<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-109857104483939627</id><updated>2011-12-29T16:56:51.079+07:00</updated><title type='text'>Forensic Cop</title><subtitle type='html'>This blog is developed to share the knowledge and science of computer forensic and its related stuff to those who would like to apply forensic investigation on computer crime.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>37</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-1051464356810408924</id><published>2011-06-20T01:20:00.002+07:00</published><updated>2011-06-20T01:48:45.062+07:00</updated><title type='text'>Audio Forensic Course at Puslabfor Mabes Polri</title><summary type='text'>This week, I will deliver lecturing theory and hands-on practice on Audio Forensic. It will be conducted at Puslabfor Mabes Polri in which the participants are representatives from all Forensic Lab Branches in Indonesia. On this course, I will guide them on how to perform Audio Forensic for voice recognition purposes. Some topics I will lecture are: Theory of Voice
Components of Voice
Procedure </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/1051464356810408924/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2011/06/audio-forensic-course-at-puslabfor.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1051464356810408924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1051464356810408924'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2011/06/audio-forensic-course-at-puslabfor.html' title='Audio Forensic Course at Puslabfor Mabes Polri'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-6083282477765728334</id><published>2011-06-20T00:58:00.000+07:00</published><updated>2011-06-20T00:58:10.851+07:00</updated><title type='text'>Computer Forensic Training at Netherlands Police Academy</title><summary type='text'>A couple weeks ago, I and my colleagues went to Netherlands for joining Computer Forensic Training at Netherlands Police Academy (NPA). It was conducted for 2 weeks. Personally I like to learn a lot about digital forensic and its related stuff, so that going to NPA for this training makes me happy. I could explore widely the world of computer forensic. On this training, I could obtain much </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/6083282477765728334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2011/06/computer-forensic-training-at.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/6083282477765728334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/6083282477765728334'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2011/06/computer-forensic-training-at.html' title='Computer Forensic Training at Netherlands Police Academy'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-5779243121626802256</id><published>2011-06-20T00:42:00.000+07:00</published><updated>2011-06-20T00:42:34.992+07:00</updated><title type='text'>Sorry .... !</title><summary type='text'>It's a very long time for me not to post a new thing on this blog. Actually I really want to do it, but honestly there are so much things which must be done soon and properly. It takes almost all my time, so that I cannot allocate my free time to open this blog. Sorry for this inconvenience. Tonight, I force my self to renew my lovely blog again with some new information.</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/5779243121626802256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2011/06/sorry.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5779243121626802256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5779243121626802256'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2011/06/sorry.html' title='Sorry .... !'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-4617617290747453573</id><published>2010-05-26T13:41:00.000+07:00</published><updated>2010-05-26T13:41:50.015+07:00</updated><title type='text'>2010 Indonesian Super Six UK Alumni</title><summary type='text'>On last April, I was awarded by British Council as one of "2010 Indonesian Super Six UK Alumni". It is really a pride and honour for me to be selected for this award. I've never dreamed it before. For this award, I thank my family for all supports given to me when I joined master degree, MSc in Forensic Informatics at the University of Strathclyde, UK. I am also gratefull to my lecturers teaching</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/4617617290747453573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/05/2010-indonesian-super-six-uk-alumni.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4617617290747453573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4617617290747453573'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/05/2010-indonesian-super-six-uk-alumni.html' title='2010 Indonesian Super Six UK Alumni'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-1947197595150791375</id><published>2010-05-26T13:16:00.000+07:00</published><updated>2010-05-26T13:16:34.272+07:00</updated><title type='text'>Cyber Crime Research at Strathclyde</title><summary type='text'>At the end of last April, I was invited to attend the first session of Cyber Crime Research which is conducted by Institutes for Advanced Studies (IAS) along with University of Strathclyde. This session was attended by representatives of UK universities, law enforcement agencies and private sectors. On this moment, I delivered presentation about ATM Crime in which I focused on modus operandi and </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/1947197595150791375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/05/cyber-crime-research-at-strathclyde.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1947197595150791375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1947197595150791375'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/05/cyber-crime-research-at-strathclyde.html' title='Cyber Crime Research at Strathclyde'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3317416387774156401</id><published>2010-02-26T23:42:00.000+07:00</published><updated>2010-02-26T23:42:49.818+07:00</updated><title type='text'>Sharing the knowledge</title><summary type='text'>In the last two weeks, I was requested by some parties to share the knowledge on digital forensic at two different activities. The first is to be keynote speaker on the digital forensic preview seminar conducted by EC-Council Representative for Indonesia (i.e. PT. Datamation) along with PT. Andalan Nusantara Teknologi. This seminar carried out in Jakarta was attended by about sixty people which </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3317416387774156401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/02/sharing-knowledge.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3317416387774156401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3317416387774156401'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/02/sharing-knowledge.html' title='Sharing the knowledge'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3491958004217989489</id><published>2010-01-02T22:29:00.000+07:00</published><updated>2010-01-02T22:29:48.023+07:00</updated><title type='text'>New Year Message</title><summary type='text'>Dear All,

