<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>geschonneck.com &#187; Forensics</title>
	<atom:link href="http://geschonneck.com/category/forensics/feed/" rel="self" type="application/rss+xml" />
	<link>http://geschonneck.com</link>
	<description>This is the private security page of Alexander Geschonneck (Berlin, Germany).</description>
	<lastBuildDate>Tue, 23 Dec 2008 20:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Windows Memory Forensics Tools</title>
		<link>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/</link>
		<comments>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 20:32:58 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[memory analysis]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=179</guid>
		<description><![CDATA[SANS recently published a good summary of Windows memory forensics acquisition and analysis tools. It&#8217;s a good compilation of must have tools for the right occasion. SANS forensics]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin-left: 3px; margin-right: 3px;" title="icon" src="/images/icons/plugin_error.png" alt="" width="16" height="16" />SANS recently published a good summary of Windows memory forensics acquisition and analysis tools. It&#8217;s a good compilation <span id="more-179"></span>of must have tools for the right occasion.</p>
<p><a href="http://sansforensics.wordpress.com/2008/12/13/windows-physical-memory-finding-the-right-tool-for-the-job/" target="_blank">SANS forensics</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/12/23/windows-memory-forensics-tools/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>new linux incident response script</title>
		<link>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/</link>
		<comments>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/#comments</comments>
		<pubDate>Sat, 18 Oct 2008 10:53:05 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[forensics tools]]></category>
		<category><![CDATA[ForensiX CD]]></category>
		<category><![CDATA[Live Response]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=172</guid>
		<description><![CDATA[We updated the ForensiX Linux Incident Response Script. You can find the new version at my german site http://computer-forensik.org/tools/ix/ix-special/.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin: 3px;" title="cover iX special" src="http://www.heise.de/kiosk/special/ix/08/01/cd_min.gif" alt="" width="60" height="60" />We updated the ForensiX Linux Incident Response Script. You can find the new version at <span id="more-172"></span>my german site <a href="http://computer-forensik.org/tools/ix/ix-special/" target="_blank">http://computer-forensik.org/tools/ix/ix-special/</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/10/18/new-linux-incident-response-script/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>open forensics jobs</title>
		<link>http://geschonneck.com/2008/10/18/open-forensics-jobs/</link>
		<comments>http://geschonneck.com/2008/10/18/open-forensics-jobs/#comments</comments>
		<pubDate>Sat, 18 Oct 2008 10:13:28 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[Jobs]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=169</guid>
		<description><![CDATA[I have some open positions in my german forensics &#38; discovery team. Please take a closer look at the following job postings: Senior Consultants (m/w) Forensic Technology &#38; Discovery Services and Consultants (m/w) Forensic Technology &#38; Discovery Services]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin-left: 3px; margin-right: 3px;" title="icon" src="/images/icons/information.png" alt="" width="16" height="16" />I have some open positions in my german forensics &amp; discovery team. Please<span id="more-169"></span></p>
<p>take a closer look at the following job postings:</p>
<p><a onclick="javascript:urchinTracker ('/outbound/article/www.jobportal.de.ey.com');" href="https://www.jobportal.de.ey.com/grabber/stelle_detail.php?id=0_3862&amp;u=eyoung&amp;init=1&amp;stellen_status=SU_KLAMMER&amp;ga=1&amp;sgl=de&amp;mid=1&amp;sid=ad34c2eb2536a2cc275cb5cec449a135" target="_blank">Senior Consultants (m/w) Forensic Technology &amp; Discovery Services</a></p>
<p>and</p>
<p><a onclick="javascript:urchinTracker ('/outbound/article/www.jobportal.de.ey.com');" href="https://www.jobportal.de.ey.com/grabber/stelle_detail.php?id=0_3865&amp;u=eyoung&amp;init=1&amp;stellen_status=SU_KLAMMER&amp;ga=1&amp;sgl=de&amp;mid=1&amp;sid=ad34c2eb2536a2cc275cb5cec449a135" target="_blank">Consultants (m/w) Forensic Technology &amp; Discovery Services</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/10/18/open-forensics-jobs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ch-ch-ch-changes</title>
		<link>http://geschonneck.com/2008/07/05/ch-ch-ch-changes/</link>
		<comments>http://geschonneck.com/2008/07/05/ch-ch-ch-changes/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 08:46:07 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[On my behalf]]></category>
