<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; hardware &amp; software</title>
	<atom:link href="http://www.system7.org/category/hardware-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:56:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Maltego 3 creators interviewed</title>
		<link>http://www.system7.org/2010/07/21/573/</link>
		<comments>http://www.system7.org/2010/07/21/573/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 15:36:01 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[hardware & software]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=573</guid>
		<description><![CDATA[In a recent Exotic Liability podcast (not PG13) Chris and Ryan interview folks from Paterva, the makers of Maltego.  You should definitely try Maltego if you&#8217;ve never used it.  They have a free version and it runs on both Windows and Linux.  The software allows you to create a visual mapping of gathered intel.  The [...]]]></description>
			<content:encoded><![CDATA[<p>In a recent <a href="http://www.exoticliability.com/">Exotic Liability</a> <a href="http://traffic.libsyn.com/exoticliability/Exotic_Liability_61.mp3">podcast</a> (not PG13) Chris and Ryan interview folks from Paterva, the makers of <a href="http://www.paterva.com/">Maltego</a>.  You should definitely try Maltego if you&#8217;ve never used it.  They have a free version and it runs on both Windows and Linux.  The software allows you to create a visual mapping of gathered intel.  The tool is a must have for penetration testing as well as gathering intel on persons of interest, a la dossier.  Maltego includes a powerful feature called <a title="List of Maltego Transforms" href="http://ctas.paterva.com/view/Category:Transforms">transforms </a>which allow you to rapidly pivot from one piece of valuable information to another.</p>
<p>FYI:  Chris and Ryan hosted <a href="http://www.youtube.com/results?search_query=tiger+team&amp;aq=f">TruTV&#8217;s Tiger Team show</a> which had a shorter life then the Microsoft Kin.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/07/21/573/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://traffic.libsyn.com/exoticliability/Exotic_Liability_61.mp3" length="82402223" type="audio/mpeg" />
		</item>
		<item>
		<title>win32 memory capture &amp; analysis cheat sheet</title>
		<link>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/</link>
		<comments>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 12:33:25 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ir]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=518</guid>
		<description><![CDATA[A high level overview to perform live memory captures and analysis: capture memory via moonsol&#8217;s win32dd parse memory snapshot with mandiant&#8217;s memoryze analyze results via audit viewer or analyze using the volatility framework &#8212; neatly packaged in SAN&#8217;S Sift Workstation]]></description>
			<content:encoded><![CDATA[<p>A high level overview to perform live memory captures and analysis:</p>
<ol>
<li><strong>capture</strong> memory via <a href="http://moonsols.com/product">moonsol&#8217;s</a> <a href="http://moonsols.com/component/jdownloads/view.download/3/2">win32dd</a></li>
<li>parse memory snapshot with mandiant&#8217;s <a href="http://www.mandiant.com/products/free_software/memoryze/">memoryze</a></li>
<li><strong>analyze</strong> results via <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer/download">audit viewer</a></li>
<li>or <strong>analyze</strong> using the <a title="Volatility Framework" href="https://www.volatilesystems.com/default/volatility" target="_blank">volatility framework</a> &#8212; neatly packaged in <a title="SIFT Workstation Image" href="https://computer-forensics2.sans.org/community/siftkit/" target="_blank">SAN&#8217;S Sift Workstation</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/06/14/win32-memory-capture-analysis-cheat-sheet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu can bypass iPhone pin to read data?</title>
		<link>http://www.system7.org/2010/06/12/ubuntu-can-bypass-iphone-pin-to-read-data/</link>
		<comments>http://www.system7.org/2010/06/12/ubuntu-can-bypass-iphone-pin-to-read-data/#comments</comments>
		<pubDate>Sat, 12 Jun 2010 12:48:06 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[iphone]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=547</guid>
		<description><![CDATA[According to this zdnet article, when plugging your iPod into an Ubuntu machine the device is mounted without ever being prompted for a PIN code.  This is working on non jail broken iPhones.  I&#8217;m surprised the article only names Ubuntu &#8212; surely this must work for other distributions?  Unfortunately I don&#8217;t own an iPhone to [...]]]></description>