Like or dislike, we have leaved the year 2009 behind and we encounter the new year 2010. So many things we have done in the last year. It could be good or bad thing. For the good thing, We hope that we could reach it again in the new year 2010 or even we could exceed it to be better than the previous year. For the bad thing, we have to leave it and do not repeat it in this year. With </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3491958004217989489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/01/new-year-message.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3491958004217989489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3491958004217989489'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/01/new-year-message.html' title='New Year Message'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-5541089111827977363</id><published>2010-01-02T22:16:00.000+07:00</published><updated>2010-01-02T22:16:33.460+07:00</updated><title type='text'>Forensic Cop Journal 3(3): Digital Forensic Principles</title><summary type='text'>Introduction

Following the fast development of IT, computer crime becomes a complex crime with the use of high technology, so that it is not easy for forensic investigators to analyse this crime, even to trace back the perpetrators. The criminals can utilise the internet or intranet in order to commit this crime by exploiting vulnerabilities which might exist in the network, or even in the </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/5541089111827977363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-33-digital.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5541089111827977363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5541089111827977363'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-33-digital.html' title='Forensic Cop Journal 3(3): Digital Forensic Principles'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-6211993984573796352</id><published>2010-01-02T22:08:00.000+07:00</published><updated>2010-01-02T22:08:13.806+07:00</updated><title type='text'>Forensic Cop Journal 3(2): Standard Operating Procedure of Seizure on Computer-based Electronic Evidence</title><summary type='text'>Introduction

Handling the evidence found in the case of computer crime or computer-related crime is different from handling other evidence such as blood, tool marks, trace, and fibres. The evidence found at such crimes is grouped as computer-based electronic evidence. As the evidence from this type of crime is easy to volatile, digital forensic analyst should be able to understand how to handle </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/6211993984573796352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-32-standard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/6211993984573796352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/6211993984573796352'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-32-standard.html' title='Forensic Cop Journal 3(2): Standard Operating Procedure of Seizure on Computer-based Electronic Evidence'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-1216969491050890484</id><published>2010-01-02T21:57:00.000+07:00</published><updated>2010-01-02T21:57:52.321+07:00</updated><title type='text'>Forensic Cop Journal 3(1): Standard Operating Procedure of Physical Analysis on Ubuntu</title><summary type='text'>In this journal, the image file is a dd file which is obtained from the acquisition process previously. After checking the hash value of the dd image file which must be identical with the evidence of storage media, the dd is then analysed in the following further actions.

Method: Physical analysis with the use of Autopsy

Autopsy is graphical interface form of The Sleuthkit (TST) created by </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/1216969491050890484/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-31-standard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1216969491050890484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1216969491050890484'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2010/01/forensic-cop-journal-31-standard.html' title='Forensic Cop Journal 3(1): Standard Operating Procedure of Physical Analysis on Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-5833377195905442796</id><published>2009-12-26T23:53:00.000+07:00</published><updated>2009-12-26T23:53:35.401+07:00</updated><title type='text'>Forensic Cop Journal 2(3): Standard Operating Procedure of Acquisition on Ubuntu</title><summary type='text'>Introduction

