<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7683355055095156894</id><updated>2012-01-02T01:34:56.517-06:00</updated><title type='text'>The Digital Standard</title><subtitle type='html'>This Blog is dedicated Digital Forensics and Incident Response, tools, techniques, policies, and procedures.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>77</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7967996498496887676</id><published>2011-12-06T10:38:00.003-06:00</published><updated>2011-12-06T10:40:09.099-06:00</updated><title type='text'>Manipulating WFP and Residual IOCs</title><content type='html'>I just posted on the &lt;a href="http://blog.spiderlabs.com/"&gt;SpiderLabs Anterior&lt;/a&gt; blog about manipulating WFP and what IOC that would leave behind.  Check it out!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://2.bp.blogspot.com/-iM5jdPsbbvU/Tt5FYvuXYXI/AAAAAAAAAQo/cQZrrFYos9c/s320/wfp_blog.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5683056071218258290" /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7967996498496887676?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7967996498496887676/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/12/manipulating-wfp-and-residual-iocs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7967996498496887676'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7967996498496887676'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/12/manipulating-wfp-and-residual-iocs.html' title='Manipulating WFP and Residual IOCs'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-iM5jdPsbbvU/Tt5FYvuXYXI/AAAAAAAAAQo/cQZrrFYos9c/s72-c/wfp_blog.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-1774228789433416014</id><published>2011-11-18T07:19:00.002-06:00</published><updated>2011-11-18T07:21:09.483-06:00</updated><title type='text'>Pauldotcom Inverview</title><content type='html'>If you missed my interview on &lt;a href="http://pauldotcom.com/"&gt;Pauldotcom &lt;/a&gt;last night, you can still watch it on their website.&lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://1.bp.blogspot.com/-TiD4fmpSKdk/TsZbsq2KnTI/AAAAAAAAAQc/KKdfVm2BLpk/s1600/pdc.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img src="http://1.bp.blogspot.com/-TiD4fmpSKdk/TsZbsq2KnTI/AAAAAAAAAQc/KKdfVm2BLpk/s320/pdc.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5676325203320937778" style="cursor: pointer; width: 320px; height: 235px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-1774228789433416014?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/1774228789433416014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/pauldotcom-inverview.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1774228789433416014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1774228789433416014'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/pauldotcom-inverview.html' title='Pauldotcom Inverview'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-TiD4fmpSKdk/TsZbsq2KnTI/AAAAAAAAAQc/KKdfVm2BLpk/s72-c/pdc.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3371840807372146113</id><published>2011-11-16T10:34:00.004-06:00</published><updated>2011-11-16T10:36:09.969-06:00</updated><title type='text'>Interview on Pauldotcom</title><content type='html'>Sweet!  I will be on &lt;a href="http://pauldotcom.com/"&gt;Pauldotcom &lt;/a&gt;tomorrow night talking about Sniper Forensics!  Check it!&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 140px;" src="http://1.bp.blogspot.com/-n5OAdCAtghk/TsPmLWCGRRI/AAAAAAAAAQQ/2LQ5e5TsSWc/s320/pauldotcom.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5675633037984285970" /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3371840807372146113?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3371840807372146113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/interview-on-pauldotcpm.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3371840807372146113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3371840807372146113'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/interview-on-pauldotcpm.html' title='Interview on Pauldotcom'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-n5OAdCAtghk/TsPmLWCGRRI/AAAAAAAAAQQ/2LQ5e5TsSWc/s72-c/pauldotcom.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-6567963162371933214</id><published>2011-11-15T14:20:00.003-06:00</published><updated>2011-11-15T14:22:20.435-06:00</updated><title type='text'>Context, Context, Context</title><content type='html'>Check out the&lt;a href="http://blog.spiderlabs.com/"&gt; SpiderLabs blog, "Anterior" &lt;/a&gt;for the latest Sniper Forensics post.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://blog.spiderlabs.com/"&gt;&lt;img src="http://2.bp.blogspot.com/-jjs0Eb63Je0/TsLJ8ctsq4I/AAAAAAAAAQE/jf6DzeKnTDU/s320/context.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5675320520777444226" style="cursor: pointer; width: 320px; height: 129px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-6567963162371933214?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/6567963162371933214/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/context-context-context.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6567963162371933214'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6567963162371933214'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/11/context-context-context.html' title='Context, Context, Context'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-jjs0Eb63Je0/TsLJ8ctsq4I/AAAAAAAAAQE/jf6DzeKnTDU/s72-c/context.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-6684091560548057488</id><published>2011-10-20T08:42:00.002-05:00</published><updated>2011-10-20T08:57:11.580-05:00</updated><title type='text'>SecTor 2011 Huge Success</title><content type='html'>I am back from Toronto, and once again &lt;a href="http://www.linkedin.com/profile/view?id=5797798&amp;amp;authType=NAME_SEARCH&amp;amp;authToken=D1J5&amp;amp;locale=en_US&amp;amp;srchid=7198c312-54dd-4c92-a6c4-b8439170a2da-0&amp;amp;srchindex=1&amp;amp;srchtotal=12&amp;amp;goback=.fps_PBCK_*1_Brian_Bourne_*1_*1_*1_*1_*2_*1_Y_*1_*1_*1_false_1_R_true_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2&amp;amp;pvs=ps&amp;amp;trk=pp_profile_name_link"&gt;Brian Bourne&lt;/a&gt;, &lt;a href="http://www.linkedin.com/profile/view?id=5986030&amp;amp;locale=en_US&amp;amp;trk=tyah2"&gt;Renu Bourne&lt;/a&gt;,  &lt;a href="http://www.linkedin.com/profile/view?id=6529540&amp;amp;authType=NAME_SEARCH&amp;amp;authToken=ke7P&amp;amp;locale=en_US&amp;amp;srchid=7c16de9d-640d-4a3a-a6f2-ce3f5e440272-0&amp;amp;srchindex=1&amp;amp;srchtotal=9&amp;amp;goback=.fps_PBCK_bruce+cowper_*1_*1_*1_*1_*1_*1_*2_*1_Y_*1_*1_*1_false_1_R_true_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2&amp;amp;pvs=ps&amp;amp;trk=pp_profile_name_link"&gt;Bruce Cowper&lt;/a&gt; and the rest of the &lt;a href="http://www.sector.ca/"&gt;SecTor&lt;/a&gt; folks out on one of the best security conferences anywhere in the world.&lt;br /&gt;&lt;br /&gt;A special thanks to &lt;a href="http://www.linkedin.com/profile/view?id=46046141&amp;amp;authType=NAME_SEARCH&amp;amp;authToken=K6wI&amp;amp;locale=en_US&amp;amp;srchid=7532a41e-2a18-45f8-8063-d76c70bd2d01-0&amp;amp;srchindex=4&amp;amp;srchtotal=10&amp;amp;goback=.fps_PBCK_melanie+wallis_*1_*1_*1_*1_*1_*1_*2_*1_Y_*1_*1_*1_false_1_R_true_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2&amp;amp;pvs=ps&amp;amp;trk=pp_profile_name_link"&gt;Melanie Wallis&lt;/a&gt; for handling the logistics for all of the speakers!&lt;br /&gt;&lt;br /&gt;If you have not been to SecTor in the past, you are seriously missing out.  The talks get better year after year, and the crowd continues to grow.  This year Brian said they had over 1100 attendees, which is fastasic!&lt;br /&gt;&lt;br /&gt;Also, &lt;a href="http://eyeonforensics.blogspot.com/"&gt;Grayson Lenik&lt;/a&gt;, &lt;a href="http://www.linkedin.com/in/jibranilyas"&gt;Jibran Ilyas&lt;/a&gt;, and I conducted a one day Forensics training seminar that went beautifully, and was very well recived.&lt;br /&gt;&lt;br /&gt;Great job again to everyone at Black Arts LTD for making SecTor 2011 a huge success!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-6684091560548057488?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/6684091560548057488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/10/sector-2011-huge-success.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6684091560548057488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6684091560548057488'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/10/sector-2011-huge-success.html' title='SecTor 2011 Huge Success'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-934701524437546390</id><published>2011-10-10T18:24:00.004-05:00</published><updated>2011-10-10T18:32:08.097-05:00</updated><title type='text'>The Great Northern Invasion</title><content type='html'>So I am heading to Canada twice this month to speak at two different security conferences.&lt;br /&gt;&lt;br /&gt;On October 17th, I am presenting a day of Law Enforcement training in Toronto at &lt;a href="http://www.sector.ca/"&gt;SecTor&lt;/a&gt; followed on the 18th by the debut of Sniper Foreniscs v3.0: Hunt.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-lpRWjO8Depw/TpN_KD1cycI/AAAAAAAAAP0/G7Z5TtK3uN4/s1600/sector.jpg"&gt;&lt;img style="cursor: pointer; width: 233px; height: 171px;" src="http://2.bp.blogspot.com/-lpRWjO8Depw/TpN_KD1cycI/AAAAAAAAAP0/G7Z5TtK3uN4/s320/sector.jpg" alt="" id="BLOGGER_PHOTO_ID_5662008967339755970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Then, on October 25th, I am speaking at &lt;a href="http://www.blogger.com/SecureTech%20Canada"&gt;SecureTech Canada&lt;/a&gt; where I am sitting on a panel discussing Cyber Extortion and Protecting Critical Data.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-_-B7bL7UvFs/TpN_7V-t4YI/AAAAAAAAAP8/IJVepIBt0wc/s1600/securetech.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 80px;" src="http://4.bp.blogspot.com/-_-B7bL7UvFs/TpN_7V-t4YI/AAAAAAAAAP8/IJVepIBt0wc/s320/securetech.jpg" alt="" id="BLOGGER_PHOTO_ID_5662009814024053122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I am really looking forward to a pile of &lt;a href="http://en.wikipedia.org/wiki/Poutine"&gt;poutine&lt;/a&gt;...and maybe a &lt;a href="http://en.wikipedia.org/wiki/Alexander_keiths"&gt;Keith's&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;If anyone is going to SecTor, I will be at Joe Bidali's right across the street from the hotel on most nights.  See you there eh!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-934701524437546390?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/934701524437546390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/10/great-northern-invasion.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/934701524437546390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/934701524437546390'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/10/great-northern-invasion.html' title='The Great Northern Invasion'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-lpRWjO8Depw/TpN_KD1cycI/AAAAAAAAAP0/G7Z5TtK3uN4/s72-c/sector.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2173033507080601129</id><published>2011-09-21T16:15:00.001-05:00</published><updated>2011-09-21T16:16:39.047-05:00</updated><title type='text'>Log2Timeline Intall Guide</title><content type='html'>Some folks have indicated that they cannot find this.  According to Kristinn, it's in the "Install" documentation.&lt;br /&gt;&lt;br /&gt;&lt;p style="padding-left:30px"&gt;&lt;em&gt;+ ------------------------------&lt;wbr&gt;------------------------------&lt;wbr&gt;------------------------------&lt;wbr&gt;---------------------------&lt;/em&gt;&lt;br /&gt;&lt;em&gt;+                             &lt;wbr&gt;  WINDOWS&lt;/em&gt;&lt;br /&gt;&lt;em&gt;+ ------------------------------&lt;wbr&gt;------------------------------&lt;wbr&gt;------------------------------&lt;wbr&gt;---------------------------&lt;/em&gt;&lt;br /&gt;&lt;em&gt;This has been tested on a Windows XP sp3 machine (32 bit), and Win7 64 bit machine.&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Download and &lt;span class="il"&gt;install&lt;/span&gt; ActiveState Perl&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Open command prompt and run the following commands (&lt;span class="il"&gt;install&lt;/span&gt; dependencies):&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; datetime&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; win32::api&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; date::manip&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; xml::libxml&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; carp::assert&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; digest::crc&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; data::hexify&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; image::exiftool&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; file::mork&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; datetime::format::strptime&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; parse::win32registry&lt;/em&gt;&lt;br /&gt;&lt;em&gt;ppm &lt;span class="il"&gt;install&lt;/span&gt; html::scrubber&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Download the latest source code for log2timeline&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Download two additional libraries:&lt;/em&gt;&lt;/p&gt;&lt;div class="im"&gt;&lt;br /&gt;&lt;em&gt;        "&lt;a href="http://search.cpan.org/CPAN/authors/id/B/BD/BDFOY/Mac-PropertyList-1.33.tar.gz" target="_blank"&gt;http://search.cpan.org/CPAN/&lt;wbr&gt;authors/id/B/BD/BDFOY/Mac-&lt;wbr&gt;PropertyList-1.33.tar.gz&lt;/a&gt;"&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        "&lt;a href="http://search.cpan.org/CPAN/authors/id/S/SI/SIXTEASE/XML-Entities-1.0000.tar.gz" target="_blank"&gt;http://search.cpan.org/CPAN/&lt;wbr&gt;authors/id/S/SI/SIXTEASE/XML-&lt;wbr&gt;Entities-1.0000.tar.gz&lt;/a&gt;"&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Uncompress&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;em&gt;Inside the XML-Entities:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy the content of the lib/XML folder to c:/perl/lib/XML/&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Inside the Mac-Propertylist:&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Create the directory c:/perl/lib/Mac&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy the content of the lib/* to c:/perl/lib/Mac&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Inside the log2timeline directory&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Delete the file lib/Log2t/input/&lt;a href="http://pcap.pm/" target="_blank"&gt;pcap.pm&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy the content of the lib/Parse/* to c:/perl/lib/Parse/&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy the content of the folder lib/Log2t to c:/perl/lib/Log2t/*&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy lib/Log2Timeline.pm to c:/perl/lib/&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy log2timeline to c:/perl/bin/&lt;a href="http://log2timeline.pl/" target="_blank"&gt;log2timeline.pl&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy l2t_process to c:/perl/bin/&lt;a href="http://l2t_process.pl/" target="_blank"&gt;l2t_process.pl&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;        Copy timescanner to c:/perl/bin/&lt;a href="http://timescanner.pl/" target="_blank"&gt;timescanner.pl&lt;/a&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Test and hope the best... ;)&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2173033507080601129?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2173033507080601129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/09/log2timeline-intall-guide.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2173033507080601129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2173033507080601129'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/09/log2timeline-intall-guide.html' title='Log2Timeline Intall Guide'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3257349638228033654</id><published>2011-08-29T06:50:00.002-05:00</published><updated>2011-08-29T06:52:07.558-05:00</updated><title type='text'>CyberSpeak Interview Available!</title><content type='html'>My interview on &lt;a href="http://cyberspeak.libsyn.com/"&gt;CyberSpeak &lt;/a&gt;is now available.&lt;br /&gt;&lt;br /&gt;Thanks to Ovie Carroll and George Starcher for taking the time to interview me!  I hope your ratings don't drop too much  =).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3257349638228033654?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3257349638228033654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/cyberspeak-interview-available.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3257349638228033654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3257349638228033654'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/cyberspeak-interview-available.html' title='CyberSpeak Interview Available!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3641624063555393169</id><published>2011-08-16T19:01:00.004-05:00</published><updated>2011-08-16T19:04:39.067-05:00</updated><title type='text'>CyberSpeak Interview</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-2tTTDDQsrs8/TksFbzmlsiI/AAAAAAAAAPs/hy4lqWwX6-4/s1600/cyberspeak.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 320px; height: 83px;" src="http://2.bp.blogspot.com/-2tTTDDQsrs8/TksFbzmlsiI/AAAAAAAAAPs/hy4lqWwX6-4/s320/cyberspeak.jpg" alt="" id="BLOGGER_PHOTO_ID_5641608933478347298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I just finished an interview with Ovie Carroll on &lt;a href="http://cyberspeak.libsyn.com/"&gt;CyberSpeak&lt;/a&gt;!  It should be posted in about two weeks!  Give it a listen!&lt;br /&gt;&lt;br /&gt;Talked about Sniper Forensics and how it rocks the hizzie!&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3641624063555393169?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3641624063555393169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/cyberspeak-interviewhttpwwwbloggercomim.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3641624063555393169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3641624063555393169'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/cyberspeak-interviewhttpwwwbloggercomim.html' title='CyberSpeak Interview'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-2tTTDDQsrs8/TksFbzmlsiI/AAAAAAAAAPs/hy4lqWwX6-4/s72-c/cyberspeak.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7048603074499541356</id><published>2011-08-12T07:35:00.003-05:00</published><updated>2011-08-12T07:50:47.969-05:00</updated><title type='text'>Investigation Plans</title><content type='html'>I presented Sniper Forensics at two different conferences this past week and I am honestly, still alarmed by the number of investigators that still don't create an investigation plan at the beginning of a case.  So, to sound like a broken record...If you are currently working cases, and NOT creating an investigation plan..START.&lt;br /&gt;&lt;br /&gt;Here is what I do...&lt;br /&gt;&lt;br /&gt;First, I open &lt;a href="http://www.qccis.com/forensic-tools"&gt;Case Notes&lt;/a&gt; and open my custom tab that I have labeled, "Investigation Plan".&lt;br /&gt;&lt;br /&gt;Second, I sit back and think about what it is that I have been asked to do.  This will obviously change from case to case, agency to agency, and person to person, but the general goal should be the same.  You have been asked to identify something for some reason.  You are not conducting the investigation for the sake of the investigation itself.&lt;br /&gt;&lt;br /&gt;Once I have my overall goal, I write it down in my Case Notes..."I have been asked to confirm blah.&lt;br /&gt;&lt;br /&gt;Third, I brainstorm on the "stuff" I will likely need to accomplish my goal.  Will I need logs, will I need to interview customer (victim) employees, will I need timeline data, registry data...whatever.&lt;br /&gt;&lt;br /&gt;Fourth, I use my tab that I have labeled, "Questions", and I ask myself questions that based on the data I just brainstormed, should help me to accomplish my overall goal.  Throughout the investigation, I answer my questions.  These answers will either terminate my line of thinking in that area and provide me with a new theory, or support my theory, enabling me to continue down the same path.&lt;br /&gt;&lt;br /&gt;Following this brief but very useful exercise will give clarity to my investigation as well as provide success indicators so that I know I have found what I am looking for!  Without a clear idea of what you have been asked to do, an investigator can easily become lost in the, "Fog of Forensics" and his case can grind to a stand still.&lt;br /&gt;&lt;br /&gt;If you are using Investigation Plans...Good on you!  If you are not...start...I promise you will see significant and immediate benefits!&lt;br /&gt;&lt;br /&gt;Now...that pretty much concludes&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7048603074499541356?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7048603074499541356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/investigation-plans.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7048603074499541356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7048603074499541356'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/08/investigation-plans.html' title='Investigation Plans'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7522636578790762496</id><published>2011-07-18T19:43:00.003-05:00</published><updated>2011-07-21T06:45:53.156-05:00</updated><title type='text'>How Do I Get There From Here?</title><content type='html'>I have had several people ask me lately, "&lt;a href="http://www.lyrics007.com/Deana%20Carter%20Lyrics/How%20Do%20I%20Get%20There%20Lyrics.html"&gt;How do I get there from here&lt;/a&gt;"?  Not referring to the Country song by &lt;a href="http://www.deana.com/"&gt;Deana Carter&lt;/a&gt;, but referring to how to get a job as a forensic investigator/incident responder.  So, after thinking about it, here are some ideas that I outlined that help me get to where I am today.  Hopefully, you will find them helpful as well.&lt;br /&gt;First of all, you need a good attitude.  You need to leave your ego or any overinflated sense of superiority at the door.  