Lwakatare Video: Metadata Information Can Easily Reveal Secret

[h=2]

MIMI NADHANI KILA MTU KW AMUDA WAKE AJICHIMBIE AJE NA KITU NITATOA PAKUANZIA TU NA MIONGOZO NINAYOOKOTEZA KUTOKA KWENYE NET.



Examining video file metadata[/h] Digital forensics examiners are very aware of the benefits of identifying metadata in files from word processing documents to image files. The metadata in image files, referred to as Exif (Exchangeable image file format), has been a source of information in forensic examinations for some time. Many files, including video files, have metadata.
If metadata is important in other investigations, can video metadata be a similar potential treasure trove? In our basic course I have extolled the examination of metadata during internet investigations, because in online documents or images, metadata can be incredibly damaging evidence.
For example, recently I was asked to examine a website set up on a "free" domain to find out who the the owner might be. Examination of the website failed to ascertain anything until I downloaded the files embedded in the site. A quick look at the files' metadata ascertained their author – who was well known to the plaintiff.
[h=2]Two types of video metadata[/h] So video metadata does exist, and it is important. To deal with video metadata, we have to understand where it comes from. There are two sources, which one article describes as:
a) Operational, automatically gathered video metadata, which is typically a set of information about the content you produce, such as the equipment you used, the software you employed, the date you created your video, GPS coordinates of shooting location, and more.
b) Human-authored video metadata, which can be created to provide more search engine visibility, audience engagement, and better advertising opportunities for online video publishers.
Most of what we are currently dealing with in metadata examination is the "operational" metadata. However, human-authored metadata may become more important.
Interestingly enough, video metadata is getting some heavy discussion from a marketing point of view. Online video providers are looking at the use of video metadata to describe the video better for two reasons: first, better coverage in the search engines, and second, so end users have more descriptive information about the video.
Additionally, video-sharing sites seek to make videos more "social" by enabling users to add metadata to the videos they host. For instance, Metacafe's Wikicafe section allows all its users to add "human authored" comments to video metadata.
Although few standards currently exist for video metadata, this is changing as video delivery becomes more important. Acceptance of standards such as the Dublin Core Metadata Element Set are becoming common. With standards in the metadata, investigators will have an ability to look for common items of information in the file.
Standard metadata also makes it easier to build tools to extract this data. The continuing conversation, and the acceptance of "human authored" metadata, will undoubtedly provide investigators with additional information regarding videos they find on the internet during investigations.
[h=2]File formats and what they contain[/h] Search Google for "video metadata forensics", and you won't find much of anything useful. It is mentioned in some places that video has metadata, but little describes the metadata in depth. However, search for RIFF (Resource Interchange File Format) and you will find a lot more. Riff, the term similar in usage to Exif data, is the format that describes the usage of metadata in many video and audio files.
Riff data can include:
riff-data.png

The amount of Riff data available depends on the file format. Riff data is a proprietary format originally developed by Microsoft and IBM for Windows 3.1. The format was released in the 1991 in the Windows Multimedia Programmer's Reference. Riff was never adopted as a standard and few new video formats have adopted the file format since the 1990's. Common files formats still in use that use Riff include .wav and .avi. Microsoft has since 2004 been using the ASF format (Advanced Systems Format) since 2004 in its .wma files.
From the Microsoft Advanced Systems Format specifications, we can find that the ASF file can contain potentially valuable information.
asf-file.png

And,
asf-file-2.png

Okay….so we have looked at the underlying structure for the metadata present in video. The question now becomes, how do we look at that data? There are a few free tools out there to assist you. Let's talk about three:
[h=2]Gspot[/h] Gspot has been the heavy lifter for most investigators looking at metadata in video files. It provides a single screen view of the available data in a video file (of the files it can translate). Most of the data is "operational" data found in the file, but it does provide you with the "human authored" data if it is present. Gspot has an export function to allow the user to save the metadata information for inclusion in a report or to add to WebCase. Gspot's failing is that it has had no recent updates since 2007.
gspot-interface.png

The Gspot report looks like this:
gspot-report.png

[h=2]MediaInfo[/h] To me, MediaInfo is a newer tool. Its basic view is much simpler than Gspot's, but it offers several different views of the data that allow you to determine what metadata is present. I personally like the "tree" view as it lays out all of the metadata present in an easy to view screen. The export options for reporting also allow the user to quickly make reports in a text or html format for inclusion in their reports or to add to WebCase. MediaInfo also adds during installation a right click function to Windows Explorer to easily access the tool.
mediainfo-interface.png

