<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Forensic 4cast &#187; forensic</title>
	<atom:link href="http://forensic4cast.com/tag/forensic/feed/" rel="self" type="application/rss+xml" />
	<link>http://forensic4cast.com</link>
	<description>Welcome to our podcast discussing issues relating to digital forensics</description>
	<lastBuildDate>Wed, 18 Aug 2010 16:32:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<!-- podcast_generator="podPress/8.8" - maintenance_release="8.8.6.3" -->
	<copyright>2008 </copyright>
	<managingEditor>lee@forensic4cast.com (Lee Whitfield)</managingEditor>
	<webMaster>lee@forensic4cast.com (Lee Whitfield)</webMaster>
	<category>Tech News</category>
	<ttl>1440</ttl>
	<image>
		<url>http://4cast.whitfields.org/4small.jpg</url>
		<title>Forensic 4cast &#187; forensic</title>
		<link>http://forensic4cast.com</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle>Forensic 4cast</itunes:subtitle>
	<itunes:summary>Welcome to the wonderful world of digital and computer forensics.  In each episode Lee will have guests on the show to discuss the latest news in the field, tell stories from the real world, and much more.</itunes:summary>
	<itunes:keywords>digital,computer,forensics,forensic,legal,law,cyber crime,investigation</itunes:keywords>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
	</itunes:category>
	<itunes:author>Lee Whitfield</itunes:author>
	<itunes:owner>
		<itunes:name>Lee Whitfield</itunes:name>
		<itunes:email>lee@forensic4cast.com</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://4cast.whitfields.org/4.jpg" />
		<item>
		<title>Forensic 4cast Awards &#8211; Results #forensicsummit</title>
		<link>http://forensic4cast.com/2010/07/09/forensic-4cast-awards-results-forensicsummit/</link>
		<comments>http://forensic4cast.com/2010/07/09/forensic-4cast-awards-results-forensicsummit/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 12:46:06 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[award]]></category>
		<category><![CDATA[ceremony]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[forensic]]></category>

		<guid isPermaLink="false">http://forensic4cast.com/?p=697</guid>
		<description><![CDATA[Last night we held the second annual Forensic 4cast Awards at the SANS Forensic Summit in Washington DC. It was tremendous fun and was broadcast live by SANS on their website. If you want to see their coverage of the event you can do so here https://www.sans.org/webcasts/live-forensic-4cast-awards-ceremony-93653. I will be posting video of the event [...]]]></description>
			<content:encoded><![CDATA[<p>Last night we held the second annual Forensic 4cast Awards at the SANS Forensic Summit in Washington DC. It was tremendous fun and was broadcast live by SANS on their website. If you want to see their coverage of the event you can do so here <a href="https://www.sans.org/webcasts/live-forensic-4cast-awards-ceremony-93653">https://www.sans.org/webcasts/live-forensic-4cast-awards-ceremony-93653</a>. I will be posting video of the event in the next few days.</p>
<p>The 2010 winners are listed below:</p>
<p>Outstanding Contribution to Digital Forensics &#8211; Individual<br />
Rob Lee</p>
<p>Outstanding Contribution to Digital Forensics &#8211; Company<br />
SANS</p>
<p>Best Digital Forensics Blog<br />
SANS</p>
<p>Best Digital Forensics Book<br />
Windows Forensic Analysis 2E</p>
<p>Best Digital Forensic Podcast<br />
Inside the Core</p>
<p>Best Computer Forensic Hardware<br />
Tableau T8</p>
<p>Best Computer Forensic Software<br />
FTK Imager</p>
<p>Best Phone Forensic Hardware<br />
Cellebrite UFED</p>
<p>Best Phone Forensic Software<br />
Mobilyze</p>
<p>Digital Forensic Investigator of the Year<br />
Nick Furneaux</p>
<p>Lifetime Achievement<br />
Craig Wilson</p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2010/07/09/forensic-4cast-awards-results-forensicsummit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Sneak Peak at the Forensic 4cast Awards</title>
		<link>http://forensic4cast.com/2010/06/24/sneak-peak-at-the-forensic-4cast-awards/</link>
		<comments>http://forensic4cast.com/2010/06/24/sneak-peak-at-the-forensic-4cast-awards/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 12:34:34 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[award]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[trophy]]></category>

		<guid isPermaLink="false">http://forensic4cast.com/?p=671</guid>
		<description><![CDATA[Want to know what the awards will look like? I have to admit, these do look pretty darn cool. I think they are very &#8216;Geek Chic&#8217;. Anyway, here they are. Feedback is appreciated and, if you&#8217;re in contention for an award this year &#8211; how much more do you want one now? If you&#8217;re not [...]]]></description>
			<content:encoded><![CDATA[<p>Want to know what the awards will look like? I have to admit, these do look pretty darn cool. I think they are very &#8216;Geek Chic&#8217;.</p>
