Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 1082 - 1111 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
1082
I am dual booting to a 15 gig hd with Windows 2000 and RH9. I do not use a boot loader, instead I use a bootable floppy. My floppy no longer works and I need...
Jason Fuller
eforensics
Offline Send Email
Dec 2, 2004
5:09 pm
1083
... Man, I love Debian but always rely on SuSE for these things. Download the boot ISO of the latest distro from an official mirror, for instance here: ...
Luis Gómez
lgomez@...
Send Email
Dec 2, 2004
5:28 pm
1084
... I'm in total agreement with you Blare,, understood you all the way.. It's that doubt aspect which should be eliminated for Law Enforcements standing in...
IanC
devorg
Offline Send Email
Dec 2, 2004
9:40 pm
1085
I would try booting from the first RH9 install CD. Your CD has to be selected before your hard disk in your computer's boot sequence. If you can get this to...
ingenieroforense
ingenierofor...
Offline Send Email
Dec 3, 2004
1:38 am
1086
Ian, My theory with this is pull the plug - or in the case of two machines I will be imaging on Monday, that I KNOW will be powered up when I get there, I'll...
The Dog's Bollix
ISXPRO
Offline Send Email
Dec 3, 2004
3:42 am
1087
Pull the plug. The reason as I understand this is that there are many programs that execute with the system is shutting down that destroy user activity. The...
Melissa Royer
defender03102
Offline Send Email
Dec 3, 2004
4:23 am
1088
[Non-text portions of this message have been removed]...
Gadi Evron
ge.rm
Offline Send Email
Dec 3, 2004
3:50 pm
1089
Fri, 3 Dec 2004 17:47:27 From: "madsys" <madsys@...> Reply-To: madsys@... To: "bugtraq" <bugtraq@...>, ...
Gadi Evron
ge.rm
Offline Send Email
Dec 3, 2004
3:55 pm
1090
... response ... Hi Gadi, AIRT is for analysis of suspected compromised *nix boxes? Cheers, Blare...
blare_sutton
Offline Send Email
Dec 4, 2004
1:06 am
1091
... I have no idea. I saw it and I figured it might interest some people here. They say it is based on linux, so I suppose it should be? Gadi....
Gadi Evron
ge.rm
Offline Send Email
Dec 4, 2004
12:35 pm
1092
... LE ... whenever ... In your opinion, should LE perform live system analysis? With regards to powering down dilemma, I'd be more concerned with knocking out...
Enda Cronnolly
endacronnolly
Offline Send Email
Dec 4, 2004
4:10 pm
1093
... That depends on what you have available as a resource, and the situation of the particular scene. Take a simple crime involving someone with a home...
blare_sutton
Offline Send Email
Dec 5, 2004
6:23 am
1094
Quoting: "blare_sutton" ... The substantive issue is whether or not LE in Ian's case should have done anything without taking a hash of the drive.... which...
Enda Cronnolly
endacronnolly
Offline Send Email
Dec 5, 2004
1:55 pm
1095
... No I don't Edna. LE's current methods for analysis should remain the same. I'm only interested in them providing a hash of a drive on the receipt they give...
IanC
devorg
Offline Send Email
Dec 6, 2004
7:51 pm
1096
In an ideal world, the ideal would be to have a device with write- blocked readers for every form of electron storage media out there that will catch a MD5...
charles.d.sterne@...
simply_persi...
Offline Send Email
Dec 7, 2004
2:34 pm
1097
Arguably, if you "cut the power" there are many things that you will not be able to KNOW. All contemporary computer systems have the ability to run process' in...
Andrew Rosen
asrdata
Offline Send Email
Dec 7, 2004
3:45 pm
1098
Yesterday someday handed me an email and asked if I could prove if the message was authentic. I combed through the headers. After an hour I had a pretty good...
Jesse Kornblum
jessekornblum
Offline Send Email
Dec 7, 2004
9:08 pm
1099
... Why go so far? ...
Gadi Evron
ge.rm
Offline Send Email
Dec 7, 2004
9:20 pm
1100
RFC 2822, the Internet Message Format and its predecessor RFC 822 both dictate what the headers *should* be and what they *should* contain. Different email...
Jesse Kornblum
jessekornblum
Offline Send Email
Dec 7, 2004
9:27 pm
1101
Those example headers won't be enough to start with unfortunately. The first step would be to look at the email address and then the first 'received line' for...
IanC
devorg
Offline Send Email
Dec 8, 2004
12:35 am
1102
I believe you forgot to post your solution to this problem. It might help others in the field if, when you identify an issue, to also post the solution so...
alex@...
sir_llew
Offline Send Email
Dec 8, 2004
3:28 pm
1103
herein lies the primary difference between traditional "data forensics" and traditional "Incident Response". A prerequisite to a solution would be the ability...
Andrew Rosen
asrdata
Offline Send Email
Dec 9, 2004
12:25 am
1104
Andrew, I agree with you. The ICAC Task Force Technology Committee is researching a continuum of acceptable responses based on many factors including...
Flint Waters
flintwaters
Offline Send Email
Dec 9, 2004
2:50 pm
1105
Hi Flint - Good to see that ICAC is at the fore and considering/examining these things. I've worked on a few cases recently where those avenues were explored...
Andrew Rosen
asrdata
Offline Send Email
Dec 9, 2004
5:39 pm
1106
It usually isn't as big an issue when dealing with the traveler cases since we find the guy at the burger king with a box of condoms and a teddy bear. It does...
Flint Waters
flintwaters
Offline Send Email
Dec 9, 2004
7:35 pm
1107
I hope to have the training schedule for 2005 online before the end of next week. There have been several nifty enhancements to the software and the curriculum...
Andrew Rosen
asrdata
Offline Send Email
Dec 9, 2004
8:32 pm
1108
The team at Vital Data have released the latest version of FoRK (1.0.2) as a pre-Christmas present for everyone in the computer forensics community. The new...
blare_sutton
Offline Send Email
Dec 10, 2004
2:39 am
1109
Sounds familiar, this is precisely the defence introduced by the "hacker" Aaron Caffrey. The trojan virus that was used to attack the computers of the Port...
echo6
echo6_uk
Offline Send Email
Dec 11, 2004
12:31 pm
1110
I've a case where the client received an email. He responded to it something like " I love you too " Of course the email he received was a virus infected email...
IanC
devorg
Offline Send Email
Dec 12, 2004
1:05 am
1111
Folks, Looking for a little help here. Recently, our Task Force had started using digital imaging in some of it's drug cases. They stored the photos on a...
Christopher M. Taylor
ctaylor156rpd
Offline Send Email
Dec 13, 2004
9:26 pm
Messages 1082 - 1111 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help