When dealing with the evidence of storage media, a digital forensic analyst must be careful in the process of acquisition. Once he makes a mistake, then the next processes would be doubted, even it could be rejected by the court. As the process of acquisition is very important in digital forensic, it should be handled properly. To obtain the output of the acquisition process is </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/5833377195905442796/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-23-standard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5833377195905442796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/5833377195905442796'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-23-standard.html' title='Forensic Cop Journal 2(3): Standard Operating Procedure of Acquisition on Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-135784934825377758</id><published>2009-12-19T04:44:00.000+07:00</published><updated>2009-12-19T04:44:37.349+07:00</updated><title type='text'>Forensic Cop Journal 2(2): Standard Operating Procedure of Audio Forensic</title><summary type='text'>IntroductionThere are many types of digital evidence which could be encountered by digital forensic analyst in dealing with computer crime or computer-related crime. Not only files, videos, digital images, encrypted items, unallocated clusters, slacks and so forth, but also digital audio files might be analysed. In certain cases, the audio files become significant evidence to show the involvement</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/135784934825377758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-22-standard.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/135784934825377758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/135784934825377758'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-22-standard.html' title='Forensic Cop Journal 2(2): Standard Operating Procedure of Audio Forensic'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-2773738954546156902</id><published>2009-12-01T09:04:00.000+07:00</published><updated>2009-12-01T09:04:08.117+07:00</updated><title type='text'>Forensic Cop Journal 2(1): Ubuntu Forensic</title><summary type='text'>Background

Ubuntu Forensic is the use of Ubuntu for digital forensic purposes. As it provides a wide range of forensic tools as well as anti-forensic and cracking tools, so it is reliable to investigate a computer crime and analyse digital evidence on it. The significant difference on forensic applications between Ubuntu and Ms Windows is that Ubuntu applications are freeware, while the </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/2773738954546156902/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-21-ubuntu-forensic.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2773738954546156902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2773738954546156902'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/12/forensic-cop-journal-21-ubuntu-forensic.html' title='Forensic Cop Journal 2(1): Ubuntu Forensic'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-7698504405183664646</id><published>2009-11-22T01:14:00.000+07:00</published><updated>2009-11-22T01:14:00.423+07:00</updated><title type='text'>Audio Forensic with Cedar</title><summary type='text'>A few weeks ago, I joined the Audio Forensic Training which was jointly conducted between Forensic Laboratory Centre of Indonesian National Police Headquarters and Cedar Cambridge. In this training, we developed the latest techniques on noise filtering by using Cedar instrument which was installed in the Audio Laboratory at my office. According to Dr. David Robinson who was also the instructor at</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/7698504405183664646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/11/audio-forensic-with-cedar.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7698504405183664646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7698504405183664646'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/11/audio-forensic-with-cedar.html' title='Audio Forensic with Cedar'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-2664112228916236445</id><published>2009-11-19T12:41:00.000+07:00</published><updated>2009-11-19T12:41:53.997+07:00</updated><title type='text'>Face Sketching</title><summary type='text'>This material actually is my slides presentation when being requested to be instructor on Frontline Forensic Course in Indonesia. This course has been being conducted since 16 November till 4 December 2009. In this course, I deliver teaching materials about Digital Forensic, Face Sketching, Photography Forensic, Fire Investigation and GPS. In this post, I just describe my materials on Face </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/2664112228916236445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/11/face-sketching.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2664112228916236445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2664112228916236445'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/11/face-sketching.html' title='Face Sketching'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-1149533279266784875</id><published>2009-11-02T12:11:00.000+07:00</published><updated>2009-11-02T12:11:41.045+07:00</updated><title type='text'>Digital Forensic: State of the art</title><summary type='text'>I think it is a long time for me not to post a new topic in this blog. For this reason, I apologise because I have been so busy with some crime scene processing and digital forensic analysis.