<p>Anyway, here they are. Feedback is appreciated and, if you&#8217;re in contention for an award this year &#8211; how much more do you want one now? If you&#8217;re not in contention for an award &#8211; go out and convince people to nominate and vote for you in 2011.</p>
<p style="text-align: center;"><a href="http://forensic4cast.com/wp-content/uploads/2010/06/DSCF6891.jpg" target="_blank"><img class="size-medium wp-image-673 aligncenter" title="Forensic 4cast Award" src="http://forensic4cast.com/wp-content/uploads/2010/06/DSCF6891-237x300.jpg" alt="Forensic 4cast Award" width="237" height="300" /></a></p>
<p style="text-align: center;"><a href="http://forensic4cast.com/wp-content/uploads/2010/06/DSCF6895.jpg" target="_blank"><img class="size-medium wp-image-674 aligncenter" title="Forensic 4cast Award Close Up" src="http://forensic4cast.com/wp-content/uploads/2010/06/DSCF6895-300x182.jpg" alt="Forensic 4cast Award Close Up" width="300" height="182" /></a></p>
<p style="text-align: left;">And yes, that is pin-point accurate laser engraving. Nice.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2010/06/24/sneak-peak-at-the-forensic-4cast-awards/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Forensic 4cast Awards &#8211; Open to All</title>
		<link>http://forensic4cast.com/2010/06/18/forensic-4cast-awards-open-to-all/</link>
		<comments>http://forensic4cast.com/2010/06/18/forensic-4cast-awards-open-to-all/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 13:02:41 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[4cast]]></category>
		<category><![CDATA[award]]></category>
		<category><![CDATA[awards]]></category>
		<category><![CDATA[cell]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[nomination]]></category>
		<category><![CDATA[nominee]]></category>
		<category><![CDATA[phone]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[vote]]></category>
		<category><![CDATA[washington]]></category>

		<guid isPermaLink="false">http://forensic4cast.com/?p=658</guid>
		<description><![CDATA[This is an important update on the Forensic 4cast Awards. SANS have announced that both the Forensic Challenge Awards and the Forensic 4Cast Awards will be open to anyone that wishes to attend. This will be the case whether or not you are a delegate for the summit. This is superb news and I&#8217;d like to [...]]]></description>
			<content:encoded><![CDATA[<p>This is an important update on the Forensic 4cast Awards.</p>
<p>SANS have announced that both the Forensic Challenge Awards and the Forensic 4Cast Awards will be open to anyone that wishes to attend. This will be the case whether or not you are a delegate for the summit.</p>
<p>This is superb news and I&#8217;d like to say a huge thankyou to SANS for making this possible. If you&#8217;re going to be in the DC area on July 8 2010 please make sure to stop by and attend the awards. If you can&#8217;t be in DC for the awards, I would first ask &#8220;WHY NOT?&#8221; but then I&#8217;d console you and tell you not worry too much as SANS are also pushing the awards out by simulcast. We&#8217;ll have the link for you closer to the time but that is awesome. This means that you have no excuse to not attend in some capacity.</p>
<p>I&#8217;ve also been informed of the possibility of food (this is yet to be confirmed though). Even if the entertainment of the awards doesn&#8217;t entice you to come the food should!</p>
<p>This should be an exceptional event as there all kinds of people will be there, from Rob Lee, to Harlan Carvey, to Mark McKinnon. Its your chance to meet these pillars our our community and to commiserate them when someone else wins their awards <img src='http://forensic4cast.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The times for the awards are:</p>
<ul>
<li>630 PM Forensic Challenge Awards</li>
<li>730 PM Forensic 4Cast Awards</li>
</ul>
<p>The events will be held at:</p>
<p>Fairmont Washington DC<br />
2401 M Street, NW<br />
Washington, DC 20037</p>
<p>Now, on to the next item of business&#8230; anyone out there willing to perform a song or two for the awards? <img src='http://forensic4cast.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2010/06/18/forensic-4cast-awards-open-to-all/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Forensic 4cast Awards 2010 &#8211; Voting is Open</title>
		<link>http://forensic4cast.com/2010/06/16/forensic-4cast-awards-2010-voting-is-open/</link>
		<comments>http://forensic4cast.com/2010/06/16/forensic-4cast-awards-2010-voting-is-open/#comments</comments>
		<pubDate>Wed, 16 Jun 2010 16:56:32 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[4cast]]></category>
		<category><![CDATA[award]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[phone]]></category>

		<guid isPermaLink="false">http://forensic4cast.com/?p=646</guid>
		<description><![CDATA[The nominations have been taken and counted and now we have narrowed down the fields to just a few for voting. You will notice that the &#8216;Blog Article&#8217; entry has not made the cut. This is because so many people nominated different articles that no two nominations were the same. I know this is the [...]]]></description>
