<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Episode 522 &#8211; Whats in your RAM?</title>
	<atom:link href="http://Hak5.org/episodes/episode-522/feed" rel="self" type="application/rss+xml" />
	<link>http://Hak5.org/episodes/episode-522</link>
	<description>Trust Your Technolust</description>
	<lastBuildDate>Tue, 22 May 2012 08:32:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: naghu</title>
		<link>http://Hak5.org/episodes/episode-522#comment-45069</link>
		<dc:creator>naghu</dc:creator>
		<pubDate>Wed, 10 Nov 2010 07:37:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-45069</guid>
		<description>Good morning dude,
I used win32dd to extract image of my pc&#039;s RAM. When i use the image file(.dmp file) in volatility framework am getting an error volatility: error: Unable to lacate valid DTB n image.Whats the prob dude..?</description>
		<content:encoded><![CDATA[<p>Good morning dude,<br />
I used win32dd to extract image of my pc&#8217;s RAM. When i use the image file(.dmp file) in volatility framework am getting an error volatility: error: Unable to lacate valid DTB n image.Whats the prob dude..?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Oestreich</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37965</link>
		<dc:creator>Kurt Oestreich</dc:creator>
		<pubDate>Mon, 24 Aug 2009 10:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37965</guid>
		<description>One of the interesting breadcrumbs that you left was for the forensics wiki at:

http://www.forensicswiki.org/wiki/Tools:Memory_Imaging

Excellent site.  I followed the links there to the system internals tool livekd at:

http://technet.microsoft.com/en-us/sysinternals/bb897415.aspx

Which led me to grab the kernel debugger (now free!!!  I have Ida, but this is so cool!!!  I knew my masm was worthwhile) at:

http://www.microsoft.com/whdc/devtools/debugging/debugstart.mspx

Which gives the debugger.  And this led me to...  Free kernel symbols!!!  at:

http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx#f

Whew.  The tools Darren and the other bloke, Mubix referenced required administrator login.  The tools from Microsoft/Sysinternals don&#039;t, and can be made portable, for the most part, except perhaps for the symbols, but I think I could make that work too.

In any case, you two uber dudes left me a really cool trail of breadcrumbs to follow and get some massive memory hacking/debugger tools for my computer.  I never bought the msoft tools because they were 1.  expensive     and      2.  bloated.  But just having the kernel debugger, combined with masm and tasm (Borland orphan) tools, makes for some real butt kicking fun!

Yahoo!

-Kurt</description>
		<content:encoded><![CDATA[<p>One of the interesting breadcrumbs that you left was for the forensics wiki at:</p>
<p><a href="http://www.forensicswiki.org/wiki/Tools:Memory_Imaging" rel="nofollow">http://www.forensicswiki.org/wiki/Tools:Memory_Imaging</a></p>
<p>Excellent site.  I followed the links there to the system internals tool livekd at:</p>
<p><a href="http://technet.microsoft.com/en-us/sysinternals/bb897415.aspx" rel="nofollow">http://technet.microsoft.com/en-us/sysinternals/bb897415.aspx</a></p>
<p>Which led me to grab the kernel debugger (now free!!!  I have Ida, but this is so cool!!!  I knew my masm was worthwhile) at:</p>
<p><a href="http://www.microsoft.com/whdc/devtools/debugging/debugstart.mspx" rel="nofollow">http://www.microsoft.com/whdc/devtools/debugging/debugstart.mspx</a></p>
<p>Which gives the debugger.  And this led me to&#8230;  Free kernel symbols!!!  at:</p>
<p><a href="http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx#f" rel="nofollow">http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx#f</a></p>
<p>Whew.  The tools Darren and the other bloke, Mubix referenced required administrator login.  The tools from Microsoft/Sysinternals don&#8217;t, and can be made portable, for the most part, except perhaps for the symbols, but I think I could make that work too.</p>
<p>In any case, you two uber dudes left me a really cool trail of breadcrumbs to follow and get some massive memory hacking/debugger tools for my computer.  I never bought the msoft tools because they were 1.  expensive     and      2.  bloated.  But just having the kernel debugger, combined with masm and tasm (Borland orphan) tools, makes for some real butt kicking fun!</p>
<p>Yahoo!</p>
<p>-Kurt</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mantech Memory DD &#124; PenTestIT</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37275</link>
		<dc:creator>Mantech Memory DD &#124; PenTestIT</dc:creator>
		<pubDate>Fri, 24 Jul 2009 12:38:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37275</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] Hak5 – Technolust since 2005 » Episode 522 – Whats in your RAM? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jefferson</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37231</link>
		<dc:creator>Jefferson</dc:creator>
		<pubDate>Wed, 22 Jul 2009 13:07:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37231</guid>
		<description>Hi, why can&#039;t some memory be dumped?

