Tag Archive for 'Methods'

Google-Free Wednesday

FindThatFile

Previously, I wrote about file searches using OSUN.ORG.

findthatfile.com provides a file search  encompassing Web, FTP, Usenet, Metalink and P2P resources (ed2k/emule) including 47 file types and 554+ file extensions including over 167 file upload services. It also offers an alert service sent to your email.

However, not all information in the search database has every property you might be searching for, therefore, you have to explore the different ways to search for the file in the advanced search screen.

In my experience, this is not a good search engine to use to search by a person’s name or a company name. The files are not well indexed in this fashion.  One must also be careful to select the “All Files” button in the “Adult Filter” to be sure all the files found appear in the search results.

I usually search by a file name for other versions of a file that I already know about. In some cases, findthatfile.com will give me an understanding of how widely circulated a file may be, or turn-up different versions of the same file.

Investigators & the Investigative Process

Sherlock Holmes with his deerstalker hat and magnifying glass is the most familiar image of the Investigator. However, this is a narrow-minded representation of the Investigator.

The investigative process does not belong to the police or private detective.  Investigation is at the heart of every human activity. Scholars investigate. Antique dealers and appraisers investigate. Investors investigate. Medical Doctors investigate. In one way or another, we all investigate something or other. To investigate is to seek a solution. It is the application of information collection skills,  logic, and analytical skills.

This is the last article of 2009.  The next article will appear on Google-Free Wednesday, 6 January 2010.

FaceBook and Investigations

Facebook: The truth is out there

… Facebook is a good source for data mining.

But one problem is that information gathered is not verified independently.

“These are not facts, just hearsay,” the former Criminal Investigation Department trainer said. “For digital photos, you can’t prove they are original as photos can be manipulated and put on the Web. You can’t authenticate them unless you get the original files from the photographer.”

He added: “This way of getting information is more trendy…but the information should be verified by conducting a proper investigation.”

Only when it is backed up will it be admissible as court evidence, he said.

… [it is] not inconceivable for someone to falsify their whereabouts on such sites.

“There really is no way of proving who was at the computer, which is the problem with any Internet-based investigation,” he said. “Today, one can update Facebook status or tweet Twitter from any device at any location.”

This is an excellent article on the value of searching  social sites.

Three Dimensions of Note-taking

I have written previously on taking notes using audio, images, and handwritten notes.  Quite a while back I wrote about video notes using a simple camcorder called the FlipUltra.

Kodak Zi8

Now the Kodak Zi8 seems like a  better pocket-sized point-and-shoot video camera.  The digital image stabilization provides better video than the Flip. It has some hardware and software advantages over the Flip. It needs SD or SDHC memory cards which I see as an advantage even if it makes the Zi8 cost more.

Internet Detective 105 - Paid Monitoring Services

Social Media Monitoring

As an Investigator, you must realise that even the Vatican uses social media. Some forms of social media are taking on some of the characteristics of email. This information rich environment is something that Investigators and Researchers must understand. To be effective, one must also understand the tools available to conduct thorough research of the social media content.

One must also be able to create accurate budgets for this type of research. To set-up, optimise, and monitor research feeds that cover multiple social media and news sites can take many hours. These services allow one to monitor the social media space for new data or derogatory content. One particular strength of these services is that they search Blog comments, and can track comments and posts of individual contributors. While these services are aimed at PR agencies, they also offer significant utility for the Investigator, but they can be very expensive tools to use.

Techrigy

Techrigy (pronounced tek-err-jee) offers a free account that gets you up to 5 Search Words/Phrases, and store up to 1000 results. This is a great way to learn how to use the system.

Radian6

Unfortunately Radian6 is expensive — you pay just to have it in your toolbox, and then pay more for each social media research project you undertake. These costs must be understood at the outset and budgeted into the costs of the Investigation.

Filtrbox

Unfortunately, at Filtrbox their annual fee for individuals appears to be $1,000USD.

