Russia faces fuel crisis after railway wagon ban
[info]esmeraldamnight

MOSCOW (Reuters) - Russia, the world's largest oil producer, faces domestic fuel shortages after authorities restricted the transport of crude oil by rail, forcing several refiners to cut production, industry and market sources said.

Analysts estimate that output of a quarter or more of refined oil products could be lost, threatening a repeat of last year's fuel shortages following Russian leader Vladimir Putin's order to oil companies to curb pump prices.

However, it is unlikely to dent crude exports, as Russia uses pipelines as its main method of transporting oil abroad.

Russia's transportation safety watchdog has banned the use of rail wagons designed to handle light oil products to ship crude and heavy fuel oil, following several rail accidents.

That has cut the number of wagons in operation, several oil refineries said, curbing supplies and forcing them to cut runs.

Mid-size producer Orsknefteorgsintez, said its heavy oil shipments have slumped by almost a half.

"We will only be able to function for 10 days in this mode," a company official said. "We hope the situation will be resolved by then."

The Khabarovsk refinery, operated by Alliance, said on Wednesday it reduced throughput by half following the ban.

"As a result (of the decision) oil refinery declined from 11,200-11,300 metric tonnes (12,346-12,456 tons) per day to 5,100," a spokesman said.

Representatives of several other refineries have expressed concerns over the ban, but would not comment on the record.

A spokesman for Rosneft, Russia's largest crude producer, said that the company has written to Acting Transportation Minister Igor Levitin asking him to postpone the ban until August 1.

The ban was set on May 5, according to a document posted on the watchdog's website www.rostransnadzor.ru.

Rostransnadzor, which is part of the ministry, could not be reached for comment.

Russian refiners processed a total of 65.6 million tonnes of oil (5.28 million barrels per day) in the first quarter of this year, or just over half of the country's total crude output.

They produced 9.4 million tonnes of gasoline, 17.4 million tonnes of diesel fuel and 19.3 million tonnes of fuel oil during those three months, according to Energy Ministry statistics.

FAR EAST AFFECTED

The ban could take between 25-30 percent of oil products from the market, an industry expert said, affecting remote regions where refineries largely rely on railway transport.

"This (ban) is very sensitive for the Far East, where oil is supplied by railways," Grigory Sergiyenko, executive director of Russian fuel union, an industry group of mid-size oil producers, told Reuters by phone.

He said it won't affect European Russia, where refineries are plugged into the pipeline system.

"On the one hand they (the government) try to create favorable conditions for business, but on the other they ... tighten administrative regulation," he said. "I don't know how far they'll go this time, but maybe (they want refineries) to stop operating at all now."

Lukoil, Gazpromneft, TNK-BP and Bashneft also expressed their concerns over the ban to the ministry, Vedomosti business daily reported on Thursday, citing the companies.

Russia's No.3 crude producer TNK-BP warned it may even cut oil output if the ban stays, Kommersant daily newspaper said on Thursday, citing Executive Vice President German Khan's letter to Levitin.

Last year motorists in Russia's remote Siberian region of Altai queued at gas stations, after an order by Putin to curb domestic pump prices led oil firms to increase export volumes.

(Writing by Alexei Anishchuk; Editing by Douglas Busvine and Hans-Juergen Peters)

ohio primary cell phone jammer sandra fluke g8 summit netanyahu aipac vanessa minnillo


SPIN METER: Rivals airbrush anti-Romney words
[info]esmeraldamnight

FILE - In this Jan. 26, 2012 file photo, Republican presidential candidates, former House Speaker Newt Gingrich and former Massachusetts Gov. Mitt Romney talk during a commercial break at the Republican presidential candidates debate in Jacksonville, Fla. Remember Gingrich calling Romney a liar? Michele Bachmann saying Romney's unelectable? Rick Santorum calling Romney "the worst Republican in the country" to run against Obama? They're hoping you don't. And acting like it never happened _ even though most of their words are just clicks away online. (AP Photo/Matt Rourke, File)

FILE - In this Jan. 26, 2012 file photo, Republican presidential candidates, former House Speaker Newt Gingrich and former Massachusetts Gov. Mitt Romney talk during a commercial break at the Republican presidential candidates debate in Jacksonville, Fla. Remember Gingrich calling Romney a liar? Michele Bachmann saying Romney's unelectable? Rick Santorum calling Romney "the worst Republican in the country" to run against Obama? They're hoping you don't. And acting like it never happened _ even though most of their words are just clicks away online. (AP Photo/Matt Rourke, File)

FILE - In this May 3, 2012, file photo, Republican presidential candidate, former Massachusetts Gov. Mitt Romney and Rep. Michele Bachmann, R-Minn., arrive at a campaign stop in Portsmouth, Va. Remember Newt Gingrich calling Mitt Romney a liar? Bachmann saying Romney's unelectable? Rick Santorum calling Romney "the worst Republican in the country" to run against Obama? They're hoping you don't. And acting like it never happened _ even though most of their words are just clicks away online.(AP Photo/Jae C. Hong, File)

FILE - In this Jan. 16, 2012 file photo Republican presidential candidates former Pennsylvania Sen. Rick Santorum counters former Massachusetts Gov. Mitt Romney, right, during the South Carolina Republican presidential debate in Myrtle Beach, S.C. Remember Newt Gingrich calling Romney a liar? Michele Bachmann saying Romney's unelectable? Santorum calling Romney "the worst Republican in the country" to run against Obama? They're hoping you don't. And acting like it never happened _ even though most of their words are just clicks away online. (AP Photo/Charles Dharapak, File)

FILE - In this April 5, 2012 file photo, Republican presidential candidate Rep. Ron Paul, R-Texas speaks Berkeley, Calif. One by one _ with the exception of holdout Paul _ the GOP also-rans have coughed up endorsements of their onetime rival. And as they do, they're pulling rhetorical backflips to distance themselves from their former harsh assessments of Romney. (AP Photo/Ben Margot, File)

WASHINGTON (AP) ? Remember Newt Gingrich calling Mitt Romney a liar? Michele Bachmann saying Romney's unelectable? Rick Santorum calling Romney "the worst Republican in the country" to run against Obama?