-&gt; Dumping 1014.11 MB of physical memory to file &#039;C:\dumpram.img&#039;.
-&gt; WARNING: Failed to map at offset 00000000 00002000! 487
-&gt; WARNING: Failed to map at offset 00000000 00003000! 487
-&gt; WARNING: Failed to map at offset 00000000 00004000! 487
-&gt; WARNING: Failed to map at offset 00000000 00005000! 487
-&gt; WARNING: Failed to map at offset 00000000 00006000! 487
-&gt; WARNING: Failed to map at offset 00000000 00007000! 487
-&gt; WARNING: Failed to map at offset 00000000 00008000! 487
-&gt; WARNING: Failed to map at offset 00000000 00009000! 487
-&gt; WARNING: Failed to map at offset 00000000 09100000! 487


259603 map operations succeeded (1.00)
9 map operations failed</description>
		<content:encoded><![CDATA[<p>Hi, why can&#8217;t some memory be dumped?</p>
<p>-&gt; Dumping 1014.11 MB of physical memory to file &#8216;C:\dumpram.img&#8217;.<br />
-&gt; WARNING: Failed to map at offset 00000000 00002000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00003000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00004000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00005000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00006000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00007000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00008000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 00009000! 487<br />
-&gt; WARNING: Failed to map at offset 00000000 09100000! 487</p>
<p>259603 map operations succeeded (1.00)<br />
9 map operations failed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pakhet</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37230</link>
		<dc:creator>pakhet</dc:creator>
		<pubDate>Wed, 22 Jul 2009 12:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37230</guid>
		<description>Snubbs dresses Darren. It a whole ger-animals deal. The tiger paw shirt matching the tiger paw pants. I miss having geranimals they made mornings so much easier. Sigh.</description>
		<content:encoded><![CDATA[<p>Snubbs dresses Darren. It a whole ger-animals deal. The tiger paw shirt matching the tiger paw pants. I miss having geranimals they made mornings so much easier. Sigh.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37220</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Wed, 22 Jul 2009 01:52:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37220</guid>
		<description>What up with Darren and snubs dressing alike?</description>
		<content:encoded><![CDATA[<p>What up with Darren and snubs dressing alike?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37140</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Sat, 18 Jul 2009 03:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37140</guid>
		<description>Hey do you use Flash CS4 to make your videos?

