星期日

Links for LiveCD

The LiveCD List - links & information on over 300 Live CDs (***)
http://www.livecdlist.com/
#這下可就一網打盡啦...

Darknet - 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery)
http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/

Links for Live USB

Live USB - Wikipedia
http://en.wikipedia.org/wiki/Live_USB
#先看維基上的一些資訊吧!!

Boot and run Linux from a USB flash memory stick | USB Pen Drive Linux
http://www.pendrivelinux.com/
Carry a portable Linux version with you on a USB flash pen drive. Easily bring your portable desktop with you wherever you go.
#這網站有許多教學,有簡體中文的網站(不過用google翻譯的)。

Ubuntu 正體中文站
http://www.ubuntu.org.tw/
Ubuntu 是一套由社群開發的作業系統,適用於筆記型電腦,桌上型電腦和伺服器。
#這個目前據說非常夯,又有中文的說明跟討論。

Slax: your pocket operating system
http://www.slax.org/
Slax is a modern, portable, small and fast Linux operating system with a modular approach and outstanding design.
#這有現成的Live USB,只要256MB的空間,且大概五分鐘就完成設定,剩的只要系統裝置有支援,真是居家必備處方、隨身必備良藥。

=====
#沒有硬碟的時代來了!!(當然指的是Linux Base)
#老是中毒的人,學一下吧!!(話說回來,老中毒的人應該完全不懂吧)

星期四

who are you?

ip information

Forensics Wiki

focused on the tools and techniques used by investigators.
http://www.forensicswiki.org/wiki/Main_Page

www.winsiderss.com

MemInfo is a tool to query information on the state of the memory manager page lists, page frame number (PFN) database entries, per-component and per-process memory usage, and for mapping virtual to physical addresses (for certain kinds of kernel-mode pointers).
http://www.winsiderss.com/tools/meminfo/meminfo.htm

ScTagQuery allows you to obtain precise information on which threads in the system are being used by what service, in order to better gauge CPU and resource usage as well as to help in debugging service-related problems.
http://www.winsiderss.com/tools/sctagquery/sctagquery.htm

Alex Ionescu’s Blog
http://www.alex-ionescu.com/

Malware Domain List

Malicious Web site Labs (恶意网站实验室) (**)
http://www.mwsl.org.cn/

Malware Domain List (***)
All domains on this website should be considered dangerous.
http://www.malwaredomainlist.com/

Malware Block List
The Malware Block List is a free, automated and user contributed system for checking URLs for the presence of Viruses, Trojans, Worms, or any other software considered Malware. The list is available in 29 formats.
http://www.malware.com.br/

DNS-BH - Malware Domain Blocklist
The DNS-BH project creates and maintains a listing of domains that are known to be used to propagate malware and spyware.
http://malwaredomains.com/

StopBadware (***)
StopBadware.org is a "Neighborhood Watch" campaign aimed at fighting badware.
http://www.stopbadware.org/

Identify File

Identify File (**) by MD5, SHA1 or Others
FileAdvisor: MD-5 or SHA-1 hash of any file
http://fileadvisor.bit9.com/

CastleCops: SHA-1, MD5, and CRC32 hash of file
http://hashes.castlecops.com/

RunScanner: Filename / Process / Guid / CLSID / MD5 hash
http://www.runscanner.net/

Prevx: (need to login)
http://www.prevx.com/

VirusTotal: hash by md5/sha1/sha256
http://www.virustotal.com/zh-tw/buscaHash.html