Some of the absolute BEST people in this industry...guys like &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt;, &lt;a href="http://www.linkedin.com/pub/rob-lee/0/742/aa2"&gt;Rob Lee&lt;/a&gt;, &lt;a href="http://www.forensicswiki.org/wiki/Ovie_Carroll"&gt;Ovie Carroll&lt;/a&gt;, &lt;a href="http://www.posthumorous.com/"&gt;Cory Altheide&lt;/a&gt;, &lt;a href="http://www.deer-run.com/%7Ehal/"&gt;Hal Pomeranz&lt;/a&gt;, &lt;a href="http://www.sans.org/security-training/instructors/Chad-Tilbury"&gt;Chad Tilbury&lt;/a&gt;, &lt;a href="http://blog.zeltser.com/post/1189792218/stuxnet-malware-research"&gt;Lenny Seltzer&lt;/a&gt;, &lt;a href="http://jessekornblum.com/"&gt;Jesse Kornblum&lt;/a&gt;, &lt;a href="http://www.linkedin.com/profile/view?id=6286260&amp;amp;authType=NAME_SEARCH&amp;amp;authToken=amfI&amp;amp;locale=en_US&amp;amp;srchid=c0d91e38-9982-4d8a-b592-b97e3e5602e7-0&amp;amp;srchindex=1&amp;amp;srchtotal=19&amp;amp;goback=.fps_PBCK_*1_Colin_Sheppard_*1_*1_*1_*1_*2_*1_Y_*1_*1_*1_false_1_R_true_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2&amp;amp;pvs=ps&amp;amp;trk=pp_profile_name_link"&gt;Colin Sheppard&lt;/a&gt;, &lt;a href="http://www.linkedin.com/profile/view?id=849153&amp;amp;authType=NAME_SEARCH&amp;amp;authToken=1bVE&amp;amp;locale=en_US&amp;amp;srchid=6160dfd5-362b-4dea-9cc5-fbd69bc9e4d0-0&amp;amp;srchindex=1&amp;amp;srchtotal=31&amp;amp;goback=.fps_PBCK_*1_Chris_Hague_*1_*1_*1_*1_*2_*1_Y_*1_*1_*1_false_1_R_true_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2_*2&amp;amp;pvs=ps&amp;amp;trk=pp_profile_name_link"&gt;Chris Hague&lt;/a&gt;, &lt;a href="http://www.linkedin.com/in/jibranilyas"&gt;Jibran Ilyas&lt;/a&gt;, &lt;a href="http://eyeonforensics.blogspot.com/"&gt;Grayson Lenik&lt;/a&gt; and &lt;a href="http://www.ericjhuber.com/"&gt;Eric Huber&lt;/a&gt; all share a common trait...Humility.  I bet if you asked any one of them if they were good at what they do, you would likely get some variant of the response, "I sure try, but there is always so much to learn!"&lt;br /&gt;&lt;br /&gt;They know they do not know everything, and work hard keep current on emerging concepts and technologies .  I have met them all, and there is absolutely NO pretense in any of these industry giants.  Also, they are passionate about their work, and love what they do. They are the best because they work the hardest.  Period.&lt;br /&gt;&lt;br /&gt;You also need to be flexible.  The slogan of this industry is "&lt;a href="http://en.wikipedia.org/wiki/Semper_Gumby"&gt;semper gumby&lt;/a&gt;" - always flexible. You need to be able to adapt to constantly changing situations, emerging evidence, difficult customers, challenging time tables, and extensive travel.  Don't be too rigid, or get frustrated when things either change unexpectedly, or don't turn out as planned.&lt;br /&gt;And Travel...loooooots of travel.  As an example, I am writing this in the airport during week three of a seven week travel spree.  You will travel...a LOT...so get used to it.&lt;br /&gt;&lt;br /&gt;Second, you have to be wired for this kind of work.  By, "wired", I mean you just have to "get" technology.  You have to have a knack for computers beyond the skills and abilities of what would commonly be referred to as a "normal" end user.  You cannot be scared by the command line, Linux, Mater Boot Records, Master File Tables, the Windows Registry, the OSI model, Perl, Ruby, and/or Python (just to name a few).  You need to be able to read, comprehend, and figure stuff out.  You should know what you are looking at, why, and be able to explain it to anyone.  In short, you need to be either inherently smart, or prepared to work really hard (I fall into the latter category - not the smartest dood in the room, but I think I work as hard as, or harder than just about anyone).  In my opinion, having a concrete foundational knowledge is essential for the job, and is really the difference maker between someone who is OK at the job, and someone who is really good.  So never stop learning!&lt;br /&gt;&lt;br /&gt;Remember, knowing how to use a tool (any tool) no more makes you an investigator, than knowing how to use MS Word makes you Stephen King.  It's a tool that does something...NOTHING more.  It's the expert set of eyes on the screen and the expert fingers on the keyboard that make up the expert.&lt;br /&gt;&lt;br /&gt;Third, you need a desire to find the truth.  The evidence is there (usually), and it's up to you to find it, and interpret it properly.  Also, there is a famous quotes by&lt;a href="http://en.wikipedia.org/wiki/Carl_Sagan"&gt; Dr. Carl Sagan&lt;/a&gt; who stated, "The absence of evidence is not the evidence of absence".  Remember, it is the job of the investigator to identify and properly interpret the evidence.&lt;br /&gt;&lt;br /&gt;These are the precepts you should hang your "hat" on.  Find the truth.  Dig it out of every registry hive, file system, unallocated cluster, slack space, and network capture you can find.&lt;br /&gt;Along those lines, Harlan and I were recently having a discussion over breakfast about context. The basic results were that many investigators will jump to conclusions based on a single data point without building appropriate context around that data point.  Why is it there?  What does it mean?  Am I drawing conclusions based on theory or fact?  Are there other data points that all indicate the same "thing" took place.  For us, best practice is to identify at least three data points that all point in the same direction.  This will give the investigator confidence in what they found (that it is indeed accurate), and give weighting to the evidence.&lt;br /&gt;&lt;br /&gt;This is something I touch on in Sniper Forensics.  NEVER EVER form your opinion about what happened and try to make the data fit your theory.  Let the data formulate your theory, and allow your investigation to flow with the evidence.  You may change directions numerous times.  Doing so doesn't mean you are wrong, or a bad investigator.  It means you know enough to allow the evidence to guide the investigation.  It's a complex, fluid combination of art and science, and if it were easy, everybody would do it and be good at it.&lt;br /&gt;&lt;br /&gt;OK...so now that we have covered some of the basics regarding attitude, and some philosophical essentials, let's talk about education.  You need it.  Personally, I am not a huge fan of the forensic degree programs currently be taught at many universities.  From what I have seen, they teach tool use, and maybe a little theory.  Which is good, but not something that is going to equip an investigator for a successful career in the field.  I would LOVE to see them teach the history of forensic science, logic, investigative methodology, technical writing, research methodologies, public speaking, conflict resolution, and systems administration.  These are the key proponents of a solid investigator...not knowing how to use a tool!  If you have the opportunity to take any class that covers these topics, I would HIGHLY recommend doing so.  You would be amazed if I told you how relevant my Pre-Socratic Philosophy class is to my job!  Or how much better my reports are after taking a technical writing course.  The independent research I have done on expert witness testimony has made me better prepared to speak on the stand.  Taking a class that certifies you in how to use a certain tool...ya...not gonna teach you ANY of those things...I'm juuuuuuuuuuuust sayin...&lt;br /&gt;&lt;br /&gt;In my opinion, if you are looking into a degree program, take something that is going to teach you what "normal" looks like.  Get a general IT degree that is well rounded with courses in Windows, Linux, networking, midrange, and emerging technologies.  You can learn the tools later, knowing the basics will serve you far better in the field.&lt;br /&gt;&lt;br /&gt;I am a fan of technical certifications...sort of.  I have several, and I feel like I got something out of studying for, taking, and passing the requisite examinations.  I think the subject matter is relatively small (compared to the larger IT world), focused, and can help to contribute to your subject matter expertise in a specific area.&lt;br /&gt;&lt;br /&gt;Now, I am only partially a fan of certifications for a couple of reasons.  I know several people who have multiple certifications, and are crummy investigators.  Alternatively,   I know several people who have few or no technical certifications, who are fantastic investigators.  Again, those little letters after your name don't make you a good investigator.  They mean you paid some money, sat in a class, and passed an exam.  Nothing more.  If you have multiple certs...good for you...don't get a big head about it.  If you don't have any...don't let it discourage you.  They are what they are...indicators that you took a class and passed a test.&lt;br /&gt;&lt;br /&gt;Don't get me wrong, from a business perspective, technical certifications go a long way in establishing you as a subject matter expert (some contracts I have worked on even required them).  Also, they can show prospective employers that you are serious about your trade, and have taken steps to set yourself apart from other applicants.  But don't ever think that just because you have a cert and someone else doesn't that you are "better" than they are.  It's simply not the case...ever...and it's just going to make you look like a jerk.  I recommend taking the approach that you love the trade and want to learn as much as you can about it.  You are fortunate enough to have the resources necessary to attend the class and take the exam.  It was a great experience, and you feel that you have benefitted from the knowledge you gained.  BUT, you realize that the forensics/IR world is a big place with a LOT to learn, and you are eager to be engaged in any way you can (recognize your efforts without breaking your arm patting yourself on the back...good skill to have).  If you are good at what you do, your actions will speak far louder than any certifications ever could.&lt;br /&gt;&lt;br /&gt;Next, know that you are going to have to interact with customers....a lot.  You are going to have to explain some very technical concepts to non-technical people - not stupid, just not technical.  You are going to have to deal with angry lawyers, crying business owners, demands, fear, and uncertainty.  Basically, every new case, is everyone's worst day.  You need to become skilled in situational analysis, leadership, public speaking, and incident management.  You will have to learn how to walk the line (a very fine line sometimes) between confidence and arrogance.  This is a difficult concept to learn, and honestly after studying it in both my undergrad and graduate degree programs, at Warrant Officer Candidate School, and reading books about it...it's something you are going to have to experience to get good at.  At least by doing to research on it, you can better prepare yourself, and decrease the time it's going to take you to become proficient.&lt;br /&gt;&lt;br /&gt;I also recommend reading Dale Carnegie's, &lt;a href="http://www.amazon.com/How-Win-Friends-Influence-People/dp/0671723650"&gt;How to Win Friends and Influence People&lt;/a&gt; at least once per year.  Take good notes, and use them.  It has a wealth of information and has been THE standard for interpersonal business relationships for almost 100 years.  Also, realize that at the end of your contract is a person...a human being.  This is their business, or their company...their livelihood.  This is how they put a roof over their head, food on their table, and their kids through school.  Be cognizant of that, and empathetic to their situation.&lt;br /&gt;&lt;br /&gt;Finally, I will share some personal details about how I broke into the industry.  When I was a sysadmin I got bored.  You can only makes things work so well, and know how to troubleshoot so much, before it becomes mundane.  That was the case with me...I was a Solaris and Windows admin at a decently sized IT shop and I was pretty good.  My systems ran well, I could troubleshoot quickly and efficiently...and I was bored to tears.  So, I searched internally for openings doing something different and I came across a posting for the Ethical Hacking Team.  I had all of the required skills (networking, Linux, Windows), no different than any of the other applicants.  But, what I had that they did not was raw desire.  I wanted this job more than anything.  I read anything I could get my hands on that dealt with the subject, spent my own money setting up a makeshift lab to play with tools, and perform experiments.  I ooozed enthusiasm.  I ended up getting the job.  After I was hired, I asked my new manager what was it about me that ended up landing me the job?  She told me something I have never forgotten to this day...&lt;br /&gt;&lt;br /&gt;"Chris, I can teach you how to use the tools.  The other folks on the team can teach you how to go after certain targets, what to look for, and how to run exploits.  What I can't teach is enthusiasm.  I know that you will be one of my best pentesters in a year simply because you want to be.  I firmly believe you wanted the job more than anyone else."&lt;br /&gt;&lt;br /&gt;So, while being passionate may not land you the job, it will set you apart from other applicants.  Read, research, study, conduct experiments.  Learn something new every day.  Learn how to use open source tools (which is like 99% of what I use).  Learn about forensic theory, investigative methodology, and logic.  Learn how to write reports, how to deal with difficult situations and difficult people, and how to LISTEN!  Most of all, love the work!&lt;br /&gt;&lt;br /&gt;I hope you find this information helpful.  If you have any specific questions, please feel free to email me at any time.  I am always willing to help!&lt;br /&gt;&lt;br /&gt;Happy Hunting!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7522636578790762496?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7522636578790762496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/how-do-i-get-there-from-here.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7522636578790762496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7522636578790762496'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/how-do-i-get-there-from-here.html' title='How Do I Get There From Here?'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-6201398018319339792</id><published>2011-07-15T17:23:00.002-05:00</published><updated>2011-07-15T17:29:48.509-05:00</updated><title type='text'>Log2Timeline and Super Timelilnes</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin-top:0in;  mso-para-margin-right:0in;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;With the recent release of &lt;a href="http://blog.kiddaland.net/"&gt;Kristinn Gudjonsson's&lt;/a&gt;&lt;a href="http://www.log2timeline.net/"&gt; Log2Timeline &lt;/a&gt;v.60, oddly named, "&lt;a href="http://en.wikipedia.org/wiki/Killer_Dwarfs"&gt;The Killer Dwarf&lt;/a&gt;" (Ya...you had to be there), generating Super timelines has now become easier than ever.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;However, before we get into the technical specifics of exactly HOW this is done, let's cover the two divergent theories about timelines.  &lt;p class="MsoNormal"&gt;For the purposes of this post, I will refer to the two groups as the Hogs and the Budgies.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Yes...I know I am terrible at naming things, but after you hear my rationale behind these names, you will at least know my thought process.&lt;span style="mso-spacerun:yes"&gt;   &lt;/span&gt;First of all, both sides agree that timelines should be made.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;In fact, I am not entirely sure how I ever conducted an investigation without making a timeline, and I am even less sure about how anyone currently conducting investigations can think they are doing a comprehensive job without timelines!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The separation in philosophies comes from exactly what data elements to include in the timeline.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Hogs want to include everything...file system data, event logs, registry last write times, application logs...whatever you have, throw it in there.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The theory is, I am not entire sure what I will need, or what I really want to see so just show me everything and I will decide later.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Budgies are the exact opposite...they want to see a much smaller data sample.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Presumably, they know precisely what is that they want, and only want to see that data.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I categorize myself as a Flying Pig, because what I want to look at changes from case to case.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Sometimes, I only need data from the active file system, while other times, I want to maybe see the event logs, and just the system hive last write times.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I think it's OK to be a Flying Pig, and in my opinion, a good marriage of including just the right data elements into your timeline.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;If you are new to making forensic timelines, my recommendation is to be a Hog.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Gather all of the data you can and throw it into your super timeline.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Hopefully, as you get more and more familiar with what data provides value to your investigations, you will get better at determining which elements to include.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The fact that you are doing timelines at all, sadly puts you in a very small (yet hopefully growing) number of investigators...so keep it up, however you choose to do it.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, on to the technical goodness!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Getting Log2Timeline to run properly in Windows was a bit of a challenge.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;I worked with Kristinn for about a month tweaking perl modules until we finally got a final product that worked properly.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;To start with, go to www.log2timeline.net and download the latest version, and the Windows install guide.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Once you have the files, unpack them into your tools directory and follow the install guide.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;I am not going to say much more about that here, other than I KNOW for a fact that it works...since I am the one that wrote it =).&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;So if you follow it step by step, you should not have any problems.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;What makes the newest release of Log2Timeline really powerful is the addition of the recurse option.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This means that you can throw all of the data you want added to your timeline into a single directory, and use Log2Timeline to recurse through that directory and add any applicable files to the timeline.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Arguably just as important and powerful of a change is the addition of file carving functionality with plugin grouping (much like &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt; uses in&lt;a href="http://regripper.wordpress.com/regripper/"&gt; Reg Ripper&lt;/a&gt;).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;For example...let's say you acquire volatile data from a Windows XP System.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;You have the event logs, the registry hives, a couple of ntuser.dat files, and the Master File Table.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;You can chunk (yes...that is an Oklahoma term) them all into a single directory and use the following command syntax.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;c:\&amp;gt;tools\log2timeline&amp;gt; perl c:\tools\log2timeline\log2timeline.pl -m "keyword" -z CST6CDT -r vol -f winxip -w c:\cases\&lt;casename&gt;\timeline\supertimline.csv&lt;/casename&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Let's take a look at these options one by one.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The -m option allows you to put in a keyword.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Normally, I use the hostname and the drive letter...for example...cpbeefcake_win7_c:\.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This can be anything that will allow you to quickly and easily distinguish one timeline from another.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The -z option allows you to set the timezone for the timeline.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This step cannot, and should not be skipped.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;While I live in the central timezone, I work cases in multiple other timezones.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;By default, if you don't specify Log2Timeline will use the timezone of the localhost.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Now, if the case you are working is say in Pacific Standard Time, and your timeline gets generated in Eastern Standard Time, your timeline will be off by as many as four hours!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;That is a HUGE margin of error, and will no doubt mess with the accuracy of your findings.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The -r option, we talked about briefly, but it is used to recurse through a directory.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Log2timeline uses file carving to identify the header of all of the files in the directory.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Once it obtains that data, it compares the headers to the known headers for the various plugin types.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;If the header is recognize, it will automatically load the appropriate plugin, and parse the chronological data from the file and put it into the timeline (pretty sweet!).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The -f option identifies the file type.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This can either be the specific file type&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;(if you are only parsing a single file) or a set of plugins if you are parsing the files from a specific operating system.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;In my example, I used the "winxp" plugin, which automatically loads all of the plugins needed for a Windows XP system.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The -w is the write option.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This tells the tool where to write the output file...pretty basic.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;By default, the tool writes the output in CSV format.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;DO NOT append the .csv file extension to the output file.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;I am not sure why this hoarks up the output file, but it does.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;For some reason, the column headers are left off file and the l2tprocess will fail.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;I need to get with Kristinn on this.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;If done correctly, your column headers should look like this...&lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;div style="mso-element:para-border-div;border:solid windowtext 1.0pt; mso-border-alt:solid windowtext .5pt;padding:1.0pt 4.0pt 1.0pt 4.0pt"&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 9.0pt;line-height:115%"&gt;c:\tools\test&amp;gt;strings 1&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 9.0pt;line-height:115%"&gt;date,time,timezone,MACB,source,sourcetype,type,user,host,short,desc,version,filename,inode,notes,format,extra&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, if you want to, you can append like the contents of the Master File Table, or a timeline you created with Mactime to your initial output file.