SLIDE 1
Chema Alonso, Enrique Rando Metadata: Information stored to give - - PowerPoint PPT Presentation
Chema Alonso, Enrique Rando Metadata: Information stored to give - - PowerPoint PPT Presentation
Chema Alonso, Enrique Rando Metadata: Information stored to give information about the document. For example: Creator, Organization, etc.. Hidden information: Information internally stored by programs and not editable. For
SLIDE 2
SLIDE 3
Metadata:
- Information stored to give information about the
document.
▪ For example: Creator, Organization, etc..
Hidden information:
- Information internally stored by programs and not
editable.
▪ For example: Template paths, Printers, db structure, etc…
Lost data:
- Information which is in documents due to human mistakes
- r negligence, because it was not intended to be there.
▪ For example: Links to internal servers, data hidden by format, etc…
SLIDE 4
Wrong management Bad format conversion Unsecure options New apps
- r program
versions Embedded files Search engines Spiders Databases Embedded files
Wrong management Bad format conversion Unsecure options
SLIDE 5
The answer is NOT. Almost nobody is cleaning documents. Companies publish thousand of documents
without cleaning them before:
- Metadata.
- Hidden Info.
- Lost data.
SLIDE 6
Total: 4841 files
SLIDE 7
SLIDE 8
Real Name Username Internal Domain .. And more…
SLIDE 9
Total: 896 files
SLIDE 10
SLIDE 11
SLIDE 12
Total: 1075 files
SLIDE 13
User Software Version Internal Server NetBIOS name Remote Printer Name Local Printer
SLIDE 14
SLIDE 15
SLIDE 16
SLIDE 17
SLIDE 18
Office documents:
- Open Office documents.
- MS Office documents.
- PDF Documents.
▪ XMP.
- EPS Documents.
- Graphic documents.
▪ EXIFF. ▪ XMP.
- And almost everything….
SLIDE 19
EXIFREADER http://www.takenet.or.jp/~ryuuji/
SLIDE 20
SLIDE 21
http://video.techrepublic.com.com/2422‐14075_11‐207247.html
SLIDE 22
SLIDE 23
SLIDE 24
SLIDE 25
Users:
- Creators.
- Modifiers .
- Users in paths.
▪ C:\Documents and settings\jfoo\myfile ▪ /home/johnnyf
History of use. Operating systems. Software versions. Paths.
- Local and remote.
Network info.
- Shared Printers.
- Shared Folders.
- ACLS.
SLIDE 26
Printers.
- Local and remote.
Internal Servers.
- NetBIOS Name.
- Domain Name.
- IP Address.
Database structures.
- Table names.
- Colum names.
Devices info.
- Mobiles.
- Photo cameras.
Private Info.
- Personal data.
SLIDE 27
Info is in the file in raw format:
- Binary.
- ASCII .
Therefore Hex or ASCII editors can be used:
- HexEdit.
- Notepad++.
- Bintext
Special tools can be used:
- Exif redaer
- ExifTool
- Libextractor.
- Metagoofil.
- …
…or just open the file!
SLIDE 28
SLIDE 29
http://www.edge‐security.com/metagoofil.php
SLIDE 30
SLIDE 31
SLIDE 32
SLIDE 33
SLIDE 34
SLIDE 35
SLIDE 36
SLIDE 37
SLIDE 38
These tools only extract metadata. Not looking for Hidden Info. Not looking for lost data. Not post‐analysis.
SLIDE 39
Fingerprinting Organizations with Collected
Archives.
- Search for documents
- Automatic file downloading
- Capable of extracting Metadata, hidden info and
lost data.
- Cluster information
- Analyzes the info to fingerprint the network.
SLIDE 40
SLIDE 41
SLIDE 42
http://www.informatica64.com/FOCA
SLIDE 43
SLIDE 44
SLIDE 45
SLIDE 46
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=144e54ed‐ d43e‐42ca‐bc7b‐5446d34e5360
SLIDE 47
SLIDE 48
OOMetaExtractor
http://www.codeplex.org/oometaextractor
SLIDE 49
SLIDE 50
http://www.metashieldprotector.com
SLIDE 51
SLIDE 52
SLIDE 53
SLIDE 54
SLIDE 55
SLIDE 56
Authors
- Chema Alonso
▪ chema@informatica64.com
- Enrique Rando
▪ Enrique.rando@juntadeandalucia.es
- Alejandro Martín
▪ amartin@informatica64.com
- Francisco Oca
▪ froca@informatica64.com
- Antonio Guzmán
▪ antonio.guzman@urjc.es
SLIDE 57