150 INDEX
Operating systems (OS) (continued)
MS-DOS 6.22, 117
and preservation of evidence, 27, 28
as programs, 22
Windows, 17, 112
Outlook, 81
Output devices, 15, 23
Ownership analysis, 125
Packet sniffers, 77
Paraben Software, 40
Partitions, 37, 41, 45, 82, 116, 121, 123, 124
Passwords
brute-force attack, 49, 82, 83
cracking, 40, 82, 123
and data extraction, 121
file slack, searching, 43
and identity theft, 93
and keystroke monitors, 80
and ownership analysis, 125
protection systems, 49
reuse of, 50, 114, 123
and social engineering, 50
and spyware, 78
and steganography, 47
and system memory, 114
and Trojan horses, 77
wireless networks, 72
Patterns, 124
Peer-to-peer (P2P) file sharing, 104, 105
Pen tablets as input devices, 15
Permissions, 81, 82, 84
Personal computers (PCs), 3, 4
PGP (Pretty Good Protection), 47, 48
Phishing, 92, 93
Photographs
digital storage, 18, 20
as documentation, 53, 54
and hashing, 113
Phreakers, 67–69
Physical disks, 32, 37
Piggybacking, 75
Piracy, 103–105
Pixels, 21
Plaintiffs, 59
Plea agreements, 62
Point of sale (POS), 90
POP, 3
POST (power-on self-test), 32
Preservation of evidence
course of action, choosing, 29, 30
importance of, 26, 27
keyboard, use of, 54
mouse, use of, 28, 30, 54
and online transactions, 99
problems with, 27, 28
record keeping, 27, 29
testing and other alteration of
evidence, 28, 29, 110, 111
Pretrial, 60, 61
Pretty Good Protection (PGP), 47, 48
Printers, 15, 23
Private key, 48, 49
Process tables, 114
Processing unit, 15–23
ProDiscover, 111, 112
Programming languages, 3, 6, 22
Proprietary technology, 14, 21
Prostitution, 100, 101
Public key, 48, 49
PUSH, 3
Quick View Plus, 124
QuickBooks, 49
RAID, 36, 110, 116
RAM (random access memory), 15
and collection of evidence, 31
printers, 23
slack, 30, 42, 43
as storage unit, 16
Ransom, 80
Real evidence, 129, 135
Record keeping
and application suites, 40
collection of evidence, 30
and evaluation of evidence, 110
on-scene documentation, 53–55
and preservation of evidence, 27, 29
system components, 116
Redundant array of inexpensive disks. See
RAID
Relevance, 132–134
Reliability of evidence, 26, 135–137
expert testimony. See Expert witnesses
scientific evidence. See Scientific
evidence
Komentarze do niniejszej Instrukcji