			<content:encoded><![CDATA[<p>The nominations have been taken and counted and now we have narrowed down the fields to just a few for voting. You will notice that the &#8216;Blog Article&#8217; entry has not made the cut. This is because so many people nominated different articles that no two nominations were the same. I know this is the risk of running nominations and I may change the format next year.</p>
<p>You will also notice that the categories will have two, three, or four nominees. This is because the nominations were so close. We didn&#8217;t want to pick and choose so we&#8217;ve just left it all up to you.</p>
<p>Finally. We&#8217;ve decided to take the &#8216;Lifetime Achievement&#8217; award off. We will still be presenting an award for this but it will be at the discretion of Forensic 4cast. This is likely to be the case for this category from now on.</p>
<p>Anyway, as before we&#8217;ve asked that you give your name and email address just so that we can stop people from spamming.</p>
<p>Voting will close on July 6 2010. That&#8217;s only three weeks so get voting!</p>
<p><iframe src="https://spreadsheets.google.com/embeddedform?formkey=dHVKeEZPT3Q3UDdWZmhQMjNYdFZodlE6MQ" width="590" height="1705" frameborder="0" marginheight="0" marginwidth="0">Loading&#8230;</iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2010/06/16/forensic-4cast-awards-2010-voting-is-open/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Episode 29 &#8211; #robleeisagiant</title>
		<link>http://forensic4cast.com/2010/06/01/episode-29-robleeisagiant/</link>
		<comments>http://forensic4cast.com/2010/06/01/episode-29-robleeisagiant/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 17:31:53 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Podcast Episodes]]></category>
		<category><![CDATA[4cast]]></category>
		<category><![CDATA[accessdata]]></category>
		<category><![CDATA[awards]]></category>
		<category><![CDATA[command line]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[ftk]]></category>
		<category><![CDATA[guidance]]></category>
		<category><![CDATA[imager]]></category>
		<category><![CDATA[nomination]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[summit]]></category>
		<category><![CDATA[tableau]]></category>

		<guid isPermaLink="false">http://forensic4cast.com/?p=623</guid>
		<description><![CDATA[CEIC 2010, Tableau and Guidance, SANS Forensic Summit and the 4cast Awards]]></description>
			<content:encoded><![CDATA[<p>Today we discuss what happened at CEIC, the Guidance acquisition of Tableau, FTK and Guidance releasing new forensic tools, the SANS Forensic Summit, and the Forensic 4cast Awards.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2010/06/01/episode-29-robleeisagiant/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
			<enclosure url="http://forensic4cast.com/wp-content/uploads/2010/06/4cast-episode-29.mp3" length="1" type="audio/mpeg" />
		<itunes:duration>00:01:01</itunes:duration>
		<itunes:subtitle>Today we discuss what happened at CEIC, the Guidance acquisition of Tableau, FTK and Guidance releasing new forensic tools, the SANS Forensic Summit, and the ...</itunes:subtitle>
		<itunes:summary>Today we discuss what happened at CEIC, the Guidance acquisition of Tableau, FTK and Guidance releasing new forensic tools, the SANS Forensic Summit, and the Forensic 4cast Awards.</itunes:summary>
		<itunes:keywords>Podcast Episodes</itunes:keywords>
		<itunes:author>Lee Whitfield</itunes:author>
		<itunes:explicit>no</itunes:explicit>
		<itunes:block>no</itunes:block>
	</item>
		<item>
		<title>MacBook Air Acquisition</title>
		<link>http://forensic4cast.com/2009/03/15/macbook-air-acquisition/</link>
		<comments>http://forensic4cast.com/2009/03/15/macbook-air-acquisition/#comments</comments>
		<pubDate>Sun, 15 Mar 2009 08:24:30 +0000</pubDate>
		<dc:creator>Lee Whitfield</dc:creator>
				<category><![CDATA[Technical Articles]]></category>
		<category><![CDATA[acquire]]></category>
		<category><![CDATA[acquisition]]></category>
		<category><![CDATA[air]]></category>
		<category><![CDATA[copy]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[macbook]]></category>
		<category><![CDATA[pictorial]]></category>
		<category><![CDATA[tableau]]></category>
		<category><![CDATA[zif]]></category>

		<guid isPermaLink="false">http://4cast.whitfields.org/?p=135</guid>
		<description><![CDATA[Lee provides show how to extract the drive ready from a MacBook Air.]]></description>
			<content:encoded><![CDATA[<p>The MacBook Air presents a unique problem that is not found with other Apple products.  With other Apple computers the ‘Macquisition’ tool can be used to create an image of the drive in question if the drive is not easily accessible.  Unfortunately Macquisition requires a free firewire (IEEE 1394) port in order to boot the computer into acquisition mode.  The MacBook Air has only one USB port, no firewire port, and no optical drive.  The Apple website suggests that only an Apple branded USB optical drive will allow booting from optical media (such as Helix).  These drives can be costly and largely pointless to purchase.<br />
