<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Modify NTFS Timestamps and Cover Your Tracks With Timestomp.exe</title>
	<atom:link href="http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Sat, 05 Nov 2011 19:36:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: admin</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-437</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Sat, 02 Apr 2011 00:25:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-437</guid>
		<description>Thanks for the heads up :) I&#039;ll have to fix the link once metasploit hosts it again. Can&#039;t seem to find it.</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up <img src='http://www.anti-forensics.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I&#8217;ll have to fix the link once metasploit hosts it again. Can&#8217;t seem to find it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nadja</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-436</link>
		<dc:creator>Nadja</dc:creator>
		<pubDate>Fri, 01 Apr 2011 10:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-436</guid>
		<description>The provided link to the timestomp.exe is not valid anymore. Maybe you want to change that.</description>
		<content:encoded><![CDATA[<p>The provided link to the timestomp.exe is not valid anymore. Maybe you want to change that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: loaded</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-423</link>
		<dc:creator>loaded</dc:creator>
		<pubDate>Thu, 10 Feb 2011 21:52:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-423</guid>
		<description>I attended a conference last year having to do with digital investigations and remember hearing something about Timestomp setting the times to xx:xx:0000 instead of xx:xx:(random #).  Anyone had any experience with this to know if this is accurate or not?</description>
		<content:encoded><![CDATA[<p>I attended a conference last year having to do with digital investigations and remember hearing something about Timestomp setting the times to xx:xx:0000 instead of xx:xx:(random #).  Anyone had any experience with this to know if this is accurate or not?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benefits of using multiple timestamps during timeline analysis in digital forensics &#124; Portable Digital Video Recorder</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-282</link>
		<dc:creator>Benefits of using multiple timestamps during timeline analysis in digital forensics &#124; Portable Digital Video Recorder</dc:creator>
		<pubDate>Wed, 18 Aug 2010 16:54:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-282</guid>
		<description>[...] information for malicious actors on the tools and methods to modify timestamps is out there already and has [...]</description>
		<content:encoded><![CDATA[<p>[...] information for malicious actors on the tools and methods to modify timestamps is out there already and has [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tami</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-114</link>
		<dc:creator>Tami</dc:creator>
		<pubDate>Fri, 01 May 2009 22:48:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-114</guid>
		<description>Very interesting site, Hope it will always be alive!</description>
		<content:encoded><![CDATA[<p>Very interesting site, Hope it will always be alive!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-74</link>
		<dc:creator>Yar</dc:creator>
		<pubDate>Thu, 16 Apr 2009 00:50:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-74</guid>
		<description>Hey BG, I&#039;m pretty sure there are not. I don&#039;t use FTK really so I can&#039;t be certain but it looks like you can make your own pretty easily. &lt;a href=&quot;http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Fwww.accessdata.com%2Fmedia%2Fen_us%2Fprint%2Ftechdocs%2Ftechdoc.Importing%2520or%2520Adding%2520Hash%2520Sets%2520to%2520FTK.en_us.pdf&amp;ei=YH_mSa72LI_wtAPL0bnmAQ&amp;usg=AFQjCNH7A7cL8UZjoUoQ2HpyZvB5BqlZbQ&amp;sig2=lAfJni2OXRW6w_SZviPUFg&quot; rel=&quot;nofollow&quot;&gt;Link (PDF)&lt;/a&gt;

However, you&#039;d be out of luck if someone brought in a packed/compressed or otherwise modified timestomp.exe into a system. One which you don&#039;t have access to create a hash out of.</description>
		<content:encoded><![CDATA[<p>Hey BG, I&#8217;m pretty sure there are not. I don&#8217;t use FTK really so I can&#8217;t be certain but it looks like you can make your own pretty easily. <a href="http://www.google.com/url?sa=t&#038;source=web&#038;ct=res&#038;cd=1&#038;url=http%3A%2F%2Fwww.accessdata.com%2Fmedia%2Fen_us%2Fprint%2Ftechdocs%2Ftechdoc.Importing%2520or%2520Adding%2520Hash%2520Sets%2520to%2520FTK.en_us.pdf&#038;ei=YH_mSa72LI_wtAPL0bnmAQ&#038;usg=AFQjCNH7A7cL8UZjoUoQ2HpyZvB5BqlZbQ&#038;sig2=lAfJni2OXRW6w_SZviPUFg" rel="nofollow">Link (PDF)</a></p>
<p>However, you&#8217;d be out of luck if someone brought in a packed/compressed or otherwise modified timestomp.exe into a system. One which you don&#8217;t have access to create a hash out of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mark</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-72</link>
		<dc:creator>mark</dc:creator>
		<pubDate>Wed, 15 Apr 2009 22:21:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-72</guid>
		<description>I rarely comment on blogs but yours I had to stop and say Great Blog!!</description>
		<content:encoded><![CDATA[<p>I rarely comment on blogs but yours I had to stop and say Great Blog!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BG</title>
		<link>http://www.anti-forensics.com/modify-ntfs-timestamps-and-cover-your-tracks-with-timestomp/comment-page-1#comment-68</link>
		<dc:creator>BG</dc:creator>
		<pubDate>Sun, 12 Apr 2009 07:08:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=125#comment-68</guid>
		<description>Are there any KFF hash files for timestomp that might flag its use?</description>
		<content:encoded><![CDATA[<p>Are there any KFF hash files for timestomp that might flag its use?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