Media Info report (txt, html, or CSV) looks like:
mediainfo-report.png

[h=2]Video Inspector[/h] A very basic tool, Video Inspector provides the user with the essential metadata present in the video file. The export function allows for exporting a text document with the metadata it finds, but it is limited. The tool was designed to assist the user in identifying missing codecs required to play the video, so reading all the available metadata is not its main function.
videoinspector.png

Video Inspector Report looks like:
videoinspector-report.png

In comparing the tools I used a video that I know had "operational" metadata in it to determine whether each program reported the data. Gspot and MediaInfo both located and reported the data. MediaInfo included the "Master date" which could either be the date the video was "mastered" or possibly the date it was uploaded to the site (I have to do some more research on that date and time stamp).
gspot-metadata.png

mediainfo-metadata.png

vi-metadata.png

So there is some usefulness in reviewing video files for metadata. Something to remember is that some sites may strip the metadata when posted on line. Also, other tools used to download videos from the Internet, like savevid.com, save the video in flash and not the original file format containing the original metadata . Investigators need to find the original video uploaded to get to the metadata.
Additionally, as previously discussed, investigators may encounter challenges in the form of social media. For example: Metacafe's attempt to add metadata to videos it hosts. Its Wikicafe section allows all its users to add "human authored" comments to video metadata.
If you are more interested in reading about metadata in video files here are some resources:
Riff Info
RIFF (Resource Interchange File Format)
Resource Interchange File Format - Wikipedia, the free encyclopedia
The Official Blitz Website
http://code.google.com/speed/webp/docs/riff_container.html
ASF File Format
ASF (Advanced Systems Format)
 
The only way to work out on this political ambiguity!

Metadata usually hide information that can embarrassingly lead to revelation of secrets resulting in leakage of business deals, hidden agendas and other crucial information, and hence a danger of exposing secrets which can be very costly!

It is known that (I will not put refs for now) even for reputable companies with server-based metadata removal, 10% of all information (provided they are in electronic form) going out of company server have metadata.

Metadata can reveal how an electronic file was created. Metadata for example can tell you whether this video was taken continuously from one place or just a combination of parts taken from different places in different times. It provides plenty of other information as well.

"One of the factors that distinguishes electronic documents from their paper counterparts and contributes to the complexity of electronic document records management is that electronically stored data is accompanied by metadata. Metadata "describes" the underlying data. It may include information such as what language it’s written in; where the data is stored; number of characters, pages and words; what tools were used to create it; when the data was created/modified and by whom." Reference: (E-discovery: What does your metadata reveal? : Municipal Association of SC)

I'm certain for large percentage, that this video is a forgery. The only way to clear this dilemma is to work it the clever way by extracting the meta information associated with the video file!

I'm convinced that there is little chance for people (who may also be not intelligent enough) who created this video to have ever thought of the meta info hidden in the file. And because the video is posted on internet, that means they cannot take it all back in order to remove metadata. Metadata can be extracted by just executing a small piece of code in the command prompt.

Yes, information should be submitted to the court as an evidence or let some geek do it before the public in the court so that everyone can witness!

Alternatively: Extract images from a video, then get EXIF (exchangeable image file) to analyze.

Mi nadhani mngehangaika na dhamana ya mtuhumiwa zaidi.
 
Mkuu Pasco,

Sikiliza maneno haya ya busara, ''UNACHOKIJUA KINAONESHA MWISHO WAKO WA KUJUA NA KUELEWA MAMBO''
Yamfaa mtu achangie akijuacho na si kuwaaminisha wengine kuwa ndivyo ilivyo na hakuna namna nyingine.
Kwa mwendelezo wa matukio ya utekaji, utesaji, kujeruhi na hata uuaji watu mfano Stanley Katabalo, Imran Kombe, Mwangosi, wafanyabiashara wa madini toka mahenge waliouawa na polisi, Ulimboka, Kibanda na wengine unajenga mizizi ya chuki na kisasi dhidi ya viongozi wa serikali.

