13.09.2013 Views

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

Post-Mortem RAM Forensics - CanSecWest

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>CanSecWest</strong>2007<br />

30<br />

PoC: FileTime<br />

• sub Win2Unix4() {<br />

• my $Lval = shift;<br />

• my $Hval = shift;<br />

• my $Time = 0;<br />

• my $Shift = 11644473600; #Shift of time<br />

• if(($Lval == 0) and ($Hval ==0)){<br />

• return $Time;<br />

• }else{<br />

• $Time = int(($Hval * 2**32 / 10000000) + ($Lval / 10000000));<br />

• $Time -= $Shift;<br />

• }<br />

• if ($Time < 0){<br />

• $Time = 0;<br />

• }<br />

• return $Time;<br />

• }<br />

Actually not that much code!<br />

VIDAS

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!