Chris Palmer & Alex Stamos: Breaking Forensics Software: Weaknesses in Critical Evidence Collection episode artwork

EPISODE · Jan 9, 2006 · 51 MIN

Chris Palmer & Alex Stamos: Breaking Forensics Software: Weaknesses in Critical Evidence Collection

from DEFCON 15 [Audio] Speeches from the hacker conventions · host DEF CON Announcements

Across the world law enforcement, enterprises and national security apparatus utilize a small but important set of software tools to perform data recovery and investigations. These tools are expected to perform a large range of dangerous functions, such as parsing dozens of different file systems, email databases and dense binary file formats. Although the software we tested is considered a critical part of the investigatory cycle in the criminal and civil legal worlds, our testing demonstrated important security flaws within only minutes of fault injection. In this talk, we will present our findings from applying several software exploitation techniques to leading commercial and open-source forensics packages. We will release several new file and file system fuzzing tools that were created in support of this research, as well as demonstrate how to use the tools to create your own malicious hard drives and files. This talk will make the following arguments: (1) Forensic software vendors are not paranoid enough. Vendors must operate under the assumption that their software is under concerted attack. (2) Vendors do not take advantage of the protections for native code that platforms provide, such as stack overflow protection, memory page protection), safe exception handling, et c. (3) Forensic software customers use insufficient acceptance criteria when evaluating software packages. Criteria typically address only functional correctness during evidence acquisition when no attacker is present, yet forensic investigations are adversarial. (4) Methods for testing the quality of forensic software are not meaningful, public, or generally adopted. Our intention is to expose the security community to the techniques and importance of testing forensics software, and to push for a greater cooperation between the customers of forensics software to raise the security standard to which such software is held. "Chris Palmer is a security consultant with iSEC Partners, performing application penetration tests, code reviews, and security research. Alex Stamos is the co-founder and VP of Professional Services at iSEC Partners, a leading provider of application security services. Alex is an experienced security engineer and consultant specializing in application security and securing large infrastructures, and has taught multiple classes in network and application security.

Episode metadata supplied by the publisher feed · Published Jan 9, 2006

Embed this episode

NOW PLAYING

Chris Palmer & Alex Stamos: Breaking Forensics Software: Weaknesses in Critical Evidence Collection

0:00 51:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of DEFCON 15 [Audio] Speeches from the hacker conventions?

This episode is 51 minutes long.

When was this DEFCON 15 [Audio] Speeches from the hacker conventions episode published?

This episode was published on January 9, 2006.

Can I download this DEFCON 15 [Audio] Speeches from the hacker conventions episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!