They're hoping you don't. And acting like it never happened (even though most of their words are just clicks away online.)

One by one ? with the exception of holdout Ron Paul ? the GOP also-rans have coughed up endorsements of their onetime rival. And as they do, they're pulling rhetorical backflips to distance themselves from their former harsh assessments of Romney.

Don't try this at home, folks. It takes a professional politician to pull it off with a straight face.

A sampling of the also-rans' anti-Romney rhetoric when they were candidates and their obligatory niceness after endorsing Romney.

___

RICK SANTORUM

The former Pennsylvania senator still doesn't have trouble curbing his enthusiasm for Romney. He waited a month after dropping out of the race to endorse Romney, then emailed his tepid endorsement in the dead of night. He finally got out the E-word in the 13th paragraph of his 16-paragraph statement.

THEN:

?"He is the worst Republican in the country to put up against Barack Obama." Santorum later said that he was referring to Romney's standing on health care reform.

?"If Mitt Romney's an economic heavyweight, we're in trouble, because he was 47th out of 50 in job creation in the state of Massachusetts when he was governor. He may have had some success at making money for himself and his partners at Bain Capital, and I give him a lot of credit for doing so, but that's a very different thing than going out and creating an atmosphere for people to create ? that create jobs."

NOW:

?"There are many significant areas in which we agree: the need for lower taxes, smaller government and a reduction in out-of-control spending. We certainly agree that abortion is wrong and marriage should be between one man and one woman. I am also comfortable with Gov. Romney on foreign policy matters, and we share the belief that we can never allow Iran to possess nuclear weapons. And while I had concerns about Gov. Romney making a case as a candidate about fighting against Obamacare, I have no doubt if elected he will work with a Republican Congress to repeal it and replace it." ? Endorsement emailed to Santorum supporters.

___

NEWT GINGRICH

Gingrich didn't formally endorse Romney when he dropped out of the race but spoke well of him and later said that was close enough. The guy who promised not to run down his GOP opponents at the start of the race had some withering things to say about Romney during the heat of the campaign. Gingrich, a former House speaker, would rather you forget that now, though: His anti-Romney videos on YouTube, once public, are now private. The man who repeatedly branded Romney a "Massachusetts moderate" now calls him a "solid conservative."

THEN:

?"Someone who will lie to you to get to be president will lie to you when he is president."

?Are you calling Mitt Romney a liar? "Yes." Questioned about his previous comment.

?"Can we drop a little bit of the pious baloney?" To Romney during a debate.

?"Why would you want to nominate the guy who lost to the guy who lost to Obama?"

?"We are not going to beat Barack Obama with some guy who has Swiss bank accounts, Cayman Island accounts, owns shares of Goldman Sachs while it forecloses on Florida and is himself a stockholder in Fannie Mae and Freddie Mac while he tries to think the rest of us are too stupid to put the dots together and understand what this is all about."

?"I think that a bold Reagan conservative with a very strong economic plan is a lot more likely to succeed in that campaign than a relatively timid Massachusetts moderate who even The Wall Street Journal said had an economic plan so timid it resembled Obama."

NOW:

?"I'm going to campaign for him, I favor him over Obama. I went through, like, seven different issues where I favor him. I'll do everything I can to help elect Romney. ... As far as I'm concerned, I've endorsed him."

?"Compared to Barack Obama, Mitt Romney is a solid conservative. And I think you have to come down to, what's the choice this November? And the choice is the most radical president in American history and a failed president at the economy and somebody who has a solid record on jobs and who, in fact, on basic principles, is conservative. And I think you can get into arguments about who's how conservative, but compared to Obama, Mitt Romney is a solid conservative."

___

MICHELE BACHMANN

Bachmann waited four months after dropping out before she endorsed Romney. The congresswoman from Minnesota campaigned with him in Virginia earlier this month but didn't bring up health care in their joint appearance.

THEN:

?"He can't beat Obama because his policy is the basis of Obamacare. The signature issue of Obama is Obamacare. You can't have a candidate who has given the blueprint for Obamacare. It's too identical. It's not going to happen."

?"He's been very inconsistent on his positions. He's been on both sides of the abortion issue, on both sides of the issue with same-sex marriage ... he was for the TARP bill, the $700 billion bailout and the global warming initiatives."

NOW:

?"I am endorsing Gov. Mitt Romney for president of the United States, a man who will preserve the American dream of prosperity and liberty."

?"This is what victory looks like." Campaigning with Romney in Portsmouth, Va., on the day she endorsed him.

?"He's very smart. He has a very optimistic message. Women trust him because they see, this is a man who started a business from scratch, for heaven's sake."

?"One thing that Mitt Romney has demonstrated, he will repeal Obamacare. That's a big compare and contrast between Barack Obama. We will never get rid of socialized medicine, which is Obamacare, under Barack Obama. Mitt Romney has committed himself to repealing Obamacare. ... A lot of people know Mitt Romney's positive agenda."

___

RICK PERRY

If he couldn't have the GOP nomination himself, Perry still wasn't about to back Romney. As he dropped out of the race, the Texas governor endorsed Gingrich. He didn't come around to endorsing Romney until Gingrich announced last month that he was planning to drop out.

THEN:

?"While you were the governor of Massachusetts in that period of time, you were 47th in the nation in job creation. ... You failed as the governor of Massachusetts."

?"If you are a victim of Bain Capital's downsizing, it's the ultimate insult for Mitt Romney to come to South Carolina to tell you he feels your pain. Because he caused it."

?"I have no doubt that Mitt Romney was worried about pink slips ? whether he'd have enough of them to hand out."