Kama Pasco unatumika ninakuonea huruma maana historia tangu kuumbwa kwa ulimwengu inaonesha hakuna utawala uliowahi kudumu milele. Tawala nyingi zilizoambatana na matukio ya namna hii, visasi viliwafuata baada ya kuondoka madarakani mpaka vizazi vyao vya tatu(mjukuu) na vya nne(vitukuu) vilibeba makosa ya baba zao.

Vi vema ukajiunga na kundi la wengi wapiganiao haki zao kuliko kujilisha vinono na watawala kwa kitambo kidogo tu.
Inauma kuona watawala kama akina Sadam na Ghadaf wakifa kwa jinsi ile lakini inauma zaidi kuona wananchi wakiteswa na kunyanyaswa ndani ya nchi yao.
 
..Kwa hiyo unataka kusema watu wanaweza umbuka na UMBUMBU WA ULIMWENGU WA DIGITALI! haya tuona yatakayojili siku za usoni! WAHENGA WALISEMA ..USILOLIJUA NI KAMA USIKU WA GIZA!

Heshima yako mkuu PUNJE, kwani mambo jamaa anayo sema si ni comment tu kwenye "code" ambazo azina role yoyote katika ku-excute program nzima zaidi ya kufahamisha mtu anayetaka kujua/mchunguzi kitu gani kinaendela, hivyo watu weledi wanaweza kuondoa hizo comment au wakahacha a null comment ili mtu asijuwe kinacho endelea! That's my observation.
 
Usitegemee polisi kumtafuta aliyeiweka hiyo Video clipp You Tube , bila shaka huo mpango unawahusu , soma kwenye uzi wa Mkwawa , unaoendelea hapahapa Jf !
 
Mkuu Pasco,

Sikiliza maneno haya ya busara, ''UNACHOKIJUA KINAONESHA MWISHO WAKO WA KUJUA NA KUELEWA MAMBO''
Yamfaa mtu achangie akijuacho na si kuwaaminisha wengine kuwa ndivyo ilivyo na hakuna namna nyingine.
Kwa mwendelezo wa matukio ya utekaji, utesaji, kujeruhi na hata uuaji watu mfano Stanley Katabalo, Imran Kombe, Mwangosi, wafanyabiashara wa madini toka mahenge waliouawa na polisi, Ulimboka, Kibanda na wengine unajenga mizizi ya chuki na kisasi dhidi ya viongozi wa serikali.

Kama Pasco unatumika ninakuonea huruma maana historia tangu kuumbwa kwa ulimwengu inaonesha hakuna utawala uliowahi kudumu milele. Tawala nyingi zilizoambatana na matukio ya namna hii, visasi viliwafuata baada ya kuondoka madarakani mpaka vizazi vyao vya tatu(mjukuu) na vya nne(vitukuu) vilibeba makosa ya baba zao.

Vi vema ukajiunga na kundi la wengi wapiganiao haki zao kuliko kujilisha vinono na watawala kwa kitambo kidogo tu.
Inauma kuona watawala kama akina Sadam na Ghadaf wakifa kwa jinsi ile lakini inauma zaidi kuona wananchi wakiteswa na kunyanyaswa ndani ya nchi yao.
Kwanini unatumia nguvu nyingi kumlazimisha aaminiunakiamini wewe!
 
Usitegemee polisi kumtafuta aliyeiweka hiyo Video clipp You Tube , bila shaka huo mpango unawahusu , soma kwenye uzi wa Mkwawa , unaoendelea hapahapa Jf !
kwa hiyo mnataka kukataa kwamba yule sio lwakatare kwenye ile video au?maana hamueleweki naona toka juzi mnatapa tapa tu,hebu acheni sheria ichukue mkondo wake acheni kuweweseka,sheria ni msumeno haijali cha upinzani wala nini
 
kama katumia kwenye internet cafe atapatikana kweli?

yaani kwenye ulimwengu wa electronics kila mtu yuko uchi.ishu ni kwamba wataangalia ID mambo mengi sana hawata rely kwenye hiyo video ya siku moja tu.

mm sijui sana haya makitu but huaga nikifuatilia ile kesi ya bosi wa FBI basi huwa najua huwez kujificha

Wakuu [MENTION]zumbemkuu [/MENTION]na [MENTION]gfsonwin [/MENTION]yaani iko hivi: hata kama huyu jamaa atakuwa ali-create hiyo youtube account siku hiyo hiyo na ku-upload kupitia internet cafe au computer nyingine kuficha identity yake still meta data inaenda mbali zaidi kama vile camera gani (model, serial no, iliuzwa kutoka duka gani, lini na aliuziwa nani) zilitumika kwenye huo mchezo na picha yenyewe ilirekodiwa muda gani na kama alivyoeleza mdau ni kwa mfululizo au in piecemeal.