In this post, I would like to describe a more detail about digital forensic from investigation flowchart and digital forensic procedure to study case. It is in the form of a presentation which will be </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/1149533279266784875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/11/digital-forensic-state-of-art.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1149533279266784875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1149533279266784875'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/11/digital-forensic-state-of-art.html' title='Digital Forensic: State of the art'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-7826963623735022159</id><published>2009-10-05T10:17:00.000+07:00</published><updated>2009-10-05T10:17:50.257+07:00</updated><title type='text'>Forensic Cop Journal 1(3) 2009: Forensically Sound Write Protect on Ubuntu</title><summary type='text'>Actually this journal is derived from my previous post concerning forensically write protect on Ubuntu which has been experimented successfully before. After considering this topic is so significant, so I take it to be an official journal. For this journal, I just put Introduction and Experiments Preparation for this post; therfore for full version of pdf of this journal, it can be downloaded at </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/7826963623735022159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/10/forensic-cop-journal-13-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7826963623735022159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7826963623735022159'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/10/forensic-cop-journal-13-2009.html' title='Forensic Cop Journal 1(3) 2009: Forensically Sound Write Protect on Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3225100559702210249</id><published>2009-10-02T12:55:00.001+07:00</published><updated>2009-10-02T12:56:17.341+07:00</updated><title type='text'>Forensic Cop Journal 1 (2) 2009: Similarities and Differences between Ubuntu and Windows on Forensic Applications</title><summary type='text'>
This post is the form of development of previous post concerning the same topic. It is about similarities and differences between Ubuntu and Windows on forensic applications. The previous post only discuss it in general and is like brief summary of experiments performed before; therefore in order to make the topic becomes comprehensive view, this post in the form of journal is issued. I only put</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3225100559702210249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/10/forensic-cop-journal-1-2-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3225100559702210249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3225100559702210249'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/10/forensic-cop-journal-1-2-2009.html' title='Forensic Cop Journal 1 (2) 2009: Similarities and Differences between Ubuntu and Windows on Forensic Applications'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-563190538519543869</id><published>2009-09-16T10:11:00.014+07:00</published><updated>2009-10-01T13:16:02.738+07:00</updated><title type='text'>Forensic Cop Journal 1(1) 2009: Symmetric and Asymmetric Cryptography in Brief Practice</title><summary type='text'>
The pdf version of this journal can be downloaded at http://www.scribd.com/doc/20461254/Forensic-Cop-Journal-11-2009Symmetric-and-Asymmetric-Cryptography-in-Brief-Practice


Introduction
 
Since cryptography offers a tight security for people to encode their message to be unreadable by third party, most people are interested in utilizing it in order to keep their privacy. It is expected that </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/563190538519543869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/overview-on-symmetric-and-asymmetric.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/563190538519543869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/563190538519543869'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/overview-on-symmetric-and-asymmetric.html' title='Forensic Cop Journal 1(1) 2009: Symmetric and Asymmetric Cryptography in Brief Practice'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vHYUtxtcOiw/SrBRqIV8hUI/AAAAAAAAAIA/Wfu-w0VkevM/s72-c/RemoraUSBDiskGuard.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-4428801486776865298</id><published>2009-09-13T10:02:00.002+07:00</published><updated>2009-09-13T10:05:46.217+07:00</updated><title type='text'>Brief Description on Similarites and Differences in Forensic Applications between Ubuntu and Windows</title><summary type='text'>
The investigators can perform forensics analysis either under Ubuntu 8.10 or under Windows XP in dealing with the case of computer crime. At certain extent, both operating systems have many similarities so that the forensics investigators do not need to be confused in deciding what operating system suitable for carrying out a particular analysis. 
Based on the explanations supported by </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/4428801486776865298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/brief-description-on-similarites-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4428801486776865298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4428801486776865298'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/brief-description-on-similarites-and.html' title='Brief Description on Similarites and Differences in Forensic Applications between Ubuntu and Windows'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-8682312092384682731</id><published>2009-09-13T09:49:00.002+07:00</published><updated>2009-09-13T09:51:03.138+07:00</updated><title type='text'>Experiment 15 on Wine as Ubuntu Super Bridge</title><summary type='text'>I like Wine application on Ubuntu a lot. It makes a significant difference between Ubuntu and Ms Windows, although not all Windows applications can be installed into Ubuntu. For some cases, it is very helpful. I suggest anybody to install and use it so that the machine becomes more flexible. 

One of amazing tools under Ubuntu 8.10 is Wine. Through this application the forensics investigators can</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/8682312092384682731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-15-on-wine-as-ubuntu-super.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8682312092384682731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8682312092384682731'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-15-on-wine-as-ubuntu-super.html' title='Experiment 15 on Wine as Ubuntu Super Bridge'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vHYUtxtcOiw/SqxcLASQAgI/AAAAAAAAAHw/_Kt7hLFMMwE/s72-c/Elcomsoft.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-2474350236400391901</id><published>2009-09-13T09:21:00.001+07:00</published><updated>2009-09-13T09:29:34.207+07:00</updated><title type='text'>Experiment 14 on Deleted Files Recovery under Ubuntu</title><summary type='text'>This experiment was performed on December 2008 in order to support my statement on similarities of forensic applications running under between Ubuntu and Windows. From all experiments I carried out under Ubuntu, I can say that Ubuntu is excellent operating system, particulalry when it is used for forensic purposes.