NOW:

?"Mitt Romney has earned the Republican presidential nomination through hard work, a strong organization and a disciplined message of restoring America after nearly four years of failed, job-killing policies from President Obama and his administration."

___

JON HUNTSMAN

The former Utah governor endorsed Romney at the same time he dropped out of the race in January, but there was no joint appearance.

THEN:

?"You can't be a perfectly lubricated weather vane on the important issues of the day."

?"Gov. Romney enjoys firing people. I enjoy creating jobs."

?"When you combine a record of uncertainty ? running first as a senator, as a liberal; governor as a moderate; then as a conservative for the presidency, people wonder where your core is."

?"He's been on three sides of every major issue of the day. And because of that it's going to be very tough in the end to be able to make that trust argument to the American people."

NOW:

?"It is now time for our party to unite around the candidate best equipped to defeat Barack Obama. Despite our differences and the space between us on some of the issues, I believe that candidate is Gov. Mitt Romney."

?"I think he's the best equipped by far to deal with the economic issues and challenges that confront us. ... He's grown a lot, he's learned a lot. He's probably better prepared to lead."

___

RON PAUL

The scrappy Texas congressman was the last man standing among Romney's GOP opponents, and he's not ready to make nice yet. Paul announced this week he won't campaign anymore, but he's still collecting delegates at state party conventions and could give Romney grief at the national nominating convention in Tampa, Fla., come September. Paul ran some scorching ads against Romney earlier this year but shied away from going after Romney in person.

THEN:

?Narrator in Ron Paul radio ad: "Mitt Romney can't fight against Obamacare because he supported the same mandates and government takeovers as governor of Massachusetts. Romney can't stand up against more bailouts because he supported them. He can't lead the charge to shrink the government because he has grown it. Romney's record is liberal and putting him up against Obama is a recipe for defeat."

NOW:

?"Not soon." Paul's answer when he was asked Tuesday when he'll endorse Romney.

___

Associated Press writer Jack Gillum contributed to this report.

___

Follow Nancy Benac on Twitter at http://www.twitter.com/nbenac

Associated Press

shannon de lima joe torre west virginia university michele bachmann jessica biel tim howard west virginia


Just what is the very best dog food for allergies - Health And Fitness ...
[info]esmeraldamnight

Food items allergens primarily are responsible for 20% of the cause of itchiness & scratching in pooches. Of the reactions experienced with canine, food allergies account 20% of the causes of itching and scratching. In fact after atopy & flea bites, it?s the 3rd most common allergic reaction. In spite of our lack of knowledge of the precise cause, there are plenty of things that we do know, like the signs or symptoms, ways to identify, and also the way to handle them.

Cats and dogs may are afflicted with diet allergies. Unlike atopy, there isn?t a formidable link between individual dog breeds and food allergies. Food allergies impact both males and females.. They may manifest as small as five months or as late as 13 years. A great deal canines with diet allergies also show concurrent inhalant or contact sensitivity.

Common food causes

A number of studies show that some basic elements have a tendency to trigger food allergies than others. In order of the most common culprits with dogs are milk products, seafood, beef, hen, lamb, corn, wheat, & soy. You might have seen, the most frequent culprits are the most typical components inside dog foods. This correlation is not a coincidence. Even though proteins might be a little more antigenic than the others, many proteins are quite similar in form so the incidence of allergies are probably associated with the amount of exposure to it.

Symptoms and signs

The symptoms of diet allergies are similar to those of many allergic reactions seen in dogs and cats. The main symptom is itchy skin affecting primarily the facial skin, ears, forelegs, underarms and the area around the rectum. Indicators can also include chronic or recurrent ear canal infection, hair loss, increased itching, hot spots, & skin infections that improve with prescription medication however reoccur right after antibiotics have been stopped. There is certainly proof that dog?s with food sensitivity may sometimes get an elevated incidence of bowel movements. One scientific study showed that non-allergic dog?s have roughly 1.5 bowel motions on a daily basis where some dog?s having food allergies can have 3 or higher per day. It?s difficult to differentiate a dog experiencing food allergies from an animal affected by atopy or other allergies based on physical clues. However, there are a few signs that increase the suspicion that food allergies may be present. One of these, is a dog with recurrent ear problems, particularly yeast infections. Another, is a very young dog with moderate or severe skin problems. A third tip off, is if a dog suffers from allergies year-round or if the symptoms begin in the winter. And the final clue, is a dog that has very itchy skin but does not respond to steroid treatment.

Identification

Diagnosing for food allergies is incredibly simple. However because of the fact that numerous other conditions result in very similar symptoms and that more often than not animals suffer from more issues than just food reactions, it is crucial that all other problems get correctly identified & addressed prior to undergoing diagnosis for food allergies. Atopy, flea bite allergies, intestinal parasite hypersensitivities, sarcoptic mange, and yeast or bacterial infections can all cause similar symptoms as food allergies. Once all the other causes have been eliminated or treated, then it is time for you to start a diet trial.

Treatment

The best management of dog food allergies is elimination of the identified causes. When the offending foods are uncovered through a food trial, they are eliminated from the food plan. Short amounts of comfort may be gained using fatty acids & steroids, but elimination of the products out of the diet plan is the only real long-term remedy.The owner of the animal has a couple of alternatives. They?re able to choose to feed the pet a particular commercially prepared diet plan or a homemade eating plan.

If homemade diets are used, it is essential that they be balanced, with the correct amount of ingredients, vitamins, and minerals. Homemade diets for

Read about dog food allergy symptoms

?Mail this post

Technorati Tags: canine, dog, dog food allergies, health and fitness, itching dog, mans best friend, pet, pet health care, vet

cotto vs margarito 2 cotto vs margarito cotto vs margarito miguel cotto cotto ncaa bowl games bowls

  • Leave a comment
  • Add to Memories

SKorea: Myanmar halting arms purchases from NKorea
[info]esmeraldamnight

YANGON, Myanmar (AP) ? Myanmar's president has confirmed that his country bought weapons from North Korea during the past 20 years and assured his South Korean counterpart that it will no longer do so.