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Again, since Log2timeline outputs into CSV format by default, you would need to append the final output from mactime, and not a bodyfile generated from FLS.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;After you have your super file the way you want it, with all of the data you want it in, you will need to make sure the file is in chronological order, since Log2Timeline will simply add the data to the super file in sequential order (in the order it was read, or appended).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;To do this, use the following command...&lt;/p&gt;  &lt;p class="MsoNormal"&gt;c:\tools\log2timeline&amp;gt;perl l2t_process -b super &amp;gt; supertimeline&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The l2tprocess will chronologically arrange the data from the super file into the correct order, with the first entry at the top, and the last entry at the bottom.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Pretty nice!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Another great feature is the ability to use the MFT in the supertimeline!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Check it...&lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;div style="mso-element:para-border-div;border:solid windowtext 1.0pt; mso-border-alt:solid windowtext .5pt;padding:1.0pt 4.0pt 1.0pt 4.0pt"&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;date,time,timezone,MACB,source,sourcetype,type,user,host,short,desc,version,filename,inode,notes,format,extra&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$SI [MACB] time,-,-,/$MFT,/$MFT,2,/$MFT,0, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$FN [MACB] time,-,-,/$MFT,/$MFT,2,/$MFT,0, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$SI [MACB] time,-,-,/$MFTMirr,/$MFTMirr,2,/$MFTMirr,1, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$FN [MACB] time,-,-,/$MFTMirr,/$MFTMirr,2,/$MFTMirr,1, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$SI [MACB] time,-,-,/$LogFile,/$LogFile,2,/$LogFile,2, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$FN [MACB] time,-,-,/$LogFile,/$LogFile,2,/$LogFile,2, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$SI [MACB] time,-,-,/$Volume,/$Volume,2,/$Volume,3, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$FN [MACB] time,-,-,/$Volume,/$Volume,2,/$Volume,3, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$SI [MACB] time,-,-,/$AttrDef,/$AttrDef,2,/$AttrDef,4, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="border:none;mso-border-alt:solid windowtext .5pt; padding:0in;mso-padding-alt:1.0pt 4.0pt 1.0pt 4.0pt"&gt;&lt;span style="font-size: 8.0pt;line-height:115%"&gt;02/26/2009,20:51:34,CST6CDT,MACB,FILE,NTFS $MFT,$FN [MACB] time,-,-,/$AttrDef,/$AttrDef,2,/$AttrDef,4, ,Log2t::input::mft,-&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;p class="MsoNormal"&gt;You see the $SI and $FN in column eight?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;That's right baby!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Timestomping has NEVER been easier to detect!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;You will see...plan as day...when the chronological data has been manipulated since they $SI and FN attributes will be different!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Provided you search by keyword, they will appear literally right on top of each other! Very nice addition!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I almost wish it were harder than that to create super timelines, but it's really not.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Kristinn has done a fantastic job on the latest release of Log2Timeline.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;There numerous other options the tool can use, and for the sake of brevity (not to mention the fact that you can read) I have not covered all potential option combinations.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;My advice is to take some time and play with the tool.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Get to know how it works, what the output looks like, and what commands you think are the most relevant for the timelines you are creating.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Serious props to Kristinn for making this extremely useful and powerful tool free to the forensic community.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;He has done an outstanding job, and honestly, like Harlan's Reg Ripper, and &lt;a href="http://www.mandiant.com/products/free_software/memoryze/"&gt;Mandiant's Memoryze&lt;/a&gt;, this is a game changer.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Happy Hunting!&lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-6201398018319339792?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/6201398018319339792/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/log2timeline-and-super-timelilnes.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6201398018319339792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6201398018319339792'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/log2timeline-and-super-timelilnes.html' title='Log2Timeline and Super Timelilnes'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3542473228328800384</id><published>2011-07-07T16:36:00.003-05:00</published><updated>2011-07-07T16:39:02.623-05:00</updated><title type='text'>Sniper Forensic Part V: Finding Evil Part II</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-iGO6lHLP7CI/ThYnXIsA2uI/AAAAAAAAAPk/wrsdWJXZzrg/s1600/pic2.png"&gt;&lt;img style="cursor: pointer; width: 354px; height: 151px;" src="http://1.bp.blogspot.com/-iGO6lHLP7CI/ThYnXIsA2uI/AAAAAAAAAPk/wrsdWJXZzrg/s320/pic2.png" alt="" id="BLOGGER_PHOTO_ID_5626728062868576994" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Check it out on the &lt;a href="http://blog.spiderlabs.com/"&gt;SpiderLabs Anterior Blog&lt;/a&gt;!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3542473228328800384?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3542473228328800384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/sniper-forensic-part-v-finding-evil.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3542473228328800384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3542473228328800384'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/sniper-forensic-part-v-finding-evil.html' title='Sniper Forensic Part V: Finding Evil Part II'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-iGO6lHLP7CI/ThYnXIsA2uI/AAAAAAAAAPk/wrsdWJXZzrg/s72-c/pic2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-6411693972363966242</id><published>2011-07-06T19:38:00.002-05:00</published><updated>2011-07-06T19:47:16.343-05:00</updated><title type='text'>MBR Analysis</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin-top:0in;  mso-para-margin-right:0in;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;A few weeks ago, &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan &lt;/a&gt;touched on the concept of analyzing the&lt;a href="http://windowsir.blogspot.com/2011/03/mbr-infector-detector.html"&gt; Master Boot Record&lt;/a&gt; (MBR or $BOOT) for signs of malware infestation.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;That got me to thinking, "what would that really look like"?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;So, I tested it and thought I would share my results.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;To recap Harlan's post, basically the MBR contains the partition tables for a Windows system.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;On a typical NTFS host , the offset for the primary partition table that contains the operating system is 0x63.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;This may vary based on the type of system or the configuration, but generally speaking, this is pretty consistent.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;An easy way to check an image for the offset values is the &lt;a href="http://www.sleuthkit.org/"&gt;The Sleuth Kit's tool&lt;/a&gt;, "mmls".&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;By running mmls against an image, you will see the offset values for the partition tables.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, how malware comes into play here, is very interesting, and very clever.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Let's take a "typical" Winodws NTFS system and assume that the OS partition is located where we would expect to see it, at offset 0x63.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;But what if there was a partition table set at offset 0x62?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Would you even recognize it, or if you did, would you even care?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;It's not offset 0x63 right, and when you mount offset 0x63 you see the NTFS file system...plain as day...so no harm no foul, right?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Wrong, and here's why.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The malware creates a partition table at offset 0x62 and copies the MBR, with a jump statement.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;The OS boots and see the MBR in offset 0x62 FIRST.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;It reads the data and if malware is present executes it.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;It then follows the jump command to offset 0x63, the NFTS file system is recognized, and normal the normal boot process resumes.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;When the malware runs on the infected system, the traces are NOT in the primary file system, because they are stored in another partition table!&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Pretty slick!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;After some digging around, I found a pretty nice perl script called, &lt;a href="http://www.garykessler.net/software/index.html"&gt;MBRparser by Gary Kessler&lt;/a&gt;.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;It's easy to use and shows you exactly what you would need to see when looking for MBR infections.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;In the screenshot below, I used Gary's tool to parse the MBR from my local Windows 7 Dell laptop.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;span style="display: block;" id="formatbar_Buttons"&gt;&lt;span class=" down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAgYAAAH2CAIAAACEJ9NzAAAgAElEQVR4nO2d6cMlRZXm8/+atmd6Ztp2erVdcN+dnmlFW3vfpltlUXBXVFxaZZN9EZSxVSAVlH0p9l1AqSqKAqFA7fnkfKi3rpkRcZ54TkTkzbz3Pr9P+UaefM5zTkbmue+touh+LYQQQvz617/+9a+7uQ0IIYRYCnsj4aa7H7/+rsf2P/38cW/6s04IIcSOMRoJN9z1+PV3PfbkoederZEghBC7x2gk3HjX49ff+diTh5579Rs1EoQQYucYf3F0zxM33r3QL476iEkTTRfvkuXrBWGtmrZSSEpNd0eEEGtjNBJuue+nN93zxIHDz7/2Lf9rbmMJhm+iyhccuNb7vptuJHTjtzBzyaQ+wUiYdEgLIdbGaCTc/uCTtz3w5MFnjrzubf97bmMJWo2Ehfwe0Dz1pCOhT9G1+xVECLEERiPhzkf273t4/6FnX3jDO/68s7+7mHrdIr421gmC++hTLUiaXWTiSR1cabJkV17rKkYna8aSYkRin/3c+0oIsWI0Eu5+9OBdjx54+ucvvumd757bWILscx6sB6+wPjVOsiLeeCsRb6B56oJgnM7bIiHEpjAaCfc+9tQ9jz11+LkX3/w/j++W92nOirFEhitxXj6LK95KxBvIpsb1klV4m9+1GwlW6qnXhRBZxiPh8afufeypw8+/+JY/O35uYwmSj3f8LsDxYN0664q3/ACfAGyGTJ0N5p1Yr1q9eYXYDsLfEo6OhKO/JSyN5iMhK1gQz4wB/gWK3+xk6oJgbCYrLoTYUMI/S7jn0YOHn1vinyX0A6xTXfTasl5VyVN9RFk8UIiPC0oG9Satunxm/SRr8UoJIZbJaCTc9ciBux7Z//TPX3zjO941tzEhhBDrZjQS7njowB0P7T/07AtvePufz21MCCHEuhmNhNse2H/bA/ufevaF171NI0EIIXaO0Ui49f4nb73/yYPPvPDat45GgvUdMf6ae5nM+903/rOBucx4/zihlf/gkqn7gPXx+vK39NwuxJYQ/BtHT95y35MHn3nhNW/5zT9oYT0S8fqmbM2hz0rPrmtXuUA/i514Kbh3WduuEuZqgnck4FP1ZlrpbMSjJ5ZPOBJuvu/Jg8+8cNyb90ZCP2B4Wby+QZuylW3vtTi+SQOTNyubjrmqeGa4ImccCW0vWb/sBj2AYsmkRsLhvZGw2mTBbkuub9COtGz3A+L4ZBOsS7J5mbNZP/FVBWaCLMy95kvwhuEmJI1Znq0sBX121QXMgPU+2oRWXVYV1qIQLkYj4eb79t987/6jI8Haf/iYf35mBDyK/HH8Y0HSOABcm/XjYnVtH719hqfI++u672Sl8Yq3D8BqNtjb5wKfWSdBV7OW+FsghEXwW8L+W+7bf/SLoz5Fl/p009vvlGWStNrwkWbyMmfjJmM/LsDt66KXEZmX9APCrCbwx53Rt2z2gnrjy+O8WZ9Aii+Z9ykExhwJwyDmKfI+QjOStMrUQj7STN7s2QI/3fhtwpjBpTF+QAnZ7My6tw9Zn2Rqpl6vLEhRKUWaFCJL8JdQ999yv0YCW1fyWjJv9mw274pYpMBMk5647nsy2KoIeOb7hk16dcDlZH+SfcbpkiWTDoVgCEbCgVvvP3DwmReHIwHvwnjHL3x39hHJU9YllporL2lp+CO4MJuasdTnXlugBFAaYwDrAG/Jlc7uW7bP1rqVyMrr9Z9tQjIRboIQZQT/9fKB2x448NSz4W8JYjngV4zYenTTxaSMRsLtDxy4/YEDTz37okbCkmE+SIotQzddrIfxSHjw4O0PaiQIIcSOMv6XUB88cMdDBw5FI8H6bIK/kOU/zjD6XbsPSvN+4Jo0b1wa+KKpbR8sqeV/ti3YtHFw2f7P6njNx7d7+f0Xi2I0EvY9dHDfQweDkUA+6smdzTgo0K/Z4lin1ZMDdKZ7PpOlMT1sZcnSWfIrqWDfMmU20SkQsa5d8i0Qi2I0Eu58+OCdDx98+ucv1v8bR+QWLNOv2d/1nl0p1gbzapiin8BDdn06kpsKRPJXgYD4FtTreP2A+77+PSk2kWAkPHXnI0+tRkJye4H1IcwWdOm7nhMmaXJ9SPJUvJj0VqATG7NSFNSFj0myPpnSQFGMPrMeZGGKitWS3uL1pFRH/LrJ6zBVAJ+gS0LEjEbCXY88ddexkWDtS2a/xjEBpGbysazf35ZCVjbpJxbEOpYIeUzKBuvJvhV30uuZ6VuNZlkVsRlLNl5Mti55qk/B6CQ9gKvAhZUtEjvFaCTc/eihux899PRzvyj4N45WkJtvan3SAKNsmYltMw6TIvwxXw6pw/cz2YcC/8m+9RGu0ooJMgKrZF2rYyYvo0PWaDlP1iWExWgk3PPooXsePXT4uV8c9+aq/6ua14Trma/c3OSjWByfdUg+/973giU7hX7NsZUu68HV7f4YQDAZmbRqmWfqwnmzOq4q4hWvjhCjkXDvY4fufezpw8//4jVvWehIqN/ZzKNoxZCvgKSOdVVWP3i2vaUxtTD6Xh1v3xrqd4PW4aKwN1cPrbqYvJYOL2h1oMyb2GVGI+H+x5++//Gnn3n+F68djIR+wPDK5HrBzuP1+ee8LKOVYrgYHFh+shXFgp3dPb5qq2lJHVwCLiqWJddBUuuUd91LP2a4GMSAvAVmsjpeKaYuITCjkfDAE4cfeOLws8//8rVv/fP8pWJKwOtJCCEmYjQSHnzi8INPHH72yC9f97Z3zW1MNPsULIQQJKOR8PDPnnn4Z8/8/Mgv3/D2d89tTAghxLoZjYRHn3z20Seffe6FX2kkBLg+sONg76f+5fyiAOpKrk/6W07zL9am7rOl7F1v4mQ5m2oK4r2x9SU3ZDQSfrL/5z/Z//PnXvjVG99x/NzGFkTZ26fVSCi7pDmgCWBIgIDp/DTRbIt3M6zHSX2W2bdlTPDqX8Kzs1mMRsLjB557/MBzz7/4H2/SSDgG8/pjLmzoYXaYR04jYagZK3vX2/qJjyulFkLcvQWaXDijkfDEweeeOPjc8y/+x5veqZGwB9hSeOeRT3s/xoq3LokXsWegzz85zCNX4McF8MD001qfqG+4S/x6PUDZ1TfQBLyIPVh5mUuS+tN1clsZj4Snnn/iqec1EoZkHyErjHzaLRHvcRc9ElM8CeBRtzowtZMgBfM68Ma3clu/3tBM8mbxx5ZJJn6KXYE9T5FxWxmNhJ8+9fxPn3r+iEbCALCT8NuEfNq9j2IfEUgNnzqmtIIHxuV5oqexpj+M/2xqV9+sMO96Q3BzmJ4kT4Frh8pMga4+x8HYm7AYjYSfHXr+Z4eeP/ILjYTfkNzW+NhaKRaseUSnoKHnST3UeJ7Obc16WyfevjGngOYs+5NZF0OCkXDkZ4eOaCQEZHd59tkA695X1VyPXEOfi/IztU+s7F1v66TVfvPGT8367+82EY6EJw8deUEjIaIfYJ1NBsc7MljPPkJWGEjapOQYK4V3vaGZ+Jjxk7w8Xm/oM7bkXZ/IUs16N24djp+0Ipx9bam3g9FIePLpI08+rZHgQ1tNCLE1aCQUoo8eQojtIxwJ+58+8sIv/p9GghBC7CCjkbD/6SP7Dx954ZfhSCC/67TWFwXwP0Wi6eI3F1f/4/tV/x0xuZ/bov0wNfgmTt3POPWG3sHxSDh8ZP/hIy+OR0LyOYyFNqgdTDm8FJOlOL4Vy7kX3n1ixRffxDhY+2GxFPgkX1DN8yZTLPk1aBH+lnDg8AvDkdAPGK7EQnHMYnvR6hXgvXaunqwhL3/HvfskCFj9WHYTk5HaD8ukzGd9dcUK2d21EYxGwoHDx0bCO47vnI9fELzkRljlJJ0PV6xg6xJrkYkndchigVRwHBwwPpPB2E+sBrwlL88uktd22g+wD8EB45PJ662LSRFXgX168zI6SZ8u/7MzGgkHn3nh4DN7I2FYRnxs9as79jvXkrvgvYXD0qy2ZEW88bj/jGA2rytFQV5sBsiS98VrBssGNxdcGPgk2xKfdcW7bhaGKTN77M1b4J8sByQC6968Nf0vK2QuxiPh8JGDh0cjISC4OG5HcscsDXzn4mKtunCN8VlXfM0WzDopSNFHZPMCM8l+duNWM1W4nLiUO+2HpvuhwD9ZDkiE1/nIzq6X6X9ZIXMRf3F05MVfhv+/BH4PZbuzBMAtTwaU3Wl+C2aTercg6dOVgjHPm8GtxncHLzLZvYvg1vB+4rOueNfNwjD+s8fe5hf4L7i/4Cp+PRnpbVr2wsWSHAn/D4yESW/nesjeObIW/HiArcbEF/TcAuTtB+DUOG8skjVD5sIZrbO8AetyoG+lA/5xXibe8lPQh2yfvfeIyVvgH/eHSQTWvXnL+u9yvhDCkXAwGgnxLknum2B9sY0ADofrwQHeZ7gPfbTbyHigEB+TVYOzlp/kOpM0awbUgn+MRVyWsk0OTnXaD9A8kxT4BDq8fuwz2bdsP0FeK364CMrcFJIjQf+jzR3C2uLzuBFzo/2w48R/vKyRsBNkP/LoLbBTaD+IowR/CfXIwWc0EoQQYkcZjYSnnjnyVGokWF/AWV/DeU2Q+k0+sMT6pBqod7oPULFJ6zgZ3CQ1ub4cmtxc7yYB+8plppWOEGXkR0JyX1pyBfuV1Oc9kBmHP5Zd2MQMmW51bPWhYX+SBpj1JRDf3KzVJrfVyuu9L610hCgjNRJ+9Zu/cdQPGK7EQnEkA68fX8VnaXX5Oh9F76thilcGvtf1+l4nTNK4D/iqVjVa98ur2UpHiDISI+EXv/qPgn/jiDlrBXtfZ5WPRJBuuJh8iVinsouWDlOCFWD1qqAnNfXGfYs9MPrMepCFKSpWS3qL1+OAMkAVs+gIQRKOhEPP7o2E+LEfHuNHN16Jr6rRr3wekim8x4Fa8keXDpa1zMepC5pT2YfVj0MDNZplVcRmLNl4ETQTryetxovT6QjRltFIOPTs0ZFQ8m8cWSsWZfreLCD16ji5mD22zBTrYNmsfvZCSypofoH/oUJwEOuTpRUTZARWs3WVGQPBs+gI4SI5Ekr+jSMcifE+ipWPRPJy69WQfWWQrxjm1cPITqFfc2yly3qwAoBatqg4MmnVMu+yBLKXnZ1CRwgv45HwzJFDz77wi1+V/BtH1gqD9zVU+UjEL4WavPwrph/j8rk6btWfmp6DkqfQ7watw0Vhb8U9JFMD53PpCOFlNBKefvaFp6OR0A+wVoJF15Yl9cG6i9hnD18T3fh9ZPlkdAJBr9v4WsunV9yqi1kHSa1T3nUv/ZjhYhDT3I+rD2vQEcJL8MXRC8d+S3j33Ma2DfB6EkKIhRD8G0fPHzz8/Iu//A+NhCnQpzwhxMIZjYSfHfz5zw7+/MiLv9JIEEKIHWQ0Eq7f9+j1+x7df+g5jYQA1wd8HOz9LWE5v1gk6+pTBFdNZyY+rhScrs/4zwaSZ6dzspxN1Qq8Cbsp+7lljEbC5dfcefk1dz7yxNNv1EgYUPb2aTUSyi5pjtWE5ISwflyDn1aabYmVt6Nvs2/LFbiWJTxBm8JoJFx69R2XXn3HQ08c0khYUfysNtyFS9vQzEjoB6zZQxPNVlh9iP1vXN8WtS0tM1P3c/sYjYTLrt536dX7NBKGgM2Eny5rJfkOBW8NfEm8iD0Dff6ZIXvCOykANJ/pp7U+Ud+spJar9fQteYrsG2gCXsQerLzZS3DAdP3cPjQSMmQfISvMuhA8/DXHXeotk63OC1bmm9DQSWAJ3xQcM7Xb5EqfektO56QzbmLNfmN0uon3Z3IzYKsiSTgSLrt638MaCQPAZsJvE+tC8Fzxx8ndP1xhngEgxVxYvNiEmv4wfc6mdvUtDgsuT1rNytaAm8P0JHkKXAvqBfquPlvG1tDPrSH4swT9lhACnlX85Fi7sECw5hGdguJiJ/LA9Keytw3dDles1MvsG3NqlqKyxtaWegvQSMiT3eXZZwOse19Vcz1y+PVR8EKZyE/Dfk7kNrmytls5xX7zxk8Bvo+Tpt4yNBIo+gHW2WRwvFOD9ewjZIWBpE1KjgEprIdwOldM3yxLycvj9YY+s7csNjPd3cz2h1zvxq3D8ZNWROadNPvWYIyEt2sksGifCSG2hmAk3HnpVRoJFPrcIYTYPvRbghBCiD2okTD8LMx8N+f97Mzox+vFH8/n/YA/UV6rKNy0hmasls7YapKCTRUHl21OHEzqWHm9fpLxBUV1RX+cEC8W5HXp1DSH6TPQLyttPeRHQmA9W4a3VFI/2W4yhaWT3CUFmsksjIG2MK2Ljxv6Ie/doijYV+Ahr0mdPOs1s/rRWxeItzR5NUuwOL4+r1ffimH6T167EDIjoR8wXLHk4ngMr2+13gvI1eoOzXWnmda5tuwUBtYDvwnjPuCrWtXY6jmy/NfUFcQXbJU4DAvy8TijN69XH6/j/vOa8zIeCVftO/rHy294+7s7/+sjGQ/w6iev9YJvT3Jj4cWk/wKd2JiVoqy04Di5yOgDn0xpoChGn1kPsjBFxWpJb/F6HEAC4rO5XP5BlxidrmKr8GetFb4P3rzeoqyYbP+ZaxeFORJw+4JNk4xJxmdbZukPqWylJZ6VtUoOBLGOq2+kMRyWbGmBfrFnpm81ml7/yVqAjXgxaCa/HtduNQfnjb3FP4J1XgccM10lT4FFMmNB3rgJWeU4ONs3oO8qbW1kRgKuCtSfrdarjxcLiHXwnYtNDlfiVpB5rQt5QaAMpLLNt/SD+AL/yb4BP5Y90jZfFLaarctlDPfKagXvH9fF65Alg+rK1uNCskkL8uJTTJZsn9umXgPBSLjj0qvueOiJQ294+7uGQfU3GFOwUYoB+zsp7o3PmgQizDHAJeXV9/qs6XPWQHa9PwYQTEYmrVrmXZZATL1OLIXr4nVIq4xzcG18qiBpQV6XOPAGrLqqXgKjkXDJVXdckhsJzK3ylsrr1zcR6K9+JP1ky2c2aFZ/RXFpyWPc50pxpq7p9LtB63BR2Fu2V7wfnNeK9+pYnhkpbx9crizByvjYTH1eS9/SwX3GHeP7uU7yI6EfYK0MwWeZeKDQpIlZ/eS+6cdPBdkEK28sCKpjqo7FY59WLka/M/rgXY+dJEuoWfeS7Y9VV6UfHM+rJf2DdZeOV8Qy30fg9aRIfMoy79IH/nFRyRQu/eTZeaF+SxDrJ97Wc7oRYjFM/Tjs+OOmkbBclvxRQgixlWgkCCGE2KPwj5fxd2feT7Xg67lksEs8mWsNH8C94nP9NrD+vN7+g3jePLlvs2qxTp96NBhLnec7cd5VfMqrAOoq1gcmmXU+S2fsiuRKmf7yqalrPBKu3gf+eHn4o2UCx2D3SSmQpZhiq0kpJktx/BpYc17+XmfjXfue2bc1fgo2lbVDCm4HWR2vkKwr+yOp7z0uSBQEZ1fK2l7MenKVFZUZCf0AnIaJsa7i9ZvcuTKrWGeK+A2CvzVx8/FVVrz3JvL7lvcz/HEKPzzxVd7nha9ruF6mX3bMJIpdWT7L9JuwtlxlicKRcPHV+1YjAWwLK30czzhm9JmzJNmd10fPhuUTX2ItMvGkDl9vmT7js/M/tLFaMhcZz6S2Yix9EtCNSj8u2qp1RP+9+tb9yh7z9yW5NyyfxfqWFLneR5DxcRVZ50xRMdFvCcdGwlAuPq5pQVweqV9cZFIEdDNZQje+PVkzVn/IeNwfRpCMj/O6PHgZNtOStRazMV10c4P44Qqjb10F+pDU9/qxMlpYwS6R5FVWfwr0XSXjvKRn4LOVvvfYysXED1uE68XrmMxICGDKsIKT18b6uNSyIoFtYClez9rDWVzxViLeQFle7CfZHxeBAmg1jq/xE/fQ8kOK4EXSA5mCN+NSsC5h7leNflle63JrS8SXF9x3cMfjpEAQ6CQDLJ9kT3BRMeZIYKQtf14rvE5ZkSBd1gNIis14zYOkTfrMV5HtjyXCmAkik1WDldVxcR+S13qlClqU9UBm4f14LSXjmfvF6/NWy+6LFeytixcv6Hx287ia7E2UxT0SvMcMvE5ZkSBd1gNIulrPChbEt+pzNh4X67ovzK1hymTuRas+4PLJKibyQ5oBkXg9PoXryv5YoF+T12pOVo0vJBlQczz80RvP+AE1khgj4W0l/8aRtY4h9fsIb6lZk8P14AA3HfTBqoKJBwrxcUHJybyMeSYp6ceqxepDMr5tH/gSgEgrP4yZ5CXYj6UPFuv1cVIyL74kbgXwCfSTZM2Q65b/rEnSDz6VJfhP1fZdclU4EoQQ20TZm2J39HccjQQhhBB7aCQIIYTYYzQSLr36To0EIYTYWdIj4fUaCUIIsXuk/sbR4xoJQgixiwR/lrD6LeHP5zYmhBBi3YxGwsVX3Xnx9+946HGNBCGE2EXGI+H7+y76/r4HHz/0urdqJAghxM4xGgkXfv+OC79/x4OPH3qtRoIQQuweo5Fwwfduv+C7tz/w2FOvfcv/ntuYEEKIdTMaCed/97bz/v22+x976jVv1kgQQoidYzQSzv3Ored+59b7f3LwNW/+X3MbE0IIsW7GI+H/3nrO/73lvp8cPO5NGglCCLFzjEbCN6685ewrNRKEEGJHGY2Ec668+exv33zfowdfvbyR0EdMmmi6eJcsXy8Ia9W0lQL/T7oLITaL0Ug4+8pbjo2EP5vbWILhS6fyBQSutf6XFK74eoKXL5MCO5loJDS8KUKI2RmNhLOuvOWsK2+59ydbPhK81874pnOlnnQk9Ck6jQQhtovxSPj2zWd9++Z7j/2WkHwFrGHdwnr7JBXwawtfYi0y8aQOrjRZsiuvdRWjkzVjXUJKWS2del0IkWX8xdF4JCyN7HMerAevsD41TrIi3ngrEW+geeqCYJwuGa+XrxBbABoJfcTRa6Zet7BiLJHhSpyXz+KKtxLxBrKpcb1kFd7md3Ak8BWB1FOvCyGyhCPh7MX/lgAWgwDrdYBfE973HUjKHGOwGTJ1Nph3knzV6rUrxNaw0yMhK1gQz4wB/h2K3+xk6oJgbKa+LiHEMglGwi1nf+vmex89+Oo3Lm4k9AOsU1302rJeUslTfURZPFCIjwtKBvUmrbp8Zv0ka/FKCSGWyfhvHH3rprO+ddO9jx5Y4EgQQggxNcFIuPnMK26695EDr9JIEEKI3WM0Es781s1nXHHTPY8ceNUbNBKEEGLnGI2EM6646etX3HTPIwde+Yb/OQzCX2fHi0v+Qnne774X1TdXH+K+Jf84ocBAMoVLx5XO0sfry9/Sc7sQW8J4JFx+49cvv/Huhw+8YjAS4kciuQXjd8TEzstpaNV17SpXtoFrgLmnTHxxM+dqgnck4FP1ZlrpLPmJExvEaCR87Zs3fu2bN9z98P5XvH5vJPQDhiux0A6OBO+1OL5J04KbRZphrrJGAojh1QoUiilIMZGrtrILf+jEpjAaCV/95o3/dtkNdz+0/xWvf2dX8Ulw4bvTKqcfEMcn34nWJdm8zNmsn/iqAjNBlqQgWUt9H3ATLGNWE0jn2T676gJmwHofbUKrLqsKa1EIF6OR8G+X3fiVy26466H9f/r6d1r7L/ucLH9fgkeRP45/LEgaB4Brs35cDN87lixvFdTFXJ5V5o+zichgb58LfGadBF3NWuJvgRAWo5HwlUtv+MqlN9z10P4/fd07+xRdbl9uxKZMltDwkWbyMmfj5mM/LsBt7aKXEVkF6celUHxfrBLIurx97iNIn0CKL5n3KQRmNBK+fOkNX770+qMjYRhUucWXRrIEpsbKenE8EOffC8O3CWMGl+Z96fANsSKtiuqPvamzOgWyIEWlFGlSiCzjkXDJ9V+65Po7i0aC9xGakaTVgrqS15J5s2ezeVfEIgVmsj2xSii+78lgl36yCVk/lkmvDricOe7sPoN0yZJJh0IwjEbCl46NhJcPRkK8C8GjaG3Z5QB84uctWRRfLCNi9blzvt1IQFIrRdZ/gQGsA7xl/SQvB3221q1EVl6v/2wTkolwE4QoI/1bwsvHvyWI5YBfMWLr0U0XkxKOhC/vjYR3zG1MmDAfJMWWoZsu1kP0xdHFP77zoSdf/lqNBCGE2DmokcB8B9q1+045qd9HuFI08dmESfPGpYEvmtr2wZJa/mdb176K92Gf+jMJb95iP/GFWX0hAMYfLw9GQryrwJMPAiwK9GvAPls9PEBnukc0WZpVb/H9Ig0w60uA2XtMvLef5L3gWxc8R1PcX7ELZEZCP2C4gkUL9nFWf4rXVvHjx6dYG95X1RSvjKnvndcJkzTuA76K2TPeZwQf81Usp/9ic0EjIftasfA+jYz+el5byUcLLyb9F+jExqwUBXXhY5KsT6Y0UBSjz6wHWZiiYrWkN3B5dpHxAPzwJZAmhUhijoTkNu3gK6xLPYp9iqQm1sd5XWDz2QvjHwNBrGOJkMekbLCOW4qVca4C/8m+1WiWVRGbsWRxb+OVZJOHABHLj6WD+5DMKARgNBK+ePGPv3jsj5fLtiBej2Om089iPT9Zq/E6aTt51rqQF2TMgxi+mck+FPhP9q2PcJVWTJARWOWze1vK+8H+LbdNGiV2BHMkDIOGW8o6tuIZptZnclmy3visPSDi7QMjO4V+zbGVLuvB1e3+GEAwGZm06nXrSu3yUyDoFRE7Tnok/Il/JBTv4zXoM7mGP5J5s08geOZ5PyvKSmvVT6+Ot28N9btB63BR2FuyhzgjKBDk9faqUlMIQH4k9AOsFbyOmVqfyRifshaDA8tM1n8s2NmPLl+y1cykjref2Da5DpJap7zrXvoxw8UgxvqxwE8fgf24BAv8CHEU6rcEsX7A60kIISZi/DeONBKWhD7lCSHWTPhbwukaCUIIsasEI+H6L1704zsf1EgIKf6a2DpbkJq/ZDqyX3w3t9r8C7Sp+2kp9/YfhEzkZ1t/y7Tq2tZ610zqiyONhDFlb6VWI6HskilI2khOiImSthKfrp/8TZ/6nrbt2xK231GsuqbYJ7tJOBK+pJEwpviV13BfLmGLky+7nR0J/QB+va0HS78y1xK2X8lnEx8AACAASURBVBKNhClIjQT9WcIAsL3wLiTfDv0YK966JF7EnoE+vsSlmQ3jAU1m+matN+9P0iFYb94o0knn7BtoAl7EHqy8rrbw3RY8GgkZso+WFUbuV0vEezz80ftoMTAP7RSPovW+wM3HMVP45J0MV6a4U3EKy4l3XzE63cT7cJiCbLVwof8uIQPYYfgtQ25Z7yPaRwRSw6eRKS0p5S2WzFhATR+YfmZTk/3ByvjyiVqXFLeKAh6yt9tKgWWzlrLEwZN2ckcYj4SLfrz3N45e8/a5jS2F5HbHx9ZKsWDNo9uKsmKny8u0t6CHDd0y69P5qekbcwpoTroPgbG15d1uNBLyZHd/9pkB695X2FyPIn6tTJe6VX+w/ync4vWp/Uyxr7zxUzDv/d0FgpHwoy9e9CONhJh+gHU2GRzv1GA9+2hZYSBpk5JjQIrp8jL96VNvW9C3KQwnby5YB/6nsFSz3o1bh+OnLorJO2n2rUcjoRbtPyHE1jAaCadf9KPTNRI49HlECLF9aCQIIYTYIz0S/ng8EsDXiIHc8j84r+07R6/4wvvWEFf/4/tl7TqvAUuf13Gh/TA1+CZO3c849YbewWAk/Pj0i34cjAS+1E1pQfxGqJFishTHt2I598X72GTjva9yS4H0kxXn8xbEt2I5+wFT4LPJ26msP3hrbQqZkdAPGK7EQhtUfKtXgPfauVq0hrz8ezluPr4qCEj+yBdovZe1HxZImc/66ooVsrtrI0BfHK2KYZ6ZDarcKif5fhmuWMHWJdYiE0/qkMUCqeA4OGB8JoOxn1gNeEtenvRMpmY0Y4fBIghm+uaNJ3XIJgCp4Dg4YHwyeb11MSniKrBPb15GJ+nT5X92zJEwLCM+zrZyzWW48N7C1Y/BJbhSa+uQ8bj/jGA2rytFQV5sBsjWGGZSJ9dXZC8MfJI24rOueNfNwtS0N3mPmLwF/slyQCKw7s1b0/+yQuYiMxICuqZbcy7wnRsWG6x3njLjs674hn1mdmr2uI/I5gVmkv3sxq3GVcR+spZIZStF0qTVNyaLK95KxBvI5nWlqGk+6Z8sByTC63xkZ9fL9L+skLkYj4QLf3T6hZm/cVRwa5cGuOXJgLI7zW/BbNLKPjP+s8eMed4MbjW+O7gQJrt3EdyaGpOueNfNwjD+s8d8z4v9e1Pgq/j1ZKS3adkLF4tGQmKR3Jr48QBbjYlv2GeQtx+AU+O8sUjWDJnLysifzQZnbwfwnLwkK1gQb/nB9yVJts/ee8TkLfCP+8MkAuvevGX9dzlfCMZIOC7xl1CDyq36F94FYHK4HhzgfQb6kNxtZDxQiI/JqsFZy09ynUmaNQNqwT9aai4D2cuH68GBlS55qo8oiwcK8THTASvYMgnWyYxZfZdPKxj0LdtPkNeKHy6CMjeF/EgQ2421xedxI+ZG+2HHGY2EL1x43RcuvG7fg0/+8XFvm9uYmJbsRx69BXYK7QdxlPRI+CONBCGE2D2okYC/PgtWCj5WMPpdow8sxT6t4Ek/QMUmreNkcJPU5PpycN1csB8K+pltGiOVDLZMCtGW8Ui44LovXHDdvgdGI8HanYEQE5OkQL/ykYjTlV3YxAyZbnVs9aFhf5IGmPUl4N2HVnxBP5l2ufyAWpZ8C8RGkxkJ/YDhSizkfRRr9Cufh+LL1/kcel9VU7wvyHu9BoJNko3kr/L2mdTJ6vP+mVNCtGI0Ej5/wY8+PxgJxY8HGebSb/g8BFLDxeRLxDqVXbR0mBK8fSjoSU29cd9iD4w+sx5kYYqK1ZLewOXZRTKGtM1oxm0vkxUCEIyE6z5/wbX7HvjZHx33Nmv/9WOSoiA++YiS+kxqhqSO9zhZbI0OlrXMx6kLOlPZh9WPQwM1mmVVxGYsWdxbvBj3P6jdak5S1roqeSEIFqIV8Ui4bjgSrK1/9GLmEbKYWj+benWcXMweW36KdbBsVj97oSU1bH6Z/6FCcBDrk6UVE2QEVpns3mbiY56smSa9EiImORLQ3zjC+7L+Acju+/qHwfW8ef0U65CyU+jXHFvpsh6sAKCWLSqOTFol3ZIZ42Bvr8i83lssRAEbNhKaPAnxU0p6YF4c2dfBCpfP1XGxT0a8TD/blkr9btA6XBT2luwhzggKBHkZD1PrCFGGMRJenfhLqMF2TG7Kgp3K61tJi9MNBbOPohXG6wSCXrfxtZZPr7hVF7MOklqnvOte+jHDxSDG+jEWYSwVtCJrvoebTYjmjEbC5y647nMXXHfHeCSIJoDXkxBCLASNhPWhj3hCiIUTjIRrP3fBtXc88LM/1EgQQojdQyOBotV3yp3/W6Pl/GJh1eVdb2gmPq4UnK7PljLIOGnrFrKppqDVo7ebjEfC+dd+7nyNhJCyt0/DfbmErWw1wXs8tZ9Wmm0p2AwTvbXb9m32bRlj9W27p2BDNBIyBNuofiTUe5gFjYQazVjZWmfO1vuJjyulFkJZt8WQ0Ug47fxrT9NIGAO2EX66yH3Zj7HirUviRewZ6PNPi1U4c9wKoM/001qfqG9WWHLdex9dAE1X30AT8CL2YOVlLrH0J+3n9qGRkCH7CFlh1oXWfq087qKtP9HutyqNk7qe5zIbsT6+KThmnU2z1tfgJ3lHmJ4k729SHMdPsSUK/Isk1kh469zGlgLYRni3kW8B71buIwKp4VPHlJaUwpe4Tk30HNb0h+lzNnWTvsXrsfgU3YtTW0mBgeQpcO1QmanL1Qerb2vr59YQjIQfnnb+DzUShiS3NT62VooFcaJsxlZgfbLeKcww/ansbUO3zPp0fmr6xpwCmlPvz2yitRnYaMZ/vHzeD08774d33K+RMCK7y7PPBlj3vqrmeuTw62P9D2GrvuG6pnDLrE/nZ4r95o2fmvXvxm0iGAnXfk4jIUU/wDqbDI6fkGA9+whZYSBpk5KTNeLU1iXT+YmPO7sV2X7GUq18xpZAP3EVbS3VrHfGLU7GT1eOZYmvQgwZf3F03rWnnffD2zUSPGiTCSG2hngkXKvfEhj0oUMIsX1oJAghhNiDGgnDz8J9iuQp3kSBfnHBDXVqsk8kG4tbzWxuxmrpjK0mabJvh4sFqYElUgFcQtaVVMiKk1LApyVekxTkxfFMFpB0JQXqLShtnQQjIfE3jpItDs6C9SwF+jWtxDqt7hDQmW4fWMpWyc33JWNgabTat97LQbBrq2f9k7cYJHX5wTbiH/Hm5JMy+ky8KwufN6lPJl0zmZHQDxiurK4Ht5ZvMaMfX+WqM3lt2bZwpVgnzO4H92s9BtaDdweWXZW8lqyU7FVWEMfzrsB+KNgqcZilaYl7k1r3kekz0yKrk0xdlg2ymWtmNBI+e94PP3v0bxy96q0dMWmTMVbvmGtBTHaRBG+RpHm82Bnby6sTG7NSlJUWHCcXGX3gkykNFMXoM+tBFqaoWC3pLXlJUo3PS66TkD5d3pKaLgUywErEJCXvYzaezOINyNa7HNIj4Q9e9Vbmllj7rzM6bt0qvo/8zQNYIt77HdfI6Fgi5DFvL1gHJr0t9Xpm+laj6fWfrAXY4PNaKwHxOlDAOlZ2fAx0siXE3iy3rrOVeYeN7VJ7LBCx4pvXVbA+L+ORcG44EvitE4Rlq/Xqk6d4+Ix4V8X1uvaNdSEvCJSBFG4+0A/iC/wn+wb8WPZI23xR2Gocz1vF5kGvvIWQPkmRYnsgLJuCPxWHWfcxlmLiXWasU/WlrRlzJAyDYuvWinfr8Pr8WT5XoENuo6wNl3lLv6CZLimvvtdnTZ+zBrLr/TGAYDIyadXSiU+RSbu6XjFOClwxHW4oRdprch/jRSaeN+NddyVdM9FIOPfoSHjLMIjZ+mVbuUy/ppVAZ/WjFUPWmNSxrsrqryguLXns7adLnKlrOv1u0DpcFPaW7BW4FkTiaxkPripcZ9fpB3eM72d8f60fLX3m8jg1XxdeZ87OxWgkfOYbP/jMN35w+/0/HY6EfkCwGGj1Y0gHZfpsfXTG4JS1GBzgrWDpJAW70o1licc+rVyMfmf0wbseO0mWULPuJduf+Mc4ex/hysufAlLeLFZY3IcyP1bTmLzdeP9Y+kCKNINPMT6TdTHr1tl5yY8EMQvD7bLMrSPELEz9OOz446aRsFyW/FFCCLGVaCQIIYTYgxoJ8ZcY4Gu1zv+bF6PP5OVzreEDeE0T1sn68xb334rndeKkZfvBCnbpWME1fnr7ObKuKjNvxcd5rS7x4qA0cC1TwqbgvTU1OP54efhjcDbpnnRA6mfz8oB0BVJMluL4NbDmvMX30dpX/H4DlzMGspe49pUVXNafOIw0wHho65+8X5ZO1iep35b1pFtPXeORcM4PPnPOD26/7zcjoR+QtJX8kbfO62e3Gk92VxXoTBG/QfA3PW4+f1UczO83K6bVTfTuT2sT1vSH8RkoF/eE8W/9WHC/Vj+CXC79hqwt3XoSjUbCp8/pP31Of/t9P/2DV76lM24DcMnEJ68l9Zl1BrybrU0Mgq1LrEUmntTh6y3TZ3wGXWLMxGrJXMlLLCkyL7k+tY51rdUfrytwYbZv3n4yuZi8ZDpr0atvddi13keQ8ZZ/spnTEYyEa46OhN9/5VuS9xJYxMdx17z6zDqJdQst/cBz1rZ11hXP99YSJOPjvC4PXobNtGS9tcfHAfF64Ce7TupY9VpXxRcOEwHZZBaQNxkJrspmBCmyufgUIN5VV5k30n/WnhU/bB3j39u3MjIjAdz1ZJ0gPsCrn13nwcqxGe+ds8664q1EvIGyvNiPdbN4AgXQaitvP36cSEtM35i6Ku9FNiPuD6+DPeO+uWohm+m9X1gf943UB8qxCBDMOrRagcPIRM0ZjYRPnXPNp8+55uhIwFawOa91Xr9JU8puoddMZdMsP649xGQnfTLmGTNBZLJqS6dmVzB9q9EBt4+RCha9t5i5O/XrvHiZnybiLv04uKAnWZOuveFN1JxwJHxKI8G/S8iN64q3/ACfSbLxuFgyb38MbAanw/0pWLdiJuqnS4r0UNZV0gzfB+v+lt2RGn1vXYyHmuPhj974KeqqJz8S+gGMuWQ8wKVf3xRgb7geHGA/vbG/rbrI+GxnyG5YJSTzMuaZpKQfqxbsllnHecsUsvFlZkCfayxhkfgsU1d2cXiqwGpWB/QtWwUZ6V23/ONKXc75ouoZjYRPnn3NJ8++5rb7nvj9V7556sRCiI1g6jfRet50giQYCVd/8uyrNRKEEGI30UgQQgixx2gkfOKsqz55lkaCEELsKBoJQggh9hiNhI+fddUnzrr61ns1EoQQYhcZj4Qzr/r4mVfdeu8T/+MVGglCCLFzjEfCGRoJQgixu4xGwsfO+N7Hz/z+rfc+rpEghBA7SDQSzvj+rfdoJAghxC4SjoSPnfE9jQQhhNhNRiPho1//3kfP+N4tGglCCLGTjEbCqV/77ke/rpEghBA7yngkfPW7p37tuxoJQgixm1gj4U1zGxNCCLFugpHw76d+7d9vueexBY6E7L+T3jbRdPEuWb5eENaqaSsF/p+AF0JsFqORcMpXv3PqV//9lruXOBK6ov97DJBishTH1xO8fJkU2MlEI6HhTRFCzM5oJHzkq9/5yFe/c/O2jwTvtTO+6VypJx0JfYq2KYQQszMeCV/5zkf+7Ts33/2ToyPBegVMvW4RXxvrBMG98akWX2ItMvGkDq40WbIrr3UVo5M1Y11CSlktnXpdCJElGglf+c7Nd/1kyb8lgOc8WA9eYX1qnGRFvPFWIt5A89QFwTidJa6XrxCbDhoJfcTRa6Zet7BiLJHhSpyXz+KKtxLxBrKpcb1kFd7md3AkALdWWJx66nUhRJbN+y0BLAYBZW+u+Kwr3vIDfAKwGTJ1Nph3gl+1ev8KsemMRsLJX7ny5K9cedPOjATyveaKZ8YA/+rEb3YydUEwNlNflxBimWzMSOgHWKe66LVlvaSSp/qIsnigEB8XlAzqTVp1+cz6if17dYQQi2U8Er585clfvvKmu37ysuWNBCGEEFNjjIQ/1UgQQoidQyNBCCHEHtRIsL6ArvxuehYs82vOblmaxQyTGtz3IMZrIJmCF/Gms/Tx+vK39NwuxJYwGgknffnKk7585Y3jkRA8EsnHuCv649O5aGi17A3Y5H1aiXUfi+O9r865muAdCfhUvZlWOkt+4sQGEYyEb5/05W/feNejq5HQDxiurK7f5ZHgvRbHN2ka/16Om1AzEuJ9wmdn1htSkGIiV21lF/7QiU0h/OJoOBKSr/uAICYbvwSskWC915LrfYQrL3M26ye+qsBMkCUpiN1a12ZTM6esJicNxJd4UzCpcV3ADFjvo01o1WVVYS0K4WI8Er505Ulf+vaNdz76sj99U3b/xeuu52dGwKPIH8c/FiSNA8C1WT8uhu8dS5axWuCHrJTP5WopGeytq8Bn1kl/DNIS2X8hAOFIOPlLV954509WIyFgeKW1v5PBiyL5aDV8pJm8zNlk87PvBZeZZPkdvIlWZGwVpyZPFd8Xy4yrrqxhKynvE0jxJfM+hcAkRsJNd6K/ccSsLHxrJq0yzx75SDN5s2cL/HTjtwljBpfmfenwDbEi+X1V1h8+dVanQBakqJQiTQqRZfzHy1+68qRjvyUMg5j9532EZiRpteAVk7yWzJs9m827IhYpMJPtSUEJLgPWItkHJh6b9OqAy5njzu4zSJcsmXQoBIM1Et64isg+eDhyafQRyVPWJZaaKy9pafgjuDCbmrHU515b2YygQGwAKwBvlh+rb9k+W+u48Hr/2SYkE+EmCFFGMBK+ffSPl39vMBLEosCvGLH16KaLSRmPhC9++6QvaiQsHeaDpNgydNPFejBGwss1EoQQYuegRgL+4jV5ymXC9XVq/aekeT9wTZrXuinJ1G37YEkt/7NtcjOTl1gijJQVWSySvPULb75YGqORcOIXv31iNBKS+yw421V8xw30rafFUZ+RDujXiDM60z2iydKY3rayZOks+a1k7Wf+kuR6Voe8Fy6drsXzKHaczEjoBwxXVtdXbkGsHx/Xb+6ax68gxdrw3pcpXhmWzvobwm+V5B4j4/EpXie753k/2fsuBCYYCd868YvfWo2E5PYKqNmC4Forb/3mthT6iOSpeNHy79WxirVa4aoLH5NkfTKlgaIYfWY9yMIUFaslvcXrSanO+etm3J/YT4EUXhQiSTQSTt8bCcltGgAe6T56BYBHDujgjGUUiyd9xoJYxxIhj0nZYD3ZUqsPWbyemb7VaJZVEZuxZOPFZOuSp/oUSQPYT1bH6kNNc8QOYv6W4N3K2fVkWKwfPwMF4gzeimI/SdtZk0kR/pgvh9ThW5rsQ4H/ZN/6CFdpxQQZgVWyrtUxn53345JyXS7EUdAXRyusjZtULNiF1mPmyluZyxL3xmdNkq8Y3Adedgr9mmMrXdaDq9v9MYBgMjJp1TLP1JVN7fJTIMX7EaILRsIJX/zWCXUjoWwXkq+SYn0m1/BH0k+2CcyDmtUP3hHe0phaGH2vjrdvDfW7QetwUdibq4dWXUzeek2rAwXGxI6THgkvTf0lVPKp9m6+WB9kTJ7yAkSS68PF4MBygnWSgp396PL1Ws1M6nibiW2T6yCpdcq77qUfM1wMYkBer5k+Avth1Eh9IQD5kSBmAbyehBBiIsYj4fQrTjj9ihvvfOSlL3/D3MZEs0/BQghBYoyEP9FIEEKInUMjgcL1gR0Hez/1L+0XBcsJcDiF/+ZfrE3dZ2/fJnWytE3VBKuuba13IkYj4UOnX/Gh06+4QSNhTNnbp9VIKLtkIgqKmuhpbD4SGurwyg03SYGT+iwL2ZZdu79ZJzQSMgTbqH4k1HuYhX4As86crfcTH7fSbIW3b9N1bKgfH1dKLQqrxsUaXhQaCRnANsK7jXza+zFWvHVJvIg9A33+EnLd68cFaD7TT2t9CX0D6/UAZVffQBPwIvZg5XU1ZP1d3SY0EjJkHyErjNyXloj3uItewVPsfv5hw81p5SR+XzB5vfGt3NavNzRD3i9mvzE63Rr35/pbuk2MR8IXLv/QFy6/YZ9Gwm8AOwm/Tcit6X0U+4hAavjUMaUlpfAlzHos3vaBrOkP0+ds6on65nJSA24O05PkKXDtUJkpsKDPlrE19HNrGI2ED37h8g9qJIxJbmt8bK0UC9Y8om0hi3KdrXfC9Keytw3d1qy3deLtG3MKaK5hf86bdzsIRsIVGgkx2V2efTbAuvdVNe8jV/YKm8JYq76Bfk7ktma9rZNW+20J+3Pe+7tNaCRQ9AOss8ngeEcG69lHyAoDSZuUnKyRLMq6sLmf+BhkzPYzlmrlk+9btp9tLdWsd+PW4fhJKyLzTpp9a4j+ePkLV2gkuNA+E0JsDam/caSRQKDPHUKI7SP4G0f6LUEIIXYX6m8ckV8LbsQH57V9t+gVX3jfGlLQ/7bfEQ/jtR+2BnwTp+6ntUWnyzgR+ZEQlOo9XiANrYJrk8re+FYs53YUPDZWJ8uKii/UflgsBT6tvrn6OcXW2hQyI6EfMFzhjxdIK6vea+dqyxryBpuENMNc1eQJx1dpPyyThrd4PQrZ3bURoJGwKsZ6jNs+rmvDegX0A4Jg0AdwibXIxJM6ZLFAKjgODhifyWDsJ1azvFmyZDrmkmQfYofBIghm+uaNJ3XIJgCp4Dg4YHwyeb11MSniKrBPb15GJ+nT5X920iPhd//kDcMyyNYkgxeI9xaufgwuwZVaW4eMtxLxBrJ5XSkK8mIzQDZeDDoP1pnUyXUglUzdaT948hb4J8sBicC6N29N/8sKmYvxSPj85R/8/GgkBHTwU0O3IcXjOxfXlSwf6FhnXfE1WzDrpCBFH5HNC8wk+9mlNhVTb8M+WFYtk/ztiM+64rM3KCuYzetK0UfwSUn/ZDkgEV7nIzu7Xqb/ZYXMxWgkfODzl3/g85dfv++R37X/xlHzW7h+wC1PBpTdaX4LZpN6tyDp05WCMc+bwa1m+mAVwmT3LgJLvI34rCvedbMwjP/sMd/zYv/eFPgqfj0Z6W1a9sLFEoyEb37g89+8ft/DBSOhYGvORfbOkVsTPx5gqzHxDfsM8vYDcGqcNxbJminIVdkHbB6EAc/JS7KCBfEN+wDy9gNwam/eAv+4P0wisO7NW9Z/l/OFYIyEP379KiLeJWDfJE8tCuBwuB4c4H2W3Ae4S0w8UIiPyarBWctPcp1JmjUDasn2ocYPI95pPxh+kutkxqy+y6cVDPqW7SfIa8UPF0GZm0J+JIjtxtri87gRc6P9sONoJOwo2Y88egvsFNoP4iijkfCvn7v8Xz93+fV3aCQIIcQuMv4twRgJwWeE5h8oGP0+wpUC6JBSVvCkH6Bik9ZxMrhJanJ9ObhuLtgPrn4y+4rvG8i75M6LLSA5Eh5J/vHy8Ef+OEuBfiWBlNcqs9iEZPnr7BV4Ky32xRTfXGzVivf2M5s32Oe8FHlKiCYEI+GbH/jcN4e/JfQDhivx8RB+4/L6DR+GYql1PpDeV9UUvaq/v60oe58yV1l9BjEFOvE+J3UKFISoIT0S/vsfv76Dr6F4fYj36WX0Gz4MgWyQN05kncouWjpMOUxvK/tTU2/ct9gDo8+sB1mYomK1pDdweXaRtBFb4i/0nhWiHnMkJPf08Efy0e1TdPB1ltSPFYpJSnmPA7Xkjy4dLGuZT7YIK+NcBf5XPw4N1GiWVRGbsWRxb+OVZJOHAB18HOvwykJMwXgknPbND5w2GgnWlu3gC4jZuFPrZ1OvjpOL2WPLTLEOls3qZy+0pII+F/gfKgQHsT5ZWjFBRmCVz+4yZmVMtgJfHgc3aZEQgPFfQj3tm/962m++OFphbdNWz/bU+szljIfshTU6pOwU+jXHVrqsBysAqGWLiiOTVr1uydRNdPB95J0IUYYxEv7IPRLwVsZMrQ/SdfAbBiZv8qUDTq1w+Vwdt+pPTc9ByVPod4PW4aKwt2QPcUZQIJPddZbJyzsRooz8SOgHWCt4HTO1Pkg3VAOPIg7jdQJBr9v4WsunV9yqi1kHSa1T3nUv/ZjhYhBj/VjsBwTzasnIPoK0JISLYCRc9q+nXXb9HQ//9z963dzGtg3wehJCiIWgkbA+9BFPCLFwRiPhXz572b989rIf366RIIQQu4hGAoXrAz4O9v6WsJxfLLzfcU/6W1HzL+Km7rOl3Nt/oDJp6xayqVox1z7cPtIj4b9pJAwoe/tYkQVbcwm72WoCU+YU/qfQn67P/GaY+l637dvs23LFXPtw+9BIyJD8xFFwYUMPs+N9zHZ5JPQD+PW2Hiz9ylyL2pYaCa0IRsKl//LZS398+0MaCSvANsK7jXwL9GOseOuSeBF7Bvr80+J9zKZ4FIEHpp/W+kR9s8IsM1nBYoC+q2+gCXgRe7DyZi9hNKfu7XagkZAh+whZYeRbwBLxHg9/ZB6hMvDzH2dcg5MgBb4pOGYiq6ST4cp0feuMm8L0JHnrk+I4forqsn2brp9bxmgk/J/PXvZ/NBLGgJ2E3ybk1vQ+in1EIDV86pjS8IMELqxfr6GmP0yfs6ldfSvrzBR9s8StooCH5Clw7VCZKa2gz5axSTu5ZRgj4Q81EvZIbmt8bK0UC9Y8olNAlpZdb+WB6U9lbxu6Zdan81PTN+YU0Jxrf64t73agkZAnu8uzzwZY976q5nrkGvpclJ+pfWLleH1T+jb80Rs/BfPe320iHgmX/fj2hzUSAvoB1tlkcLwjg/XsI2SFgaRNSo6xUnjXG5qJjxk/ycvj9YY+Y0vWOvA/haWa9W7cOhw/dVFM3kmzbw0aCbVonwkhtoZgJFyqL45I9LlDCLF9jEbCP3/20n/+7KU/uv2h//aHr53bmBBCiHUzHgmfufSfP5MYCfzXgmUfnEn9Vh/M5/2AP1FepmnW2bYGyPXlAPqTDR5e4tpXQCeIKfPvKip7ifcO4qJAPCmSzZsUAadc4qRP3ARvaWsjPxIC69Zx/CMJqQ/yFqSze3hmcAAAHFJJREFUdFrdIaAz3T6wlHEbG/phDCwN7x624r37M5uXvDVAJ+mtWMd1E107IbtIpubFC/SteO8x421eMiMh3g3esjFl+jWtBDqt7tBcd9q1+1v102tgPQSbKhvJX2XtGW8/8d7rBxT7d1mydMr2SRxpVWRpVvYzu14T4/Vc4239oJEAtkXNdllRrF/TSnx7hiRPxYuWf69ObMxKUVZacFzQz6xPpjRQFKPPrAdZmKJitaQ3cHl2kbQRWyrzb2l6dVwiyXLwOo4s6AO5XhPD5GL88/1cJ+ZIAC0INk28CNaTbWL0QQovlkJWNukzFsQ6lgh5zNsL1oFJbz+9npm+1Wh6/SdrATZwY/FinwJcgo9jHcZ/XAuvYwlirMh4HXTGWgcZ43igPzzLF4WtuvzzqdfJaCT802cu/afxSIi7EBz0ua1s4dUPLqyv3LqFWavxeucpPynCH/MVYalk8xn9IL7Af7JvwI9lj7TNF4WtMtkLLFkZk61w+Qe3gNdxmbGKAutZw2RepljvejYR4wH4d+VdG+OR8OlL/unTl+C/ceQ9ZnDpVPYR6GfTMfFZh0Cksp8uKa++12dNn7MGsuv9MYBgMjJplXRLZuQv4e+L9xbwOi6RrPN4vYl5Mt67nk1EemiSd21s2EiobyLQX/1I+sne6WQAEEmeWlFcWvLYe79c4kxd0+l3g9bhorC3ZK9wRlAgk911NhlD+ud12tbF9817f706Xv22/vH6vKRHwn9N/SXUoELQR1edBfruKnMZcYrhYnCAbzboTyzY1W2dWDz2aeVi9DujD9712EmyhJp1L9n+ZH+MRUhLIJKXAv4LzIA+lEklxeNm4pZa+kx8c/1ssbx+fGp28iNBzMJwuyxz6wgxC1M/Djv+uGkkLJclf5QQQmwlo5Hwj5++5B81EoQQYlcZj4RPXfKPn7rkR7eFIyH4oMp8d+b6YFugz4snc63hA3hlE9bG+vN6+2/FSyd5SY3OprCtdS2BYCRc/I+fujgYCUHrmeP4R0CBfuVWaCvFZCmOXwNrzuvdJ1a8dIBasU4r1pNrrkdmu8mMhH7AcIU55rcyoxlf5SvUuLxGynvtFu9g7x3nr7LipWOpYf01sLZc6yxqdzBGwh9k/o0jcNwPwLld+skLy8DpAvHhihVsXWItMvGkDl9vmT7jsyt6eQVqyVxMPNmNbdUJ1LL6WRFLilzvI8j4uIqsc7I5woU5Eobtxnc9iOntnW3dfkY/OFVTM9AHfuLs2Illnoy3EvEGyPg4r8uDl2EzLVlrMRmTXA/YAh2yq0yfswo1x1YuJj7ZH2CebI5wMRoJ//Cpi//hUxdfNxgJAcMrk/c1eUeTePXJUwx4h8VmvDvVOuuKtxLxBsryYj/WzeIJFECrcTzW4fNuus5QjdF3iXT2fQeCQCcZYPkke4iLEl7MkTAMyt7jLnqYXXeL0SdPNUmXLM1rIz7rirf8tG0y75Mxz5jB+yTWseKxDp9303WssDKdONK6EAgmTwEz2Js3kahkPBI+efE/fPLi62576HdyIyG74rpbXv3KrdBqy67Ws4IF8ZYfbx+y8bhYMm9/DGwGp0v2x4rHtvm8m65jhdX4qTm2amHiGT+gRtGEYCRc9A+fvOi62x78nT94zSqiHxCsBFr9GNJBmb6vSk5kuB4c4E3Zp57G5IWueKAQHxeUnMzLmGeSkn6sWqw+WH68fdgmnQ5ulTI/Nesdsc9dIq5TopL8SBBCCLEjjEbC33/yor/XSBBCiF1FI0EIIcQeGglCCCH2GI+ET1z095+46LpbNRKEEGIXCUbChX//iQuvu/XB3/l9jQQhhNg5NBKEEELsMRoJf/eJC//uExdeq5EghBA7iUaCEEKIPdIj4b9oJAghxO6hkSCEEGKP8Uj4+IV/93GNBCGE2FGCkXDB3338gmtvfeC//P5xcxsTQgixbkYj4W8/fsHfaiQIIcSuopEghBBij40ZCX3EpImmi3fJ8vWCsFZNWyngRDUphBDzsjEjoWv9P1ZjshTH1xO8fJkU2MnUI2HqUS2EWAPjkfCxC/72Yxdce8uWjwTvtTO+6VypJx0JfYrk2eIUQojZMUbC/ziu4/4HkFOsW8TXxjpBcG/8P2DxJdYiE0/q4EqTJbvyWlcxOlkzydIst5ZOnH3qdSFEltFI+JuPnf83Hzv/h8dGwtLIPuf4VdWnxklWxBtvJeINNE9dEIzT1dclhFgmaCT0EUevmXrdwoqxRIYr/JsrPuuKtxLxBrKpcb1kFd7md3AkuKSs+KnXhRBZNu+3BLAYBFivA/yaiM+64i0/wCcAmyFTZ4N5J/hVq/evEJvOTo8E8r3mimfGAP/qxG92MnVBMDaTbawQYkMZj4SPnv83H13oSOgHWKe66LWFX17Jl2byQlc8UIiPC0oG9Satunxm/Vj+vWpCiAWyMSNBCCHE1IxGwl9/9Py/1kgQQohdJRgJ5/31R8/74S33ayQIIcQOYo2EVw+DwHfTSdElf6FsfbG+5uyWpVnMkKmt+IJ+bsEfPDQxvwV9EFtGeiT858FICLasdWzFL5BsCS6pgrygb8VOvCRf6wXxXh1XGKNTL1Km3/B+Lfx5ETvFeCScet5fnzoaCfGnGPw+jeMXSKuR4L0WxzdpGt/8uAn8SBjGe3VitWKm3mZr28YLf17ETjEaCX916nl/NRgJ4LGPj634BYLLic0n1/sIV17mbNZPfFWBmSBL9p5a8ZWtAM1MrvcRZNJ6fbCYrC5rkvQvxBowRwK5xZMxC9/iLv/ZPtQkjQPAtVk/LlbX9uM3exe95XE80GGyJ1em6L83V1YfBHvvV819FKItmZEQMLwy+UiA+OWQfEoLHmlvja5XTBe1NOvHRaBs3c1sPNbB2a2VSfsP+pk1Cc5iz3FePpEQ6yQYCef+1annBn+83BlbtvhZmp3k07u2VxJ5tsBPN3gBkWZwaWAl6BuwBLJbK1P0n+8hqQ/MeBviKkSISSkcCa6nZWmAVxsI6Oy3AFlvk1dMN3gLW/elwIyrJ1ZMtkYQNnX/m+uD5mcbm5USYi7GI+GUc//qlHN/eHP6L6EGO9vaxMkHYzn0EclT1iWWmisvaWn4I7gwm5qx1Odei1Y8WCdTW4lAcHzKlRTUxej3EcGpbLHMKSFmYTQS/vKUc//ylHN/cHP4W4JYDuDVKYQQlRgj4WUaCctFHy2FEBOhkSCEEGKP9Ej47Ze5/40j8AVrljL94s/I837KnjRvXBr4oqltHyypGVtN4t1UVvym6wjRRSPhG395yjeCkRBsKebYRZl+ZTpLpNWTA3Smez6TpU1674ABZn0JePeVFb/pOkIcZTwSPvKNv/zIaCT0A4Yr+JinWL94i0+hCVKsDebV0PbeZT1k16cj2FTZSP4qK37TdYQ4ymgkvP8j33j/YCSA7YWPSVz61rVerAv7iOSpeDHpuUAnNmalKKgLH5NkfTKlgaIYfWY9yMIUFaslvTHxwJUr75p1hDiKORKGeyj5eAT7LLkYr8dbltQfUrm/LeWsbNJnLIh1LBHymJQN1pP9BB3mcxX4T/atRrOsitiMJWstJmOS6wEz6giByYyEeAuuAJuM2X/F+q02tzdjbDL5ZGYdJkX4Y74cUofvZ7IPBf6TfesjXKUVE2QEVnE81uHzzqUjxFHQF0crkvsJbDLv/uP163f2UCFQy2Zk4rMmgQhz7JWdQr/m2EqX9eDqdn8MIJiMTFoFK0Gf+ZYuTUeIoxSOBLzi3X+MfpkyVkg+7SDGirdSJAOASPJU8Gx7S2NqYfS9Ot6+NdTvBq3DRWFv2R5aMVaNTN65dIQ4yngkfPic93/4nB/cdN9vv+xVq4h+QLASaMWRDLx+12hnA5/J9eFicIB9WjpJQVAdX7XVzKQOLgEXFcuS6yCpdcq77qUfM1wMYkA8WHflnVFHiC4YCe/78Dnv+/A5/XgkiFkArychhJgIYyT8nkbC/OgjnhBizaRHwks0EoQQYvfQSKAo/m7XOluQmr9kIib9brr5F2XT9W3q7+i39bdD/dnGRqCRkKfsbdVqJJRd0pzAQ3NLzUdCQx2gufA+zL5tVkzdN9EKjYQMxVu54aZfwvMTv6qW/Cpsq2NpLrwPS9g2K6bum2jFaCT8xcln/8XJZ2skDAF7Fz+91kpyxiQfEusUXsSegT6+JBBv/kiDZjL9sdY3ug/AZ3YdFIUXsQcr7+x9E63QSMiQfUStMOvC5KNYf9ylnrpsdTxD8Th1K/34fYGbjGOmeO9M3YfOuH01+4HR6TZ8/4hWaCRkAHsXv32Y9xcQwcdDAin+kQNSOJjUd1FTL9O3bOqF9CFIlDUJDCRPgWu9dS2zb6ISjYQMyccGH1srxYI1r4BWBI9981zeeit7VelzmX1gTgHNjd4/ohUaCXmyT1H22QPr3lfbvI/0dLla9WHq986m9GH44y7sH9EKjQSKfoB1NhkcP4HBevYRtcJA0iYlxySLaiseH3d2adn+xFINrU7X7Wy95Ho3bgWOn7SiOMV0WUQlo5Hw3pPOeu9JZ11z470aCTza30KIrcEaCa+c29jS0ecdIcT2YYyEl2okCCHEzkGNBPJrx4344NxHTJpouvjNxdt/K77gPsbx1vHa2NxHSWwl+ZFAPkKzP1o8Da2Ca5PK3vhWLOd2JF/rBfFeHStsCfvWyrvw50hsJaOR8J6TznrPeCTEn1Y0EpI6U8S3Yg15g01CmmGusuK9OrGapZ8VaY5GglgO45Fw4lnvOfE3IwE8ftZxHL9AsiUMzWdfQ+ASa5GJJ3XIYoFUcBwcMD6TwdhPrGZ5y8YXdMNaiY+tJiTVLCfMetI8WZQQDQlGwpnvOfHMoyOB3PrMI7E0vI/i6sfgElyp9Qog461EvIFsXleKgrzYDJC1FpMx8SVM9uTKEo6xWyGmJjMSAoZXBivBs7rkrYyfwNj/cIV5kq2zrviaV0nWSUGKPiKbF5hJ9rNLbR4rHuvg7NZKzbHlweob0MGCQkxKeiT8FvwbR8lFZosvhGw5zKMO1q2zrviCVxLvpCAFY543g1sNVgI/9a3w9jmbNOkfO2FihFgPhSOBf7QWSPZJ9j7VzKvBG1/8SnL57Afg1DhvLJI1U5bLqqUsO8g11zF2K8TUjEbC8SeeeXw0EvoBwUqgFUcuEGByuB4c4Ie2N96P8VlXPFCIj8mqwVnLT3KdSZo1A2qx+sD4JFMzi8Bbb0yv2Ex2HaQg6xKiFeORcMKZx5+Q+C1BbDHWq2oeN0KIWdFI2FG8H2mFELtAMBLOOP6EM6658R6NBCGE2EGokUB+0en6gNlHWKfiC30l5vKSgsDPdB+oY5PWcTK4SWpyfTl4b27ZPly+jhAFWCPhFauIYAt6jy2smORjkL3KRaxZdmFDS9l0q+NW/fcaYNaXgHfDWPGbriNEGaOR8O4Tznj3CWdcPRgJ/YDhCn9swbxuhqljJ8UUi6zzOWReDTX9L/CQXZ8O/tZb+8cbv+k6QpSBRgLYjvyxhRUTJA3CmjwJgdXhYvJhs05lFy0dppBsf8AxSU29cd9iD4w+s955XoKBGeyNiQeuXHnXrCNEGeOR8KEz3v2hM66+4Z7feukrhnsu+TjF+zK53qfIinTHXtbW2RqAT/7YslSsg2Ut83Hqgv5U9mH149BAjWZZFbEZS9ZaTMYk1wNm1BGiLemR8J+OjYR4y66wNmXBZh1eYj0hxeLZdJYHfGxZKtbBsln97IWWVHBzC/wn71cf4SqtmCAjsIrjsQ6fdy4dIcoIRsLX3/2hr199wz3/6XdfMQxK7j9rUxZs1uElwUMbqDV5ErLlMMeWWrEOKTuFfs2xlS7rwQoAatmi4sikVbAS9Jlv6dJ0hCijcCS4nuck1v5OPrEF+mTqDn7DgL1lHSZPBc826TN4NRT4ZMTL9LNtqdTvBq3DRWFv2R5aMVaNTN65dIQoYzQS3vWhr78rGgn9gGAl0OKfW0s5Xo+TerOApEOpOFeyrqwloBMIet3G11o+veJWXcw6SGqd8q576ccMF4MYEA/WXXln1BGigPxIEE0ArychhFgI45Hwwa+/64MaCVOhj3hCiIWjkSCEEGIPjQSK4u+CrbMFqflLJmLS77Kbf7E2Xd+m/k5/W3+b1J+FbAQaCXnK3latRkLZJc0JPDS31HwkNNQBmgvvw+zbZsXUfROt0EjIULyVG276JTw/8atqya/CtjqW5sL7sIRts2LqvolWaCRkAHsXP73WSnLGJB8S6xRexJ6BPr4kEG/+SINmMv2x1je6D8Bndh0UhRexByvv7H0TrdBIyJB9RK0w68Lko1h/3KWeumx1PEPxOHUr/fh9gZuMY6Z470zdh864fTX7gdHpNnz/iFZoJGQAexe/fZj3FxDBx0MCKf6RA1I4mNR3UVMv07ds6oX0IUiUNQkMJE+Ba711LbNvohKNhAzJxwYfWyvFgjWvgFYEj33zXN56K3tV6XOZfWBOAc2N3j+iFRoJebJPUfbZA+veV9u8j/R0uVr1Yer3zqb0YfjjLuwf0Qr9gxYU/QDrbDI4fgKD9ewjaoWBpE1KjkkW1VY8Pu7s0rL9iaUaWp2u29l6yfVu3AocP2lFcYrpsohKgpFwxruO/v8SNBJotL+FEFuDRkIh+rwjhNg+NBKEEELsMRoJ+H+0ubqGWc8m9uqDeC/zfsCfKK9VFO5bQzNWS2dsNYl3X7n27Zp1mPWsFOnTa6nYD1lXE5Ot9PsUYB3UW1BaDdZIeKWVPllDsM5Yr9GvAfts1XGgM919ZVoaHzf0Q97TRWHtN2/8EnSY46wUNuCSYny6RICOV9+rU6Pfcfc3K0v2rZL0SPgtbiQMN1Bly1z6NQCfU6RYJ3xLrcU1GFgPw53DRPJX8ft/Lh0c49Xx+rEyMj4Zz7xPXr8mF+k/eX/BOqM5EeORcMKZ7z7hzKtvvJcZCf2AAute/VbtwHmTReHFznhsvDqxMW/52ZZ2xhYke5v1yZQGimL0mfUgC1NUrJb0xsQDV668Lp2k5zgX48c6Jv0wGb1+GJ81+t5cZBMYS9l7x4i0JTMS4k0wrCHpMhkfq3n1rfgCLJGsMrA6PIV1LBHymLcXrAOT3pZ6PTN9q9H0+k/WAmxYi8mY5HpAQ53gVLK6Pmo+8EPWS3bVdSrpPI4Hp3h9MgWfN5sIrzPi3rxlmCPBshL4DlyWmeb1a7JkRfCdi++W5RPbAx1jjvmKsFQfQeoH8QX+k30Dfix7pG2+KGwVx2MdPm+ZTtJqHEP6GcZ7/eCM5OUd3D/eRT7RFCnIVmTrLUhdRvlIsE4VmCD1k/H1ubCsNz5rj9wKBY11SXn1vT5r+pw1kF3vjwEEk5FJq2Al6Cff0rY6OJhphaXj9QPCyGuxH6Dm0meualsFXm91H+sJRsIZyT9LAHZXP3r3zdT63rxMLiveSpEMACLJUyuKS0see/vpEmfqmk6/G7QOF4W9Mb1Kxlg1MnlrdPj+lOmQUskw7/1i4mv0a3S6CF6/LC9ebwv6LaEfEDsLTvUR2dwufRDvBehgP93grmAzTF2BYFe3FWLx2KeVi9HvjD5412MnyRJq1r1k+2PVlYzhLU2hw6wDkfi4wE8ydR+RjHfVZQV7L8max/FZKSuezItPNWc0Eo4/4czjTzjzmuiLI7F+hrd/PVtBiFmYentvuv6a0UhYLuv8aCCEEF04Ek488/gTNRKEEGJHsUbCq8B3c9Z6B79uCyjQb/KpGeRti1d8rt8G1p/X1X9ynxSkLtZh/DBSrXSSJYC+rQIY5UANJ2XybjTbWteQzEiIL0jugOQpjFe/OBFOUS/FZCmOXwNrzgv2D3NJzX5oosPsT0aqlY4Vhi903XRrJyf7tubtFLCe1PPWODXBSDjr+BPP4kdCf4zO36Ya/cpb0kqqVclbwPBOMZGuq7L3yyvSGa/gMjOWDpZqpWM5ty7sB2RlgY4Vwys3Z22pZ6xxDZSPhGBvedtUo195Syyp5NOCPeBLrEUmntTh6y3TZ3x2RS+vQC2ZCx8ng7N5wbpLx/IPujSFjuUcX0jKkpHeHiYvt0og1/sIMj72nO18QY0bRGYkWK3sjv2OFrSVuVVMfKwPLvGS1QGWYj84C15hkpLHjGwyPs7r8uBl2ExLNtmK5P2KF/sU2HNSP6sT/wjW63XIrjJN42VJnZ67WVnnNcdWUUz80C2Ix4m2htFIeM9JZ73npL2RMAyK2xR3kGmlBaOfDC4D3+lh9mA9aZXP4oq3EhX02esT+En2xwW+v0nxbMmMn2yMq5mxf1zXdDqMedxSXtm6yrvOhPURWU2gkwyw+kzeO1zU5lI+EoJTrp4GMPrJ4DLKtg6pA8664i0/xX3mq8j2xxJhzOD7m9TJlsykzt7TSv+4rul0mLDiYjtuv3nXGZMFmtm9QaYoS7Q1pEfCS8Z/lsC01buPvfq8cpZWWydZO7jKFc/0p6bPTN6jPzI6/TGwGZzO6k82piA1rrrAv1ewlY4VxtwvSyfb/IJjxnmlfrKHTDzjx4rZPoKRcPZ7Tjr7mhvve8lLX9UN9kdyP1m7h+9XsX5hrTmTw/XgAG8O7D9bghUPFOLjgpKTeRnzTFLSj1XLRH6wTo1/sD61TperC4j3xpbIihesu8yX6fPxjIjr1NaARoIQYnfY7jedIDFGwu9pJAghxM6hkSCEEGIPjQQhhBB7jEfCyee85+Rzrrnpvpf83qvnNiaEEGLdjEbCe08+570aCUIIsatoJAghhNgjGAnfeO/J39BIEEKI3UQjQQghxB4aCUIIIfYIRsK57z353Gtuul8jQQghdpDxSPjwue/9sEaCEELsKBoJQggh9hiNhL/48Ll/8eFze40EIYTYSTQShBBC7DEaCe8bjIQ+IrgS/2Pi2X9lt0Afr/Ngk7vzTwQ3uV/Z+wjU+HXGFX+VSwSv93X/qwAhlsZ4JHzkvPd9+Lz+pvtf8rJX421tPQwgIKvAnK1/2OLXWfMUOPtEyl5a3a+CdlnvzYL3acObVVDgdLtUiLkIRsL57/tIZiTg5zmIAYnL9OsftthnjVpx6klTMFna3i+vQ/6YV6ukQKpVT4RYDuORcMr57zvlvP7mqt8SyHe3V5+5igEoWM6Hi8kyrfjheh8R+4mPg6TYZ1c0EgK1ZK54PQ4g4Wv3qmV1QN+AFF5v0hMhlkM8Es7vb35gNRKsfQ8exR6+Oq31rD5edwEe5jjF8EfmmJTK6nepHpJ5GYaClmy8GLeOXM/6L6srjmR0kutkcLG+EBuBORKGQfjBG64kn/wsjD5eL6DyFQBeDf0YnJHRGZ7qI/iS47zW/cLiNXfH8l9WVxzJ9DOpTxYF9LNSQiyf0Uh4/ykXvP+UC35w8wMvedlxwyD84A1Xsk9LEka/QDabi3k1WPHeYyadN96qjmkRvl9Yp+buFPSNVKvUJ4tifPL+hVga5kjAWz+7kn0qvPqkbJaCV0M/BusA/dWP3njef2ASAHK5fGb7Sfr36oDIfkA2L5aK1xmfvH8hlgb6LQE8WsypbG6XPsjrxRLJpoj9xMdDHXwKx2dtVDahM+5X0jDO6/LD9JAvDVuygkFdrvU4kasVQiwQ6oujXabsVSWEEJvIeCScesH7T73gB7doJIzQRz8hxI6QHgm/rZEghBC7RzASLnz/qRf+4JYHNRKEEGIH0UgQQgixh0aCEEKIPUYjQQghhNBIEEIIscf/B2RBpyOBOulgAAAAAElFTkSuQmCC" alt="" /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;span style="display: block;" id="formatbar_Buttons"&gt;&lt;span class=" down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin-top:0in;  mso-para-margin-right:0in;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal"&gt;As you can see, since I have a typical NFTS file system, my first partition table is set to 0x63, exactly what I would expect to see.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;What I would NOT expect to see, is a entry prior to offset 0x63.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;If I exported the MBR (again, $BOOT) from a target system and parsed it with MBRparser, and I saw a partition table prior to 0x63, I would immediately become suspicious.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, don't think that every time you have a partition table before the NTFS file system that you have MBR malware.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;There are systems that intentionally put partitions with vendor tools, or other data there intentionally.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;So, "Don't Panic"...at least not yet.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;If you see something there before the NTFS file system you can either mount it with a tool like ImDisk, or FTK Imager, or you can extract the data using The Sleuth Kit's, "blkls".&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Then you can see the data and decide for yourself if it's just benign vendor stuff, or if it's, malware. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;The&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;real takeaway here is to actually start looking.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;By adding this step to your malware detection methodology, you will increase your chances to catch an infection of this nature.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;And, since you were likely not doing this in the first place, you have made yourself an exponentially better investigator.&lt;/p&gt; &lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="display: block;" id="formatbar_Buttons"&gt;&lt;span class=" down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;img src="img/blank.gif" alt="Link" class="gl_link" border="0" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-6411693972363966242?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/6411693972363966242/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/mbr-analysis.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6411693972363966242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6411693972363966242'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/07/mbr-analysis.html' title='MBR Analysis'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-326139851550216193</id><published>2011-06-30T07:50:00.003-05:00</published><updated>2011-06-30T07:53:25.311-05:00</updated><title type='text'>Speaking at GFIRST</title><content type='html'>I will be delivering a special version of the Sniper Forensics presentation at the GFIRST National Conference this year!  I'm sure it will be a fantastic event, and I am really looking forward to it!&lt;br /&gt;&lt;br /&gt;If anybody is going to be there, I would love to be able to meet you in person!  Just let me know!&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-6uzJBp3pGs8/TgxxcZ09b5I/AAAAAAAAAPc/h9u3EnePr_I/s1600/logo.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 125px;" src="http://1.bp.blogspot.com/-6uzJBp3pGs8/TgxxcZ09b5I/AAAAAAAAAPc/h9u3EnePr_I/s320/logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5623994767462199186" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-326139851550216193?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/326139851550216193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/speaking-at-gfirst.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/326139851550216193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/326139851550216193'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/speaking-at-gfirst.html' title='Speaking at GFIRST'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-6uzJBp3pGs8/TgxxcZ09b5I/AAAAAAAAAPc/h9u3EnePr_I/s72-c/logo.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3634419382766062517</id><published>2011-06-09T14:37:00.002-05:00</published><updated>2011-06-09T14:49:31.474-05:00</updated><title type='text'>SANS What Works Summit HUGE success...again...