One of requests which is often asked to the forensics investigators is deleted </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/2474350236400391901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-14-on-deleted-files-recovery.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2474350236400391901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2474350236400391901'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-14-on-deleted-files-recovery.html' title='Experiment 14 on Deleted Files Recovery under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqxXIUDyTsI/AAAAAAAAAHo/H_Tgp9g2yiQ/s72-c/AutopsyDeletedFiles.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-9027138541307365715</id><published>2009-09-13T09:10:00.003+07:00</published><updated>2009-09-13T09:12:37.706+07:00</updated><title type='text'>Experiment 13 on Internet Explorer Analysis under Ubuntu</title><summary type='text'>
This experiment was part of class assignments performed at computer laboratory of CIS Strathclyde. Surprisingly in this laboratory, all machines run Ubuntu as the operating system, so that all forensic activities carried out under Ubuntu. All applications used during the activities are free and flexible, even some of them are more powerful than commercial applications running under Ms Windows.

</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/9027138541307365715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-13-on-internet-explorer.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/9027138541307365715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/9027138541307365715'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-13-on-internet-explorer.html' title='Experiment 13 on Internet Explorer Analysis under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vHYUtxtcOiw/SqxTaqf_oqI/AAAAAAAAAHg/1BLOv1LFo10/s72-c/GnumericIE.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3646564640086973211</id><published>2009-09-13T08:49:00.002+07:00</published><updated>2009-09-13T08:56:11.899+07:00</updated><title type='text'>Experiment 12 on Windows Registry Analysis under Ubuntu</title><summary type='text'>This experiment is the same as the experiment 9, 10 and 11 which are part of a set of experiments related to the class assignments performed on December 2008. In my point of view, the assignment report will be more reliable if it is supported by a number of experiments as well as literature study; therefore for most of my assignments during my course at Strathclyde, I usually peformed some </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3646564640086973211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-12-on-windows-registry.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3646564640086973211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3646564640086973211'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-12-on-windows-registry.html' title='Experiment 12 on Windows Registry Analysis under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_vHYUtxtcOiw/SqxP5_xTAsI/AAAAAAAAAHI/E-Fnn3y82aQ/s72-c/RegistrySAM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-4468980757879784202</id><published>2009-09-13T08:11:00.005+07:00</published><updated>2009-09-13T08:34:10.022+07:00</updated><title type='text'>Experiment 11 on Similarity in Forensic Imaging between Ubuntu and Windows</title><summary type='text'>This experiment was performed in order to seek similarity in forensic imaging between  applications running under Ubuntu and Windows XP. It was part of a big experiments related to class assignments at Strathclyde on December 2008.


This is the first thing to do in performing forensics analysis to the hard drive evidence. If this is not handled appropriately, so the next phases of forensics </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/4468980757879784202/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-11-on-similarities-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4468980757879784202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4468980757879784202'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-11-on-similarities-of.html' title='Experiment 11 on Similarity in Forensic Imaging between Ubuntu and Windows'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqxGgZp6MfI/AAAAAAAAAGQ/nQW-DNiiuSg/s72-c/fdisk-l.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-1031623541669436147</id><published>2009-09-11T13:12:00.004+07:00</published><updated>2009-09-13T09:30:59.235+07:00</updated><title type='text'>Experiment 10 on Analysing a Fake Image under Ubuntu</title><summary type='text'>This experiment which was performed on December 2008 was part of a set of experiments related to the class assignments seeking the similarities of forensic analysis between Ubuntu and Windows XP.


EXIF which stands for Exchangeable Image File Format is the image file format specification with the addition of metadata tags for JPEG, TIFF Rev. 6.0 and RIFF WAV file formats. The specific metadata </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/1031623541669436147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-10-on-analysing-fake-image.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1031623541669436147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/1031623541669436147'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-10-on-analysing-fake-image.html' title='Experiment 10 on Analysing a Fake Image under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vHYUtxtcOiw/SqnqjBFvDOI/AAAAAAAAAGA/yWR-2VcxGcU/s72-c/EXIFOriginal.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-4958057799864749470</id><published>2009-09-11T11:34:00.006+07:00</published><updated>2009-09-13T09:31:31.269+07:00</updated><title type='text'>Experiment 9 on Forensically Sound Blocks Imaging under Ubuntu</title><summary type='text'>
This experiment was part of experiments regarding with essay assignment in my course (i.e MSc in Forensic Informatics at the University of Strathclyde, UK) about the differences of forensic applications between Ubuntu and Windows XP. It was performed on December 2008.
 