In a meeting with visiting South Korean President Lee Myung-bak, Myanmar President Thein Sein said his country never had nuclear cooperation with North Korea but did have deals for conventional weapons, Lee's presidential Blue House said in an announcement Tuesday.

Thein Sein told Lee that Myanmar will no longer buy weapons from North Korea, honoring a U.N. ban, South Korean presidential official Kim Tae-hyo told reporters traveling with Lee, according to Blue House officials in Seoul.

Lee is on an official visit to Myanmar, the first by a South Korean president since North Korean commandos staged a bloody 1983 attack on visiting South Korean dignitaries.

Myanmar cut off diplomatic relations with North Korea after the attack, but restored them in 2007 as it sought allies in the face of international sanctions over its human rights record and failure to install a democratic government. Myanmar also began buying weapons from North Korea, and was suspected of obtaining nuclear weapons technology as well.

Myanmar is taking steps to emerge from international isolation after decades of military rule ended last year. Those changes were highlighted Tuesday when Lee met opposition leader Aung San Suu Kyi, who was held for years under house arrest but is now a member of Parliament.

Suu Kyi said after the 45-minute meeting that South Korea and Myanmar have much in common in having had to "take the hard road to democratic leadership."

Lee, speaking through an interpreter, said he and Suu Kyi had agreed that "democracy, human rights and freedom must never be sacrificed because of development."

He said he had praised Thein Sein's contribution to democratization when he met the Myanmar president on Monday.

He also said he told Thein Sein that he hoped his government "will refrain from any activities" with North Korea that could be considered in violation of U.N. Security Council resolutions. He described this as a formal request.

A U.N. resolution bars countries from obtaining all but small arms and light weapons from North Korea.

Lee on Tuesday made a brief visit to the site of the 1983 bombing, Martyr's Mausoleum, a monument to Suu Kyi's father, Myanmar independence hero Gen. Aung San. The attack left 21 dead, 17 of them South Korean, but failed to kill its target, then-President Chun Doo-hwan, who arrived late and was not harmed.

A statement from Lee's office said he also agreed to expand South Korean financial assistance to Myanmar.

It said South Korea agreed to help Myanmar develop human resources, build a think tank and invite Myanmar students to South Korea in an effort to share its successful experience in economic development.

___

Associated Press writer Hyung-jin Kim in Seoul contributed to this report.

jennifer love hewitt secret service prostitution 4 20 george zimmerman sheree whitfield weather dallas pat summitt


EMERGENCY BREAKING JUST WHAT IN THE HECK IS COMPUTER
[info]esmeraldamnight

COMPUTER FORENSICS

? is the art and science of applying computer science to aid the legal process. Although plenty of science is attributable to computer forensics, most successful investigators possess a nose for investigations and a skill for solving puzzles, which is where the art comes in. ? Chris L.T. Brown, Computer Evidence Collection and Preservation, 2006

Thus, it is more than the technological, systematic inspection of the computer system and its contents for evidence or supportive evidence of a civil wrong or a criminal act. Computer forensics requires specialized expertise and tools that goes above and beyond the normal data collection and preservation techniques available to end-users or system support personnel. One definition is analogous to ?Electronic Evidentiary Recovery, known also as e-discovery, requires the proper tools and knowledge to meet the Court?s criteria, whereas Computer Forensics is simply the application of computer investigation and analysis techniques in the interests of determining potential legal evidence.?[1] Another is ?a process to answer questions about digital states and events?[2]. This process often involves the investigation and examination computer system(s), including, but not limited to the data acquisition that resides on the media within the computer. The forensic examiner renders an opinion, based upon the examination of the material that has been recovered. After rendering an opinion and report, to determine whether they are or have been used for criminal, civil or unauthorized activities. Mostly, computer forensics experts investigate data storage devices, these include but are not limited to hard drives, portable data devices (USB Drives, External drives, Micro Drives and many more). Computer forensics experts:

  1. Identify sources of documentary or other digital evidence.
  2. Preserve the evidence.
  3. Analyze the evidence.
  4. Present the findings.

Computer forensics is done in a fashion that adheres to the standards of evidence that are admissible in a court of law. Thus, computer forensics must be techno-legal in nature rather than purely technical or purely legal. Refer to Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations for the US Department of Justice requirements for Computer Forensices and electronic evidence processing.

?

Understand the suspect

It is absolutely vital for the forensics team to have a solid understanding of the level of sophistication of the suspect(s). If insufficient information is available to form this opinion, the suspects must be considered to be experts, and should be presumed to have installed countermeasures against forensic techniques. Because of this, it is critical that you appear to the equipment to be as indistinguishable as possible from its normal users until you have shut it down completely, either in a manner which probably prohibits the machine modifying the drives, or in exactly the same way they would.

If the equipment contains only a small amount of critical data on the hard drive, for example, software exists to wipe it permanently and quickly if a given action occurs. It is straightforward to link this to the Microsoft Windows ?Shutdown? command, for example. However, simply ?pulling the plug? isn?t always a great idea, either? information stored solely in RAM, or on special peripherals, may be permanently lost. Losing an encryption key stored solely in Random Access Memory, and possibly unknown even to the suspects themselves by virtue of having been automatically generated, may render a great deal of data on the hard drive(s) unusable, or at least extremely expensive and time-consuming to recover.

Electronic evidence considerations

Electronic evidence can be collected from a variety of sources. Within a company?s network, evidence will be found in any form of technology that can be used to transmit or store data. Evidence should be collected through three parts of an offender?s network: at the workstation of the offender, on the server accessed by the offender, and on the network that connects the two. Investigators can therefore use three different sources to confirm the data?s origin.

