Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 1269 - 1298 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
1269
Looking at a drive and I can't locate the index.dat files for Internet History. MS Internet Explorer version 3 was used here mostly. I know I should be looking...
devorg
Offline Send Email
Feb 5, 2005
1:25 am
1270
Greetings, Maybe you are thinking of Mm256.dat and Mm2048.dat Files Quote: The Mm256.dat and Mm2048.dat files are cache files used by Internet Explorer...Note...
Christine Siedsma
packys_99
Offline Send Email
Feb 5, 2005
5:53 pm
1271
Thanks Christine. Those are the ones. They were empty though so I thought I was looking at the wrong files....
IanC
devorg
Offline Send Email
Feb 5, 2005
6:19 pm
1272
If those files were empty, and the computer HAD been used to access the web, then there's a strong shot that a "cleaner" was used. Almost all advertise to...
The Dog's Bollix
ISXPRO
Offline Send Email
Feb 5, 2005
10:20 pm
1273
There's no indication that a cleaner was used at all so I think Internet Explorer was set to use the minimum amount of disk space for historic files, thus the...
IanC
devorg
Offline Send Email
Feb 6, 2005
5:47 pm
1274
Defense side of things. Can anyone recommend a Dr. that's conversant in court regarding distinguishing what is, (or not) a depiction of a real child off an...
IanC
devorg
Offline Send Email
Feb 6, 2005
8:22 pm
1275
You dont need a Dr. An experienced sexual abuse investigator that has been certified as an expert in a federal court will work. I believe retired Las Vegas...
Larry S
lasvegascop
Offline Send Email
Feb 6, 2005
8:47 pm
1276
... I am sure you know what you are doing, but as a guy who unfortunately had a close look at CP related laws in different countries, I'd suggest staying as...
Gadi Evron
ge.rm
Online Now Send Email
Feb 6, 2005
8:48 pm
1277
... Rest assured. You can consider me as being 100% within the law in regards to this type of forensic image shite. And 99+% within the law on other things...
IanC
devorg
Offline Send Email
Feb 6, 2005
9:30 pm
1278
Are you working with the defense or the prosecution? Rob J. ... [Non-text portions of this message have been removed]...
Rob Jones
moltisanti15601
Offline Send Email
Feb 7, 2005
4:50 am
1279
Never mind ... [Non-text portions of this message have been removed]...
Rob Jones
moltisanti15601
Offline Send Email
Feb 7, 2005
4:51 am
1280
Hello group, I have a 40GB 3.5" Toshiba Hard drive that has a partition setup like this: /dev/hda ~40,000,000,000 /dev/hda1 ~15,000,000,000 Windows FAT32 ...
securehell
Offline Send Email
Feb 7, 2005
4:43 pm
1281
Slightly off topic, but the Atlanta Chapter of the HTCIA is again hosting the 2005 Southeast Cybercrime Summit in metro Atlanta. www.atlccs.com. The Summit is...
wiseguypi
Offline Send Email
Feb 7, 2005
10:41 pm
1282
why don't you post the output to : # sfdisk -l -Su /dev/hda That may provide a little more information. Tony. securehell <securehell@...> wrote: Hello...
The Dog's Bollix
ISXPRO
Offline Send Email
Feb 8, 2005
3:34 am
1283
... Did you try testdisk (www.cgsecurity.org/testdisk.html) or gpart (http://www.stud.uni-hannover.de/user/76201/gpart/)? Dietmar...
Dietmar Mauersberger
mausburger
Offline Send Email
Feb 8, 2005
7:54 am
1284
O.K. Here's the output of "sfdisk -l -sU /dev/hda", "fdisk -l /dev/hda" and "fdisk -l -u /dev/hda": # sfdisk -l -Su /dev/hda Disk /dev/hda: 4864 cylinders, 255...
securehell
Offline Send Email
Feb 8, 2005
5:08 pm
1285
... It looks like the logical partition starts (hda5) starts way farther into the extended partition than is normal (63 sectors). You'll have to get some...
Barry J. Grundy
grundy_b
Offline Send Email
Feb 8, 2005
5:35 pm
1286
(Without write blockers) If both are windows operating systems what actually alters on a slave drive upon normal boot up? Recycle bin is on both of course....
IanC
devorg
Offline Send Email
Feb 8, 2005
11:21 pm
1287
If you are using NT, 2K, XP, and the second drive is NTFS, the MFT table will be changed (I.E will clean up any thing in the MFT that was not in order.) Joe...
joe.brown@...
joeb1kenobe
Offline Send Email
Feb 8, 2005
11:46 pm
1288
2nd question to this thread. I appreciate this is a *nix group but I still think it might be a valid point here. ~~~~ If I use Windows (like maybe iLook...
IanC
devorg
Offline Send Email
Feb 9, 2005
12:14 am
1289
... I've heard that "testing" is a pretty good way to answer questions like this. .c...
Altheide, Cory B. (IA...
digitalquincy
Offline Send Email
Feb 9, 2005
12:21 am
1290
... I don't like the answers I'm seeing at the moment. Have progressed slightly down hill, but still testing though :-)...
IanC
devorg
Offline Send Email
Feb 9, 2005
12:30 am
1291
This may not be what your looking for, but according to a forensic book I have and some courses I've taken, Windows alters some 200 + files each and every time...
Luis Salazar
Luis.Salazar@...
Send Email
Feb 9, 2005
12:31 am
1292
Now I am sure that was some very helpful information. ... http://us.click.yahoo.com/TzSHvD/SOnJAA/79vVAA/M4xqlB/TM...
David Wilson
drindles
Offline Send Email
Feb 9, 2005
12:34 am
1293
Read-only mode or virtual image view mode would work fine Luis. But the restoring (and not shutting off the system immediately thereafter) appears to alter...
IanC
devorg
Offline Send Email
Feb 9, 2005
12:56 am
1294
Thanks for the follow-up, I knew my answer was to basic. But I couldn't resist joining the thread. I'll keep reading. Thanks. ... Read-only mode or virtual...
Luis Salazar
Luis.Salazar@...
Send Email
Feb 9, 2005
1:19 am
1295
You bring up another good point here Luis. Regarding what is actually on the drive that the user knows about, installed,, or even a forensic examination can't...
IanC
devorg
Offline Send Email
Feb 9, 2005
2:23 am
1296
Hello, I have a weird linux forensics related question. I typed up a long document in a window inside of mozilla firefox. For some reason it failed; I...
Marc M
maxwellmarc
Offline Send Email
Feb 9, 2005
3:07 am
1297
... Hello Marc, ... In all the system generally a lot of part of data is recoverable. The first thing to do in order to recover the swap space in a Linux ...
Francisco Pecorella
fpecorel
Offline Send Email
Feb 9, 2005
3:00 pm
1298
Hello everyone, My name is David and I am new to Computer Forensics and have just started reading the old posts. I have a question and wondering if anyone can...
David L
v_1dlivi
Offline Send Email
Feb 9, 2005
4:31 pm
Messages 1269 - 1298 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help