Forensically Sound Blocks Imaging is a small thing but it makes a significant difference between Ubuntu 8.10 and Windows XP on </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/4958057799864749470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-9-on-forensically-sound.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4958057799864749470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4958057799864749470'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/experiment-9-on-forensically-sound.html' title='Experiment 9 on Forensically Sound Blocks Imaging under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vHYUtxtcOiw/SqnQAUsniSI/AAAAAAAAAFg/OiL0ZhcrzmE/s72-c/dcflddBlock.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-845102363434585789</id><published>2009-09-10T12:03:00.010+07:00</published><updated>2009-09-13T09:32:29.796+07:00</updated><title type='text'>Experiment 8 on Understanding File System under Ubuntu</title><summary type='text'>This experiments were my private experiments in order to understand about file systems particularly FAT. Hopefully it could help anyone who would like to explore it.
 
Introduction :
Computer needs a method to deal with their files in order to arrange and manage them. This method is simply called File System which is useful for computer to manage the files stored in storage media such as magnetic</summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/845102363434585789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/eighth-experiments-on-understanding.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/845102363434585789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/845102363434585789'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/eighth-experiments-on-understanding.html' title='Experiment 8 on Understanding File System under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqiJQca-KJI/AAAAAAAAAEY/CgLLCUKPu7A/s72-c/Picture1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-943887300039642424</id><published>2009-09-08T11:57:00.003+07:00</published><updated>2009-09-13T09:34:34.127+07:00</updated><title type='text'>Experiment 7 on Ms Windows Live Flashdisk</title><summary type='text'>Before these experiments, I would like to have a flashdisk which can run live to boot a machine. The flashdisk contains Ms Windows system files. Below is my email contents sent by email to my colleagues at Strathclyde on 11 December 2008. I just wanna share again my successful experiment last night. It is about how to make Ms Windows OS Live Flash disk, so that we can boot a computer through </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/943887300039642424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/seventh-experiments-on-ms-windows-live.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/943887300039642424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/943887300039642424'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/seventh-experiments-on-ms-windows-live.html' title='Experiment 7 on Ms Windows Live Flashdisk'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-8034481471675719928</id><published>2009-09-08T11:50:00.000+07:00</published><updated>2009-09-08T11:50:49.769+07:00</updated><title type='text'>Poetry of Life</title><summary type='text'>This poetry was sent to my colleagues at Strathclyde on 10 December 2008. 
 I would like to share my poetry. The title is 'FI and White Snow in the New Year'. Below is the complete poetry.

---------------------------------------------------------
"FI and White Snow in the New Year"
by Muhammad Nuh Al-Azhar on 9 December 2008

It's like a dream comes true
When I was announced to be one of </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/8034481471675719928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/poetry-of-life.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8034481471675719928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8034481471675719928'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/poetry-of-life.html' title='Poetry of Life'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-7772391917450160264</id><published>2009-09-08T11:45:00.002+07:00</published><updated>2009-09-13T09:35:40.653+07:00</updated><title type='text'>Experiment 6 on Making Bootable Ms Windows Flashdisk</title><summary type='text'>This experiments were performed in order to install Ms Windows OS into a netbook which does not have a CD-ROM. The description of this successful experiments below are my email contents sent to my colleagues at Strathclyde on 9 December 2008.