Like any other piece of evidence used in a case, the information generated as the result of a computer forensics investigation must follow the standards of admissible evidence. Special care must be taken when handling a suspect?s files; dangers to the evidence include viruses, electromagnetic or mechanical damage, and even booby traps. There are a handful of cardinal rules that are used to ensure that the evidence is not destroyed or compromised:

  1. Only use tools and methods that have been tested and evaluated to validate their accuracy and reliability.

In order to verify that a tool is forensically sound, the tool should be tested in a mock forensic examination to verify the tool?s performance. There are government agencies such as the Defense Cyber Crime Institute that accept requests to test specific digital forensic tools and methods for governmental agencies, law enforcement organizations, or vendors of digital forensic products at no cost to the requestor.

  1. Handle the original evidence as little as possible to avoid changing the data.
  2. Establish and maintain the chain of custody.
  3. Document everything done.
  4. Never exceed personal knowledge.

If such steps are not followed the original data may be changed, ruined or become tainted, and so any results generated will be challenged and may not hold up in a court of law. Other things to take into consideration are:

  1. The time that business operations are inconvenienced.
  2. How sensitive information which is unintentionally discovered will be handled.

In any investigation in which the owner of the digital evidence has not given consent to have his or her media examined ? as in most criminal cases ? special care must be taken to ensure that you as the forensic specialist have legal authority to seize, image, and examine each device. Besides having the case thrown out of court, the examiner may find him or herself on the wrong end of a hefty civil lawsuit. As a general rule, if you aren?t sure about a specific piece of media, do not examine it. Amateur forensic examiners should keep this in mind before starting any unauthorized investigation.

Some of the most valuable information obtained in the course of a forensic examination will come from the computer user themself. In accordance with applicable laws, statutes, organizational policies, and other applicable regulations, an interview of the computer user can often yield invaluable information regarding the system configuration, applications, and most important, software or hardware encryption methodology and keys utilized with the computer. Forensic analysis can become exponentially easier when analysts have passphrase(s) utilized by the user open encrypted files or containers used on the local computer system, or on systems mapped to the local computer through a local network or the internet.

Secure the machine and the data

Unless completely unavoidable, data should never be analyzed using the same machine it is collected from. Instead, forensically sound copies of all data storage devices, primarily hard drives, must be made. Exceptional consideration to this practice are detailed below regarding live system considerations.

To ensure that the machine can be analyzed as completely as possible, the following sequence of steps must be followed:

Examine the machine?s surroundings

?

?

A USB keydrive

?

?

XD Picture Card

?

?

Secure Digital card

The collection phase starts off with the computer forensic team analyzing its surroundings. Similar to police investigating a crime in any other case, all printouts, disks, notes, and other physical evidence must be collected to take back to the laboratory for analysis. Furthermore, an investigating team must take digital photographs of the surrounding environment before any of the hardware is dealt with. This initial collection phase sets the tone for the rest of the investigation and therefore the evidence must be locked away securely, with limited access granted to authorized team members only.

Look for notes, concealed or in plain view, that may contain passwords or security instructions. Secure any recordable media, including music mixes. Also look for removable storage devices such as keydrives, MP3 players or security tokens. See Category:Solid-state computer storage media.

Examine the Live System and record open applications

If the machine is still active, any intelligence which can be gained by examining the applications currently open should be recorded. If the machine is suspected of being used for illegal communications, such as terrorist traffic, not all of this information may be stored on the hard drive. If information stored solely in RAM is not recovered before powering down it may be lost, so acquiring the data while the RAM is still powered is a priority. For most practical purposes, it is not possible to completely scan contents of RAM modules in a running computer. Though specialized hardware could do this, the computer may have been modified to detect chassis intrusion (some Dell machines, for example, can do this stock; software need only monitor for it) and removing the cover could cause the system to dump the contents. Ideally, prior intelligence or surveillance will indicate what action should be taken to avoid losing this information.

Several Open Source tools are available to conduct an analysis of open ports, mapped drives (including through an active VPN connection), and of significant importance, open or mounted encrypted files (containers) on the live computer system. Additionally, through Microsoft?s implementation of the Encrypted File System (EFS), once a system is powered down, the difficulty to examine previously mounted EFS files and directory structures is substantially increased. Utilizing open source tools and commercially available products, it is possible to obtain an image of these mapped drives and the open encrypted containers in an unencrypted format. For Windows based systems, these Open Source tools include Knoppix and Helix. Commercial imaging tools include Access Data?s Forensic Tool Kit and Guidance Software?s EnCase application. Both companies make available their imaging tools for free; however, in order to analyze the data imaged using these tools you will need to purchase a full licensed version of the application.

The aforementioned Open Source tools can also scan RAM and Registry information to show recently accessed web-based email sites and the login/password combination used. Additionally these tools can also yield login/password for recently access local email applications including MS Outlook.

With MS most recent addition, Vista, and Vista?s use of BitLocker and the Trusted Platform Module (TPM), the importance of developing procedures for examining and imaging live (mounted unencrypted) systems is anticipated to significantly increase.

It is possible that in utilizing tools to analyze and document a live computer system that changes can be made to the content of the hard drive. During each phase of system analysis, the forensic examiner must document what they did and why they did it. Specifically, the examiner should detail the potentially perishable information that can/will be lost during a system power down process. The examiner must balance the need to potentially change data on the hard drive versus the evidentiary value of such perishable data.

RAM can be analyzed for prior content after power loss. Although as production methods become cleaner the impurities used to indicate a particular cell?s charge prior to power loss are becoming less common. Data held statically in an area of RAM for long periods of time are more likely to be detectable using these methods. The likelihood of such recovery increases as the originally applied voltages, operating temperatures and duration of data storage increases. Holding unpowered RAM below ? 60 ?C will help preserve the residual data by an order of magnitude, thus improving the chances of successful recovery. However, the practicality of utilizing such a method in a field examination environment severely limits this approach.

As expeditious destruction of chronic residual stress within the module can really only be achieved by impractical exposure to high energies, applications written with data security in mind will periodically bit-flip critical data, such as encryption keys, to eliminate ?imprinting? of this data on the RAM, thus preventing the need to actively destroy it in the first place.[1]
It is important to note that that when preforming a live analysis that the order of volatility be followed. The data that is most likely to be modified or damaged first should be captured first. The order of volatility is.