</title><content type='html'>Once again, &lt;a href="http://www.sans.org/security-training/instructors/Rob-Lee"&gt;Rob Lee&lt;/a&gt; and the folks at &lt;a href="http://www.sans.org/"&gt;SANS&lt;/a&gt; put on THE conference to attend in the IR/Forensic space!  I would like to extend my personal thanks to Rob, the staff at SANS, and all of those in attendance.  You all are what continually make this conference such a rousing success year after year.&lt;br /&gt;&lt;br /&gt;The presenters just keep getting better year after year (although &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt; was sorely missed)!  &lt;a href="http://log2timeline.net/"&gt;Kristinn &lt;em&gt;Gudjonsson&lt;/em&gt;&lt;/a&gt; slayed it with the new and drastically improved version of Log2Timeline, &lt;a href="http://www.deer-run.com/%7Ehal/"&gt;Hal Pomeranz&lt;/a&gt; stunned us with the evolution of the EXT4 filesystem and the massive proliferation that is looming on the horizon, and..as always...&lt;a href="http://www.amazon.com/Cory-Altheide/e/B004MD0240"&gt;Cory Altheide&lt;/a&gt; showed once again why he is the Cloud Master!&lt;br /&gt;&lt;br /&gt;I don't want to fail to mention the other talks by Sean Morressy whose &lt;a href="http://katanaforensics.com/"&gt;Katana Lantern&lt;/a&gt; product is a MUST HAVE for any agency doing Apple device forensics! Andrew Hay also did a "bang up job" - no pun intended - on his five points talk...very very good stuff!&lt;br /&gt;&lt;br /&gt;If I left anyone out, forgive me!  I am just touching on the talks that really stuck with me, but all of the content was exceptional this year.&lt;br /&gt;&lt;br /&gt;I have said it before, and I will say it again...if you can only attend ONE IR/Forensics conference next year GO TO THIS ONE!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3634419382766062517?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3634419382766062517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/sans-what-works-summit-huge.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3634419382766062517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3634419382766062517'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/sans-what-works-summit-huge.html' title='SANS What Works Summit HUGE success...again...'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3398393032966738810</id><published>2011-06-06T07:36:00.003-05:00</published><updated>2011-06-06T07:37:16.903-05:00</updated><title type='text'>SANS What Works in Incident Response Today!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-e_t1DnujBek/TezJ2C9cC-I/AAAAAAAAAPU/8G8gPkFClSs/s1600/sans_2011.jpg"&gt;&lt;img style="cursor: pointer; width: 527px; height: 93px;" src="http://3.bp.blogspot.com/-e_t1DnujBek/TezJ2C9cC-I/AAAAAAAAAPU/8G8gPkFClSs/s320/sans_2011.jpg" alt="" id="BLOGGER_PHOTO_ID_5615084765768846306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will be presenting Sniper Forensics v2.0 at the SANS Summit tomorrow.  Hope to see you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3398393032966738810?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3398393032966738810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/sans-what-works-in-incident-response.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3398393032966738810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3398393032966738810'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/06/sans-what-works-in-incident-response.html' title='SANS What Works in Incident Response Today!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-e_t1DnujBek/TezJ2C9cC-I/AAAAAAAAAPU/8G8gPkFClSs/s72-c/sans_2011.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2620959024773422717</id><published>2011-05-05T11:46:00.001-05:00</published><updated>2011-05-05T11:47:27.437-05:00</updated><title type='text'>GFIRST: Sniper Forensics</title><content type='html'>Sweet!  Sniper Forensics has been accepted at GFIRST!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-bp-3ILX99h4/TcLUmBTf8rI/AAAAAAAAAPI/lf57pfdtvms/s1600/gfirst_logo.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 123px;" src="http://4.bp.blogspot.com/-bp-3ILX99h4/TcLUmBTf8rI/AAAAAAAAAPI/lf57pfdtvms/s320/gfirst_logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5603274636052656818" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2620959024773422717?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2620959024773422717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/05/gfirst-sniper-forensics.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2620959024773422717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2620959024773422717'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/05/gfirst-sniper-forensics.html' title='GFIRST: Sniper Forensics'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-bp-3ILX99h4/TcLUmBTf8rI/AAAAAAAAAPI/lf57pfdtvms/s72-c/gfirst_logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-209893588096363366</id><published>2011-03-25T11:26:00.002-05:00</published><updated>2011-03-25T11:27:35.560-05:00</updated><title type='text'>Sniper Forensics Part IV: "Finding Evil"</title><content type='html'>Posted on the &lt;a href="http://blog.spiderlabs.com/"&gt;SpiderLabs Anterior&lt;/a&gt; blog.  Check it!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-KANaPfkJL-k/TYzCWPcu7cI/AAAAAAAAAPA/fyJ0JcrSc6c/s1600/SF4.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 84px;" src="http://1.bp.blogspot.com/-KANaPfkJL-k/TYzCWPcu7cI/AAAAAAAAAPA/fyJ0JcrSc6c/s320/SF4.jpg" alt="" id="BLOGGER_PHOTO_ID_5588054925019901378" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-209893588096363366?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/209893588096363366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/03/sniper-forensics-part-iv-finding-evil.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/209893588096363366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/209893588096363366'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/03/sniper-forensics-part-iv-finding-evil.html' title='Sniper Forensics Part IV: &quot;Finding Evil&quot;'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-KANaPfkJL-k/TYzCWPcu7cI/AAAAAAAAAPA/fyJ0JcrSc6c/s72-c/SF4.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7358260971353845255</id><published>2011-03-10T15:50:00.003-06:00</published><updated>2011-03-10T15:53:48.484-06:00</updated><title type='text'>SANS What Works Summit 2011</title><content type='html'>I was just informed by &lt;a href="http://computer-forensics.sans.org/instructors/"&gt;Rob Lee&lt;/a&gt; that Sniper Forensics 2.0: Target Acquisition has been selected for this year's &lt;a href="http://www.sans.org/forensics-incident-response-summit-2011/"&gt;SANS What Works in Incident Response Summit&lt;/a&gt; in Austin Texas!  Sweet!  See you there!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-1khFLWSDQ0s/TXlIXVlyNyI/AAAAAAAAAO4/lBJvfscnkWE/s1600/SANS_WW11_logo.jpg"&gt;&lt;img style="cursor: pointer; width: 424px; height: 107px;" src="http://3.bp.blogspot.com/-1khFLWSDQ0s/TXlIXVlyNyI/AAAAAAAAAO4/lBJvfscnkWE/s320/SANS_WW11_logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5582572778872256290" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7358260971353845255?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7358260971353845255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/03/sans-what-works-summit-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7358260971353845255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7358260971353845255'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/03/sans-what-works-summit-2011.html' title='SANS What Works Summit 2011'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-1khFLWSDQ0s/TXlIXVlyNyI/AAAAAAAAAO4/lBJvfscnkWE/s72-c/SANS_WW11_logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-4084051076421587303</id><published>2011-02-23T16:17:00.004-06:00</published><updated>2011-02-23T16:39:48.778-06:00</updated><title type='text'>Time Stomping is for Suckers</title><content type='html'>OK...So I have been seeing this more lately, so I feel like it's time to post about it again.&lt;br /&gt;&lt;br /&gt;Chronological data about the files on a Windows system are stored in something called the Master File Table or $MFT.  This is the place that the operating system and various GUI utilities (Insert Forensic GUI Utility of choice) pulls timeline, or MACB times.  As a refresher, MACB stands for:&lt;br /&gt;&lt;br /&gt;M - Modified&lt;br /&gt;A - Accessed&lt;br /&gt;C - Created&lt;br /&gt;B - Birth&lt;br /&gt;&lt;br /&gt;Now...there are two places in the MFT that store this chronological data.  One is the $Standard_Information ($S_I) attribute, and the other is the $File_Name ($F_N) attribute.  So now you are asking yourself, why are there two places that store this data, and why do I care...well...I will tell you...&lt;br /&gt;&lt;br /&gt;The data is stored in two different places because they are accessed by two different parts of the system (loosely).  The $S_I is accessed by the OS, various applications, and the user.  So, it is able to be modified or stomped.  THEREBY " fooling ANY and ALL forensic utilities.  ALL OF THEM...since they all pull the chronological data from the $S_I.  So, if a file has been modified, and you sort in your little GUI column sorter, the malicious file(s) that has (have) been stomped will be sort in like 2008, 1969, or whatever date the attacker decided to give it.&lt;br /&gt;&lt;br /&gt;Sucks to be you right?  Wrong!  Sucks to be a crappy tool...not a smart investigator!&lt;br /&gt;&lt;br /&gt;Here is why...&lt;br /&gt;&lt;br /&gt;While the $S_I attribute is able to be modified by the OS and stuff, the $F_N attribute is not.  So what does that mean?  It means you can use this hand-dandy little perl script called, "&lt;a href="http://code.google.com/p/winforensicaanalysis/downloads/detail?name=mft.pl"&gt;mft.pl&lt;/a&gt;"from none other than the illustrious &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan Carvey &lt;/a&gt;to parse the MFT and just pull out the $S_I and $F_N attributes (Which incidentally, Harlan was nice enough to post on Google Code...THANK YOU HARLAN).  Then, when you compare the two values, you can see right away if the MACB times have been modified!&lt;br /&gt;&lt;br /&gt;Here is the syntax to use mft.pl..&lt;br /&gt;&lt;br /&gt;C:\tools&gt;Perl mft.pl $MFT_from_suspect_system &gt; ripped_mft.txt&lt;br /&gt;&lt;br /&gt;Now if you cat or strings that file, it will look like a bunch of nonsense, so here is what I suggest:&lt;br /&gt;&lt;br /&gt;C:\tools&gt; strings ripped_mft.txt | grep -A 6 -B 6 -i &lt;filename&gt;filename_you_are_looking_for&lt;br /&gt;&lt;br /&gt;This will give you the six (6) lines both before and after the hit in the MFT.  The MACB times on the top are from the $S_I attribute, while the ones on the bottom (as indicated by the little "FN" are from the $F_N attribute.&lt;br /&gt;&lt;br /&gt;So, if the top does not match the bottom, you have a file that has had its MACB times modified by something.  Then you can indicate that, and show that the times on the bottom are the correct ones.  Use those in your case timelines.&lt;br /&gt;&lt;br /&gt;So you see, Time Stomping is for suckers!  You can fool a tool, but you CAN'T fool an investigator.&lt;br /&gt;&lt;br /&gt;Well...I guess technically you CAN, but it would have to be an investigator who is relying on the tool to solve his case for him and not his brain.  In which case, I would refer to that person as more of a click monkey than an actual Investigator...but I digress...&lt;br /&gt;&lt;br /&gt;Happy Hunting!&lt;/filename&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-4084051076421587303?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/4084051076421587303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/time-stomping-is-for-suckers.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/4084051076421587303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/4084051076421587303'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/time-stomping-is-for-suckers.html' title='Time Stomping is for Suckers'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-1797884590623571276</id><published>2011-02-23T15:43:00.003-06:00</published><updated>2011-02-23T15:48:30.012-06:00</updated><title type='text'>Named Top 25 Blog!</title><content type='html'>I was just informed that TheDigitalStandard was named one of the top 25 Forensics blogs!  Nice!&lt;br /&gt;&lt;br /&gt;This distinction comes from http://www.criminaljusticedegreeschools.com/top-forensics-blogs/.&lt;br /&gt;&lt;br /&gt;Thank you!  Notice a couple of other names in the computer forensics world?  Namely &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan&lt;/a&gt; and &lt;a href="http://eyeonforensics.blogspot.com/"&gt;Grayson&lt;/a&gt;...great work fellas!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-Jc4uS2JGgqY/TWWActWSTOI/AAAAAAAAAOw/J8dqmkGEUoU/s1600/top25.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 220px;" src="http://4.bp.blogspot.com/-Jc4uS2JGgqY/TWWActWSTOI/AAAAAAAAAOw/J8dqmkGEUoU/s320/top25.jpg" alt="" id="BLOGGER_PHOTO_ID_5577004944265989346" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-1797884590623571276?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/1797884590623571276/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/named-top-25-blog.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1797884590623571276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1797884590623571276'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/named-top-25-blog.html' title='Named Top 25 Blog!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Jc4uS2JGgqY/TWWActWSTOI/AAAAAAAAAOw/J8dqmkGEUoU/s72-c/top25.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-1208258588033041379</id><published>2011-02-21T12:04:00.001-06:00</published><updated>2011-02-21T12:06:49.886-06:00</updated><title type='text'>Sniper Forensics Part 3</title><content type='html'>Now posted on &lt;a href="http://blog.spiderlabs.com/"&gt;SpiderLabs Anterior&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-exMhjkQGQAc/TWKprJxE25I/AAAAAAAAAN4/Lpo4nHtluw8/s1600/sf3_image.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 135px;" src="http://1.bp.blogspot.com/-exMhjkQGQAc/TWKprJxE25I/AAAAAAAAAN4/Lpo4nHtluw8/s320/sf3_image.jpg" alt="" id="BLOGGER_PHOTO_ID_5576205847459322770" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-1208258588033041379?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/1208258588033041379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/sniper-forensics-part-3.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1208258588033041379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1208258588033041379'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/sniper-forensics-part-3.html' title='Sniper Forensics Part 3'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-exMhjkQGQAc/TWKprJxE25I/AAAAAAAAAN4/Lpo4nHtluw8/s72-c/sf3_image.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2143685297099659544</id><published>2011-02-17T11:43:00.006-06:00</published><updated>2011-02-18T08:01:55.834-06:00</updated><title type='text'>Dumpy Goodness</title><content type='html'>OK...I know the title sounds a bit wonky, but I really think a lot of you are going to find this post interesting and useful.&lt;br /&gt;&lt;br /&gt;So...in my quest to be ever more efficient in my volatile data acquisition I stumbled upon (thanks to &lt;a href="http://windowsir.blogspot.com/"&gt;Harlan&lt;/a&gt; and &lt;a href="http://www.linkedin.com/profile/view?locale=&amp;amp;id=18330949&amp;amp;authType=name&amp;amp;authToken=sWVJ"&gt;Troy&lt;/a&gt;) a tool that is resident to Windows systems that has proved to be extremely helpful.  It's called reg.exe, and it's pretty freaking sweet.&lt;br /&gt;&lt;br /&gt;Normally, when extracting volatile data from a Windows system, I would dump RAM, run my volatile collection script, then fire up &lt;a href="http://accessdata.com/support/adownloads"&gt;FTK Imager&lt;/a&gt; (usually in conjunction with &lt;a href="http://www.f-response.com/"&gt;F-Response&lt;/a&gt; if against a live system) and manually extract the registry hives and ntuser.dat files.  I thought this was pretty efficient, but it always bothered me that I could not script the process.  I mean, how quick and easy would it be if my data collection script dumped RAM, gather volatile data, extracted the registry hives and ntuser.dat files, AND...for good measure...ripped them for me with &lt;a href="http://regripper.net/"&gt;RegRipper&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;That would not only save me time, but it'd be freaking sweet...so I set my mind to figuring this problem out.  After a couple of days of poking around and trial and error, I got it to work!  So, here's how...&lt;br /&gt;&lt;br /&gt;reg.exe is resident to all Windows releases that I have in my lab (2000, XP, 7, Vista, Server 2003, and Server 2008), but just to be safe, I copied it from my lab XP system to the same directory with all of my tools.  Then, when I scripted it into my batch file, it looks like this...&lt;br /&gt;&lt;br /&gt;@ECHO     Dumping Registry Hives&lt;br /&gt;@ECHO     Dumping SAM Hive&lt;br /&gt;@reg save HKLM\SAM %DST%\%NAME%\vol\%NAME%_SAM_Hive&lt;br /&gt;@md5deep.exe -b %DST%\%NAME%\vol\%NAME%_SAM_Hive          &gt; %DST%\%NAME%\vol\%NAME%_SAM_Hive.md5&lt;br /&gt;&lt;br /&gt;@ECHO     Dumping SYSTEM Hive&lt;br /&gt;@reg save HKLM\SYSTEM %DST%\%NAME%\vol\%NAME%_SYSTEM_Hive&lt;br /&gt;@md5deep.exe -b %DST%\%NAME%\vol\%NAME%_SYSTEM_Hive       &gt; %DST%\%NAME%\vol\%NAME%_SYSTEM_Hive.md5&lt;br /&gt;&lt;br /&gt;@ECHO     Dumping SECURITY Hive&lt;br /&gt;@reg save HKLM\SECURITY %DST%\%NAME%\vol\%NAME%_SECURITY_Hive&lt;br /&gt;@md5deep.exe -b %DST%\%NAME%\vol\%NAME%_SECURITY_Hive     &gt; %DST%\%NAME%\vol\%NAME%_SECURITY_Hive.md5&lt;br /&gt;&lt;br /&gt;@ECHO     Dumping SOFTWARE Hive&lt;br /&gt;@reg save HKLM\SOFTWARE %DST%\%NAME%\vol\%NAME%_SOFTWARE_Hive&lt;br /&gt;@md5deep.exe -b %DST%\%NAME%\vol\%NAME%_SOFTWARE_Hive     &gt; %DST%\%NAME%\vol\%NAME%_SOFTWARE_Hive.md5&lt;br /&gt;&lt;br /&gt;@DELAY.EXE %DELAY%&lt;br /&gt;&lt;br /&gt;@ECHO     Ripping SAM Hive&lt;br /&gt;@rip.exe -r %DST%\%NAME%\vol\%NAME%_SAM_Hive -f sam   &gt; %DST%\%NAME%\vol\%NAME%_SAM_Hive_ripped.txt&lt;br /&gt;&lt;br /&gt;@ECHO     Ripping SYSTEM Hive&lt;br /&gt;@rip.exe -r %DST%\%NAME%\vol\%NAME%_SYSTEM_Hive -f system   &gt; %DST%\%NAME%\vol\%NAME%_SYSTEM_Hive_ripped.txt&lt;br /&gt;&lt;br /&gt;@ECHO     Ripping Software Hive&lt;br /&gt;@rip.exe -r %DST%\%NAME%\vol\%NAME%_SOFTWARE_Hive -f sam   &gt; %DST%\%NAME%\vol\%NAME%_SOFTWARE_Hive_ripped.txt&lt;br /&gt;&lt;br /&gt;@ECHO     Ripping SECURITY Hive&lt;br /&gt;@rip.exe -r %DST%\%NAME%\vol\%NAME%_SECURITY_Hive -f sam   &gt; %DST%\%NAME%\vol\%NAME%_SECURITY_Hive_ripped.txt&lt;br /&gt;&lt;br /&gt;Nice huh!  So now, you can add this little snippet to your own volatile collection script.  For more on reg.exe, you can also just run, "reg /?"...&lt;br /&gt;&lt;br /&gt;C:\tools&gt;reg /?&lt;br /&gt;&lt;br /&gt;Console Registry Tool for Windows - version 3.0&lt;br /&gt;Copyright (C) Microsoft Corp. 1981-2001.  All rights reserved&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;REG Operation [Parameter List]&lt;br /&gt;&lt;br /&gt;Operation  [ QUERY   | ADD    | DELETE  | COPY    |&lt;br /&gt;           SAVE    | LOAD   | UNLOAD  | RESTORE |&lt;br /&gt;           COMPARE | EXPORT | IMPORT ]&lt;br /&gt;&lt;br /&gt;Return Code: (Except of REG COMPARE)&lt;br /&gt;&lt;br /&gt;0 - Succussful&lt;br /&gt;1 - Failed&lt;br /&gt;&lt;br /&gt;For help on a specific operation type:&lt;br /&gt;&lt;br /&gt;REG Operation /?&lt;br /&gt;&lt;br /&gt;Examples:&lt;br /&gt;&lt;br /&gt;REG QUERY /?&lt;br /&gt;REG ADD /?&lt;br /&gt;REG DELETE /?&lt;br /&gt;REG COPY /?&lt;br /&gt;REG SAVE /?&lt;br /&gt;REG RESTORE /?&lt;br /&gt;REG LOAD /?&lt;br /&gt;REG UNLOAD /?&lt;br /&gt;REG COMPARE /?&lt;br /&gt;REG EXPORT /?&lt;br /&gt;REG IMPORT /?&lt;br /&gt;&lt;br /&gt;As you can see from my script, I used reg save...&lt;br /&gt;&lt;br /&gt;C:\tools&gt;reg save /?&lt;br /&gt;&lt;br /&gt;Console Registry Tool for Windows - version 3.0&lt;br /&gt;Copyright (C) Microsoft Corp. 1981-2001.  All rights reserved&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;REG SAVE KeyName FileName&lt;br /&gt;&lt;br /&gt;KeyName    ROOTKEY\SubKey&lt;br /&gt;  ROOTKEY  [ HKLM | HKCU | HKCR | HKU | HKCC ]&lt;br /&gt;  SubKey   The full name of a registry key under the selected ROOTKEY&lt;br /&gt;FileName   The name of the disk file to save. If no path is specified, the&lt;br /&gt;           file is created in the current folder of the calling process&lt;br /&gt;&lt;br /&gt;Examples:&lt;br /&gt;&lt;br /&gt;REG SAVE HKLM\Software\MyCo\MyApp AppBkUp.hiv&lt;br /&gt;  Saves the hive MyApp to the file AppBkUp.hiv in the current folder&lt;br /&gt;&lt;br /&gt;***Remember...I am running this against a LIVE system!  As far as I know, without either using reg.exe or something like FTK Imager, you cannot access the registry hives from a live system.***&lt;br /&gt;&lt;br /&gt;Now, you would pretty much repeat the same process for ntuser.dat files, only instead of entering the hive information, you would use HKU (instead of HKLM) followed by a backslash and the SID of the specific user.  Here is what the syntax looks like for the admin account on my XP box...&lt;br /&gt;&lt;br /&gt;c:\tools&gt;reg save hku\S-1-5-21-746137067-1547161642-839522115-500 outputfile.dat&lt;br /&gt;&lt;br /&gt;Now, this may be "old new" to some of you, but I will tell you that for me...and I have been doing this for about seven years now...I had not heard of or used reg.exe until this week.  AND, I have never seen it scripted before as part of a volatile collection script.  It's not to say that it hasn't been done already, just that I have not seen it.&lt;br /&gt;&lt;br /&gt;So...now, you can easily write a batch file that will dump RAM, grab volatile data, copy the registry hives and parse them, and copy ntuser.dat files and parse them.  Total time saver!&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;Happy Hunting!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2143685297099659544?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2143685297099659544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/dumpy-goodness.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2143685297099659544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2143685297099659544'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/dumpy-goodness.html' title='Dumpy Goodness'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-9051788194248084431</id><published>2011-02-14T08:50:00.003-06:00</published><updated>2011-02-14T13:24:08.399-06:00</updated><title type='text'>Windows Registry Forensics Released!</title><content type='html'>I  received my copy of &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan Carvey's&lt;/a&gt;, "&lt;span style="font-style: italic;"&gt;&lt;a href="http://www.amazon.com/Windows-Registry-Forensics-Advanced-Forensic/dp/1597495808"&gt;Windows Registry Forensics&lt;/a&gt;" &lt;/span&gt;over the weekend and I am really excited to start reading it!&lt;br /&gt;&lt;br /&gt;The registry is a GOLD MINE of forensic artifacts that can really put some teeth in your investigations.  