Chapter 9: Internet Artifacts Flashcards

1
Q

what is a browser

A

a program/ application a user can use to access websites via the world wide web

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the most common browsers

A
  1. chrome (55%)
  2. safari (12%)
  3. internet explorer (8%)
  4. firefox (6%)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

where does chrome store data

A

within diff databases, allowing options to sync across multiple platforms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what file are bookmarks (chrome)

A
  • JSON Javascript object notation formatting file
  • will not have a file extension
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what info can we see when you open a JSON bookmark file in a text reader

A
  • date added
  • last visited
  • name of bookmark
  • url
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what folders are found under the root directory when viewing a JSON bookmark file in a text viewer

A
  • bookmark_bar additional children folders and their info
  • other
  • synced
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

is the presence of an incriminating bookmark enough to act on

A

may or may not, typically you should show they acc visited the page

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what can be found in the chrome history database

A
  • downloads (where they got it from, where it is stored, start/stop time of download, and size)
  • keyword search (what terms were searched)
  • URL types (what was put into the search bar)
  • history (URL visited by user, number of times, and date/time of visis)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are cookies

A
  • a dataset created by a website and stored on the user’s system
  • designed to track the users activity (adding an item to cart or which pages were visited)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

is the presence of a cookie evidence the user knowingly visited the site

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what type of file are cookies in Chrome

A
  • SQLite database
  • no file extension
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what key thing of interest can be seen on cache

A

server IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

where can you find the password info saved in chrome

A

in the Logon Data file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what type of file is the saved password info in Chrome

A
  • SQLight database
  • no file extension
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

how are passwords saved in their SQLight database form in Chrome

A
  • not the acc passwords
  • stores info about the account, to encrypt passwords
  • Chrome Pass will decrypt passwords
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

what is the web browser of the microsoft windows OS

A

internet explorer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

how are bookmarks saved in internet explorer

A

URL format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

how long does internet explorer track users activity

A

20 days (can be changed by the user tho)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

edge and internet explorer version 10 and higher use which ESE database

A

WebCasheV01.dat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

what do you want to look at in the WebCasheV01.dat file to find info about IE history

A
  • containers
  • there are 16 tables, we care about 12, 14, 15, 16
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

describe the naming conventions of the MSHist01 tables

A

the dates they span from (year/month/day)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

what is found in table 12 in the containers file in internet explorer

A

daily history file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

how do we find the date/time values for the files found in table 12 in the containers file in internet explorer

A
  • take the decimal number
  • convert it into hex
  • use DCode to get the date/time
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

when a user types a URL into the address bar, what happens in internet explorer

A

a record is created in the user’s NTUSER.dat file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

what do you want to look at in the WebCasheV01.dat file to find info about IE cache

A
  • use Internet Explorer Cache Viewer
  • itll give you the filename, and URL of where it came from
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

how does IE save cookie files

A

as simple text files

27
Q

which table of WebCacheV01.dat has info about cookies

A

5

28
Q

what is one unique feature offered by firefox

A

the use of multiple profiles (can segregate their activity)

29
Q

how does firefox store cache

A

under each profile

30
Q

how does firefox store cookies

A
  • uses SQLite database to store info
  • NOT as single files
  • found in the Roaming folder
31
Q

how does firefox store history

A
  • in the SQLite database file called places.sqlite
  • types URLs are also here
32
Q

where does firefox store passwords

A
  • in two files:
  • kay#.db (can be key3 or key4)
  • logins.json
33
Q

where does firefox store bookmarks

A

in an SQLite database file

34
Q

what is social media

A

the use of apps or programs to create and share info, forms of expression, opinions, ideas, and so on through the global internet

35
Q

which locations are there for you to find digital evidence related to your investigation surrounding social media

A
  • user system
  • service provider
36
Q

what is the important part of the facebook URL

A

the profile ID (unique set of numbers for each profile)

37
Q

what is the difference between twitter’s handle and UID

A
  • handles can change
  • UID remains the same
38
Q

what info does the service provider have on their subscriber

A
  • name
  • age
  • address
  • usage dates/times
  • IP address
39
Q

how do you get info from the service providers on their subscriber

A

serve them w appropriate judicial paperwork

40
Q

what does P2P stand for

A

peer-to-peer

41
Q

how does P2P file sharing work

A
  • user installs app
  • they designate which files/folders they want to share to the network
  • you can search for files on the network and if they want it, the app identifies the nodes possessing the file
  • the app then connects them and starts downloading pieces of the file
42
Q

what is Ares

A

an open source P2P app using decentralized network configuration

43
Q

what can you find in the Data folder of Ares

A
  • two files: ShareH.net and ShareL.dat
  • these files track the filename, hash value, date/time stamp, and sharing status
44
Q

what is eMule

A

an open source P2P app using decentralized network configuration

45
Q

what happens when a user installs eMule

A
  • created an eMule folder
  • contains 2 subfolders: incoming and temp
46
Q

what happens when files are downloaded on eMule

A
  • as they are downloading, they’re stored in temp
  • once it is complete, they’re moved to incoming
47
Q

what can you find in the config subdirectory of eMule

A
  • the preferences.ini file
  • this tells the nickname and location of incoming and temp directories
48
Q

what is found in the prederences.dat file

A

the unique identification number for each user

49
Q

what is found in the AC_SearchStrings.dat file in eMule

A

the last 30 searched terms by user

50
Q

what is found in known.met file in eMule

A

list of files that have been downloaded by the app and files shared by the app

51
Q

what is Shareaza

A

an open source P2P app using decentralized network configuration

52
Q

what is found in the Shareaza folder

A

local and roaming folders

53
Q

what is found in the Data folder of Shareaza

A
  • file called Profile.xml
  • contains user-created and app created artifacts
54
Q

what is stored in the IncompletePath in shareaza

A

incomplete files

55
Q

what service models of cloud-based computing might we encounter

A
  • infrastructure as a service
  • software as a service
  • platform as a service
56
Q

what are the deployment methods of cloud resources to choose from

A
  • public cloud made available to public or specific members of a group
  • private cloud available to specific members w specific rights
  • community cloud similar to private users comprise multiple organizations w similar focus
  • hybrid cloud made up of 2 or more diff deployment methods
57
Q

describe infrastructure as a service

A
  • offered to customer for use
  • provider maintains ownership and control
  • customer pays for hardware/service needed
58
Q

describe software as a service

A
  • apps are provided to the customer via network
  • costumer pays subscription fee to vendor to use software
  • content is stored on the server and can be used/shared w other members
59
Q

describe platform as a service

A
  • OS of the client is provided to the customer via a cloud server
  • user can install apps and maintain settings
  • provider manages hardware and OS
  • client is responsible for system admin
60
Q

what are the most common cloud-based storage options

A

dropbox and google drive

61
Q

which databases are of interest in dropbox

A
  • config.dbx user ID, account email, username and path for dropbox folder
  • filecache.dbx file journal table, w info on files being synched
62
Q

which databases are of interest in google drive and why

A
  • sync_config.db email associated, USB deviced being synced, path for folders
  • snapshot.db local_entry table w info about files being synced
  • cloud_entry contain filename, modified date/time stamps, file size etc
  • device_db.db the external_devices table w device ID, USB device label, upload date/time stamps, and any sync
  • devices_file contain device ID, file name, file path, date/time of sync
63
Q
A