1. Network connections

Network connections can close quickly and often leave no evidence of where they were connected to or the data being transferred.

2. Running Processes

It is important to note which programs are running on a computer before further analysis is conducted.

3. RAM

The systems Random Accessing Memory contains information on all running programs as well as recently run programs. The information that can be gained from the system ram includes Passwords, encryption keys, personal information and system and program settings.

4. System settings

The Operating system settings can now be extracted. this includes User lists, currently logged in users, system date and time, currently accessed files and current security policies.

5. Hard Disk

The hard disk can then be imaged. It is important to note that it is not forensically sound to image a hard drive while it is running live unless there are extenuating circumstances.[2]

?

Power down carefully

If the computer is running when seized, it should be powered down in a way that is least damaging to data currently in memory and that which is on the hard disk. The method that should be used is dependent on many differing values, such as the operating system in use, and the role of the computer to be seized. Performing a proper shut down may cause malicious scripts to be run, or volatile data to be lost. On the other hand, removing the power plug may cause corruption of the filesystem or loss of crucial data.

Be aware of the fact that computers may feature an internal uninterruptible power supply (UPS). With such devices the computer may stay running long after the power cable has been removed.

Inspect for traps

Fully document hardware configuration

Completely photograph and diagram the entire configuration of the system. Note serial numbers and other markings. Pay special attention to the order in which the hard drives are wired, since this will indicate boot order, as well as being necessary to reconstruct a RAID array. A little time being thorough here will save you more later.

Duplicate the electronic media (evidence)

The process of creating an exact duplicate of the original evidenciary media is often called Imaging. Using a standalone hard-drive duplicator or software imaging tools such as DCFLdd or IXimager, completely duplicate the entire hard drive. This should be done at the sector level, making a bit-stream copy of every part of the user-accessible areas of the hard drive which can physically store data, rather than duplicating the filesystem. Be sure to note which physical drive each image corresponds to. The original drives should then be moved to secure storage to prevent tampering.

Usually some kind of hardware write protection to ensure no writes will be made to the original drive is used. Even if operating systems like Linux can be configured to prevent this, a hardware write blocker is usually the best practice. The Defense Cyber Crime Institute warns that if a hardware write-block is used the examiner should take into consideration the fact that write-blocks can introduce extra benign data when being used to image damaged media (bad sectors).[3] Special consideration is also given to hard drives with Host Protected Areas (HPAs) and Device Configuration Overlays (DCOs). These small areas of a hard drive, normally reserved for hard drive device and diagnostic utilities and hidden from the operating system, can be altered up to the entire capacity of the hard drive and used to store information (potential evidence) that many imaging applications and devices fail to image. You can image to another hard disk drive, a tape, or other media. Tape is a preferred format for archive images, since it is less vulnerable for damage and can be stored for a longer time. There are two goals when making an image:

  1. Completeness (imaging all of the information)
  2. Accuracy (copying it all correctly)

The imaging process is verified by using the SHA-1 message digest algorithm (with a program such as sha1sum) or other still viable algorithms. To make a forensically sound image, you need to make two reads that result in the same output by the message digest algorithm. Generally, a drive should be hashed in at least two algorithms to help ensure its authenticity from modification in the event one of the algorithms is cracked. This can be accomplished by first imaging to one tape labeled as the Master and then make an image labeled Working. If onsite and time is critical, the second read can be made to Null.

Note: Ultimately the methodology used by computer forensic investigators in capturing potential evidence on a system (such as imaging hard drives) will be dictated by the proportionality of the likely importance of that evidence in the matter for which these services are engaged. Additional influences such as claims of privilege and potential damages sought for business interruption create potential headaches for corporate investigations where forensic soundness is often sacrificed for practicality. Law enforcement personnel moving into the corporate environment tend to be overly strict in their application of computer forensic principles in litigations where the burden of proof does not require it. There is an increasing need to capture servers live and capturing less than whole disks worth of data in an effort to work within a time and cost framework. Even an unsolved murder investigation must be wound up at some point where there are diminishing gains to be had in progressing the investigation, so too with computer forensic investigations in both the corporate and criminal arenas where the sheer quantity of digital evidence can become overwhelming and threaten to overburden investigators. Also, it must be remembered that any computer evidence is potentially admissible regardless of the methodology by which it came to the attention of the court. If an examiner fails to create a SHA or MD5 hash on the original hard drive, the data is not necessarily worthless or non admissible. Traditional discovery has been happening for at least a decade (often without a hashes). Application of proper forensic principles will however improve its overall credibility and diminish admissibility challenges. However, reasonable attempts should be made to ensure that the most complete and accurate image possible is obtained.

E-mail review

E-mail has become one of the primary mediums of communication in the digital age, and vast amounts of evidence may be contained therein, whether in the body or enclosed in an attachment. Because users may access email in a variety of ways, it?s important to look for different kinds of emails. The user may have used a dedicated program, or Mail User Agent (MUA), a web browser, or some other program to read and write email. Additionally, files for each of these programs may be stored on a local hard drive, a network device, or a removable device. A good examiner will search all of these locations for email data. Be aware that many email clients will save a copy of outgoing messages, so both the sender and the recipient may have a copy of each message. Finally, mail may also be stored on a dedicated mail server, either awaiting delivery or as permanent storage.

E-mail headers

All email programs generate headers that attach to the messages. The study of these headers is complex. Some investigators favor reading the headers from the bottom up, others from the top down. Under normal circumstances, headers are supposed to be created by the mail user agent and then prepended by mail servers, the bottom up method should work. But a malicious mail server or forger may make this difficult.

The headers added by an MUA are different from those added by mail servers. For example, here is the format for headers generated by Mozilla Thunderbird 1.0 running on Microsoft Windows.

