Showing posts with label Forensics. Show all posts
Showing posts with label Forensics. Show all posts

Monday, July 22, 2019

Recovering Formatted files with Photorec

Welcome to hacking a rise in this post we are going to show you step by step to recovering deleted files or lost data from a reformatted partition or corrupted file system with Photorec.

What is Photorec? 

 Before we talk about how you can recover your data, let’s get to know something about the tool we are going to use Photorec. PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from hard disks, CD-ROMs, and lost pictures (thus the Photo Recovery name) from digital camera memory. 


PhotoRec ignores the file system and goes after the underlying data, so it will still work even if your media’s file system has been severely damaged or reformatted. Photorec is free and runs on Windows, Linux, FreeBSD, NetBSD, OpenBSD, Sun Solaris, Mac Os and almost every unix system.

How to run Photorec  

If you don’t have photorec on your system, feel free to download Photorec here and download the one best for your operating system. After downloading the file, extract everything inside the archives.


For those on Windows, look for where you extracted  PhotoRec. Open the folder and  right click photorec_win.exe and then click Run as administator to launch PhotoRec.


For BSD, Unix, Linux user, open terminal and please make sure you are a root user and navigate into the extracted folder and type ./photorec_static  and press the Enter key as show below.

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B17-03-13%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

For our Mac Os user,  navigate into the extracted folder and start /photorec_static but please make sure you are  root user otherwise PhotoRec will restart itself using sudo after a confirmation on your part. Sudo will ask for a password – enter your Mac OS X user password.

if you were able to install Photorec successfully the i guess we are good to continue, if not leave a comment and we will get back to you..


 Selecting your Disk

if you got the installation right installation right you show see like this for all Os  but I’m running mine from linux

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B17-18-17%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

 and please make sure the want to recover has been insert.


From the image above you will see the media available listed. In other to select a media use  up/down arrow keys to select the media that contains the formatted files. Press Enter to proceed

Selecting a Source Partition

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B17-49-03%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

If the disk you are trying to recover was a partitioned disk, then you will have to select the partition that holds the formatted files. In my case, I’m  trying to recover the formatted files on  whole partition so i selected the whole disk. Before we proceed, there are some options we need to have a look before we recover our file and it can be seen at the bottom of the image above.

Search after selecting the partition that holds the lost files to start the recovery,Options to modify the options, File to modify the list of file types recovered by PhotoRec. Let’s see how the Search, Options and File Opt work. Lets start with the Options

Options

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B20-34-05%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

From the image above you can see that

  • Paranoid By  default is set to Yes (Bruteforce disabled) which means recovered files are verified and invalid files rejected but when we enable bruteforce, it implies that you want to recover more fragmented JPEG files, note it is a very CPU intensive operation.
  • Allow partial last cylinder modifies  how the disk geometry is determined – only non-partitioned media should be affected.
  • The expert mode option  allows the user to force the file system block size and the offset. Each filesystem has his own block size (a multiple of the sector size) and offset (0 for NTFS, exFAT, ext2/3/4), these value are fixed when the filesystem has been created/formatted. When working on the whole disk (ie. original partitions are lost) or a reformatted partition, if PhotoRec has found very few files, you may want to try the minimal value that PhotoRec let you select (it’s the sector size) for the block size (0 will be used for the offset).
  • Enable Keep corrupted files to  keep files even if they are invalid in the hope that data may still be salvaged from an invalid file using other tools.
  • Enable Low memory if  your system does not have enough memory and crashes during recovery. It may be needed for large file systems that are heavily fragmented. Do not use this option unless absolutely necessary.

 Selecting File type

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B20-53-06%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

 File option gives you the opportunity to select the file type by pressing the space bar to select/deselect the file type or S to select/deselect all of them simultaneously. After the change press B to save the change.