		<category><![CDATA[Alexander Geschonneck]]></category>
		<category><![CDATA[Computer Forensik]]></category>
		<category><![CDATA[e-Discovery]]></category>
		<category><![CDATA[Forensic Investigation]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Jobs]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=167</guid>
		<description><![CDATA[After ten happy and successful years with HiSolutions, I&#8217;m now with the Ernst &#38; Young Fraud Investigation &#38; Dispute Services department. I&#8217;m leading as a senior manager the Forensic Technology &#38; Discovery Services unit in Germany. And yes, we&#8217;re hiring]]></description>
			<content:encoded><![CDATA[<p><img style="vertical-align: middle; margin-left: 3px; margin-right: 3px;" src="/images/icons/information.png" alt="icon" width="16" height="16" />After ten happy and successful years with HiSolutions, I&#8217;m now with the <span id="more-167"></span>Ernst &amp; Young Fraud Investigation &amp; Dispute Services department. I&#8217;m leading as a senior manager the Forensic Technology &amp; Discovery Services unit in Germany. And yes, we&#8217;re hiring <img src="http://geschonneck.com/wp-content/plugins/more-smilies/Phoenity/cool.png" alt="8)" class="wp-smiley" /> </p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/07/05/ch-ch-ch-changes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous Quote</title>
		<link>http://geschonneck.com/2008/05/21/anonymous-quote/</link>
		<comments>http://geschonneck.com/2008/05/21/anonymous-quote/#comments</comments>
		<pubDate>Wed, 21 May 2008 16:53:14 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=164</guid>
		<description><![CDATA[“If you’re a good hacker…everybody knows. If you’re a GREAT hacker…nobody knows.”]]></description>
			<content:encoded><![CDATA[<p><img style="vertical-align: middle; margin-left: 3px; margin-right: 3px;" src="/images/icons/emoticon_evilgrin.png" alt="icon" width="16" height="16" />“If you’re a good hacker…<span id="more-164"></span>everybody knows.<br />
If you’re a GREAT hacker…<strong>nobody</strong> knows.”</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/05/21/anonymous-quote/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3rd edition of my book</title>
		<link>http://geschonneck.com/2008/05/04/3rd-edition-of-my-book/</link>
		<comments>http://geschonneck.com/2008/05/04/3rd-edition-of-my-book/#comments</comments>
		<pubDate>Sun, 04 May 2008 06:47:35 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Alexander Geschonneck]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[digital investigations]]></category>
		<category><![CDATA[forensics book]]></category>

		<guid isPermaLink="false">http://geschonneck.com/?p=161</guid>
		<description><![CDATA[3rd Edition of “Computer-Forensik. Computerstraftaten erkennen, ermitteln, aufklären.” The new revised edition of my book on computer forensics in German language is available. For detailed information and the TOC check out computer-forensik.org or go directly to amazon.]]></description>
			<content:encoded><![CDATA[<h3><img class="alignleft" style="float: left; margin-left: 3px; margin-right: 3px;" src="http://computer-forensik.org/images/cover_computer-forensik_3.jpg" alt="Cover Computer Forensik" width="100" height="143" />3rd Edition of “Computer-Forensik. Computerstraftaten erkennen, ermitteln, aufklären.”</h3>
<p>The new revised edition of my book on computer forensics in German language is available.</p>
<p>For detailed information and the <a href="http://computer-forensik.org/2008/04/16/inhaltsverzeichnis-der-3-auflage/" target="_blank">TOC</a> check out  <a onclick="javascript:urchinTracker ('/outbound/article/computer-forensik.org');" href="http://computer-forensik.org/" target="_blank">computer-forensik.org</a> or go directly to <a onclick="javascript:urchinTracker ('/outbound/article/www.amazon.de');" href="http://www.amazon.de/exec/obidos/redirect?link_code=as2&amp;path=ASIN/3898645347&amp;tag=computerforen-21&amp;camp=1638&amp;creative=6742" target="_blank">amazon</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/05/04/3rd-edition-of-my-book/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>computer forensics workshops in Berlin and Frankfurt</title>
		<link>http://geschonneck.com/2008/04/04/computer-forensics-workshops-in-berlin-and-frankfurt/</link>
		<comments>http://geschonneck.com/2008/04/04/computer-forensics-workshops-in-berlin-and-frankfurt/#comments</comments>
		<pubDate>Fri, 04 Apr 2008 15:00:33 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Speeches]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[computer forensics training]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[Heise]]></category>
		<category><![CDATA[iX]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2008/04/04/computer-forensics-workshops-in-berlin-and-frankfurt/</guid>