Message-ID: <41B5F981.5040504@example.net>
 Date: Tue, 07 Dec 2004 13:42:09 -0500
 From: User Name <username@example.net>
 User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
 X-Accept-Language: en-us, en
 MIME-Version: 1.0
 To: recipient@example.com
 Subject: Testing
 Content-Type: text/plain; charset=ISO-8859-1; format=flowed
 Content-Transfer-Encoding: 7bit

Extensions such as enigmail may add extra headers.

The Message-ID field has three parts:

  1. The time the message was sent in seconds past the epoch in hexadecimal (Unix 32 bit Big Endian Hex Value)
  2. A random value called a salt. The salt is of the format #0#0#0# where # is a random digit. Because Thunderbird treats the salt like a number, it may be shorter if the leading digits are zeros. For example, a salt of ?0030509? would display as ?30509?.
  3. The fully qualified domain name of the sender.
Message-ID: [time].[salt]@[domain-name]

Information on the Message-ID header was derived from the source code in mozilla/mailnews/compose/src/nsMsgCompUtils.cpp in function msg_generate_message_id() and therefore applies only to mail sent by this application. Generally the format of the Message-ID is arbitrary, and you should refer to the applicable RFCs.

Sorting through the masses

While theoretically possible to review all e-mails, the sheer volume that may be subject to review may be a daunting task; large-scale e-mail reviews cannot look at each and every e-mail due to the sheer impracticality and cost. Forensics experts use review tools to make copies of and search through e-mails and their attachments looking for incriminating evidence using keyword searches. Some programs have been advanced to the point that they can recognize general threads in e-mails by looking at word groupings on either side of the search word in question. Thanks to this technology vast amounts of time can be saved by eliminating groups of e-mails that are not relevant to the case at hand.

Also, emails may contain In-Reply-To: headers that allow threads to be reconstructed. Good email clients can do this.

Computer forensic examples

Forensics can be defined as the use of technology and science for investigation and fact recovery when dealing with criminal matters. Computer forensics is the technological aspect of retrieving evidence to use within criminal or civil courts of law. They are able to recover damaged and deleted files. Some cases in particular used the art of computer forensics as their lead of evidence to indict a criminal offender or find the location of a missing person.

Example

Chandra Levy, who went missing on April 30, 2001, was a Washington, D.C. intern whose disappearance was widely publicized. While her location was unknown, she had used the Internet as well as e-mail to make travel arrangements and to communicate with her parents. The use of this technology helped a computer criminalist trace her whereabouts. The information found on her computer led police to her location, even though she had been missing for one year.

Example two

There have been a number of cases at private schools where authority figures have been charged with possession of child pornography. These discoveries were made using computer forensics. By tracking the buying and selling of pornography online, computer forensic investigators have been able to locate people involved in these crimes. They are able to use information found on the computers as circumstantial evidence in court, allowing prosecution to occur.

Example three

A final example of how computer forensics is affecting the current workplace is the aspect of security. Employees? work computers are now being monitored to ensure no illegal actions are taking place in the office. They also have heightened security so outsiders cannot access a company?s confidential files. If this security is broken a company is then able to use computer forensics to trace back to which computer was being tampered with and what information was extracted from it, possibly leading to the guilty parties and other potential parties involved.

Comparison to Physical Forensics

There are many core differences between computer forensics and ?physical forensics.? [3] At the highest level, the physical forensic sciences focus on identification and individualization. Both of these processes compare an item from a crime scene with other substances to identify the class of the item (i.e. is the red liquid fruit juice or blood?) or the source of the item (i.e. did this blood come from person X?). Computer forensics on the other hand focuses on finding the evidence and analyzing it. Therefore, it is more analogous to a physical crime scene investigation[4] than the physical forensic processes.

Like this:

Be the first to like this post.

This entry was posted on May 14, 2012 at 9:28 pm and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

lone ranger aaron brooks dave matthews band solar flares 2012 whitney houston will toyota recall northern lights

  • Leave a comment
  • Add to Memories

The Changing Confront of private Coaching | Accident Welfare ...
[info]esmeraldamnight

1 time we started out being a personal trainer around 15 in the past, it was greatly a market job. While dining celebrations in the event the dialogue would likely use work opportunities, folks might ask ?So what now ? for a living?In . I would often let them know very ?I?m an individual trainer!Inch, the particular reaction had been constantly the exact same, ?Oh that will sounds exciting, do you teach anybody popular?Inches

Naturally the very fact personally as well as is usually a long way away from your stereotypical view a large number of even now need of our own career. Tan body-beautiful conditioning teachers strolling very easily over the seaside with the just as stunning Hollywood celebrity! Whilst I usually find this picture products all of us purportedly just about all accomplish daily getting relatively patronising, this particular well-liked thought of the Sector has certainly not completed us any damage. Actually it has largely fuelled the particular speedy increase of the individual coaching Business since i have have first started, aiding this to obtain the two a favourite occupation selection along with an similarly well-liked pursuit for anybody thinking of getting match and get the specific groups of the much-loved celebrity.

As i competent 14 in the past there exists little or no option with regards to classes and certification. Nowadays you will find several caribbean vacation packages qualifications and also degrees and diplomas to choose from. Furthermore, now there are health and fitness trade body for your occupation that provide assist and assistance form of hosting coaches, although imposing strict codes of training to be able to preserve criteria in the health and fitness Market. Nothing beats this been with us initially when i first launched about my own fitness career. For quite some time my biggest obstacle ended up being obtain individuals to acquire our career significantly. Even our kids struggled to take my personal job choice significantly for quite some time! Ultimately it would appear that the provides turned a large part, along with the result?s we are generally experiencing a lot more top quality profession pros entering the. You?ll find fitness coaches which now focus on a wide range of disciplines coming from low back pain management, in order to postnatal workout in order to physical fitness regarding older persons to injuries treatment. Increasingly more teenagers entering that is a have grown to be settling on follow levels within Sporting activities Science along with consequently doing, acquire understanding to some new stage using consultant certification and also programs. This makes myself quite happy becoming a section of this kind of interesting Industry and i?m abided by to make use of numerous excellent private fitness teachers every single day.