Taarifa nyingine muhimu kutoka "metadata" ni computer gani (brand, serial no, owner, n.k.) zilitumika kwenye mchezo mzima hadi huyo aliyekuwa ana-edit hiyo "picha" typing speed yake ilikuwaje. Kama alitumia internet cafe, ni cafe gani ilitumika na muda gani mchezo huo ulifanyika.

Kwa nchi ambayo iko serious na masuala ya usalama, hizo taarifa ni too much kuweza kukamata hao wapuuzi wanaotaka kuhatarisha usalama wa taifa letu. IT ni muhimu kwa maendeleo ya taifa letu lakini isiwafanye washenzi wachache kuweka rehani nchi yetu na bahati mbaya kwao mabingwa wa IT waliobuni hizo teknolojia walishaona hayo yote na ku-implement namna ya kupambana nayo. Hoja hapa ni je, "tunao utashi wa kisiasa"? Hapa ndipo tatizo la msingi lilipo na wala sio IT!
 
kwa hiyo mnataka kukataa kwamba yule sio lwakatare kwenye ile video au?maana hamueleweki naona toka juzi mnatapa tapa tu,hebu acheni sheria ichukue mkondo wake acheni kuweweseka,sheria ni msumeno haijali cha upinzani wala nini

Kama ndiye vyombo vya usalama vichukue hatua zinazostahili. Lakini subiri utashangaa na roho yako.
 
Hivi kweli kuna mtu anadhani serikali ya Tanzania ikitaka kujua mtu aliyeiweka ile video YouTube itashindwa?

Kuna watu wako so illiterate na kompyuta wanadhani kuwa uki-uplaod video Youtube na ID feki basi huwezi kuwa tracked down.

Everything that people do on the Internet, including on YouTube, can be tracked down so easily. I mean everything.

Sioni ugumu wowote wa kum-track aliyeweka ile video.

Na kwa vile ile video inaongelea conspiracy to kill someone na kwa vile terms na conditions za YouTube zinakataza ku-upload video za aina hiyo, Google watakuwa tayari ku-cooperate na Tanzania kumpata aliyeiweka ile video ya conspiracy to commit a deadly crime.
The qustion here is interest to do the right thing. Je vyombo vyetu viko tayari kutenda haki? Unakumbuka issue ya Zeutamu? mbona walifuatilia mpaka wakapata kila kitu?????? Because there was plenty of interest to apprehend the culprits!
 
Wakuu zumbemkuu na gfsonwin yaani iko hivi: hata kama huyu jamaa atakuwa ali-create hiyo youtube account siku hiyo hiyo na ku-upload kupitia internet cafe au computer nyingine kuficha identity yake still meta data inaenda mbali zaidi kama vile camera gani (model, serial no, iliuzwa kutoka duka gani, lini na aliuziwa nani) zilitumika kwenye huo mchezo na picha yenyewe ilirekodiwa muda gani na kama alivyoeleza mdau ni kwa mfululizo au in piecemeal.

Taarifa nyingine muhimu kutoka "metadata" ni computer gani (brand, serial no, owner, n.k.) zilitumika kwenye mchezo mzima hadi huyo aliyekuwa ana-edit hiyo "picha" typing speed yake ilikuwaje. Kama alitumia internet cafe, ni cafe gani ilitumika na muda gani mchezo huo ulifanyika.

Kwa nchi ambayo iko serious na masuala ya usalama, hizo taarifa ni too much kuweza kukamata hao wapuuzi wanaotaka kuhatarisha usalama wa taifa letu. IT ni muhimu kwa maendeleo ya taifa letu lakini isiwafanye washenzi wachache kuweka rehani nchi yetu na bahati mbaya kwao mabingwa wa IT waliobuni hizo teknolojia walishaona hayo yote na ku-implement namna ya kupambana nayo. Hoja hapa ni je, "tunao utashi wa kisiasa"? Hapa ndipo tatizo la msingi lilipo na wala sio IT!
is not gonna help either,mnajaribu kupotosha kijanja ili upepo upite but the fact yule ni lwakatare na yale alikua akiyatamka yeye full stop!
 