		<description><![CDATA[In collaboration with the german IT journal iX I’m going to give again computer forensics lessons in Frankfurt and Berlin. 05. &#8211; 06. June 2008, Frankfurt/M. 12. &#8211; 13. June 2008, Berlin More information on my computer forensics website or the iX conference website.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ix-konferenz.de/images/workshop.gif" alt="iX logo" align="left" height="66" hspace="3" width="69" />In collaboration with the german IT journal <em>iX</em> I’m going to give again computer forensics lessons in Frankfurt and Berlin.</p>
<p><span id="more-157"></span></p>
<ul>
<li>05. &#8211; 06. June 2008, Frankfurt/M.</li>
<li>12. &#8211; 13. June 2008, Berlin</li>
</ul>
<p>More information on my <a href="http://computer-forensik.org/2008/03/23/computer-forensik-workshops-2008-mit-der-ix/" target="_blank">computer forensics website</a> or the <a href="http://ix-konferenz.de/anmeldung.php?konferenzid=37&amp;st=Anmeldung" target="_blank"><em>iX</em> conference website</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/04/04/computer-forensics-workshops-in-berlin-and-frankfurt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista Forensics Slides</title>
		<link>http://geschonneck.com/2008/03/06/vista-forensics-slides/</link>
		<comments>http://geschonneck.com/2008/03/06/vista-forensics-slides/#comments</comments>
		<pubDate>Thu, 06 Mar 2008 14:21:23 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[Presentation]]></category>
		<category><![CDATA[vista forensics]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2008/03/06/vista-forensics-slides/</guid>
		<description><![CDATA[I pulished my Vista Forensics slides on my german computer forensics website. Link to computer-forensik.org]]></description>
			<content:encoded><![CDATA[<p>I pulished my Vista Forensics slides on my german computer forensics website.<span id="more-154"></span></p>
<p><a href="http://computer-forensik.org/2008/03/06/folien-zu-windows-vista-forensics-cebit-2008/" target="_blank">Link to computer-forensik.org<br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/03/06/vista-forensics-slides/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bypassing a Windows login password with forensic tools</title>
		<link>http://geschonneck.com/2008/02/24/bypassing-a-windows-login-password-with-forensic-tools/</link>
		<comments>http://geschonneck.com/2008/02/24/bypassing-a-windows-login-password-with-forensic-tools/#comments</comments>
		<pubDate>Sun, 24 Feb 2008 13:37:40 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[windows forensics]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2008/02/24/bypassing-a-windows-login-password-with-forensic-tools/</guid>
		<description><![CDATA[Lance Mueller published a good article about bypassing a Windows login password with forensic tools . You can use his instructions if you plan to boot an Windows image within a virtual machine and like to login.The other way is of course attacking the password hash with rainbow tables. But sometimes this is not the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/folder_key.png" alt="icon" align="absmiddle" height="16" hspace="3" width="16" />Lance Mueller published a good article about bypassing a Windows login password with forensic tools . You can use his instructions if you plan to boot an Windows image within a virtual machine and like to login.<span id="more-152"></span>The other way is of course attacking the password hash with rainbow tables. But sometimes this is not the best option.</p>
<p>Read the <a href="http://www.forensickb.com/2008/02/bypassing-windows-login-password-in.html" target="_blank">full story</a> on Lance&#8217;s blog.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/02/24/bypassing-a-windows-login-password-with-forensic-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>frozen memory aquisition</title>
		<link>http://geschonneck.com/2008/02/22/frozen-memory-aquisition/</link>
		<comments>http://geschonneck.com/2008/02/22/frozen-memory-aquisition/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 15:33:09 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Live Response]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[disk encryption]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2008/02/22/frozen-memory-aquisition/</guid>
		<description><![CDATA[Cool stuff from Princeton researchers. They published a paper &#8220;Cold Boot Attacks on Encryption Keys&#8221; and showed that whole disk encryption can be defeated by relatively simple methods.  They demonstrated their methods by using them to defeat three disk encryption products: BitLocker,  FileVault, which comes with MacOS X; and dm-crypt, which is used with Linux. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/plugin_error.png" alt="icon" align="absmiddle" height="16" hspace="3" width="16" />Cool stuff from Princeton researchers. They published a paper &#8220;Cold Boot Attacks on Encryption Keys&#8221; and showed that whole disk encryption can be defeated by relatively simple methods.  They demonstrated their methods by using them to defeat three disk encryption products: BitLocker,  <span id="more-151"></span>FileVault, which comes with MacOS X; and dm-crypt, which is used with Linux.</p>