So what exactly is the longer term for that free desktop wallpaper ? I do think it?ll nonetheless attract improved numbers of career physical fitness teachers who have the need to be able to continuously enhance their expertise as well as knowing ? rendering it an occupation to become pleased about. With examples of being overweight regretfully still rising in order to brand-new crisis amounts, it appears as if the actual curiosity about personal training will finally continue to go up for many years ahead of time.

Similar Posts:

katharine mcphee cold mountain valentines day ideas the villages florida egoraptor gisele bundchen turbotax

  • Leave a comment
  • Add to Memories

Republicans rally around Wisconsin governor at state party convention as recall election nears (Star Tribune)
[info]esmeraldamnight
Share With Friends: Share on FacebookTweet ThisPost to Google-BuzzSend on GmailPost to Linked-InSubscribe to This Feed | Rss To Twitter | Politics - Top Stories Stories, RSS Feeds and Widgets via Feedzilla.

indoor football league newt gingrich wife callista rick perry travis barker get back on board rob lowe peyton manning

  • Leave a comment
  • Add to Memories

Chronicle of a trial foretold: Breivik is following his manifesto's script
[info]esmeraldamnight

Anders Behring Breivik's manifesto includes instructions on what a 'Templar' should do if tried in a European court.

Among the early headlines from the fourth day of the trial of Anders Behring Breivik for the murder of 77 people last July was that, for the first time, Mr. Breivik did not perform his now-familiar clenched-fist salute upon arrival at the court. Several families of Breivik's victims said they found the salute offensive, and his lawyers apparently were able to convince him to stop and avoid undermining his case.

Skip to next paragraph

But the drop of the salute is not only significant for its effect on his defense's strategy. It also marks a significant departure from Breivik's playbook: his 1,500-page manifesto. Breivik wrote extensively not only about his own beliefs about the alleged activities of "the Marxist tyrants of Europe" and the mission of the Knights Templar, or "Templars," the group to which he claims to belong. He also wrote a comprehensive set of instructions and guidelines for what a Templar should do if tried in a European court. He appears to be following it to the extent he is able.

Breivik wrote a short section on his salute, which he claims to be "the military salutation" of the Templars. He writes that the salute, which he recommends being performed in a white glove, symbolizes strength, purity, and resistance against "the Marxist tyrants of Europe." Interestingly, he claims the salute has nothing to do with either racist "white power" salutes or with the similar, open-palmed Nazi salute.

While Breivik's manifesto does not mention the salute specifically in reference to a trial, its use at trial fits closely into what Breivik argues is the best way to use trials: as propaganda. Breivik writes that after being captured, "the subsequent court proceedings may present several propaganda opportunities." He adds that "This trial is (from our point of view), not against you but rather a trial against the regime."

One of the key openings for propaganda that Breivik saw is the opportunity to present an opening and closing statement. Breivik includes a four-page sample opening statement, which he seemed to use as a source for his own.?

His sample draws parallels between the quest of the "Templars" and that of Native American leaders like Sitting Bull ? parallels he made on the first day of testimony in his own trial. As the Monitor reported, ?Were they terrorists for fighting for their indigenous culture ? or were they heroes?? Breivik asked the court. ?My acts are based on goodness, not evil,? he added. ?If anyone is vicious it is the Socialists.?

In the manifesto, Breivik also outlines a dress code for Templars, which he says should be adhered to in court. "Our dress uniform ... will be used for the sole?purpose of representing the authority of our military order and tribunal during trial," he writes. The uniform is to include a US Marine Corp dress jacket in dark blue or black, dress pants in the same color, and an extensive set of medals and decorations including epaulettes and Templar badges. Judging from the photos of his appearances in court, Breivik seems to have been following his own dress code as best he can, though he has appeared sans pseudo-military decorations.

In his game plan for Templar trial appearances, Breivik shows every expectation of losing. The heading for his sample closing statement reads: "Closing statement ? last day of trial, after judgment (guilty)." But he also expresses hope that the trial may lead to the introduction of stiffer criminal sentences, and perhaps even introduction of the death penalty, which is currently illegal in Norway.

The trial itself may not end up as anything else than a formality where the goal can be to change the law, forcing the parliament of that country to introduce the death penalty, or harshen the penal laws in other ways. Indirectly forcing the parliament of your country to change the laws will be an indirect victory to our movement because it will provide significant media coverage of our cause and thus will contribute to future recruitment efforts.

Breivik echoed this thinking during his second day of testimony, the Monitor reported.

?No, I don?t want [capital punishment], but I would have respected that,? he said, adding that if Norway doubled the current maximum sentence it would ?serve his cause? and ?prove Norway had thrown their principles out the window."

nfl games jesus montero hiroki kuroda kuroda nfl scores nfl scores gene hackman

  • Leave a comment
  • Add to Memories

Friday Afternoon Jam: Bob Schneider - Honeypot (Little green footballs)
[info]esmeraldamnight
Share With Friends: Share on FacebookTweet ThisPost to Google-BuzzSend on GmailPost to Linked-InSubscribe to This Feed | Rss To Twitter | Politics - Top Stories Stories, RSS Feeds and Widgets via Feedzilla.

clooney arrested southern miss rod blagojevich rod blagojevich uconn ncaa march madness mario williams

  • Leave a comment
  • Add to Memories

He's a Chameleon! The Many Faces of Johnny Depp
[info]esmeraldamnight

From his early role in Edward Scissorhands to his vampire turn in Dark Shadows, see the actor's ever-changing onscreen transformations 

guacamole recipe jason wu for target underwood buffalo wings superbowl kick off time 2012 new york giants hot wings recipe


You are viewing [info]esmeraldamnight's journal