Backtype

Backtype lets you search comments that mention a brand, company, or topic, but it also lets you search comments left by a particular person.

Attaain

AttaainCI costs $150 per month for unlimited searching and monitoring. It’s less sophisticated than Radian 6 and Filtrbox which rate Blog comments from positive to negative. This is aimed at the Competitive Intelligence professional rather than the PR agency.

Internet Detective 104 — Forums, Boards, & Social Sites

Searching Boards, Forums, and Social Media sites can be a hit and miss affair using the large search engines. Google does an excellent job, but it is not the only game in town.

BoardTracker

BoardTracker – searches across 37,000 forums representing more than 63 million threads. Set up your own custom alerts using RSS or use the site’s search function.

SocialMention

SocialMention – this will find your search term in many different blogs and social outlets.  It will tell you how many times a keyword was used, the time frame, and let you subscribe to an RSS feed for that term or export the information as a CSV file.

Internet Detective 103 - Monitoring Changes

In Real-time Search Engine,  I looked at a Meta search engine called Colecta that is useful for real-time monitoring certain types of sites. Now I will look at monitoring changes in sites that interest you.

Copernic Tracker

Copernic Tracker – automatically looks for new content on Web pages, forums, and Social sites. When a change is detected, our Web site tracking software can notify you by sending an email, including a copy of the Web page with the changes highlighted, or by displaying a desktop alert.

WatchThatPage

WatchThatPage is a service that enables you to automatically collect new information from your favorite pages on the Internet. You select which pages to monitor, and WatchThatPage will find which pages have changed, and collect all the new content for you. The new information is presented to you in an email and/or a personal web page. You can specify when the changes will be collected, so they are fresh when you want to read them. The service is free!

Internet Detective 102 — Pipes

Yahoo Pipes  is an interactive feed aggregator and manipulator. Using Pipes, you can create feeds that are more powerful, useful and relevant.

Yahoo Pipes is a free online service that lets you remix popular feed types and create data mashups using a visual editor. A Web mashup is a Web application that combines data from more than one Web data source into a single integrated Web application. Yahoo Pipes combines several different data sources but is generally not sufficient to create a useful application, it is a data mashup tool rather than a complete mashup editor.

How-to videos abound to act as tutorials on using Pipes. The best I found was here. You might also read Working with Yahoo! Pipes, No Programming Required.

Stealth Searching III

In a previous article on Stealth Searching I wrote:

You will not click on any links on the cached pages as these will go to live pages. You will not allow your browser to download any images on the cached pages, as they may be live images from the target domain. You will be STEALTHY. They won’t see you coming.

A reader suggested that this requires some further explanation.

Google Cache Risks

Google caches only the text of the Web page. When  the Googlebot copies the first 101K of HTML to a Google server, external files such as Javascript, Cascading Style Sheets, images, Flash, etc. are not saved. The images load from the live site not the Google cache.  Normally, when you view the cached copy, you are not connecting to the live site. However, following any link on the cached page will connect you to the live Web site, if it still exists. Some pages in Google’s cache load the entire page from the original server thanks to a simple redirection script. If a cached page has no external files, then you will not show up in the site’s log by viewing Google’s cache; but how likely is that?

The Wayback Machine

The Wayback Machine changes the links of cached pages, to allow navigation within the cached pages. However, there is always the chance that you will navigate yourself out to the original site. Remember, nothing is prefect and this stuff wasn’t designed with anonymity as its objective.

The Dangers of TOR

Using TOR to explore the Google cache and The Wayback Machine seems to be the only option. However, Web history and geographic origin affects search results when you use TOR or similar methods.

TOR does require a certain level of technical knowledge and sophistication or it can backfire on you. For example, the SSLstrip attack that is now in the wild:

The attack is more than theoretical. Marlinspike tested the software on a public server he hosted for users of the Tor anonymous browsing network; he was, by his own account, able to grab passwords to 117 e-mail accounts, 16 credit cards numbers, seven Paypal logins and about 300 other logins to supposedly secure sites ranging from Gmail to Ticketmaster to Facebook.