If you do not have this book yet, BUY IT!!!  Harlan has not disappointed yet with any of his published works, and I don't expect this will be any different.&lt;br /&gt;&lt;br /&gt;Look for a book review from me in the coming weeks.  But seriously, if you are doing forensic investigations on Windows systems, and you don't yet have a copy of this book, you are really missing something.  You have NO IDEA how useful this information can be!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-9051788194248084431?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/9051788194248084431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/windowa-registry-forensics-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9051788194248084431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9051788194248084431'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/02/windowa-registry-forensics-released.html' title='Windows Registry Forensics Released!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2774062169581691802</id><published>2011-01-21T09:17:00.003-06:00</published><updated>2011-01-21T09:19:43.233-06:00</updated><title type='text'>Sniper Forensics Part 2 Posted</title><content type='html'>I have posted part two of Sniper Forensics to the&lt;a href="http://blog.spiderlabs.com/"&gt; SpiderLabs Anterior blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Check it out!  Great stuff! (or at least I think so)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/TTmjzgGA4HI/AAAAAAAAANs/9wFo8VKdBrc/s1600/screenshot2.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 200px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/TTmjzgGA4HI/AAAAAAAAANs/9wFo8VKdBrc/s320/screenshot2.jpg" alt="" id="BLOGGER_PHOTO_ID_5564658919776772210" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2774062169581691802?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2774062169581691802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/01/sniper-forensics-part-2-posted.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2774062169581691802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2774062169581691802'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/01/sniper-forensics-part-2-posted.html' title='Sniper Forensics Part 2 Posted'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XcfI2W3KXa8/TTmjzgGA4HI/AAAAAAAAANs/9wFo8VKdBrc/s72-c/screenshot2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-252881969472876850</id><published>2011-01-19T13:01:00.004-06:00</published><updated>2011-01-19T13:11:03.831-06:00</updated><title type='text'>SpiderLabs Anterior - Sniper Forensics</title><content type='html'>Sniper Forensics: Part 1&lt;br /&gt;&lt;br /&gt;I have recently blogged about the Sniper Forensics methodology at the &lt;a href="http://blog.spiderlabs.com/"&gt;SpiderLabs Anterior&lt;/a&gt; blog...which is THE official blog of the Trustwave SpiderLabs.  Check it out!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_XcfI2W3KXa8/TTc257-KjMI/AAAAAAAAANk/oZsFXa1T8rc/s1600/Picture%2B1.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 212px;" src="http://3.bp.blogspot.com/_XcfI2W3KXa8/TTc257-KjMI/AAAAAAAAANk/oZsFXa1T8rc/s320/Picture%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5563976233618410690" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-252881969472876850?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/252881969472876850/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/01/spiderlabs-anterior-sniper-forensics.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/252881969472876850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/252881969472876850'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2011/01/spiderlabs-anterior-sniper-forensics.html' title='SpiderLabs Anterior - Sniper Forensics'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_XcfI2W3KXa8/TTc257-KjMI/AAAAAAAAANk/oZsFXa1T8rc/s72-c/Picture%2B1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-4973272882498699986</id><published>2010-11-16T08:26:00.002-06:00</published><updated>2010-11-16T08:28:20.597-06:00</updated><title type='text'>Sniper Forensics Videos!</title><content type='html'>The kind folks at SecTor just posted the &lt;a href="http://www.sector.ca/presentations.htm"&gt;videos&lt;/a&gt; from SecTor 2010!  ALSO, there is a link there for the videos from 2009.&lt;br /&gt;&lt;br /&gt;If you have not had a chance to see either of the Sniper Forensics talks, now is your chance to download the videos or the slide decks!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-4973272882498699986?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/4973272882498699986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/11/sniper-forensics-videos.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/4973272882498699986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/4973272882498699986'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/11/sniper-forensics-videos.html' title='Sniper Forensics Videos!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-1126385224983722970</id><published>2010-10-27T07:26:00.003-05:00</published><updated>2010-10-27T07:49:20.553-05:00</updated><title type='text'>Sniper Forensics 2.0 Tools, Links, and Commands</title><content type='html'>OK...so I figured that there would be a lot of questions about the tools I use and the command syntax that I covered in SF2.  There is obviously a LOT I was not able to cover due to time constraints, so if anyone has any specific questions about which tools do what, how to use them, and how to interpret the output, please let me know and I will create a FAQ blog post.&lt;br /&gt;&lt;br /&gt;Thank you for attending my talk!  I hope you get out of it as much I put into it!&lt;br /&gt;&lt;br /&gt;Happy Hunting!&lt;br /&gt;&lt;br /&gt;Tools&lt;br /&gt;====&lt;br /&gt;F-Response (http://www.f-response.com/)&lt;br /&gt;Memoryze (http://www.mandiant.com/products/free_software/memoryze/)&lt;br /&gt;Audit Viewer ( http://www.mandiant.com/products/free_software/mandiant_audit_viewer/)&lt;br /&gt;UnxUtils (http://sourceforge.net/projects/unxutils/)&lt;br /&gt;Grep (http://gnuwin32.sourceforge.net/packages/grep.htm)&lt;br /&gt;TextPad (http://www.textpad.com/download/)&lt;br /&gt;Case Notes (http://www.qccis.com/forensic-tools)&lt;br /&gt;The Sleuth Kit (http://www.sleuthkit.org/sleuthkit/download.php)&lt;br /&gt;Log2Timeline (http://log2timeline.net/)&lt;br /&gt;SIFT Workstation (https://computer-forensics2.sans.org/community/siftkit/)&lt;br /&gt;AnalyzeMFT (http://www.integriography.com/)&lt;br /&gt;RegRipper (http://regripper.net/?page_id=150)&lt;br /&gt;RipXP (http://regripper.net/?page_id=150)&lt;br /&gt;FTK Imater 3.0 (http://www.accessdata.com/downloads.html)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Syntax&lt;br /&gt;=====&lt;br /&gt;Use these commands to rip registry hives.&lt;br /&gt;C:\tools\RegRipper\rip.exe –r c:\cases\customerX\registry\SAM –f SAM &gt; c:\cases\ripped\systemY_sam_ripped.txt&lt;br /&gt;&lt;br /&gt;C:\tools\RegRipper\rip.exe –r c:\cases\customerX\registry\system –f System&gt; c:\cases\ripped\systemY_system_ripped.txt&lt;br /&gt;&lt;br /&gt;C:\tools\RegRipper\rip.exe –r c:\cases\customerX\registry\ntuser.dat –f ntuser&gt; c:\cases\ripped\systemY_ntuser.dat.userX_ripped.txt&lt;br /&gt;&lt;br /&gt;Use these commands to create a bodyfile and timeline.  If you want a more detailed explanation of how to generate timelines, read my blog posts about timeline creation.&lt;br /&gt;&lt;br /&gt;C:\tools\TSK\fls –m ‘C:/’ –f ntfs –r \\.\F: &gt; c:\cases\customerX\timelines\systemY_bodyfile&lt;br /&gt;&lt;br /&gt;Perl C:\tools\TSK\mactime.pl –d –b C:\cases\customerX\timelines\systemY_bodyfile\systemY_timeline.csv&lt;br /&gt;&lt;br /&gt;You can add logs to your bodyfile with Log2Timeline&lt;br /&gt;C:\&gt;Perl C:\Perl\bin\Log2timeline –t &lt;log&gt; &gt;&gt; c:\cases\customerX\timelines\systemY_bodyfile&lt;br /&gt;You can hives and NTUSER.dat files to your bodyfile with regtime&lt;br /&gt;C:\&gt;Perl C:\tools\bin\regtime.pl –m HKLM/system –r c:\cases\customerX\hives\system &gt;&gt; \c:\cases\customerX\timelines\systemY_bodyfile&lt;br /&gt;&lt;br /&gt;Search for suspect keywords&lt;br /&gt;C:\cases\customerX\ripped&gt;strings *.txt | grep –i &lt;keyword&gt;&lt;br /&gt;C:\cases\customerX\timeline&gt;strings *.csv | grep –i &lt;keyword&gt;&lt;br /&gt;&lt;br /&gt;Search for suspect timeframe&lt;br /&gt;C:\cases\customerX\ripped&gt;strings *.txt | grep –i &lt;date&gt;&lt;br /&gt;C:\cases\customerX\timeline&gt;strings *.csv | grep –i &lt;date&gt;&lt;br /&gt;&lt;br /&gt;Know how to stack your searches!  CRITICAL!!!&lt;br /&gt;&lt;br /&gt;Grep –i &lt;keyword&gt; | grep –i &lt;date&gt;&lt;br /&gt;Grep –i &lt;year&gt; | grep –i &lt;month&gt; | grep –i &lt;time&gt;&lt;br /&gt;Grep –o &lt;keyword&gt;&lt;br /&gt;Gawk “{print $#}”&lt;br /&gt;Cut –d&lt;delimiter&gt; -f#&lt;br /&gt;&lt;br /&gt;Search for suspected date, all files “born” on that date.&lt;br /&gt;&lt;br /&gt;C:\cases\customerX\timeline&gt;strings_hostname_timeline.csv | grep -i "may 26 2010" | grep "..b,r"&lt;/delimiter&gt;&lt;/keyword&gt;&lt;/time&gt;&lt;/month&gt;&lt;/year&gt;&lt;/date&gt;&lt;/keyword&gt;&lt;/date&gt;&lt;/date&gt;&lt;/keyword&gt;&lt;/keyword&gt;&lt;/log&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-1126385224983722970?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/1126385224983722970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/sniper-forensics-20-tools-links-and.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1126385224983722970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1126385224983722970'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/sniper-forensics-20-tools-links-and.html' title='Sniper Forensics 2.0 Tools, Links, and Commands'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-148364552845318897</id><published>2010-10-24T17:42:00.005-05:00</published><updated>2010-10-24T17:50:32.934-05:00</updated><title type='text'>SecTor 2010 - Debuting SF2</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/TMS2fJnTN7I/AAAAAAAAANI/Zs_K1uAyL80/s1600/sector_logo.jpg"&gt;&lt;img style="cursor: pointer; width: 341px; height: 75px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/TMS2fJnTN7I/AAAAAAAAANI/Zs_K1uAyL80/s320/sector_logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5531746888590768050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will be debuting the second version of Sniper Forensics, titled, "Target Acquisition" at SecTor in Toronto, Ontario, Canada on October 27th.  It's a great conference and I couldn't be more excited!&lt;br /&gt;&lt;br /&gt;Here are some quotes about what others are saying about SF2!&lt;br /&gt;&lt;br /&gt;“As environments continue to grow in size and complexity, incident response teams entrenched in the “image everything” methodology will find themselves not able to understand the situation as fast as the threat is evolving within a target environment. Adopting the Sniper Forensics Methodology, will decrease the cost of the investigations while providing results many times faster over traditional approaches when applied to modern environments.”&lt;br /&gt;&lt;br /&gt;- Nicholas Percoco&lt;br /&gt;Senior Vice President, Trustwave SpiderLabs&lt;br /&gt;&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;“If you have a specific goal, you are much more likely to achieve it. Knowing what you want out of an investigation, before you start, will help you know when you're finished.”&lt;br /&gt;&lt;br /&gt;- Jesse Kornblum&lt;br /&gt;Computer Forensics Research Guru, Kyrus Technology&lt;br /&gt;&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;"Using F-Response as part of the "Sniper Forensics" model is the perfect logical extension of our original mission. Get answers, not just information."&lt;br /&gt;&lt;br /&gt;- Matt Shannon&lt;br /&gt;Founder, F-Response&lt;br /&gt;&lt;br /&gt;=============================&lt;br /&gt;&lt;br /&gt;“'Sniper Forensics: Target Acquisition' walks up to an analyst and slaps him right in the face!  Here are targeted tools and techniques, straight from successful field ops, that every analyst needs to know!   Once you've defined your target, go grab the data you need, and optimize your time and resources to get the job done!”&lt;br /&gt;&lt;br /&gt;- Harlan Carvey&lt;br /&gt;Vice President of Advanced Technical Projects, Terremark Worldwide&lt;br /&gt;Author of “Windows Forensic Analysis 2nd Edition”&lt;br /&gt;Author of the Blog, “WindowsIR.blogspot.com”&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_XcfI2W3KXa8/TMS3w4-JzyI/AAAAAAAAANQ/yYt3jtqaWuU/s1600/sector_name.jpg"&gt;&lt;img style="cursor: pointer; width: 211px; height: 145px;" src="http://3.bp.blogspot.com/_XcfI2W3KXa8/TMS3w4-JzyI/AAAAAAAAANQ/yYt3jtqaWuU/s320/sector_name.jpg" alt="" id="BLOGGER_PHOTO_ID_5531748292872490786" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-148364552845318897?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/148364552845318897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/sector-2010-debuting-sf2.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/148364552845318897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/148364552845318897'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/sector-2010-debuting-sf2.html' title='SecTor 2010 - Debuting SF2'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XcfI2W3KXa8/TMS2fJnTN7I/AAAAAAAAANI/Zs_K1uAyL80/s72-c/sector_logo.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2792995059461009309</id><published>2010-10-23T13:54:00.004-05:00</published><updated>2010-10-23T14:01:01.067-05:00</updated><title type='text'>The “Not So” Perfect Keylogger</title><content type='html'>I have seen a number of cases lately in which the method of data aggregation on Point of Sale Terminals was the use of &lt;a href="http://www.blazingtools.com/"&gt;Blazing Tools Perfect Keylogger&lt;/a&gt;.  This is a commercial tool that is used to track the computer use of individuals within a family or a company.  This blog is not about the legality or ethics of this tool, but rather about the technical specifics when looking for this tool during a compromise.&lt;br /&gt;&lt;br /&gt;Below, is a timeline excerpt from a case I was working recently in which I saw Perfecet Keylogger running natively (ie…under the default naming convention).  It should be noted, that the means of infiltration in 99% of these cases in an open remote administration port and default administrative passwords.  This gave the intruders an easy path onto the target systems, and the credentials necessary to install the malware.&lt;br /&gt;&lt;br /&gt;Pay special attention if you will, to the file names besides bpk.exe, specifically the letters after the “k” in “bpk”.&lt;br /&gt;&lt;br /&gt;F:\timelines&gt;strings _timeline.csv | grep -i bpk&lt;br /&gt;Fri Aug 21 2009 02:42:56,499712,m..b,r/rrwxrwxrwx,0,0,13919-128-3,'C:/'/WINDOWS/system32/bpk.exe&lt;br /&gt;Fri Aug 21 2009 02:42:56,19456,m..b,r/rrwxrwxrwx,0,0,13920-128-3,'C:/'/WINDOWS/system32/bpkr.exe&lt;br /&gt;Fri Aug 21 2009 02:42:56,19968,m..b,r/rrwxrwxrwx,0,0,13922-128-3,'C:/'/WINDOWS/system32/bpkhk.dll&lt;br /&gt;Fri Sep 04 2009 01:12:50,188895,ma.b,r/rrwxrwxrwx,0,0,14008-128-3,'C:/'/WINDOWS/security/bpk.chm&lt;br /&gt;Mon Oct 19 2009 07:02:03,623,ma.b,r/rrwxrwxrwx,0,0,13996-128-1,'C:/'/WINDOWS/system32/bpk.dat&lt;br /&gt;Sat Aug 21 2010 02:43:06,22586,...b,r/rrwxrwxrwx,0,0,13923-128-4,'C:/'/WINDOWS/Prefetch/BPK.EXE-06BA93D1.pf&lt;br /&gt;&lt;br /&gt;As you can see, some of the key file names associated with Perfect Keylogger are: bpk.exe, bpkr.exe, bpkhk.dll, bpk.dat, and the configuration file not listed in the first timeline excerpt, pk.bin.  These files are normally found in the C:\Windows\System32 directory, but can really run from any custom location, as indicated by the second timeline excerpt.  When it’s seen in a RAM dump, it looks like this:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_XcfI2W3KXa8/TMMvpQ0mrvI/AAAAAAAAAM4/YZ26MpG_YYQ/s1600/bpk_ram1.JPG"&gt;&lt;img style="cursor: pointer; width: 282px; height: 120px;" src="http://1.bp.blogspot.com/_XcfI2W3KXa8/TMMvpQ0mrvI/AAAAAAAAAM4/YZ26MpG_YYQ/s320/bpk_ram1.JPG" alt="" id="BLOGGER_PHOTO_ID_5531317153277849330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Below is a second example, in which the naming convention has been changed to confuse the would be investigator.  Look at the letters after the “t” in “wuault.exe”.  Do they look familiar?  They should!&lt;br /&gt;&lt;br /&gt;F:\timelines&gt;strings timeline.csv | grep -i wuault&lt;br /&gt;Fri Sep 04 2009 01:34:51,438272,m..b,r/rrwxrwxrwx,0,0,14055-128-3,'C:/'/WINDOWS/security/wuault.exe&lt;br /&gt;Fri Sep 04 2009 01:34:51,24576,m..b,r/rrwxrwxrwx,0,0,14056-128-3,'C:/'/WINDOWS/security/wuaulthk.dll&lt;br /&gt;Fri Sep 04 2009 01:34:51,40960,m..b,r/rrwxrwxrwx,0,0,14059-128-3,'C:/'/WINDOWS/security/wuaultwb.dll&lt;br /&gt;Fri Sep 04 2009 01:34:51,215040,m..b,r/rrwxrwxrwx,0,0,14060-128-3,'C:/'/WINDOWS/security/wuaulti.dll&lt;br /&gt;Fri Sep 04 2009 01:34:51,7680,m..b,r/rrwxrwxrwx,0,0,14061-128-3,'C:/'/WINDOWS/security/wuaultr.exe&lt;br /&gt;Sat Sep 04 2010 05:44:06,16674,...b,r/rrwxrwxrwx,0,0,13976-128-4,'C:/'/WINDOWS/Prefetch/WUAULT.EXE-0E3FBF35.pf&lt;br /&gt;&lt;br /&gt;When captured in a RAM dump, it looks like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/TMMwALRgobI/AAAAAAAAANA/td5q_RHKtZc/s1600/renamed_bpk2.JPG"&gt;&lt;img style="cursor: pointer; width: 297px; height: 120px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/TMMwALRgobI/AAAAAAAAANA/td5q_RHKtZc/s320/renamed_bpk2.JPG" alt="" id="BLOGGER_PHOTO_ID_5531317546925466034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Notice that the path is C:\windows\security.  Also of note, look at the timeline above…see the “birth” date in my timeline?  It says “Fri Aug 21 2009 02:42:56”, but the first prefetch file shows a timestamp of, “Sat Aug 21 2010 02:43:06”.  About 10 seconds later…exactly one year later?  What’s up with that?  Well…let me tell you, but first, let’s quickly go over the Master File Table ($MFT), specifically the Standard_Information ($S_I), and File_Name ($F_N) attributes.&lt;br /&gt;REAL basically, we all know that the $MFT holds information about the files on the disk.  Well, one of those attributes, the $S_I, is accessible by the operating system (OS) and the user.  So, what…that means that they can be changed, accessed, and yes…stomped.  BUT, the $F_N attribute is not touched by anything except the kernel. So what does that mean?  It means no modifications by the OS or the user…ie…no stomping.&lt;br /&gt;&lt;br /&gt;So, &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan&lt;/a&gt; sent me a Perl script he wrote which goes through the $MFT and extracts and parses the $S_I and $F_N attributes.  So with our friend bpk.exe, it would look like this:&lt;br /&gt;&lt;br /&gt;13919      FILE 14   1    0x38 4     1&lt;br /&gt;0x0010 96   0   0x0000&lt;br /&gt;0x0000&lt;br /&gt; M: Fri Aug 21 07:42:56 2009 Z&lt;br /&gt; A: Tue Oct 19 16:24:13 2010 Z&lt;br /&gt; C: Tue Oct 19 16:12:26 2010 Z&lt;br /&gt; B: Fri Aug 21 07:42:56 2009 Z &lt;span style="font-weight: bold; font-style: italic;"&gt; ← This is the “modified” birth date of the file on the system.&lt;/span&gt;&lt;br /&gt;0x0030 104  0   0x0000&lt;br /&gt;0x0000&lt;br /&gt;FN: bpk.exe  Parent Ref: 847  Parent Seq: 1&lt;br /&gt; M: Sat Aug 21 07:42:56 2010 Z&lt;br /&gt; A: Sat Aug 21 07:42:56 2010 Z&lt;br /&gt; C: Sat Aug 21 07:42:56 2010 Z&lt;br /&gt; B: Sat Aug 21 07:42:56 2010 Z &lt;span style="font-weight: bold; font-style: italic;"&gt; ← This is the actual “birth” date of the file on the system.&lt;/span&gt;&lt;br /&gt;0x0080 88   1   0x0000&lt;br /&gt;0x0000&lt;br /&gt;&lt;br /&gt;And…it matches our Prefetch file, which further supports our finding that the timestamps have been modified.  So be wary…if you come across Perfect Keylogger in a case, it will be offset by one year – I have seen this to be true in every Perfect Keylogger case I have worked, and it seems to be done as part of the install script.  Now, while I have seen the binaries and associated dlls renamed, I have not seen the dump file (bpk.dat) or the configuration file (pk.bin) renamed.  After downloading a trial version of Perfect Keylogger, I can see that you can change the output file, and path, so it’s possible…but like I said…just never seen it.  I’m not certain the same can be said for the configuration file.  I have tried several times unsuccessfully, so I think it may be hard coded into the program.&lt;br /&gt;&lt;br /&gt;So if you try to open the bpk.dat, and the pk.bin they appear to be encrypted.  Or are they?  Through the efforts of the SpiderLabs Research Team, we found that they are NOT really encrypted, but rather encoded with a single xor key, 0xAA.  So, when you use a simple xor script, against either one, you may get something that looks like this (since this was from a real case, I have modified the output, but the methods and the output format looks the same):&lt;br /&gt;&lt;br /&gt;PK Password:     "y0uv3b33np0wn3d"&lt;br /&gt;License Name:    "www.hacked.ws"&lt;br /&gt;License:         "PGTDFADBEPRCHGB"&lt;br /&gt;Email Enabled?:  true&lt;br /&gt;SMTP Server:     "10.10.10.10"&lt;br /&gt;SMTP Port:       25&lt;br /&gt;SMTP Username:   "user"&lt;br /&gt;SMTP Password:   "p@ssw0rd"&lt;br /&gt;Email Address:   "p0wn3d@hackmemail.com"&lt;br /&gt;FTP Enabled?:    false&lt;br /&gt;Hotkey Hex:      keycode=0xdc modifier=0x07&lt;br /&gt;Key-combo:       SHIFT + CTRL + ALT + 6&lt;br /&gt;&lt;br /&gt;So, this is great! You have the attacker’s email, the server he was using, his username and password!  Better yet, you have the key-combo which is used to bring the Keylogger out of hidden mode. If the attacker wanted to use FTP instead of SMTP, you would see the same type of login information as you do for the SMTP example provided above. If you know that it’s running, but you don’t see the icon in the bottom of the screen, it’s in hidden mode.  Simply use this key combination, and BAM, the icon will suddenly appear!  Then, simply enter in the “PK Password” and you have access to the admin console of the keylogger!  This configuration file will give you access to the time intervals in which the dump file is emailed or FTP’d.  Pretty slick eh!&lt;br /&gt;&lt;br /&gt;Now, it also uses the same xor to encode the dump file!  So if you run the same xor script, you may see something that looks like this:&lt;br /&gt;&lt;br /&gt;F:\ &gt;cat bpk.dat.out&lt;br /&gt;06-09-2010 03:22&lt;br /&gt;wuault.exe&lt;br /&gt;BlazingTools Perfect Keylogger: Options&lt;br /&gt;[Password captured: p@ssw0rd]&lt;br /&gt;15&lt;br /&gt;$#$#$#$#$#$#$#$#$#$#$#$#$#$&lt;br /&gt;19-10-2010 10:53&lt;br /&gt;Explorer.EXE&lt;br /&gt;Run&lt;br /&gt;cmd&lt;br /&gt;$#$#$#$#$#$#$#$#$#$#$#$#$#$&lt;br /&gt;19-10-2010 10:54&lt;br /&gt;cmd.exe&lt;br /&gt;C:\WINDOWS\system32\cmd.exe&lt;br /&gt;d:&lt;br /&gt;dir&lt;br /&gt;mkdir images&lt;br /&gt;cd im&lt;br /&gt;$#$#$#$#$#$#$#$#$#$#$#$#$#$&lt;br /&gt;19-10-2010 10:56&lt;br /&gt;cmd.exe&lt;br /&gt;C:\WINDOWS\system32\cmd.exe&lt;br /&gt;mkdir vol&lt;br /&gt;&lt;br /&gt;Nice!  Note that if you don’t have any scripting-fu (Perl, Ruby, Python, etc) you can simply install the trial version of Perfect Keylogger in a vmimage, and use the “view the log” option to see the decoded versions of the logs.