			<content:encoded><![CDATA[<p>According to this <a title="Ubuntu Lucid Lynx 10.04 can read your iPhone's secrets" href="http://www.zdnet.com/blog/hardware/ubuntu-lucid-lynx-1004-can-read-your-iphones-secrets/8424" target="_blank">zdnet article</a>, when plugging your iPod into an Ubuntu machine the device is mounted without ever being prompted for a PIN code.  This is working on <strong>non</strong> jail broken iPhones.  I&#8217;m surprised the article only names Ubuntu &#8212; surely this must work for other distributions?  Unfortunately I don&#8217;t own an iPhone to test first hand.</p>
<p>On a side note, is Ubuntu taking over the world?  Sometimes you don&#8217;t want to make things too easy otherwise all of the idiots will flock from Mac and Windows and plague all of our favorite distributions with requests for ports of ___ (insert favorite fan boi single platform software here).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/06/12/ubuntu-can-bypass-iphone-pin-to-read-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DNS Performance &amp; Security&#8230;</title>
		<link>http://www.system7.org/2010/06/11/dns-performance-security/</link>
		<comments>http://www.system7.org/2010/06/11/dns-performance-security/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 12:27:15 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=538</guid>
		<description><![CDATA[I&#8217;ve gotten tired of Road Runner&#8217;s DNS redirection/hijacking service which I opt out of yet it keeps coming back.  I decided to do some DNS benchmarking, comparing my assigned ISP name servers against publicly provided DNS such as Google.   The results were very surprising.  It turns out I have less latency and hops reaching some [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve gotten tired of Road Runner&#8217;s <a title="DNS Hijacking" href="http://en.wikipedia.org/wiki/DNS_hijacking">DNS redirection/hijacking</a> service which I opt out of yet it keeps coming back.  I decided to do some DNS benchmarking, comparing my assigned ISP name servers against <a title="Public DNS Servers" href="http://www.topbits.com/public-dns-servers.html">publicly provided DNS</a> such as Google.   The results were very surprising.  It turns out I have less latency and hops reaching some of the publicly available DNS servers instead of those provided by my ISP (the servers actually resolve lookups faster).</p>
<p>Here&#8217;s what I did:</p>
<ol>
<li>Download and run DNS Benchmark (Windows or Wine): <a title="DNS Benchmark" href="http://www.grc.com/dns/benchmark.htm">http://www.grc.com/dns/benchmark.htm</a></li>
<li>Add your ISP assigned DNS servers into the DNS benchmark tool for comparison (Windows: ipconfig /all  Linux: cat /etc/resolv.conf)</li>
<li>Load any additional public DNS servers into the tool: <a title="Public DNS Servers" href="http://www.topbits.com/public-dns-servers.html">publicly provided  DNS</a></li>
<li>If public DNS is faster, <a href="http://support.hotkey.net.au/content/view/165/36/">configure</a> your machine for hardcoded DNS (not to pickup from DHCP).</li>
</ol>
<p>Coincidentally, Symantec has just released their own version of a public DNS that provides malware filtering.  You can read <a title="Symantec's Secure Public DNS Service" href="http://www.h-online.com/security/news/item/Symantec-s-Norton-DNS-service-to-block-malware-1015912.html">The H article here</a>.  Symantec&#8217;s &#8220;secure&#8221; DNS servers are 198.153.192.1 and 198.153.194.1</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/06/11/dns-performance-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google beta&#8217;s SSL for web searches</title>
		<link>http://www.system7.org/2010/05/24/google-betas-ssl-for-web-searches/</link>
		<comments>http://www.system7.org/2010/05/24/google-betas-ssl-for-web-searches/#comments</comments>
		<pubDate>Mon, 24 May 2010 16:54:35 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=527</guid>