If a TOR server is set-up for the purpose of running SSLstrip, then you’re in trouble. The very nature of TOR makes the possibility of a corrupt TOR server rerouting your data to the attacker very possible and an ideal situation for the crook.To use TOR effectively, the proxy must be configured properly and the user must be very observant to prevent an attack via SSLslip and similar threats. Google Cache Google The Onion Router The Wayback Machine Private Investigator Toronto Ontario Canada

Internet Detective School 101

Google Alerts

We all know know and love Google, but how many people use its best investigative features? Investigations aren’t done in one day so why search Google on only one day?

Google Alert service is free and it allows you to create custom RSS feeds using Google search results, or you can receive the alerts by email.  Thus, if you create focused searches using phrases, site qualifiers, etc. in Google, you now can have those results as a RSS Feed.

Login to you Google account, then use the advanced query options to construct your search.  Select the Feed setting in the “Deliver to” column to activate your RSS feed.  It’s that simple; there is no need to program a Google API. Alternatively, select email to have the results sent to you by email.

Your search can be set-up to notify you as the new data appears if you select email notification. You may select as-it-happens, daily, or weekly. Simply make the selection in the “How often” column. Of course the RSS feed option doesn’t need to be told when to send you the results, it captures new data as it appears and publishes it in the feed.

To receive the feed you will have to wait until it is populated with some results. Once there are results in the feed, you may then click on the feed link for the Alert and copy the URL into your newsreader.  This takes about one day to occur in my experience.

Internet Detective School

Internet Tracking

Mantracker hunts people by following their spoor for a popular TV show.

On the Internet, Investigators have to do the same thing. However, the digital spoor may be on a computer in Singapore while your prey is in Corner Brook Newfoundland.

For this series of articles, the terms tracking, monitoring, and alerts  all mean the same thing. These terms are applied to methods of collecting new information as it appears in a variety of searches of many sources throughout the Internet.  This is a systematic way of locating information about a subject as it becomes available. These are sources and methods that monitor news reports, social media, blogs, or other open sources of information relevant to your investigation. I will illustrate how to construct the search statement and get the results in your hands on an ongoing basis.

I will start with the large search engines and move onto the lesser know sources and methods.

Research & Goals

There are two types of research.

Strategic Research

This is to determine the best course of action. For example, in which direction to drive.

Tactical Research

This is how to achieve the best course of action. This is deciding which road to take. This is also about the essential details to reaching your strategic goal.

This might seem obvious, but I’m forever being reminded that it isn’t.

Three Dimensions of Note-taking

I have written previously on taking notes using audio, images, and handwritten notes. Now I am contemplating taking video notes using a simple camcorder called the FlipUltra. This seems like a briefcase-friendly device for this purpose. The problem with the alternatives is the size and weight of the device.  This simple plug-and-play device is good for conducting interviews, taking street scenes, and other recordings that use-up less than 60 minutes of recording time. Using the FlipUltra should be a lot easier and give better results than using my point-and-shoot Lumix camera and of course, longer recording time.

Flag, Pen, & Bookmark

Here’s an interesting gadget to use when you’re sorting through a lot of documents or other written material.

Find the Bookmarker here.

Disappearing & Invisible Ink

MOSSAD PEN

This writes like a normal pen, but if you heat the paper the written words disappear. Putting the paper in the freezer makes the words reappear.

RUSSIAN KGB DISAPPEARING INK PEN

This pen features a special gel ink developed by real KGB scientists during the Cold War (and made in Russia), that disappears completely. Because it is a gel pen, you don’t need to press hard which prevents paper indenting.

UV Sensitive INK PEN

I guess every good spy needs to have his missives disappear, but I  need to secretly mark documents for later reference.

Pens like this have been  around for quite some time.  The Fisher Space Pen was at one time offered with UV Sensitive Ink refills. I occasionally use UV sensitive ink to mark important documents for security purposes.