributing-to-into-the-boxes/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/82b6058737e2dc757c5ebdd9adc77627?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cutaway</media:title>
		</media:content>
	</item>
	</channel>
</rss>
