|
Evtx Parser Version 1.0.7 |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : By Andreas Schuster Copyright 2011 int for ensic blog . All rights reserved. Reproduction for commercial purposes including online advertisement interdicted. I'm releasing version 1.0.7 of my Windows Event Log Parser. This release fixes a couple of errors and enhances the handling of XML templates. The archive is available for download here. The most important changes since version 1.0.5 are Fixed an error in CRC32 checks. Thanks to Michael Felber for reporting this bug. Thanks to Andrew Hoog for reporting an error in the documentation. Precision of the time stamp reported by Type0x11.pm have been increased by one decimal. The outer structure's creation time stamp was not properly parsed by Event.pm. The value can now be accessed as a formatted string through get_time_created . The contents of all BXmlNodes can now be retrieved as a hex dump by calling get_hexdump . Handling of XML templates and NameStrings has been improved to support further research into that subject. Versions up to and including 1.0.5 built strings and template dictionaries on the fly while they parsed a chunk. From now on the dictionaries can be populated based on tables and lists in the chunk header, which is much faster. Template.pm now reports the GUID. The example program evtxtemplates.pl was rewritten to make use of the new features. There is now an option to dump templates in hex, too. . evtxtemplates.pl --hex sample1.evtx Template ECD34601-0225-3E67-B639-D77B70281CE9 at chunk 0, offset 0x0612 0 type 0x81, optional 2 type 0x0e, optional 0610 00 00 00 00 01 46 d3 ec 25 02 67 3e b6 39 .....F..pourcents.g.9 0620 d7 7b 70 28 1c e9 78 00 00 00 0f 01 01 00 01 ff . p ..x......... 0630 ff 6c 00 00 00 39 06 00 00 00 00 00 00 44 82 09 .l...9.......D.. 0640 00 45 00 76 00 65 00 6e 00 74 00 44 00 61 00 74 .E.v.e.n.t.D.a.t 0650 00 61 00 00 00 02 01 00 00 1c 00 00 00 61 06 00 .a...........a.. 0660 00 00 00 00 00 8a 6f 04 00 44 00 61 00 74 00 61 ......o..D.a.t.a 0670 00 00 00 02 0e 00 00 81 04 01 02 00 20 00 00 00 ............ ... 0680 84 06 00 00 00 00 00 00 21 b8 06 00 42 00 69 00 ........ ...B.i. 0690 6e 00 61 00 72 00 79 00 00 00 02 0e 02 00 0e 04 n.a.r.y......... 06a0 04 00 .. Les éléments de la revue Twitter pour les mots clé : parser
Les derniers articles du site "int for ensic blog " :
- Evtx Parser Version 1.1.1 - DFRWS 2012 - Evtx Parser Version 1.1.0 - Timers and Times - Evtx Parser Version 1.0.8 - Mac OS X memory analysis with Volafox - Evtx Parser Version 1.0.7 - Recent Advances in Memory Forensics - Linking Event Messages and Resource DLLs - Evtx Parser Version 1.0.1
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|