Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 3128 - 3157 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
3128
Alan, I would take a look at this class: SANS Security 606: Drive and Data Recovery Forensics <http://www.sans.org/training/description.php?mid=1237> . I have...
Stacey Randolph
staceyerandolph
Offline Send Email
Aug 25, 2009
1:21 pm
3129
Stacey -- The described *simple data recovery* is a very risky procedure if the evidence in the information recorded on the hard drive is truly important. Why...
Steve Fowler
sfowler@...
Send Email
Aug 25, 2009
7:16 pm
3130
Steve, My actual background is Data Recovery, as is that of some of the best forensic experts out there. Before there even was a computer forensics field,...
Daniel, Adam (AU - Sy...
addaniel@...
Send Email
Aug 27, 2009
10:57 pm
3131
I think her point was more along the lines of pointing out that you can try to 'recover' data using common tools like dd-rescue or targeted file copies and if...
Jeff Bryner
jbryner1
Offline Send Email
Aug 28, 2009
5:52 pm
3132
... Alan, All the comments you've gotten so far are on point. If what your looking for is low cost or no cost tools your in for a rude awakening. Most of these...
ray_velez
Offline Send Email
Sep 1, 2009
9:16 am
3133
Hi, I had a debian lenny machine in our office lab back in July. I let one of my coworkers login to it, and he subsequently left the company later that month....
mikepenn01
Offline Send Email
Sep 19, 2009
10:34 am
3134
Hi Mike, Depending upon the underlying file system you could have a bit of work ahead of you. The link below describes the structure and detailed information...
farmerdude
farmerduderl
Offline Send Email
Sep 19, 2009
2:00 pm
3135
The Register - LinuxCon 2009: Does Linux desktop even need to be popular? There are, shall we say, differing options among the open source cognoscenti gathered...
Douglas
digitalforen...
Online Now Send Email
Sep 26, 2009
1:17 pm
3136
Hello, I am new to this field. I am trying to learn my way into the world of computer forensics, and as such, I have a "real-world" need for the tools...
Donald Raikes
dnraikes
Offline Send Email
Oct 2, 2009
9:33 pm
3137
The fastest/easiest way to do it will just be power down the machines, put the hard drives in the Debian machine and use dd. Putting all the drives on the...
swinginscott
Offline Send Email
Oct 2, 2009
10:09 pm
3138
Hello Gents, Maybe I am not seeing the proverbial "Schwartz" here, but once you have the image how are you going to go about and try and find the key logger?...
Adrian Cuellar
adriancuellar
Online Now Send Email
Oct 3, 2009
9:03 am
3139
Scott, I would like to use netcat to copy the drives, but the commands I got from the web didn't make a whole lot of sense to me. If you have any...
Donald Raikes
dnraikes
Offline Send Email
Oct 3, 2009
9:03 am
3140
Don If I were you I would start your adventures at http://www.linuxleo..com and read the introductory guide available there! It will give you some answers but...
Stuart Bird
e_tective
Offline Send Email
Oct 3, 2009
10:04 am
3141
... I must admit I was thinking of the same thing. Are you going to examine your machines for evidence of malware? You mention that you want to see if...
Jacques B.
jboucher_work
Offline Send Email
Oct 3, 2009
12:51 pm
3142
I'd suggest using some basic timeline analysis to see what that turns up. If there is a file being written to log keystrokes, it should lite up in a timeline....
Jeff Bryner
jbryner1
Offline Send Email
Oct 3, 2009
5:53 pm
3143
... Hash: SHA1 Don, The important part is to get an image as early as possible. I wouldn't worry too much about the method you use to image. There has been...
echo6
echo6_uk
Offline Send Email
Oct 3, 2009
7:04 pm
3144
Hi All, Recently I came across a firefox plug-in named Tamper Data. And during its trial run i found that it is easy to tamper even encrypted data using this ...
nehal dattani
e_motion_nmd
Offline Send Email
Oct 3, 2009
8:24 pm
3145
Hi Nehal, Are you looking to identify if the Tamper Data plugin was installed on a system, or something else? Am not clear. Cheers! farmerdude ...
farmerdude
farmerduderl
Offline Send Email
Oct 3, 2009
11:05 pm
3146
Jacques, Thank you for the honest response and warnings. I realize there are some real issues with trying to hunt this down, however, since I have been...
Donald Raikes
dnraikes
Offline Send Email
Oct 4, 2009
1:06 am
3147
Although I normally don't top post, I suspect that is probably more practical in your case. Not sure if the accessibility software properly skips to the...
Jacques B.
jboucher_work
Offline Send Email
Oct 4, 2009
1:28 am
3148
Hi farmerdude I am looking for a feature in web server that is it possible to IDENTIFY about status of data. I mean that weather it is system/browser...
nehal dattani
e_motion_nmd
Offline Send Email
Oct 4, 2009
4:10 pm
3149
We brought out the SFDumper 2.1, now finally all the problems on the file names and filtering by extension have been resolved. Try it: ...
Nanni Bassetti
nannib7013
Offline Send Email
Oct 6, 2009
9:32 am
3150
Hi all, Please forgive the cross-posting. I am trying to find any information on MS office metadata, and how to extract it. Is there a spec available for...
Donald Raikes
dnraikes
Offline Send Email
Oct 8, 2009
8:36 pm
3151
Payne Consulting's Metadata Assistant for versions of Office prior to 2007. Make sure that you have Office 2003 installed not Office 2007 and don't convert...
sean.mclinden
Offline Send Email
Oct 8, 2009
9:03 pm
3152
Take a look here for several ideas: http://viaforensics.com/computer-forensic-howtos/howto-extract-metadata- microsoft-word-linux.html ...
Lehr, John
slopd4256
Offline Send Email
Oct 8, 2009
9:10 pm
3153
linkblast: https://blogs.sans.org/computer-forensics/2009/07/10/office-2007-metadata/ http://blog.kiddaland.net/dw/cat_open_xml.pl ...
Jeff Bryner
jbryner1
Offline Send Email
Oct 8, 2009
11:24 pm
3154
If you are into Perl programing, look at Harlan Carvey's Perl mod File::MSWord and see: http://windowsir.blogspot.com/2006/09/metadata-and-ediscovery.html you...
Bob Kardell
bobkardell
Offline Send Email
Oct 8, 2009
11:49 pm
3155
I use libextractor for traditional MS Office files and custom-written tools for the XML-based file formats. You may also find this interesting: Garfinkel, S.,...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Oct 12, 2009
1:14 am
3156
Hi, folks ! What ssdeep hashset do you use to sort/filter a forensic image ? NSRL doesn't have it, yeah ? []s -- Tony Rodrigues, CISSP, CFCP Forense...
Tony Rodrigues
fotografo_to...
Offline Send Email
Oct 19, 2009
9:07 pm
3157
Today was born Caine 1.0, new tools, new mounting policies (safer), new patch....enjoy it! http://www.caine-live.net/ bye ... Dott. Nanni Bassetti Consulente...
Nanni Bassetti
nannib7013
Offline Send Email
Oct 29, 2009
11:54 pm
Messages 3128 - 3157 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help