CONTENTS

Forensics: Installation Instructions

Installation Instruction.  This section will cover the installation if you want to complete this tutorial using your computer. 

1. Install Hex Workshop (run “hw32v423.exe”)

a.  Download the file “hw32v4423.exe” from the website:  http://www.bpsoft.com/downloads/index.html

b.   Create shortcut to desktop (prompts during install)

2.  Install MD5Hash (copy folder from CD into c:\forensictools, run setup.exe)

a. Download the zip file “hash.zip” and extract files into a temporary directory.

b. Run the “setup.exe” file to install the MD5Hash executable.

c. Create a shortcut to desktop.

3.  Create the following directory structure:

a.  c:\forensictools\PortRedirection

b.  c:\forensictools\Pasco&Galleta

c.  c:\forensictools\Pasco&Galleta\data

d.  c:\temp\forensicdata\original

e.  c:\temp\forensicdata\modified

4.  Arrange data for Hex Workshop

a. Copy sol.exe (original copy) from the c:\%SystemRoot%\System32\sol.exe into “c:\temp\forensic data\original as spider.exe”

b. Download “spider.zip” and extract spider.exe (modified copy) into “c:\temp\forensic data\modified”

5.  Download the following tools for Port Redirection exercise:

a.  Quick 'n Easy FTP Server:  http://www.pablosoftwaresolutions.com/html/downloads.htm

b.  FPIPE zipped file:  http://www.foundstone.com/resources/freetooldownload.htm?file=fpipe2_1.zip

c.  FPORT http://www.foundstone.com/resources/freetooldownload.htm?file=fport.zip

6.  Install tools for Port Redirection exercise in the folder “c:\forensictools\PortRedirection”:

a. Copy the executable “FTPServer.exe” file to the folder.

b. Copy the executables “fpipe.exe” and “fport.exe” to the folder.

c. Create shortcuts to desktop.

7.  Download the following tools for Internet Explorer Cache exercise:

a. Download the zip file for “pasco.exe” from http://www.foundstone.com/resources/freetooldownload.htm?file= pasco.zip

b. Download the zip file for “galleta.exe” http://www.foundstone.com/resources/freetooldownload.htm?file=galleta.zip

8. Install tools and data for Port Redirection exercise to the folder “c:\forensictools\Pasco&Galleta”.

a. Copy the executable “pasco.exe” file to the folder.

b. Copy the executable “galleta.exe” file to the folder.

c. Download the file “ieData.zip” from http://www.sis.pitt.edu/~lersais/download/IntroSec/lab2/ieData.zip and extract contents into the folder “c:\forensictools\Pasco&Galleta\data”

d. Create shortcuts to desktop.

9.  Install JPEG Hide and Seek tool for steganography.

a. Download the Steganography tool as zipped file “jphs_05.zip: http://linux01.gwdg.de/%7Ealatham/stego.html and install it.

b. Create shortcut to desktop.

10.  The environment for this tutorial is ready.