		<description><![CDATA[According to this H article, Google is beginning to beta a new feature of providing SSL for their standard web search service. As one commenter noted, Google is still collecting the same information from your searches but this will limit 3rd parties from eavesdropping on your search queries. Remember SSL doesn&#8217;t guarantee absolute privacy as [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a title="Google secures search with SSL encryption" href="http://www.h-online.com/security/news/item/Google-secures-search-with-SSL-encryption-1006020.html">this H article</a>, Google is beginning to beta a new feature of providing SSL for their standard web search service.  As one commenter noted, Google is still collecting the same information from your searches but this will limit 3rd parties from eavesdropping on your search queries.  Remember SSL doesn&#8217;t guarantee absolute privacy as there&#8217;s <a title="Moxie Marlinspike DefCon SSL presentation" href="http://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf">Moxie Marlinspike&#8217;s work</a>, chance of <a href="http://www.system7.org/2010/04/14/more-must-have-firefox-add-ons/">CA intermediaries</a>, and your <a title="SSL man in the middle" href="www.schneier.com/blog/archives/2010/04/man-in-the-midd_2.html">employer loading their own trusted CA&#8217;s</a> into your corporate devices.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/05/24/google-betas-ssl-for-web-searches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google &amp; Privacy</title>
		<link>http://www.system7.org/2010/04/16/google-privacy/</link>
		<comments>http://www.system7.org/2010/04/16/google-privacy/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 14:04:52 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=503</guid>
		<description><![CDATA[Bruce Schneier recently posted an article about the erosion of privacy.  Specifically how the social networking sites are accelerating this &#8220;privacy decay.&#8221;  Along with attacked social networking sites he through in Google.  I just came across an interesting Forbes article where a Google engineer rebukes Schneier. You can find that article here: http://www.forbes.com/2010/04/12/privacy-facebook-gmail-technology-security-google.html Two interesting [...]]]></description>
			<content:encoded><![CDATA[<p>Bruce Schneier recently<a href="http://www.schneier.com/essay-311.html"> posted an article</a> about the erosion of privacy.  Specifically how the social networking sites are accelerating this &#8220;privacy decay.&#8221;  Along with attacked social networking sites he through in Google.  I just came across an interesting Forbes article where a Google engineer rebukes Schneier. You can find that article here: <a href="http://www.forbes.com/2010/04/12/privacy-facebook-gmail-technology-security-google.html">http://www.forbes.com/2010/04/12/privacy-facebook-gmail-technology-security-google.html</a></p>
<p>Two interesting tidbits in the article are Google&#8217;s privacy control pages which you may not be aware of:</p>
<ol>
<li><a href="http://www.google.com/dashboard">Google Dashboard</a> &#8211; Control your Google privacy settings for all of google&#8217;s applications</li>
<li><a href="http://google.com/ads/preferences">Ads Preferences Manager</a> &#8211; Control whether ads are tailored to your viewing habits or not.  You can opt out here.  *Warning this site sneakily redirects through doubleclick.net &#8212; bastards!<a href="http://google.com/ads/preferences"><br />
</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/04/16/google-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Determining the optical cluster size for your volumes</title>
		<link>http://www.system7.org/2010/01/31/determining-the-optical-cluster-size-for-your-volumes/</link>
		<comments>http://www.system7.org/2010/01/31/determining-the-optical-cluster-size-for-your-volumes/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 13:08:15 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[hardware & software]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=438</guid>
		<description><![CDATA[If you&#8217;re like most people then you have a separate partition where you store your data (mp3s, torrents, software, movies etc).  Most people set these partitions up with the default settings (NTFS, 4kb cluster size).  However, in most cases the 4kb cluster size is horribly inefficient for the purpose of these data partitions.  Chances are [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re like most people then you have a separate partition where you store your data (mp3s, torrents, software, movies etc).  Most people set these partitions up with the default settings (NTFS, 4kb cluster size).  However, in most cases the 4kb cluster size is horribly inefficient for the purpose of these data partitions.  Chances are most of the files on this data partition will be at least 1mb.  The smaller cluster size causes your drive to perform extra seeks to read and write the data.  With the sudden rise of the new GUID Partition Table (<a href="http://en.wikipedia.org/wiki/GUID_Partition_Table">GPT</a>) and drives beginning to ship with a larger default sector size than 512bytes you should get ahead of the curve.</p>
