Forensics on Terminal Server Client

View: New views
4 Messages — Rating Filter:   Alert me  

Forensics on Terminal Server Client

by gamgamus :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hello all,

I was looking for a tool to view or analize the bcache22.bmc file (Bitmap Caching for Terminal Server Client)

Any help will be very helpfull!

Regards,

Gam.

RE: Forensics on Terminal Server Client

by Sanabria, Adrian :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Can't find any discernable structure in the file. It is obviously all binary, but I can't find anything that matches any image header types, especially not bitmap. Perhaps it is compressed or encrypted/obfuscated in some format (but then, I can't find any headers that would suggest that either)?

-----Original Message-----
From: listbounce@... [mailto:listbounce@...] On Behalf Of gamgamus@...
Sent: Tuesday, October 30, 2007 2:15 PM
To: forensics@...
Subject: Forensics on Terminal Server Client

Hello all,



I was looking for a tool to view or analize the bcache22.bmc file (Bitmap Caching for Terminal Server Client)



Any help will be very helpfull!



Regards,



Gam.

-----------------------------------------
Note:  The information contained in this email and in any
attachments is intended only for the person or entity to which it
is addressed and may contain confidential and/or privileged
material.  Any review, retransmission, dissemination or other use
of, or taking of any action in reliance upon, this information by
persons or entities other than the intended recipient is
prohibited.  The recipient should check this email and any
attachments for the presence of viruses.  Sender accepts no
liability for any damages caused by any virus transmitted by this
email. If you have received this email in error, please notify us
immediately by replying to the message and delete the email from
your computer.  This e-mail is and any response to it will be
unencrypted and, therefore, potentially unsecure.  Thank you.  NOVA
Information Systems, Inc.

RE: Forensics on Terminal Server Client

by Mike Theriault :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

It's probably compressed so in that case you probably wont find any header information.

Mike Theriault
Security Enginer

Re: Forensics on Terminal Server Client

by TheGesus :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

If you dump one of the *.bmc files it's pretty obvious from the number
of repeating byte patterns that it's not compressed (or encrypted).

And if you compress one of the files, it will compress nicely, which
is a fairly good indicator that they're not compressed to begin with.

On Nov 10, 2007 3:28 PM, Mike Theriault <Mike_Theriault@...> wrote:
> It's probably compressed so in that case you probably wont find any header information.
>
> Mike Theriault
> Security Enginer