-Eric</description>
		<content:encoded><![CDATA[<p>Hey do you use Flash CS4 to make your videos?</p>
<p>-Eric</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carl Campbell</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37137</link>
		<dc:creator>Carl Campbell</dc:creator>
		<pubDate>Sat, 18 Jul 2009 02:49:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37137</guid>
		<description>I&#039;ve been watching for a while now but have to stop and say your show is the best thing that ever happened to my tv experience</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been watching for a while now but have to stop and say your show is the best thing that ever happened to my tv experience</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ró?ne takie</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37136</link>
		<dc:creator>Ró?ne takie</dc:creator>
		<pubDate>Fri, 17 Jul 2009 22:44:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37136</guid>
		<description>[...] Hak5: Whats in your RAM?, [...]</description>
		<content:encoded><![CDATA[<p>[...] Hak5: Whats in your RAM?, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steveo17</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37122</link>
		<dc:creator>steveo17</dc:creator>
		<pubDate>Fri, 17 Jul 2009 06:22:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37122</guid>
		<description>gr8 shows dudes i loved all d info in it, this show is 100% more qualified to teach computer skills than any ecdl courses im involved with, although the show was gr8 i missed d multiple segments from matt and snubs and the multitude of topics consequently making the show shorter however i got a crash course in ram and its contents while watching it so tyvm guys</description>
		<content:encoded><![CDATA[<p>gr8 shows dudes i loved all d info in it, this show is 100% more qualified to teach computer skills than any ecdl courses im involved with, although the show was gr8 i missed d multiple segments from matt and snubs and the multitude of topics consequently making the show shorter however i got a crash course in ram and its contents while watching it so tyvm guys</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://Hak5.org/episodes/episode-522#comment-37117</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 16 Jul 2009 19:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1298#comment-37117</guid>
		<description>Great show. I&#039;m one of the people who subscribes through my Tivo. It&#039;s a sweet way to watch podcasts on my big screen TV. Just a little fyi, the links on your lower thirds had the left side cut off. That can be resolved by keeping them in TV safe area when you&#039;re editing. I&#039;m a video editor for a TV station (and THE I.T. Dept/Sys Admin) and I also post our news broadcasts (converted from mpeg to flash with Sorenson)to our TV station&#039;s website so I&#039;ve seen the difference between what shows in a flash player (everything) and what you see on TV. It&#039;s not a big deal, I came here to find the links to formost and the other tools you mentioned. I&#039;d love to see more shows on forensics.

Since I&#039;m here, it&#039;s a good time to tell you I&#039;m a long time viewer. I think I found you when you were still in your first season about the 4th episode in. I&#039;m an old Sch00l3r. Which means I&#039;m 40 and started with an Apple ][+ in &#039;82 and a 300 baud modem. I consider myself pretty knowledgeable about &quot;computer/network security&quot; and really like your show because you teach this 0ld Dawg some new tricks. If you see Dr-Gonzo on your irc server, that&#039;s me. Anyways, thanks for all the shows and info! And keep up the great work! Thanks for teaching me to Trust My Technolust ;)</description>
		<content:encoded><![CDATA[<p>Great show. I&#8217;m one of the people who subscribes through my Tivo. It&#8217;s a sweet way to watch podcasts on my big screen TV. Just a little fyi, the links on your lower thirds had the left side cut off. That can be resolved by keeping them in TV safe area when you&#8217;re editing. I&#8217;m a video editor for a TV station (and THE I.T. Dept/Sys Admin) and I also post our news broadcasts (converted from mpeg to flash with Sorenson)to our TV station&#8217;s website so I&#8217;ve seen the difference between what shows in a flash player (everything) and what you see on TV. It&#8217;s not a big deal, I came here to find the links to formost and the other tools you mentioned. I&#8217;d love to see more shows on forensics.</p>
<p>Since I&#8217;m here, it&#8217;s a good time to tell you I&#8217;m a long time viewer. I think I found you when you were still in your first season about the 4th episode in. I&#8217;m an old Sch00l3r. Which means I&#8217;m 40 and started with an Apple ][+ in &#8217;82 and a 300 baud modem. I consider myself pretty knowledgeable about &#8220;computer/network security&#8221; and really like your show because you teach this 0ld Dawg some new tricks. If you see Dr-Gonzo on your irc server, that&#8217;s me. Anyways, thanks for all the shows and info! And keep up the great work! Thanks for teaching me to Trust My Technolust <img src='http://Hak5.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- This Quick Cache file was built for (  hak5.org/episodes/episode-522/feed ) in 0.85561 seconds, on May 22nd, 2012 at 10:17 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on May 22nd, 2012 at 11:17 am UTC -->