<p>First, you need to determine what the optimal cluster(block) size is for your data.  The best way to figure this out is taking the median file size of the partition.  Once you know the best cluster size then you will need to copy the data to another partition or drive.  Finally, you can repartition with the new cluster size and then copy your data back.</p>
<p>Here are the steps:</p>
<ol>
<li>Run one of the below scripts, open in Excel/Calc and run the median() function &#8212; does anyone have a quicker way to determine median file size?  <a title="Keyboard Kung Fu" href="http://blog.commandlinekungfu.com/">keyboard kung fu</a>?</li>
<li>Calculate the median size of files on the volume (<a href="http://www.system7.org/wp-content/uploads/2010/01/listFilesSize.zip">listFilesSize</a> &#8211; vbscript) (<a href="http://www.system7.org/wp-content/uploads/2010/01/listFileSizes_python.zip">listFileSizes_python</a>/linux &#8212; first attempt at python!)</li>
<li>Move data off the volume</li>
<li>Reformat volume using optimal cluster size</li>
<li>Verify new cluster size: [root@localhost]# ntfsinfo -m -d /dev/sdaX</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/01/31/determining-the-optical-cluster-size-for-your-volumes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Try something new&#8230;. AskEraser&#8230;.</title>
		<link>http://www.system7.org/2009/11/13/try-something-new-askeraser/</link>
		<comments>http://www.system7.org/2009/11/13/try-something-new-askeraser/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 17:30:19 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=329</guid>
		<description><![CDATA[I&#8217;ve been looking around for a new search engine besides Google.  I&#8217;m worried about giving them all the business and their privacy policy scares me.  They&#8217;re collecting more and more of our information and no one seems to notice.  (Take a look at Google&#8217;s new Dashboard if you want to see what they&#8217;re collecting on [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been looking around for a new search engine besides Google.  I&#8217;m worried about giving them all the business and their privacy policy scares me.  They&#8217;re collecting more and more of our information and no one seems to notice.  (Take a look at Google&#8217;s new <a title="Google Dashboard" href="https://www.google.com/dashboard/">Dashboard</a> if you want to see what they&#8217;re collecting on you)  I&#8217;ll admit, I haven&#8217;t started running my own <a title="postfix" href="http://www.postfix.org">MTA</a> again but I&#8217;m getting close. Do you want my public key?  I hope you have one.  There&#8217;s guys in <a href="http://www.schneier.com/blog/archives/.../nsa_building_ma.html">Utah</a> and <a href="http://www.salon.com/news/feature/2006/06/21/att_nsa/">St. Louis</a> looking through your email contents as I write this&#8230;.</p>
<p>Anyways&#8230;back on track&#8230;.</p>
<p>It&#8217;s not the easiest task comparing privacy policies even if you limit your search to the big players (google, yahoo, bing, baidu, ask, altavista).  Besides <a href="http://www.scroogle.org">Scroogle</a> which is a Google proxy &#8212; returning scrubbed results cookie free, most of the large search engines are very similar with their policies.  They all store some type of tracking cookie and say they can use this to target specific advertisements towards you and or share with third parties.  HOWEVER, all is not lost, I did come across the <a href="http://sp.ask.com/en/docs/about/askeraser.shtml">Ask.com AskEraser</a>.  Navigate over to Ask.com and in the top right corner you&#8217;ll see &#8220;AskEraser On | Off&#8221;  turn this guy and check your cookies for yourself&#8230;.it does make a difference&#8230;</p>
<p><em>When enabled, AskEraser will completely delete your search queries and data from Ask.com servers, including: your IP address, User ID and Session ID cookies, as well as the complete text of your search query&#8211;all within a matter of hours,</em></p>
<p>We&#8217;ll have to take Ask&#8217;s word that they&#8217;re actually removing our search data from their servers unless someone has a better idea?  Raid one of their NOCs on a Friday night hoping to bribe the night security guard with a pizza and a hooker? (maybe the pizza and a mountain dew would be enough)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/11/13/try-something-new-askeraser/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows Anti Forensics Tip of the Day&#8230;</title>
