AOH :: HP Unsorted F :: B06-2650.HTM

Forensic memory dumping intricacies - physicalmemory, dd, and caching issues



Forensic memory dumping intricacies - PhysicalMemory, DD, and caching issues
Forensic memory dumping intricacies - PhysicalMemory, DD, and caching issues



Summary:

Memory dumping tools that use the PhysicalMemory device in Windows XP 
can be blocked by allocating memory buffers with special memory types. 
In older versions of Windows the tools instead could possibly cause 
cache incoherence with some processor types, or other adverse side 
effects. The problem can also occur on a system that has not been 
manipulated at all by any attacker. One *example* of an affected tool is 
DD from the Forensic Acquisition Utilities.

Full text:

http://ntsecurity.nu/onmymind/2006/2006-06-01.html 

Regards /Arne Vidstrom

http://ntsecurity.nu 
http://vidstrom.net 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.