&lt;br /&gt;&lt;br /&gt;Additionally, the only registry entries I have seen for Perfect Keylogger are in the UserAssist key of an ntuser.dat file, showing initial execution, and in the RUN key of the SOFTWARE hive, showing that it’s set to start up at reboot.&lt;br /&gt;&lt;br /&gt;NTUSER.DAT – UserAssist Key&lt;br /&gt;=========================&lt;br /&gt;UEME_RUNPATH:C:\Documents and Settings\&lt;user&gt;\Desktop\i_bpk2007.exe (3) ← Indicates execution of the installation binary.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Software Hive&lt;br /&gt;=========&lt;br /&gt;Software\Microsoft\Windows\CurrentVersion\Run&lt;br /&gt;C:\P15xx\DisableWriteCache.exe -s all&lt;br /&gt;"C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper&lt;br /&gt;C:\WINDOWS\System32\bpk.exe  ← Indicates that the keylogger will start each time the system boots.&lt;br /&gt;&lt;br /&gt;So, if you are working on a case and you expect that you may have Perfect Keylogger, here are the key indicators of compromise:&lt;br /&gt;&lt;br /&gt;Presence of:&lt;br /&gt;•    pk.bin, or bpk.dat (configuration or dump files)&lt;br /&gt;•    bpk.exe, wuault.exe, wuauclt.exe (running from the incorrect directory)&lt;br /&gt;•    binary and dlls timestopmed (check the $MFT)&lt;br /&gt;•    Entries in the ntuser.dat and SOFTWARE hives&lt;br /&gt;•    Active process running RAM with the same ending letters (as seen in the timeline example)&lt;br /&gt;&lt;br /&gt;You can decode the configuration file and dump files with a simple xor, 0xAA key.  Alternatively, you can use the demo version of the keylogger itself to open the dump file.&lt;br /&gt;&lt;br /&gt;Good luck, and happy hunting!&lt;br /&gt;&lt;br /&gt;&lt;/user&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2792995059461009309?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2792995059461009309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/not-so-perfect-keylogger.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2792995059461009309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2792995059461009309'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/not-so-perfect-keylogger.html' title='The “Not So” Perfect Keylogger'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_XcfI2W3KXa8/TMMvpQ0mrvI/AAAAAAAAAM4/YZ26MpG_YYQ/s72-c/bpk_ram1.JPG' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7432800225182353021</id><published>2010-10-12T10:03:00.002-05:00</published><updated>2010-10-12T10:07:46.324-05:00</updated><title type='text'>Call for quotes</title><content type='html'>I will be delivering Sniper Forensics v2.0 - Target Acquisition at &lt;a href="http://www.sector.ca/"&gt;SecTor&lt;/a&gt; this month in Toronto, Canada.  To add some down home flavor to the preso, I would like to issue a "call for quotes" to anyone who uses the Sniper Forensics methodology.  I will use between 5 and 10 quotes depending on your responses...so...I may not use any!  But please, if you have heard my talk or read about it, and use the SF methodology, please let me know what you think!&lt;br /&gt;&lt;br /&gt;Thanks!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7432800225182353021?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7432800225182353021/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/call-for-quotes.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7432800225182353021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7432800225182353021'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/10/call-for-quotes.html' title='Call for quotes'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7969821937721459419</id><published>2010-08-27T08:13:00.003-05:00</published><updated>2010-08-27T08:36:36.050-05:00</updated><title type='text'>Court Approved?</title><content type='html'>I continue to hear this phrase mentioned by fellow forensicators in email lists and at conferences, so I thought I would, once again, help to dispel the myth. &lt;br /&gt;&lt;br /&gt;THERE IS NO SUCH THING AS COURT APPROVED TOOLS.&lt;br /&gt;&lt;br /&gt;Saying that one tool is court approved and another is not, is like saying you can take crime scene photos with a Nikon, but not a Kodak.  It's just silly, and it's a myth perpetuated by those who seek to benefit from the existence of such a rumor. &lt;br /&gt;&lt;br /&gt;Now, there ARE tools that have been used in court cases, which may be more familiar to attorneys and/or judges.  This does NOT make them court approved, it simply means that they have been used before...nothing more.  Pay careful attention to what I am writing here...simply using a tool...any tool...DOES NOT make your findings any more relevant, valid, or indisputable then if you had used any other tool to come to the same conclusions.  The data is simply the data.&lt;br /&gt;&lt;br /&gt;Your job as a forensic investigator is to produce forensically sound results.  This too is a term that is often used incorrectly or as a buzz word.  Forensically sound means that if given the same set of data, any other investigator, using any other tool, would come to the same conclusion. &lt;br /&gt;&lt;br /&gt;Now really think about what this means.  Let's say you have been asked to identify a date range for files in a specific directory.  If given the same image, 10 different people, using 10 different tools, should come to the exact same results...EnCase, FTK, TSK, MFL, Perl scripts, Python, whatever...the conclusion should be the same because the means by which you would extract that data is the same.&lt;br /&gt;&lt;br /&gt;The implications of a conclusion being forensically sound invalidate the entire premise of something being court approved.  How can one tool that comes to the same conclusion as another tool be approved while the other is not?  They DO the same THING.  While the GUI may change, or the vendor - open source code versus proprietary - Linux versus Windows...it doesn't matter.  The data is the data.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7969821937721459419?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7969821937721459419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/08/court-approved.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7969821937721459419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7969821937721459419'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/08/court-approved.html' title='Court Approved?'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3394772066120991272</id><published>2010-08-05T09:01:00.002-05:00</published><updated>2010-08-05T09:05:07.178-05:00</updated><title type='text'>Surgery!</title><content type='html'>In case you haven't noticed, I have not posted anything in awhile.  That is due to the fact that last week during Black Hat, DEF CON, BSIDES week, my wife ended up in the Emergency Room, and surgery.&lt;br /&gt;&lt;br /&gt;She is OK now, an at home recovering, but obviously my focus had to shift from forensics to my family.  Once she is back on her feet and feeling better, I will be back to my usual forensic-y goodness.&lt;br /&gt;&lt;br /&gt;I also want to give a HUGE thanks to all of you from BSIDES and SANS for sending me your thoughts and prayers.  I also want to issue s public apology to the folks at The Next HOPE conference and DEF CON for having to miss my speaking engagements.  You have my most sincere apologies, and hope you realize that my absence was a significant medical issue. &lt;br /&gt;&lt;br /&gt;Thanks again!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3394772066120991272?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3394772066120991272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/08/surgery.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3394772066120991272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3394772066120991272'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/08/surgery.html' title='Surgery!'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-6494910072327586305</id><published>2010-07-11T20:38:00.002-05:00</published><updated>2010-07-12T08:03:49.762-05:00</updated><title type='text'>SANS What Works 2010 - HUGE Success</title><content type='html'>This past week, I had the great privilege of attending and speaking at the&lt;a href="http://www.sans.org/forensics-incident-response-summit-2010/"&gt; SANS What Works in Incident Response Summit&lt;/a&gt; in Washington, DC.&lt;br /&gt;&lt;br /&gt;The Conference once again had some of the best speakers in the world of incident response and forensics including, Major &lt;a href="http://www.linkedin.com/ppl/webprofile?vmi=&amp;amp;id=62705871&amp;amp;pvs=pp&amp;amp;authToken=MfRo&amp;amp;authType=name&amp;amp;locale=en_US&amp;amp;trk=ppro_viewmore&amp;amp;lnk=vw_pprofile"&gt;Carol Newell&lt;/a&gt; of the&lt;a href="http://www.brokenarrowok.gov/Index.aspx?page=64"&gt; Broken Arrow, OK Police Department&lt;/a&gt;, &lt;a href="http://computer-forensics.sans.org/instructors/author.php"&gt;Rob Lee&lt;/a&gt;, &lt;a href="http://www.windowsir.blogspot.com/"&gt;Harlan Carvey&lt;/a&gt;, &lt;a href="http://jessekornblum.com/"&gt;Jesse Kornblum&lt;/a&gt;, &lt;a href="http://www.zoominfo.com/Search/PersonDetail.aspx?PersonID=78295471"&gt;Troy Larson&lt;/a&gt;, &lt;a href="http://www.linkedin.com/ppl/webprofile?vmi=&amp;amp;id=3125902&amp;amp;pvs=pp&amp;amp;authToken=6jJL&amp;amp;authType=name&amp;amp;locale=en_US&amp;amp;trk=ppro_viewmore&amp;amp;lnk=vw_pprofile"&gt;Kris Harms&lt;/a&gt;, and &lt;a href="http://www.linkedin.com/in/robertshullich"&gt;Robert Shullich&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This is the second year for the conference, and I think that without question, the conference continues to improve.  In a field as dynamic and fluid as Incident Response and Computer Forensics, investigators really need to keep current with not only their skill sets, but with emerging technologies, theories, and methodologies.  This only makes sense, since the "bad guys" we are all trying to catch, are undoubtedly doing the same thing!  This is crux of the summit, and the true value add for the attendees...you get to hear and see what is ACTUALLY working from some of the best minds in the industry.&lt;br /&gt;&lt;br /&gt;The major focus this year was on the new challenges we face with the arrival of Windows 7, which is very different than XP, and Vista.  There are new registry entries, gobs of new event logs, and a new file system layout.  All in all, it going to mean countless hours of research by investigators to be efficient and effective at performing comprehensive forensic investigations.&lt;br /&gt;&lt;br /&gt;The other big takeaway from the conference is the involvement with corporate investigators with law enforcement agencies...something I am a HUGE advocate of!  Look for a LOT MORE of this to come, but the gist is this...LE agencies do not use police for forensic pathology, or for forensic dentistry, or forensic arson investigations.  Why would they?  For this, they would use doctors, dentists, and fireman.  Why?  Because they are subject matter experts in those fields.  Why then, when it comes to computer forensic (arguably one of the most difficult of the forensic sciences - based on the vast array of digital media current in use by the "average" person) do LEs want to keep these types of investigations in house?  Why not treat cases involving digital media, the same way they would any other case involving a forensic scientist, and seek the assistance of subject matter experts?  This is the direction we want to start moving.&lt;br /&gt;&lt;br /&gt;If you are an investigator, and want to start helping in LE cases, here are a few tips from Major Newell:&lt;br /&gt;&lt;br /&gt;1. Certifications...get them!  They look great on the stand, and will help you with the vetting process by the PD and as an expert witness.&lt;br /&gt;&lt;br /&gt;2. Be presentable.  You don't have to be a cover model by any stretch...but you ARE going to be representing the PD or the DA's office.  Dress accordingly!&lt;br /&gt;&lt;br /&gt;3. Letters of recommendation.  Get these from any law enforcement agency, public official, military officer, or business executive you can.  ALSO...get them from fellow investigators...IE...if Rob Lee, Harlan Carvey, and say...Jesse Kornblum say...hey...this guy is legit, then chances are that is going to carry a lot of weight with any respective PD.&lt;br /&gt;&lt;br /&gt;4. Be an effective communicator.  We deal with some of the most technical information in the IT world...and when on the stand, we may have to explain some of that highly technical information to a jury of our "peers"...which according to most PDs, is about as educated as the average 7th grader.  So, know your audience...talk TO them, but never DOWN to them.  Save the $5 words for the lawyers...remember the KISS pronciple on the stand.&lt;br /&gt;&lt;br /&gt;ALSO...there is something I call the, "Your Mom" principle.  If you can get your mom to understand (or some non-technical person provide your mom is either not around, or is in fact an IT engineer as well), then you should be good to go.  Remeber, the goal is to convey the "story" of what happened...without spin...to the jury, not impress them with how smart you are.&lt;br /&gt;&lt;br /&gt;Again, Kudos to Rob Lee and the SANS Institute for putting on yet another fantastic conferece.  I said this last year, and I will say it again...if you only have the funding for one conference per year, THIS IS THE ONE to attend.  There are more expert speakers, more potential to make great contacts, and more opportunity to learn at THIS conference, than any other confernce I have attended or spoken at!  Great job ROB!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-6494910072327586305?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/6494910072327586305/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/07/sans-what-works-2010-huge-success.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6494910072327586305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/6494910072327586305'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/07/sans-what-works-2010-huge-success.html' title='SANS What Works 2010 - HUGE Success'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-9038377516137125521</id><published>2010-06-21T17:29:00.002-05:00</published><updated>2010-06-21T17:35:03.793-05:00</updated><title type='text'>B-SIDESLV 2010</title><content type='html'>Freaking Sweet!  Sniper Foreniscs got picked up for the &lt;a href="http://www.securitybsides.com/BSidesLasVegas"&gt;B-SIDES Security Conference&lt;/a&gt; in Las Vegas on July 28th and 29th...right before DEFCON!  If you are going to be town for DEFCON, check it out!!!&lt;br /&gt;&lt;br /&gt;Going to be at the &lt;a href="http://www.2810vegasestate.com/"&gt;2810 Vegas Estate&lt;/a&gt;...Not too shabby!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_XcfI2W3KXa8/TB_pCA5_faI/AAAAAAAAAMo/mQ8xqYAdVs4/s1600/b-sides-location.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 171px;" src="http://1.bp.blogspot.com/_XcfI2W3KXa8/TB_pCA5_faI/AAAAAAAAAMo/mQ8xqYAdVs4/s320/b-sides-location.jpg" alt="" id="BLOGGER_PHOTO_ID_5485359091972799906" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-9038377516137125521?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/9038377516137125521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/b-sideslv-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9038377516137125521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9038377516137125521'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/b-sideslv-2010.html' title='B-SIDESLV 2010'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_XcfI2W3KXa8/TB_pCA5_faI/AAAAAAAAAMo/mQ8xqYAdVs4/s72-c/b-sides-location.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2714174652858796027</id><published>2010-06-21T08:59:00.004-05:00</published><updated>2010-06-21T09:10:18.270-05:00</updated><title type='text'>Timeline Spikes</title><content type='html'>I was playing with the output from &lt;a href="http://www.sleuthkit.org/sleuthkit/download.php"&gt;The Sleuth Kit&lt;/a&gt;'s &lt;a href="http://www.sleuthkit.org/sleuthkit/man/fls.html"&gt;FLS&lt;/a&gt; (great tool for making timelines) timelines this morning, and I was thinking about file system activity.  Would a spike in activity mean something?  Would a reduction in activity mean something?  Could these deviances from "normal" activity be easily identified?  If they were identified, could you determine the root cause more quickly?&lt;br /&gt;&lt;br /&gt;Well...here are the commands to parse your timelines to show you exactly that...&lt;br /&gt;&lt;br /&gt;To see file system activity represented numerically:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Strings timeline&lt;timeline&gt;.csv | &lt;a href="http://gnuwin32.sourceforge.net/packages/grep.htm"&gt;grep&lt;/a&gt; –i &lt;month&gt; | grep –i &lt;year&gt; | &lt;a href="http://gnuwin32.sourceforge.net/packages/gawk.htm"&gt;gawk&lt;/a&gt; “{print $3}” | sort | uniq –c&lt;/year&gt;&lt;/month&gt;&lt;/timeline&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This command will show you the days of that month, sorted numerically, with a count of the number of hits on that day to the left.  This will show both spikes and lulls as well as letting you get a feel for what “normal” file system activity looks like.&lt;br /&gt;&lt;br /&gt;You can also see which files were created on a certain date:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Strings timeline&lt;/span&gt;&lt;timeline&gt;&lt;span style="font-weight: bold;"&gt;.csv | grep –i &lt;/span&gt;&lt;month&gt;&lt;span style="font-weight: bold;"&gt;, | grep –i &lt;/span&gt;&lt;year&gt;&lt;span style="font-weight: bold;"&gt; | grep –i “...b,r”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This command will show you all of the files “birthed” on that month.  You can also drill down to the day by adding a grep for the specific day...which is actually easier since the format in the timeline is a contiguous &lt;day&gt;.  Or you can pull out a specific directory by adding the path to the end of the command...like this:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Strings &lt;/span&gt;&lt;timeline&gt;&lt;span style="font-weight: bold;"&gt;.csv | grep –i &lt;/span&gt;&lt;month&gt;&lt;span style="font-weight: bold;"&gt; | grep –i &lt;/span&gt;&lt;year&gt;&lt;span style="font-weight: bold;"&gt; | grep –i “...b,r” | grep –i system32&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;One thing that I have noticed in my experience with timelines is that nefarious activity (like file creations, and download activity) is that it occurs in clusters.  When I review my timeline, I will see the bad guys dumping say three or four files onto the target system (usually in the %windir% or %windir%\system32 directories.  So would this activity register as a spike in "normal" activity?  What if you added the Event logs into the timeline with &lt;a href="http://log2timeline.net/"&gt;Log2Timeline&lt;/a&gt;?  Would additional statistical information becmore more clear by simply looking at the numerical count for activity on a specific date?&lt;br /&gt;&lt;br /&gt;I know that this is a really short blog post...sorry...been REALLY busy lately, but I hope that it shows you the possibilities that are available to you when you use the command line and your brain.  Timelines are really really useful pieces of data!&lt;/year&gt;&lt;/month&gt;&lt;/timeline&gt;&lt;/day&gt;&lt;/year&gt;&lt;/month&gt;&lt;/timeline&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2714174652858796027?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2714174652858796027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/timeline-spikes.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2714174652858796027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2714174652858796027'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/timeline-spikes.html' title='Timeline Spikes'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-2193849085560788</id><published>2010-06-03T06:28:00.002-05:00</published><updated>2010-06-03T06:30:53.365-05:00</updated><title type='text'>DEFCON 18 - Sniper Forensics</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/TAeSGrF2wrI/AAAAAAAAAMg/AKRwYx0HWmI/s1600/5.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 98px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/TAeSGrF2wrI/AAAAAAAAAMg/AKRwYx0HWmI/s320/5.JPG" alt="" id="BLOGGER_PHOTO_ID_5478508115063653042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Freaking Sweet!  I just found out this morning that Sniper Forensics was picked up for DEFCON 18!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-2193849085560788?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/2193849085560788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/defcon-18-sniper-forensics.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2193849085560788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/2193849085560788'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/06/defcon-18-sniper-forensics.html' title='DEFCON 18 - Sniper Forensics'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XcfI2W3KXa8/TAeSGrF2wrI/AAAAAAAAAMg/AKRwYx0HWmI/s72-c/5.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7254218753110925769</id><published>2010-05-28T11:13:00.004-05:00</published><updated>2010-05-28T12:10:57.377-05:00</updated><title type='text'>Case Notes</title><content type='html'>OK...so, if you are not using &lt;a href="http://www.qccis.com/forensic-tools"&gt;Case Notes&lt;/a&gt; (CN) by QCC Information Security, I have to ask, "why not?"&lt;br /&gt;&lt;br /&gt;If you answered, "What's Case Notes?", let me splain.&lt;br /&gt;&lt;br /&gt;Case Notes is an awesome tool for taking notes during your investigations.  Unlike simply using Notepad or Word Pad, Case Notes timestamps your entries, allows you to password protect your notes file, has customizable tabs, and keeps creates an audit log of your activity.&lt;br /&gt;&lt;br /&gt;Once you download and install CN (either 32 or 64 bit version) you are prompted to set up your preferences...like this...&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_XcfI2W3KXa8/S__s8Emr0KI/AAAAAAAAAMQ/9qr6E8gFKn8/s1600/1.JPG"&gt;&lt;img style="cursor: pointer; width: 255px; height: 320px;" src="http://1.bp.blogspot.com/_XcfI2W3KXa8/S__s8Emr0KI/AAAAAAAAAMQ/9qr6E8gFKn8/s320/1.JPG" alt="" id="BLOGGER_PHOTO_ID_5476356188678115490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see, I can set up to 10 fields of metadata such as my name, my agency, the case type etc...very handy.  Then you can customize up to four (4) additional tabs for specific notes.  The main space for notes is a tab called, "Case Notes" and cannot be changed.  You will also have a tab labeled, "Audit Log" which also cannot be changed.  So if you use all four like I did, you will have a total of six tabs.&lt;br /&gt;&lt;br /&gt;I use my tabs to keep track of evidence items...systems, hostnames, IP addresses, etc, Dirty Words (keywords)...stuff I run across that I want to search for on my image(s), Questions that need to be answered and the subsequent answers, and my Investigation plan...what am I trying to accomplish, and why.&lt;br /&gt;&lt;br /&gt;So, once you are all set up, your screen will look like this...