Re: Router Investigations

From: Christine Siedsma (csiedsmaat_private)
Date: Thu Sep 05 2002 - 10:56:36 PDT

  • Next message: Mark G. Spencer: "Identifying and dating MS operating systems?"

    Thomas Akin gave a presentation at the Blackhat conference this past summer
    entitled "Cisco Router Forensics".
    The link to his PP presentation is
    http://www.blackhat.com/presentations/bh-usa-02/bh-us-02-akin-cisco/bh-us-02
    -akin-cisco.ppt
    There is an accompanying document, but the link that I originally obtained
    that from is not working, so if you would like to contact me off list, I can
    send that to you.
    
    
    Christine Siedsma
    Program Manager
    Computer Forensic R&D Center
    Utica College of Syracuse University
    Utica, New York
    315-792-3708
    csiedsmaat_private
    
    ----- Original Message -----
    From: "Thad Horak" <thadhorakat_private>
    To: <forensicsat_private>
    Sent: Wednesday, September 04, 2002 3:27 PM
    Subject: Router Investigations
    
    
    > I've been tasked to add to our existing incident
    > handling process a methodology to investigate our
    > Cisco routers and switches. I've found a few documents
    > when searching on google, but it seems that most
    > people just want to teach this through a course. Can
    > anyone suggest any documents that they written or
    > found helpful? Many thanks.
    >
    > Thad
    >
    > __________________________________________________
    > Do You Yahoo!?
    > Yahoo! Finance - Get real-time stock quotes
    > http://finance.yahoo.com
    >
    > -----------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service.
    > For more information on this free incident handling, management
    > and tracking system please see: http://aris.securityfocus.com
    >
    
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sun Sep 08 2002 - 10:43:30 PDT