<p>Link to the <a href="http://citp.princeton.edu/memory/" target="_blank" onclick="javascript:urchinTracker ('/outbound/article/citp.princeton.edu');">project</a> with <a href="http://www.youtube.com/watch?v=JDaicPIgn9U" target="_blank" onclick="javascript:urchinTracker ('/outbound/article/www.youtube.com');">sample video</a><a href="http://citp.princeton.edu/memory/" target="_blank"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/02/22/frozen-memory-aquisition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insider Threat Research</title>
		<link>http://geschonneck.com/2008/01/28/insider-threat-research/</link>
		<comments>http://geschonneck.com/2008/01/28/insider-threat-research/#comments</comments>
		<pubDate>Mon, 28 Jan 2008 17:25:28 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[insider threat]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2008/01/28/insider-threat-research/</guid>
		<description><![CDATA[CERT and the United States Sectret Service published an insider threat research that focuses on both technical and behavioral aspects of actual compromises. The key findings are Current and former employees carried out insider activities in nearly equal numbers. Sixty-three percent of the insiders held technical positions within the targeted organizations. Thirty-eight percent of insiders [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/images/icons/flag_red.png" alt="icon" height="16" hspace="3" width="16" />CERT and the United  States Sectret Service published an <span class="style1">insider threat research that focuses on both technical and behavioral aspects of actual compromises. The key findings are</span></p>
<ul>
<li>Current and former employees carried out insider activities in nearly equal numbers.</li>
<li>Sixty-three percent of the insiders held technical positions within the targeted organizations.<span id="more-146"></span></li>
<li>Thirty-eight percent of insiders had prior arrests.</li>
<li>A specific work-related event triggered most (73%) insiders’ actions.</li>
<li>The majority (76%) of insiders planned their activities in advance.</li>
<li>Half (50%) of the insiders had authorized access to the system/network at the time of the incident.</li>
<li>Over half (58%) of the insiders used relatively sophisticated tools or methods for their illicit activities, including scripts or programs, autonomous agents, toolkits, probing, scanning, flooding, spoofing, compromising computer accounts, or creating unauthorized backdoor accounts.</li>
<li>Insiders committed their illicit activities both from the workplace (51%) and remotely (43%) in nearly equal numbers.</li>
<li>The incidents took place during (51%) and outside (49%) normal working hours in nearly equal numbers.</li>
<li>Most (80%) of the insider incidents were only discovered through manual (non-automated) detection of an irregularity or failure of an information system.</li>
<li>The majority (74%) of the insiders took steps to conceal their identities and their activities.</li>
</ul>
<p><a href="http://www.cert.org/insider_threat/" target="_blank">http://www.cert.org/insider_threat/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2008/01/28/insider-threat-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Talk about Windows Vista Forensics</title>
		<link>http://geschonneck.com/2007/12/29/talk-about-windows-vista-forensics/</link>
		<comments>http://geschonneck.com/2007/12/29/talk-about-windows-vista-forensics/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 10:52:50 +0000</pubDate>
		<dc:creator>Alexander Geschonneck</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Speeches]]></category>
		<category><![CDATA[computer forensics]]></category>
		<category><![CDATA[DFN-CERT]]></category>
		<category><![CDATA[Presentation]]></category>
		<category><![CDATA[vista forensics]]></category>

		<guid isPermaLink="false">http://geschonneck.com/2007/12/29/talk-about-windows-vista-forensics/</guid>
		<description><![CDATA[I&#8217;m going to talk about Windows Vista Forensics at the DFN-CERT workshop. The workshop will be held on Februray 13 and 14, 2008 in Hamburg, Germany. You can find the full program and registration information here.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m going to talk about Windows Vista Forensics at the DFN-CERT workshop. The workshop will be held on Februray 13 and 14, 2008 in Hamburg, Germany.<span id="more-142"></span></p>
<p>You can find the full program and registration information <a href="http://www.dfn-cert.de/events/ws/2008/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://geschonneck.com/2007/12/29/talk-about-windows-vista-forensics/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