This guide provides a (relatively) simple method of removing the internal drive and imaging the drive using EnCase (or whatever brand of imaging tool you use).<br />
Firstly, meet the MacBook Air:</p>
<p><img class="aligncenter size-full wp-image-157" title="air11" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air11.jpg" alt="air11" /></p>
<p>The first thing you will notice is that this is a very thin computer; it has an aluminium (aluminum for you non-Brits) case.  This is quite slippery so take care not to drop it.<br />
The first thing you will need to do is turn it over.<br />
There are ten screws that need removing (circled below).  The front six screw are the same size; the rear-corner screws are a little longer; the middle-rear screws are longer still.  Keep track of these for putting it back together.</p>
<p><img class="aligncenter size-full wp-image-161" title="air2" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air2.jpg" alt="air2" /></p>
<p>Once the bottom of the case is off you are going to focus your attention on the rear-right corner of the computer (highlighted below).</p>
<p><img class="aligncenter size-full wp-image-162" title="air3" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air3.jpg" alt="air3" /></p>
<p>When you look closer at this corner you can see two ribbon cables.  The first of these is disconnected at ‘A’ by pulling on tab ‘B’ below:</p>
<p><img class="aligncenter size-full wp-image-165" title="air4" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air4.jpg" alt="air4" /></p>
<p>Once this has been completed you will see four more screws (circle below).  The top two screws are easily enough removed, the bottom two screws are partially obscured by a thin wire.  The wire is tucked in the drive cage.  Gently pry the cable away until the screws are exposed and remove the screws.</p>
<p><img class="aligncenter size-full wp-image-166" title="air5" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air5.jpg" alt="air5" /></p>
<p>We are now ready to remove the second ribbon cable.  Gently pull it away (marked in red below) until it is no longer connected.</p>
<p><img class="aligncenter size-full wp-image-167" title="air6" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air6.jpg" alt="air6" /></p>
<p>Removing the drive is not difficult, carefully life the drive cage and slide the hard drive out from underneath.  Do not pull it out from the top or try to remove the drive cage as you may cause irreparable damage.</p>
<p><img class="aligncenter size-full wp-image-168" title="air7" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air7.jpg" alt="air7" /></p>
<p>Once you have removed the drive the drive turn it over and carefully remove the black tape covering the ribbon connection (marked below).</p>
<p><img class="aligncenter size-full wp-image-173" title="75" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/75.jpg" alt="75" /></p>
<p>Once the tape has been removed the ribbon connection is exposed.  Carefully pull the ribbon cable out of the connector (marked below).</p>
<p><img class="aligncenter size-full wp-image-169" title="air8" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air8.jpg" alt="air8" /></p>
<p>When finished you should have something the looks like the picture below:</p>
<p><img class="aligncenter size-full wp-image-170" title="air9" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air9.jpg" alt="air9" /></p>
<p>This is a ‘ZIF’ drive.  These drives are commonly found in iPods and ultraportable PCs.  In order to image this drive you will require the following:</p>
<ul>
<li>Either a ‘Tableau T14 IDE’ or a ‘Tableau T35e’ write blocking device</li>
<li>A ‘TDA5-ZIF’ drive adapter kit</li>
</ul>
<p>Why so specific? Well, Tableau state that the ‘ZIF’ adapter is only guaranteed to work with one of the two Tableaux mentioned above.  I do not want to risk something going wrong so I’ll follow their advice.  Thankfully I had a ‘T35e’ already available.  You can try using this adapter with a different model, or even a different brand of write-blocker, but its not recommended.<br />
Carefully insert the new ribbon (provided with the adapter) into the ribbon connector on the hard drive and then connect the other end of the ribbon into the adapter (see below).  Then plug the adapter into the Tableau.</p>
<p><img class="aligncenter size-full wp-image-171" title="air10" src="http://4cast.whitfields.org/wp-content/uploads/2009/03/air10.jpg" alt="air10" /></p>
<p>From this point forward it is exactly the same as acquiring any other hard drive.  The Tableau will pick up the drive allowing you to image as normal.</p>
<p>Hope this is useful to someone out there.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensic4cast.com/2009/03/15/macbook-air-acquisition/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