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S__uLFe-feI/AAAAAAAAAMY/0Nu2rTmOlEo/s1600/2.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 185px;" src="http://4.bp.blogspot.com/_XcfI2W3KXa8/S__uLFe-feI/AAAAAAAAAMY/0Nu2rTmOlEo/s320/2.JPG" alt="" id="BLOGGER_PHOTO_ID_5476357546123886050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now that we have covered the tool, let's cover the concept.&lt;br /&gt;&lt;br /&gt;Harlan and I were talking this morning and we were wondering why so many investigators don't create an investigation plan.  I mean, it seems like a no brainer doesn't it.  What are you looking for?  What have you been hired to do?  What is the overall purpose of the investigation?  That would be the first thing you should write down. &lt;br /&gt;&lt;br /&gt;Next, you can break the investigation into smaller, more manageable chunks that feed into the overall investigation plan.  This is where you would use the Alexiou principle...&lt;br /&gt;&lt;br /&gt;1. What question are you trying to answer?&lt;br /&gt;2. What data do you need to answer that question?&lt;br /&gt;3. How do you extract and analyze that data?&lt;br /&gt;4. What does the data tell you?&lt;br /&gt;&lt;br /&gt;Here is an example...&lt;br /&gt;&lt;br /&gt;1. I want to know if the admin user account was used to launch malware.exe&lt;br /&gt;2. I need the ntuser.dat file for the admin user&lt;br /&gt;3. I am going to parse the MUICache and UserAssist Keys with Reg Ripper&lt;br /&gt;4. The data from the UserAssist key indicates that malware.exe was launched by the admin user&lt;br /&gt;&lt;br /&gt;This is pretty basic example, but it illustrates my point.  You can ask yourself questions and answer them...inputting both into your case notes.  Once you have your questions answered, you can update your investigation plan with HOW that information is relevant to the case.&lt;br /&gt;&lt;br /&gt;For example, in this case what would the fact that malware.exe was launched locally by admin.  Well, for one, I now know that the intruder had admin access.  I also know that because the data appeared in the UserAssist key, that they had an interactive session with the shell.  So what does that mean?  Well, that means they had to login from somewhere, right?  So now, I just generated some additional questions that need to be answered...so in my case notes, I would update my investigation plan and my To be answered sections.&lt;br /&gt;&lt;br /&gt;1. How did the intruder gain admin access?  I need to crack the passwords from the NTLM hashes and see what they are.  I also need to parse the SAM hive to determine if the passwords were recently changed, and get the last login times for users in the admin group.  If the passwords for admin users were changed recently, I need to get the passwords before the change.  I can check to see if the system was taking restore points (or shadow volume copies) and extract the SAM and SYSTEM hives from the date immediately prior to the change.  Then I can crack the NTLM hashes and get the passwords before the change occurred.&lt;br /&gt;&lt;br /&gt;2. When did they gain access?  I can tell this by looking at my timeline (which is one the FIRST things you need to create) and check the first appearance of malware.exe.  That should give me a great place to start looking for remote access.  I can then look for remote access attempts in the Security event logs.  Does the customer have a VPN?  Does it log?  What about remote management tools?  Which ones are in use (RDP, pcAnywhere, VNC, etc)?  Are they open to the external internet?  Do they log?&lt;br /&gt;&lt;br /&gt;All of this from JUST answering a single question!  Then as you progress through you case, if you take good notes you will make report writing MUCH MUCH easier!  Also, since cases are getting more and more complex, and like me, you may be working more than one case at a time, good notes will keep you from trying to remember what you were doing three days ago and what you were thinking that made you do whatever it was that you were doing?  Finally, should you get pulled off the case for any reason (or you just need help) good notes will help your fellow investigators know what you were doing, what you were thinking, and where you were headed.&lt;br /&gt;&lt;br /&gt;So, back to my original question...if you are not using Case Notes...why?  It's free.  It's a great tool that has some really nice options.  And taking good notes will help you keep your thoughts organized, and write your final report.&lt;br /&gt;&lt;br /&gt;Lesson learned...TAKE GOOD NOTES!!!!!!  I will give a dollar to anyone who can give me a good reason for not taking notes during a case.  I am going to bet dollars to doughnuts that nobody is going to have any reason compelling enough for me to part with my GWs.&lt;br /&gt;&lt;br /&gt;Happy hunting...and remember...TAKE GOOD NOTES!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-7254218753110925769?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/7254218753110925769/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/case-notes.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7254218753110925769'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/7254218753110925769'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/case-notes.html' title='Case Notes'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_XcfI2W3KXa8/S__s8Emr0KI/AAAAAAAAAMQ/9qr6E8gFKn8/s72-c/1.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-3072921999315881862</id><published>2010-05-26T14:16:00.002-05:00</published><updated>2010-05-26T14:19:10.798-05:00</updated><title type='text'>CyberJungle Interview</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_1z5N4sEmI/AAAAAAAAAMI/VVcwW1CXZtM/s1600/cj_logo.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 61px;" src="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_1z5N4sEmI/AAAAAAAAAMI/VVcwW1CXZtM/s320/cj_logo.JPG" alt="" id="BLOGGER_PHOTO_ID_5475660148769559138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Tomorrow morning, I am going to be interviewed by &lt;a href="http://www.iravictor.net/"&gt;Ira Victor&lt;/a&gt; for the radio show, &lt;a href="http://www.thecyberjungle.com/"&gt;The Cyber Jungle&lt;/a&gt;.  He is going to be asking me about Sniper Forensics...what it is, what it means to investigators, and how using it can help you!&lt;br /&gt;&lt;br /&gt;Listen in if you get the chance!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-3072921999315881862?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/3072921999315881862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/cyberjungle-interview.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3072921999315881862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/3072921999315881862'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/cyberjungle-interview.html' title='CyberJungle Interview'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_XcfI2W3KXa8/S_1z5N4sEmI/AAAAAAAAAMI/VVcwW1CXZtM/s72-c/cj_logo.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-1180689991803445664</id><published>2010-05-25T10:10:00.003-05:00</published><updated>2010-05-25T10:34:22.008-05:00</updated><title type='text'>SANS What Works 2010</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_XcfI2W3KXa8/S_vogEmxBBI/AAAAAAAAAMA/W5Cl3n9i1d0/s1600/1.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 56px;" src="http://3.bp.blogspot.com/_XcfI2W3KXa8/S_vogEmxBBI/AAAAAAAAAMA/W5Cl3n9i1d0/s320/1.JPG" alt="" id="BLOGGER_PHOTO_ID_5475225409688765458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will be delivering Sniper Forensics at the &lt;a href="http://blogs.sans.org/computer-forensics/2010/05/20/2010-digital-foreniscs-incident-response-summit-final-agenda-released/"&gt;SANS What Works&lt;/a&gt; conference in DC on July 8th and 9th.  Last year's conference was awesome, so I'm sure this year's will be even better.  If you have some money budgeted for a conference this year, and can only pick one, this would be the one to attend!&lt;br /&gt;&lt;img src="file:///C:/DOCUME%7E1/User/LOCALS%7E1/Temp/moz-screenshot.png" alt="" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-1180689991803445664?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/1180689991803445664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/sans-what-works-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1180689991803445664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/1180689991803445664'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/sans-what-works-2010.html' title='SANS What Works 2010'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_XcfI2W3KXa8/S_vogEmxBBI/AAAAAAAAAMA/W5Cl3n9i1d0/s72-c/1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-9126486013244253941</id><published>2010-05-24T14:10:00.006-05:00</published><updated>2010-05-24T15:35:04.384-05:00</updated><title type='text'>Crack-a-Lacka</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;OK…so you may have heard that’s it pretty easy to crack SAM hives using tools like Cain &amp;amp; Able or Ophcrack, but, you have never done it before, you don’t know where to start looking, and you feel like a dolt.&lt;span style=""&gt;  &lt;/span&gt;No worries my friend, I am here to help.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;First, download Cain from &lt;a href="http://www.oxid.it/cain.html"&gt;Oxid.it&lt;/a&gt;, and &lt;a href="http://ophcrack.sourceforge.net/"&gt;Ophcrack&lt;/a&gt; from Sourceforge.&lt;span style=""&gt;  &lt;/span&gt;These files WILL be identified as malware by your AV software, so make sure you drop them into a good tools directory that is not being monitored.&lt;span style=""&gt;  &lt;/span&gt;Creating an exception for specific files and folders is a function most (if not all) current AV releases can do, and should be done if you are working in the incident response/forensics industry since you will likely have a slew of tools that would make most AV engines freak out.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Once you have your tools downloaded, use FTK lite and extract your local SAM and SYSTEM hives.&lt;span style=""&gt;  &lt;/span&gt;While Cain will dump your NTLM hashes from you local system, I want to show you how to do this as if you were working on an actual case.&lt;span style=""&gt;  &lt;/span&gt;I think it goes without saying that you would NEVER install Cain or Ophcrack onto a customer system...but there...I just said it now didn't I?&lt;br /&gt;&lt;/p&gt;  &lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;OK…so as you can see below, I have FTK Lite fired up, I have navigated to C:\Windows\system32\config, and I have highlighted my SAM and SYSTEM hives.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_XcfI2W3KXa8/S_rPp-f9p0I/AAAAAAAAALI/hptFC-Ne330/s1600/1.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 158px;" src="http://1.bp.blogspot.com/_XcfI2W3KXa8/S_rPp-f9p0I/AAAAAAAAALI/hptFC-Ne330/s320/1.JPG" alt="" id="BLOGGER_PHOTO_ID_5474916617080907586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;Next, I simply right click, and select “Export Files”.&lt;span style=""&gt;  &lt;/span&gt;I drop them into a specific folder on my desktop, and I am ready to roll…go ahead and close FTK Lite at this point.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Next open Cain, go to tools, and select “Syskey Decoder”…like this…&lt;/p&gt;  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_rPqOOXDII/AAAAAAAAALQ/kJnXKlHmATk/s1600/2.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 158px;" src="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_rPqOOXDII/AAAAAAAAALQ/kJnXKlHmATk/s320/2.JPG" alt="" id="BLOGGER_PHOTO_ID_5474916621302041730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;From here, you will get a popup that looks like this…click on the tripe dots and navigate to where you dropped the system hive you just copied with FTK Lite.&lt;/p&gt;  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_XcfI2W3KXa8/S_rPqWRFJbI/AAAAAAAAALY/uUuoG5w8UCM/s1600/3.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 69px;" src="http://3.bp.blogspot.com/_XcfI2W3KXa8/S_rPqWRFJbI/AAAAAAAAALY/uUuoG5w8UCM/s320/3.JPG" alt="" id="BLOGGER_PHOTO_ID_5474916623460935090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;Once you click on the system hive, that little window under where it says, “Boot Key (HEX) will be populated with a long string of numbers and letters.&lt;span style=""&gt;  &lt;/span&gt;Copy that to your clipboard as you will need it in the next step.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, select the “Cracker” tab, and click on the big blue plus sign that sits right beneath the “Tools” menu tab.&lt;span style=""&gt;  &lt;/span&gt;Then navigate to the SAM hive you just copied using FTK Lite, and paste in the Syskey that you just copied to your clipboard…should look like this…&lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/S_rPq2qmH6I/AAAAAAAAALg/v6gvddcZcAY/s1600/4.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 212px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/S_rPq2qmH6I/AAAAAAAAALg/v6gvddcZcAY/s320/4.JPG" alt="" id="BLOGGER_PHOTO_ID_5474916632157888418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;When you click “Next”, Cain will dump the NTLM hashes from the SAM hive.&lt;span style=""&gt;  &lt;/span&gt;Your table will now be loaded with whatever user accounts are on that machine, along with the NTLM hashes.&lt;span style=""&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Next, highlight whichever users you want to crack, right click, and select export.&lt;span style=""&gt;  &lt;/span&gt;Save them to the same place you dropped your hives (for ease of use), and close Cain.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now open Ophcrack.&lt;span style=""&gt;  &lt;/span&gt;My .lc out put file, when I open it with Textpad, looks like this…&lt;/p&gt;  &lt;p class="MsoNormal"&gt;cepogue:"":"":E4C3436DDD1F625CEBB15F4C062DCC55:EC85B8E81AE28777453327655700B6AE&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I am interested in this part only…&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;  &lt;/span&gt;E4C3436DDD1F625CEBB15F4C062DCC55:EC85B8E81AE28777453327655700B6AE&lt;/p&gt;  &lt;p class="MsoNormal"&gt;THAT is the NTLM hash for the user account cepogue. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;On Ophcrack, click “Load”, then “Sinlge Hash” and paste the NTLM hash you want to crack in the little window like so…&lt;/p&gt;  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XcfI2W3KXa8/S_rPrJJhErI/AAAAAAAAALo/EvQ2-szNv-w/s1600/5.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 186px;" src="http://2.bp.blogspot.com/_XcfI2W3KXa8/S_rPrJJhErI/AAAAAAAAALo/EvQ2-szNv-w/s320/5.JPG" alt="" id="BLOGGER_PHOTO_ID_5474916637119419058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;Click OK.&lt;span style=""&gt;  &lt;/span&gt;Now simply highlight, and click “Crack”.&lt;span style=""&gt;  &lt;/span&gt;In less than a minute, my password was cracked!&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_rQeGVPcaI/AAAAAAAAAL4/mSYloPGQQUE/s1600/6.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_rQeGVPcaI/AAAAAAAAAL4/mSYloPGQQUE/s320/6.JPG" alt="" id="BLOGGER_PHOTO_ID_5474917512536617378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;/span&gt;Blamo!&lt;span style=""&gt;  &lt;/span&gt;Pretty slick huh &lt;span style=""&gt;&lt;/span&gt;(Yes…I changed my password for the purpose of this example)!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, notice that I have two little green dots at the bottom of my screen.&lt;span style=""&gt;  &lt;/span&gt;Those indicate that I have The “XP Free Fast”, and “XP Free Small” tables loaded.&lt;span style=""&gt;  &lt;/span&gt;These are free (as indicated by the name) and can be downloaded from the web.&lt;span style=""&gt;  &lt;/span&gt;You can also purchase larger tabs, or create custom tabs for specific tables (like Rainbow tables, or tables you have created with a word permuter).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I pretty much do this on every case.&lt;span style=""&gt;  &lt;/span&gt;It’s quick, and gives me a great insight into the security posture of my customer.&lt;span style=""&gt;  &lt;/span&gt;If like the admin password is “password”, or the “sqldevadmin” password is “sqldevadmin”, I know I they were likely wide open at the time of the incident.&lt;span style=""&gt;  &lt;/span&gt;If I can crack the passwords in under five minutes, so can the bad guys. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;Also, don’t let the customer fool you and say, “oh…our passwords have ALWAYS been strong!”.&lt;span style=""&gt;  &lt;/span&gt;Parse&lt;span style=""&gt;  &lt;/span&gt;the SAM hive with Harlan’s RegRipper and look at the “PWD Reset Date” under&lt;span style=""&gt;  &lt;/span&gt;that username.&lt;span style=""&gt;  &lt;/span&gt;If it’s a recent date, A) Obviously they’ve changed it, and B) You can always go to the _system_volume_information and extract the previous SAM hive (provided the system is taking restore points or shadow volume copies.&lt;span style=""&gt; ) &lt;/span&gt;Then simply extract the previous SAM hive, and repeat the same steps outlined above.&lt;span style=""&gt;  &lt;/span&gt;Once you get the previous password you can be all…dood…”You changed you password on THIS date (as evidenced by the SAM hive), and your previous password was THIS..as I was able to extract it from the previous SAM hive that I extracted from the restore point from the day before you changed the password…SUCKA!”&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Happy Hunting!&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7683355055095156894-9126486013244253941?l=thedigitalstandard.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thedigitalstandard.blogspot.com/feeds/9126486013244253941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/crack-lacka.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9126486013244253941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7683355055095156894/posts/default/9126486013244253941'/><link rel='alternate' type='text/html' href='http://thedigitalstandard.blogspot.com/2010/05/crack-lacka.html' title='Crack-a-Lacka'/><author><name>cepogue</name><uri>http://www.blogger.com/profile/15373293682953028712</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://4.bp.blogspot.com/-0nnaPg6zJHs/TWUQ2Yo7GTI/AAAAAAAAAOI/RDzQchiab9w/s220/Secret_Squirrel.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_XcfI2W3KXa8/S_rPp-f9p0I/AAAAAAAAALI/hptFC-Ne330/s72-c/1.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7683355055095156894.post-7657982785883582817</id><published>2010-05-20T08:23:00.010-05:00</published><updated>2010-05-20T10:18:20.887-05:00</updated><title type='text'>Command Line Goodness Part IV</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;br /&gt;So, in this installment of Command Line Goodness, I  am going to cover a few different utilities that I’m certain will prove  useful in your investigations going forward.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;  &lt;/span&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="font-size:85%;"&gt;Once again, I am going to use my own FireFox  history as my example file.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;  &lt;/span&gt;&lt;span style="font-size:85%;"&gt;For those of you who  don’t know, this file is located in C:\Documents and Settings\&lt;username&gt;\Application  Data\Mozilla\Firefox\Profiles\&lt;some_garble&gt;.default\places.sqlite.&lt;/some_garble&gt;&lt;/username&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="font-size:85%;"&gt;Now, to make things easier on myself, I use the  UnxUtils “ls” instead of the native Windows “dir”.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;  &lt;/span&gt;&lt;span style="font-size:85%;"&gt;It’s  quick, has numerous command options, and I don’t have to flip flop back  and forth trying to remember if I am on a *nux or DOS command prompt  (something you will come to appreciate the more you use command line  utilities).&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:85%;"&gt;So, I use ls to list all of the  contents of my current working directory (frequently referred to as the  CWD). And I get something that looks like this…&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;&lt;a style="font-weight: bold;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_XcfI2W3KXa8/S_VNAqKXdyI/AAAAAAAAAJg/-9SSFmWUScw/s1600/1.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 63px;" src="http://1.bp.blogspot.com/_XcfI2W3KXa8/S_VNAqKXdyI/AAAAAAAAAJg/-9SSFmWUScw/s320/1.JPG" alt="" id="BLOGGER_PHOTO_ID_5473365595851814690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-weight: bold;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-weight: bold;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-weight: bold;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:85%;"  &gt;OK…so what…that’s not very kewl Chris…well…like I said, there are plenty of command opti&lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:85%;"  &gt;ons that will make your life easier.&lt;span style=""&gt;  &lt;/span&gt;In particular, I am going to use the options to provide me with long listing (more information such as file permissions, ownership, and last access time) , sorted by last access time, as well as by size.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-weight: bold;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-weight: bold;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-weight: bold;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;a style="font-weight: bold;" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_VPswU1WdI/AAAAAAAAAJ4/DWB2SU1LoPU/s1600/2.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_VPswU1WdI/AAAAAAAAAJ4/DWB2SU1LoPU/s320/2.JPG" alt="" id="BLOGGER_PHOTO_ID_5473368552443828690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-weight: bold;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-weight: bold;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-weight: bold;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;OK…so the screenshot above is a bit kewler.&lt;span style=""&gt;  &lt;/span&gt;It provides me some additional information as well as it has sorted the files by last access time, recursively (newest files on the bottom).&lt;span style=""&gt;  &lt;/span&gt;I can also issue the same command without the “r” (for recursive) and the newest files will appear at the top. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;I can also sort by size, which is very helpful with trying to quickly locate either large or small files.&lt;span style=""&gt;  &lt;/span&gt;In this case, my browser history is likely a pretty large file, so I am going to sort recursively by size, placing the largest file on the bottom.&lt;/p&gt; &lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link style="font-weight: bold;" rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link style="font-weight: bold;" rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link style="font-weight: bold;" rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XcfI2W3KXa8/S_VNI6DV5II/AAAAAAAAAJo/viY8Kvr7KXg/s1600/2.JPG"&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5Ccepogue%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false
