
admin 2021年4月3日19:21:59评论41 views字数 6771阅读22分34秒阅读模式




Computer memory leaks a turn off, Aug 11, 2012

When you switch off your computer any passwords you used to login to web pages, your bank or other financial account evaporate into the digital ether, right? Not so fast! Researchers in Greece have discovered a security loophole that exploits the way computer memory works and could be used to harvest passwords and other sensitive data from a PC even if it is in standby mode.

Writing in a forthcoming issue of the International Journal of Electronic Security and Digital Forensics, Christos Georgiadis of the University of Macedonia in Thessaloniki and colleagues Stavroula Karayianni and Vasilios Katos at the Democritus University of Thrace in Xanthi explain how their discovery could be used by information specialists in forensic science for retrieving incriminating evidence from computers as well as exploited by criminals to obtain personal data and bank details.

The researchers point out that most computer users assume that switching off their machine removes any data held in random access memory (RAM), this type of fast memory is used by the computer to temporarily hold data currently used by a given application. RAM is often referred to as volatile memory, because anything contained in RAM is considered lost when a computer is switched off. Indeed, all data is lost from RAM when the power supply is disconnected; so it is volatile in this context.

However, Georgiadis and colleagues have now shown that data held in RAM is not lost if the computer is switched off but the mains electricity supply not interrupted. They suggest that forensics experts and criminals might thus be able to access data from the most recently used applications. They point out that starting a new memory-intensive application will overwrite data in RAM while a computer is being used, but simply powering off the machine leaves users vulnerable in terms of security and privacy.

"The need to capture and analyse the RAM contents of a suspect PC grows constantly as remote and distributed applications have become popular, and RAM is an important source of evidence," the team explains, as it can contain telltale traces of networks accessed and the unencrypted forms of passwords sent to login boxes and online forms.

The team tested their approach to retrieving data from RAM after a computer had been switched off following a general and common usage scenario involving accessing Facebook, Gmail, Microsoft Network (MSN) and Skype. They carried out RAM dumps immediately after switch off at 5, 15 and 60 minutes. They then used well-known forensic repair tools to piece together the various fragments of data retrieved from the memory dumps.

The team was able to reconstruct login details from the memory dumps for several popular services being used in the Firefox web browser including Google Mail (GMail), Facebook, Hotmail, and the WinRar file compression application. "We can conclude that volatile memory loses data under certain conditions and in a forensic investigation such memory can be a valuable source of evidence," the team says.

Explore further: Innovation promises to cut massive power use at big data companies in a flash

More information: "A framework for password harvesting from volatile memory" in Int. J. Electronic Security and Digital Forensics, 2012, 4, 154-163.

Journal reference: International Journal of Electronic Security and Digital Forensics

Provided by Inderscience


When you switch off your computer any passwords you used to
login to web pages, your bank or other financial account evaporate into
the digital ether, right? Not so fast! Researchers in Greece have
discovered a security loophole that exploits the way computer memory
works and could be used to harvest passwords and other sensitive data
from a PC even if it is in standby mode.


in a forthcoming issue of the International Journal of Electronic
Security and Digital Forensics, Christos Georgiadis of the University of
Macedonia in Thessaloniki and colleagues Stavroula Karayianni and
Vasilios Katos at the Democritus University of Thrace in Xanthi explain
how their discovery could be used by information specialists in forensic
science for retrieving incriminating evidence from computers as well as
exploited by criminals to obtain personal data and bank details.

在即将发行的国际电子安全和数字取证杂志上,塞萨洛尼基的马其顿大学的Christos Georgiadis和他的同事Stavroula Karayianni以及克桑西的色雷斯-谟克利特大学的vasilios Katos将展示了数据取证专家如何通过他们的发现来进行数据取证以及犯罪分子如何收集个人资料和银行信息。

researchers point out that most computer users assume that switching
off their machine removes any data held in random access memory (RAM),
this type of fast memory is used by the computer to temporarily hold
data currently used by a given application. RAM is often referred to as
volatile memory, because anything contained in RAM is considered lost
when a computer is switched off. Indeed, all data is lost from RAM when
the power supply is disconnected; so it is volatile in this context.


Georgiadis and colleagues have now shown that data held in RAM is not
lost if the computer is switched off but the mains electricity supply
not interrupted. They suggest that forensics experts and criminals might
thus be able to access data from the most recently used applications.
They point out that starting a new memory-intensive application will
overwrite data in RAM while a computer is being used, but simply
powering off the machine leaves users vulnerable in terms of security
and privacy.


need to capture and analyse the RAM contents of a suspect PC grows
constantly as remote and distributed applications have become popular,
and RAM is an important source of evidence," the team explains, as it
can contain telltale traces of networks accessed and the unencrypted
forms of passwords sent to login boxes and online forms.

团队认为“ 随着远程分布式系统的流行,需要进行采集和分析的嫌疑人的电脑内存数据不断增多,内存数据逐渐成为一个重要的证据来源”。因为它可以包含访问网络的历史记录和登录框及在线表单中的未加密密码。

team tested their approach to retrieving data from RAM after a computer
had been switched off following a general and common usage scenario
involving accessing Facebook, Gmail, Microsoft Network (MSN) and Skype.
They carried out RAM dumps immediately after switch off at 5, 15 and 60
minutes. They then used well-known forensic repair tools to piece
together the various fragments of data retrieved from the memory dumps.
The team was able to reconstruct login details from the memory dumps for
several popular services being used in the Firefox web browser
including Google Mail (GMail), Facebook, Hotmail, and the WinRar file
compression application. "We can conclude that volatile memory loses
data under certain conditions and in a forensic investigation such
memory can be a valuable source of evidence," the team says.



相关推荐: dedecms最新版本修改任意管理员漏洞 + getshell + exp

此漏洞无视gpc转义,过80sec注入防御。 补充下,不用担心后台找不到。这只是一个demo,都能修改任意数据库了,还怕拿不到SHELL? 起因是全局变量$GLOBALS可以被任意修改,随便看了下,漏洞一堆,我只找了一处。 include/dedesql.cl…

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
  • 本文由 发表于 2021年4月3日19:21:59
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):


匿名网友 填写信息