Mwisho wa siku itakuwa aibu kubwa kwa wapangaji wa hizi njama. Watu smart wangetumia wataalamu wa teknolojia kuliko hawa wachumia tumbo kina Nchemba.
 
kwa hiyo mnataka kukataa kwamba yule sio lwakatare kwenye ile video au?maana hamueleweki naona toka juzi mnatapa tapa tu,hebu acheni sheria ichukue mkondo wake acheni kuweweseka,sheria ni msumeno haijali cha upinzani wala nini

Tatizo linaweza lisiwe sheria, bali laweza kuwa u-Rwakibalila!
 
The only way to work out on this political ambiguity!

Metadata usually hide information that can embarrassingly lead to revelation of secrets resulting in leakage of business deals, hidden agendas and other crucial information, and hence a danger of exposing secrets which can be very costly!

It is known that (I will not put refs for now) even for reputable companies with server-based metadata removal, 10% of all information (provided they are in electronic form) going out of company server have metadata.

Metadata can reveal how an electronic file was created. Metadata for example can tell you whether this video was taken continuously from one place or just a combination of parts taken from different places in different times. It provides plenty of other information as well.

"One of the factors that distinguishes electronic documents from their paper counterparts and contributes to the complexity of electronic document records management is that electronically stored data is accompanied by metadata. Metadata "describes" the underlying data. It may include information such as what language it’s written in; where the data is stored; number of characters, pages and words; what tools were used to create it; when the data was created/modified and by whom." Reference: (E-discovery: What does your metadata reveal? : Municipal Association of SC)

I'm certain for large percentage, that this video is a forgery. The only way to clear this dilemma is to work it the clever way by extracting the meta information associated with the video file!

I'm convinced that there is little chance for people (who may also be not intelligent enough) who created this video to have ever thought of the meta info hidden in the file. And because the video is posted on internet, that means they cannot take it all back in order to remove metadata. Metadata can be extracted by just executing a small piece of code in the command prompt.

Yes, information should be submitted to the court as an evidence or let some geek do it before the public in the court so that everyone can witness!

Alternatively: Extract images from a video, then get EXIF (exchangeable image file) to analyze.

Thanks,for giving a lesson.
 
dudus what m sure of ni kwamba kama serikali itakuwa tayari kuwekeza kwenye usalama wa taifa hili it wont take even a sec kuupata ukweli wote.

kwanza kabisa wakifuatilia tu simu yake mawasiliano aliyoyafanya ili kuweka huo mkutano yatatosha kabisa kumtia hatian ama kumweka huru. kwani kama alipigia watu simu basi ni wazi kwamba connection yake itakuwepo tu.

kama ni planted scenario pia itajulikana as software info zote huwa zinatoa hadi namba ya komputa na muda na hata wakati ilipotumika.

so far kwa wale wataalam wa mambo ya GIS wanaweza kusaidia as kuna programm moja sijui inaitwaje hii inaweza kufanya criminal detection so easily as it can give you pics za mahali walipokuwa na nini kilifanyika. mbona hata kumjua aliyempiga ni simple sana kama wakitaka kutumia haya makitu??

naskitika tu somo la GIS nilikuwa silipendi mweeeh!...............lilikuwa gumu sana but pengine ningejitahd ningekuwa nasaidia taifa khaaa!
 
Last edited by a moderator:
Aliiweka kwenye you tube ili watu waione kwa urahisi, hii ni 7bu lengo ni kuiangamiza CDM. We unafikiri angeiweka kwenye CD wangapi wangeiona?

cdm haiwezi kuangamia kwa video ya You Tube. ndo tunarudi kulekule kwa video za Osama. alikuwa aki-upload video zake You Tube kwa lengo la kuangamiza Marikana, matokeo yake kaangamia yeye.

CCM=chama cha mapumbafu mmekurupuka sana kwene hii ishu. siku hizi watu hawakubavitu kirahisi hivyo, ngojeni wataalam wa video waidadavue, itafahamika tu.

ccm mnafikiria kwa kutumia akili za nchemba! what a shame!
 
Back
Top Bottom