Quando si parla di "#attribuzione" in ambito #informaticaforense si cerca qualunque elemento possa identificare un soggetto ma anche un dispositivo.
Non sempre si trova un identificativo certo o associabile a un soggetto/dispositivo, spesso dietro un IP si cela una #VPN, un MAC Address può cambiare a rotazione, un'indirizzo mail essere registrato a prestanome se non anonimo o temporaneo, un VolumeID di un disco cambiare alla formattazione, etc... ma tra tutto in genere si riescono a ottenere buoni risultati.
Nel recente caso dell'arresto del diciannovennte, gli inquirenti sono arrivati a lui tramite il #GDID "6755467234350028", un identificativo univoco di #Windows che non cambia con gli update e in modo incrociato ha permesso di risalire a lui tramite analisi delle sue attività di gioco, registrazione, utilizzo dei social network nonostante l'attacco informatico fosse stato lanciato tramite #ngrok da dietro una #VPN.
Una storia interessante, che si può leggere direttamente dagli atti giudiziari ufficiali reperibili sul sito dell' U.S. Department of Justice.
https://t.co/vp6IVC0xfW
In #informaticaforense si utilizzano frequentemente valori #hash per identificare elementi di interesse, artefatti sospetti o file specifici ad esempio per circoscrivere il proprio #knowhow che diventano poi frutto di ricerca nelle #copieforensi in ambito di descrizioni giudiziarie per misure cautelari, perquisizioni o sequestri. 🕵
Purtroppo sempre più spesso le liste di hash - le cosiddette #hashlist - vengono fornite mediante codifica con algoritmi non sempre supportati o accettati come input dagli strumenti in uso al laboratorio, ad esempio spesso viene utilizzato lo SHA1 quando la maggior parte dei tool accettano in input hash MD5 o SHA256. 😕
Sarebbe banale, anche se computazionalmente impegnativo, ricalcolare il valore hash nel proprio algoritmo preferito, avendo a disposizione i file originali, ma spesso - ad esempio quando vengono secretati ex art 121 ter CPI - il know how originale non è disponibile. 👀
Per ovviare a questa fastidiosa limitazione, ho sviluppato un tool che funziona interamente all'interno del browser (senza quindi caricare sul sito alcun hash) che converte i valori hash da un formato a un altro, senza necessità di ricalcolo a partire dai file originali ma derivando il risultato attraverso una trasformazione deterministica del #digest fornito in input.
Tra le caratteristiche principali del tool online HashConv, Smart Hash Converter:
✅ Supporta 12 formati diversi di hash, i principali in uso agli strumenti di #digitalforensics in dotazione a chi si occupa di #perizieinformatiche;
✅ Funziona anche con hash non presenti nelle comuni rainbow table, lookup o reverse hash list (CrackStation, L0phtCrack ma anche Hashcat o John the Ripper);
✅ Riconoscimento automatico del formato hash in input (es. 390cb69fae0bf57dfb1ef44b30d5eb87 viene riconosciuto come MD5, mentre d242978892617903e1fe9d42fdb9c5507dcc0c0aff4677bfdd67ca02d7f60a5c come SHA256, etc...);
✅ Possibilità d'inserire più valori hash in colonna, uno per riga, per convertire in batch intere hashlist da passare ad esempio a software come Intella, X-Ways Forensics, FTK, Nuix, Axiom o tanti altri;
✅ Basato sulla modalità forense "hashconv" del tool dcfldd usata per convertire o calcolare l'hash dei dati durante un processo di #copiaforense di un disco o di un file;
✅ Possibilità d'invertire source <-> target format;
✅ Privacy by design: nessun dato viene passato al server, tutto rimane sul proprio PC.
🔐 Lo strumento è gratuito e disponibile pubblicamente da oggi al seguente link: https://t.co/jM2k85ez16
Sono benvenuti feedback per migliorare l'algoritmo di conversione e aggiungere nuove funzionalità.
This is Cortical Cloud. Live neural networks that you can interact with and train!
Now open to the public. What will you discover?
Credits: Frank Yang and a big thank you and acknowledgement to the rest of the Cortical Labs team.
Sign up for Cortical Cloud: https://t.co/Y8b1WojPRA
Learn more about us: https://t.co/tvcLEOFnnN
Check out our API: https://t.co/P9opFAALxr
Check out our API Docs: https://t.co/dZrsmiX85U
Check out our Developer Guide: https://t.co/HhwbOK2qIq
Join our Discord: https://t.co/5UQbBaJsd7
Some of you will be old enough to remember this. Defragging - and it actually did serve a purpose. It was essential for optimizing slow, mechanical hard drives by rearranging scattered data into contiguous blocks. By doing so increased data load times (since the physical head of the hard drive didn't have to move that much).
However, what I remember most was the almost hypnotical satisfaction of seeing all those little blocks flashing, being organized, and just "knowing" that it was good for my computer.
In times when you fiddled around with autoxec.bat and config.sys, when every little Kilobyte of RAM mattered, and when hard drives were measured in Megabytes, not Terrabytes, the weekly routine of defragging almost felt like cleaning up your room.
Chinese scientists have developed,
The best shortest-path algorithm in 41 years!
A team from Tsinghua University has broken Dijkstra's "sorting barrier" - the first improvement since 1984.
Just use for a world-map 🤯
Paper - https://t.co/0AhR5O7vl4
https://t.co/a9KMVRuYGx
We deployed 44 AI agents and offered the internet $170K to attack them.
1.8M attempts, 62K breaches, including data leakage and financial loss.
🚨 Concerningly, the same exploits transfer to live production agents… (example: exfiltrating emails through calendar event) 🧵
supervision, the open-source library I created 2 years ago, is crossing 30,000 stars on GitHub!
thank you to everyone who helped me build this project! it took us 4,000+ commits, 1,000+ PRs and 100+ contributors to do it.
link: https://t.co/xXMRaS3Guk
What’s an IMSI Catcher?
Devices that mimic cell towers to track, locate or spy on you without you noticing.
This thread explains (clearly and simply)
How they work
How to detect them
How to protect yourself
Why 2G (GSM) matters
And how Faraday bags help
This content is for educational purposes only. I do not promote or justify illegal use in any way.
🔐 Real mobile privacy
Let’s begin🧵👇
#IMSI #GSM #MobilePrivacy