File system type  

When the partition source is selected and other settings are put in place. It’s now time for us to validate the search. PhotoRec needs to know how the data blocks are allocated. Unless it is an ext2/ext3/ext4 filesystem, choose other

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B21-02-55%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

Select where recovered file should be kept

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B21-23-38%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

choose the directory to save the recovered files. Use the up/down key to choose the folder and uses  “..” to exist the current directory. And if you are recovering data into an external disk you can find the disk location in /media or /mnt

Hacking A Rise Screenshot-2019-7-20%2BScreenshot%2Bfrom%2B2019-07-20%2B21-23-38%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

 

 

Recovery update

Hacking A Rise Screenshot-2019-7-22%2BScreenshot%2Bfrom%2B2019-07-22%2B21-55-16%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

Now we can see the recovery process in the above image. The output shown in the above image base on the file type. One thing about this tool is, you can access the files found during the recovery process. You can find with folder name like this recup_dir in the destination you selected for the recovery

Recovery Complete

Hacking A Rise Screenshot-2019-7-23%2BScreenshot%2Bfrom%2B2019-07-23%2B10-15-41%2Bpng%2B%2528PNG%2BImage%252C%2B1366%2B%25C3%2597%2B768%2Bpixels%2529%2B-%2BScaled%2B%252882%2525%2529

At the Stage the Photorec recovery process is complete. The details of the recovery process will be shown along with the directory the recover files was save to..

Hope you had a great time recovering your files..Have a nice day and don’t forget to share the link..

Wednesday, June 19, 2019

Steganography

Welcome to hacking a rise yes its me laughing man with another yes another post lol in this were and going to talk about Steganography this were you hide a message in plain site the best example i can think of is in prison way the prisoner hide there messages in plan site from the officers this method is easy to remember and easy to so so with much more talk lets start

What is Steganography

Steganography is the practice of concealing a file, message, image, or video within another file, message, image, or video. The word steganography combines the Greek words steganos, meaning “covered, concealed, or protected”, and graphein meaning “writing”.
find out more here

why we love it

The research also stated that cyber criminals are using Steganography a unique way to spread Payload malware, to infect the targeted systems. … Steganography is a technique used by attackers to hide malicious code within the image that is mainly employed by exploiting kits to hide their malvertising traffic.
Find out more

Getting started

so first of all open your terminal and type apt-get install steghide -y
Hacking A Rise steghide1-300x288

now we get are files the image and the txt file i have added mine to my Desktop
Hacking A Rise twofiles-300x234

so cd Desktop and then type steghide embed -ef the text file -cf the image u want two embed it to as you see ive to add steghide embed -ef hideme.txt -cf asds.jpg
Hacking A Rise embed-300x44
boom its done all u need to do is add a passphrase and send it

Now we add want to extract the file out the image so type steghide extract -sf asds.jpg -xf text or were ever you have the image
Hacking A Rise extract-300x25

thanks for reading
LAUGHINGMAN

Exif Image Recon

Welcome to hacking a rise in this post we talk about exif (Exchangeable image file) this is a the info stored on images (metadata) so here we will show you the command line tool on kali and online tools and firefox plug ins to gain the meta of the image
(note some sites like social media strip out the some the data like gps and this method can be highly actuate with its results form hard and software )

What is Exif

Exchangeable image file (exif) format is a standard that specifies the formats for images, sound, and ancillary tags used by digital cameras, scanners and other systems handling image and sound files recorded by digital cameras,phones etc..

Command line

so if you have a kali system exif tool is install just type exif --help
Hacking A Rise exifhelp-300x289

so say we want to get the info of a image we use exif path to jpeg since i have mine downloaded to desktop i wanna change my dir to desktop so cd Desktop if your image is save there other wise put proper path now i type exif 20190619_001834.jpg
Hacking A Rise exifoutput1-297x300
as you can see it gave’s a lot of info like phone type model number
time and date etc …

online tools

http://metapicz.com/#landing
Hacking A Rise onesite-280x300

https://www.get-metadata.com
Hacking A Rise site2-300x300

firefox

there few plug in you can install on firefox to help you get the meta of a image

first is exif viewer
Exif viewer
Hacking A Rise pluginone-300x171

gps-detect
gps-detect
Hacking A Rise plugin2-300x163

Now lads its not that hard to find info on images as you can see with my top image this can come in handy during a dox but remember social media sites strip all the gud stuff out hahaha

Right god bless

LAUGHINGMAN

Tuesday, April 16, 2019

How to install the zoo on Kali Linux

welcome to hacking a rise in this one we are install zoo on Kali

What is theZoo.py

theZoo is a project created to make the possibility of malware analysis open and available to the public. Since we have found out that almost all versions of malware are very hard to come by in a way which will allow analysis, we have decided to gather all of them for you in an accessible and safe way. theZoo was born by Yuval tisf Nativ and is now maintained by Shahak Shalev

git clone https://github.com/Hackingriseofficial/theZoo
i forked it so u can install it 🙂

This a old you tube video from my channel