I just wanna share my successful experience in creating 'bootable Ms Windows OS flashdisk' which was carried out by me a few weeks ago. It is useful in </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/7772391917450160264/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/sixth-experiments-on-bootable-ms.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7772391917450160264'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/7772391917450160264'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/sixth-experiments-on-bootable-ms.html' title='Experiment 6 on Making Bootable Ms Windows Flashdisk'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-4000386640064344375</id><published>2009-09-08T10:28:00.004+07:00</published><updated>2009-09-11T11:06:16.827+07:00</updated><title type='text'>Experiment 5 on Ubuntu Forensically Sound Write Protect</title><summary type='text'>In Ms Windows OS, there are many forensically sound write protect tools either in software or hardware offered to users. Most of them are commercial. The same thing can be performed on Ubuntu, but this is for free. We just make a little modification on fstab file to configure Ubuntu machine becomes forensically sound write protect. The description below is my email contents I sent to my </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/4000386640064344375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/fifth-experiments-on-forensically-sound.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4000386640064344375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/4000386640064344375'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/fifth-experiments-on-forensically-sound.html' title='Experiment 5 on Ubuntu Forensically Sound Write Protect'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3773269228062704138</id><published>2009-09-08T10:06:00.005+07:00</published><updated>2009-09-13T09:36:23.377+07:00</updated><title type='text'>Experiment 4 on Network Scanning under Ubuntu</title><summary type='text'>This experiments were performed when I got free time after semester 1 finished and waiting for semester 2 commenced. FYI, at that time I still joined MSc in Forensic Informatics at the University of Strathclyde. It is same as other posts, below is the email I sent on 26 January 2009 to my colleagues after successful experiments on network scanning. For security purpose, I rename the website I </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3773269228062704138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/third-experiments-on-network-scanning.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3773269228062704138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3773269228062704138'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/third-experiments-on-network-scanning.html' title='Experiment 4 on Network Scanning under Ubuntu'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-3014487417624972364</id><published>2009-09-08T09:49:00.002+07:00</published><updated>2009-09-11T13:28:13.921+07:00</updated><title type='text'>Experiment 3 on Cracking ZIP File and Ubuntu User Account</title><summary type='text'>Below is my email contents I sent to my colleagues on 17 February 2009 regarding with my experiments on how to crack zip file and user account on Ubuntu machine. At that time, it was perfomed in order to refresh my mind from stuck on assignments.
It's a long time for me not to share the experiments because too many assignments I've got in this semester (I've ever calculated the number of words </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/3014487417624972364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/fourth-experiments-on-cracking-zip-file.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3014487417624972364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/3014487417624972364'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/fourth-experiments-on-cracking-zip-file.html' title='Experiment 3 on Cracking ZIP File and Ubuntu User Account'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-8953128858946071955</id><published>2009-09-08T09:31:00.001+07:00</published><updated>2009-09-11T11:07:55.389+07:00</updated><title type='text'>Experiment 2 on Cracking Windows User Account Password</title><summary type='text'>This is my second experiments on Ubuntu. It was performed when I was still joining MSc in Forensic Informatics at the University of Strathclyde. Below is the experiments results which I sent to my colleagues by email on 17 December 2008. 
 Again, I just wanna share my experiment on using Opchrack for cracking the password of Windows XP. I carried out experiment of Ophcrack application under my </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/8953128858946071955/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/second-experiments-on-cracking-windows.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8953128858946071955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/8953128858946071955'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/second-experiments-on-cracking-windows.html' title='Experiment 2 on Cracking Windows User Account Password'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-735388151623750568</id><published>2009-09-07T13:47:00.006+07:00</published><updated>2009-09-11T11:08:48.555+07:00</updated><title type='text'>Experiment 1 on Email Encryption and Virtual Machine</title><summary type='text'>Below is my email contents which was sent to my lecturers on 7 December 2008 after performing two successful forensic experiments on Ubuntu machine. It was performed when I was still joining MSc in Forensic Informatics at the University of Strathclyde, UK.


Based on teaching materials of CS935 and CS936, I performed an experiment in the last few days with the result was successful. It is about </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/735388151623750568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/first-private-experiments-at.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/735388151623750568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/735388151623750568'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/first-private-experiments-at.html' title='Experiment 1 on Email Encryption and Virtual Machine'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-109857104483939627.post-2115956937063730110</id><published>2009-09-07T12:22:00.000+07:00</published><updated>2009-09-07T12:22:18.167+07:00</updated><title type='text'>Welcome Message</title><summary type='text'>Dear All,

Welcome to my blog, I dedicate this blog for everyone who would like to involve in computer forensic investigation. I realise this blog is still far from satisfaction of readers, nevertheless I try to deliver a good forensic stuff to know and understand. Perhaps some of them are obsolete and already known by some readers, but in my point of view, any knowledge particularly computer </summary><link rel='replies' type='application/atom+xml' href='http://forensiccop.blogspot.com/feeds/2115956937063730110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://forensiccop.blogspot.com/2009/09/welcome-message.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2115956937063730110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/109857104483939627/posts/default/2115956937063730110'/><link rel='alternate' type='text/html' href='http://forensiccop.blogspot.com/2009/09/welcome-message.html' title='Welcome Message'/><author><name>Muhammad Nuh Al-Azhar</name><uri>http://www.blogger.com/profile/16776878695198387238</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://2.bp.blogspot.com/_vHYUtxtcOiw/SqSyAyhcU4I/AAAAAAAAACo/6eXRUPwMTHw/S220/ForensicCop.jpg'/></author><thr:total>0</thr:total></entry></feed>
