| blog | tools | publications | media |

subscribe to site updates: rss feed

contact Wesley McGrew: | email - wesley@mcgrewsecurity.com | gpg key | aim - wesleymcgrew | twitter - mcgrewsecurity |

McGrew Security Blog

Archive for May, 2008

Holy crap, Shmoocon 2008 videos

Saturday, May 31st, 2008

They’ve finally been put online.  It’s late and it’s a weekend so I don’t really have a whole lot to say about it, but if you read this blog there’s a good chance you’re the same kind of geek that’s been waiting for them to post these videos.  

links for 2008-05-28

Wednesday, May 28th, 2008

The Defendant, Wesley McGrew

Wednesday, May 28th, 2008

I just received these two pictures via email from my major professor, and thought I’d share.  They’re from a series of mock trials that were held for this past fall semester’s computer forensics class.  The students had the opportunity to take the stand and present expert witness testimony regarding the evidence that they had examined as part of a class project.  We had a real courtroom, a real judge, real attorneys, and another university’s students sitting as a jury.  I sat as the accused for a few cases, and also helped guide the defense attorneys through some of the more technical aspects of the forensics.

Thankfully, with the inexperience of the expert witnesses, and coaching my attorney a bit (he had an engineering background, which helped), I was found to be not guilty :) .

Really clever Vista trick!

Sunday, May 25th, 2008

EditThe real action’s going on down below here in the comments :) .  Be sure to catch up on them after you read the post.

Jesse Varsalone, a computer forensics expert that happens to be a reader of this site, just emailed me a link to a cool video where he demonstrates a quick and easy way of obtaining SYSTEM privileges on a Vista system, given physical access to the machine.  In the video, he uses BackTrack to replace Utilman.exe with a copy of cmd.exe .  The nice thing about replacing Utilman.exe is that you can make it run before you’re even logged-in by pressing Windows-U.  The video is available on the Offensive Security (maintainers of BackTrack) site:

If you’re into doing physical-presence penetration tests, you might want to roll your own custom CD or bootable USB drive that boots faster than BackTrack, and automatically swaps Utilman.exe out for the executable of your choice.  Perhaps something that installs a nice rootkit or Core Impact agent, and then places the real Utilman.exe back into its rightful place. 

Thanks Jesse!  Excellent choice of soundtrack as well!

links for 2008-05-25

Sunday, May 25th, 2008

links for 2008-05-23

Friday, May 23rd, 2008

Troopers 2008 Videos Available

Wednesday, May 21st, 2008

I haven’t posted in a while, mostly because I’ve been busy hacking away at SCADA equipment and software, but I did spot some new conference video online in my usual rounds (Shmoocon 2008 video? knock knock :) ).  It looks to be deserving of a post.

I wasn’t aware of this conference before now, but the topics look very interesting.  There’s some SCADA, some virtualization, some reversing, and several more that I hope to sit down long enough to watch soon.  All of it’s hosted on the extraordinarily fast EasyNews mirror.  If you’re not already familiar with this mirror, poke around a directory up from the link and you’ll find a lot more conference audio/video to keep you busy.

Enjoy!

links for 2008-05-16

Friday, May 16th, 2008

links for 2008-05-15

Thursday, May 15th, 2008

links for 2008-05-14

Wednesday, May 14th, 2008