		<link>http://www.system7.org/2009/11/11/windows-anti-forensics-tip-of-the-day/</link>
		<comments>http://www.system7.org/2009/11/11/windows-anti-forensics-tip-of-the-day/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 18:04:05 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=350</guid>
		<description><![CDATA[I previously wrote about how to have your system automatically clear the pagefile before a reboot or shutdown.  There&#8217;s a couple other steps I recommend you make on your system&#8230; Automatically permanently delete (Nuke on Delete)- Normally Delete sends files to the Recycle Bin and a Shift+Delete will permanently delete them.  With the registry tweak [...]]]></description>
			<content:encoded><![CDATA[<p>I <a href="http://www.system7.org/2009/06/10/windows-forensics-tip-of-the-day/">previously wrote </a>about how to have your system automatically clear the pagefile before a reboot or shutdown.  There&#8217;s a couple other steps I recommend you make on your system&#8230;</p>
<p><strong>Automatically permanently delete (Nuke on Delete)- </strong>Normally Delete sends files to the Recycle Bin and a Shift+Delete will permanently delete them.  With the registry tweak below the normal Delete will also behave as a permanent delete. ***Note: Delete does not mean a file is deleted.  It only frees up the file record and clusters so they _could_ be overwritten.</p>
<ol>
<li>Go to Start -&gt; Run and type Regedit</li>
<li>On the left hand side select the “+” to navigate to the following.</li>
<li>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ BitBucket</li>
<li>On the right look for NukeOnDelete</li>
<li>Right click it and set the key value for NukeOnDelete to 1</li>
</ol>
<p><strong>Scheduled Task to Zero out unused disk space &#8211; </strong>As I mentioned above a deleted file only insures that there is a _chance_ the file will be overwritten.  If you run the below command it will zero out all unused disk space which _should_ be good enough to prevent file content recovery. ***Note: The deleted file name will still be lying around until a new file happens to overwrite it.</p>
<p>&gt;cipher /W:[directory_to_wipe]</p>
<p>Here&#8217;s my scheduled task: C:\WINDOWS\system32\cmd.exe /c cipher /W:C:\</p>
<p><strong>Scheduled Task to Delete Recent Items &#8211; </strong>Even if you permanently delete a file and or use Eraser there&#8217;s a copy of the filename in your Recent directory.  I have the following scheduled task command which clears my Recent items once a day&#8230;.</p>
<p>Task for Recent Items:</p>
<p>&gt;C:\WINDOWS\system32\cmd.exe /c del &#8220;c:\documents and settings\<strong>[username]</strong>\recent\*.lnk&#8221;</p>
<p>Task for Recent Office Items:</p>
<p>&gt;C:\WINDOWS\system32\cmd.exe /c del /Q &#8220;C:\Documents and Settings\<strong>[username]</strong>\Application Data\Microsoft\Office\Recent\*.*&#8221;</p>
<p><strong><a href="http://sourceforge.net/projects/eraser ">Eraser </a>-</strong> I highly recommend using this great freeware utility.  One of many things it does is adds a new option in your content menu to permanently delete a file and zero out the contents all at the same time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/11/11/windows-anti-forensics-tip-of-the-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jailbreak: Export non-exportable Windows certificates</title>
		<link>http://www.system7.org/2009/10/13/jailbreak-export-non-exportable-windows-certificates/</link>
		<comments>http://www.system7.org/2009/10/13/jailbreak-export-non-exportable-windows-certificates/#comments</comments>
		<pubDate>Tue, 13 Oct 2009 14:32:02 +0000</pubDate>
		<dc:creator>The Gunslinger</dc:creator>
				<category><![CDATA[microsoft]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=322</guid>
		<description><![CDATA[I came across a handy (&#38; free) Windows utility that allows you to export &#8220;non exportable&#8221; certificates.  Do you want to get at those recovery certificates or private keys? Jailbreak can be snatched here: https://www.isecpartners.com/jailbreak.html]]></description>
			<content:encoded><![CDATA[<p>I came across a handy (&amp; free) Windows utility that allows you to export &#8220;non exportable&#8221; certificates.  Do you want to get at those recovery certificates or private keys? Jailbreak can be snatched here: <a href="https://www.isecpartners.com/jailbreak.html">https://www.isecpartners.com/jailbreak.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2009/10/13/jailbreak-export-non-exportable-windows-certificates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
