Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 1773 - 1804 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
1773
Dear Colleagues, Here is an interesting thing that I found. Its a 3D animation of Linux source code development. Its a bit large file of about 9 MB. But its...
Hussain Hyder Ali Kho...
hhalik
Offline Send Email
Oct 1, 2005
1:55 pm
1774
I'd like to formally announce my latest open-source tool called tcpxtract. <a href="http://tcpxtract.sf.net">http://tcpxtract.sf.net/</a> tcpxtract is a tool...
Nicholas Harbour
nicholasharbour
Offline Send Email
Oct 7, 2005
1:29 pm
1775
We may have a project coming up where we need to image copy 10 to 20 drives from various PC's and servers, in relatively short order. The opportunity to make...
Gary Funck
garyfunck
Offline Send Email
Oct 7, 2005
4:48 pm
1776
Is using the actual machines (PC's & servers) themselves an option? If so, drop an IDE drive in each of the machines (on the second IDE channel, or if they are...
Jacques B.
jboucher_work
Offline Send Email
Oct 7, 2005
6:41 pm
1777
Jacques's approach has worked for me. I have done over 20 in one day with this approach, single-handed. (Average drive size was about 40Gb on that one, but...
Stevens R. Miller
bobhey2000
Offline Send Email
Oct 7, 2005
8:36 pm
1778
... This is certainly a good idea, and something that may be applicable in a different situation. Unfortunately, some or most of the servers have been in...
Gary Funck
garyfunck
Offline Send Email
Oct 7, 2005
8:51 pm
1779
... I dearly hope those servers are working well enough to boot a diskette, at least the ones with RAID controllers. There may be software that truly does ...
Stevens R. Miller
bobhey2000
Offline Send Email
Oct 7, 2005
9:11 pm
1780
There are two schools of thoughts on imaging RAIDS, relying on the RAID volumes served up by the hardware RAID controller, or acquiring the individual drives...
Jacques B.
jboucher_work
Offline Send Email
Oct 7, 2005
9:48 pm
1781
... This depends on your analysis tools, and the sources acquired. For example, using SMART for Linux to acquire using the partition aligned option allows for...
farmerduderl
Offline Send Email
Oct 9, 2005
1:45 am
1782
By the way if you are working on the Windows side and don't have a forensic tool such as EnCase, FTK, ProDiscover, or other such tool that will allow you to...
Jacques B.
jboucher_work
Offline Send Email
Oct 9, 2005
2:56 am
1783
... !!!!!! You mean it's finally here!?!?? Come on Thomas put us all out of our misery, release the darn thing :-)...
Echo Six
echo6_uk
Offline Send Email
Oct 9, 2005
6:56 pm
1784
... SMART is not open source, and rather costly, IMO. We've heard good things about SMART, and perhaps we aren't viewing it from the proper ROI point of view,...
Gary Funck
garyfunck
Offline Send Email
Oct 9, 2005
7:32 pm
1785
... [...] ... I was thinking that if we have to set up partition-by-partition image copies that there would be more steps involved than just copying the entire...
Gary Funck
garyfunck
Offline Send Email
Oct 9, 2005
8:29 pm
1786
The thing to remember about SMART is that so far ASRData has never charged for an upgrade. To date they've all be absolutely free for the past 15+ years (and...
Jacques B.
jboucher_work
Offline Send Email
Oct 9, 2005
8:30 pm
1787
... things ... point of ... Correct - SMART for Linux is not open source. As for "rather costly, IMO" - I *think* you contradict yourself because you say in...
farmerduderl
Offline Send Email
Oct 9, 2005
8:41 pm
1788
... longer. True, using pure Linux there would be. And, even scripting this would take time. More time than just firing up SMART for Linux and ...
farmerduderl
Offline Send Email
Oct 9, 2005
8:46 pm
1790
I would like to know how you would go about tracking Instant messenger. I am especially interested in how to track where a message came from and any logs. ...
Dennis Borkhus-Veto
dbveto
Offline Send Email
Oct 14, 2005
3:57 pm
1791
Background: I've never tried working with Linux USB support, and perhaps I should ... but before I try that ... I was wondering .... We're looking for ways to...
Gary Funck
garyfunck
Offline Send Email
Oct 15, 2005
1:18 am
1792
... depends on the unit's BIOS, you could use a boot floppy that lets you boot via USB in some cases ... w/ knoppix, and other live images that have usb mass...
styroteqe
Offline Send Email
Oct 15, 2005
1:24 am
1793
Personally when I want to mount a USB device in Linux, I simply connect it and then execute the dmesg command. The last lines displayed should show you how...
Jacques B.
jboucher_work
Offline Send Email
Oct 15, 2005
7:53 pm
1794
Based on farmerdude's recommendations, and those of others on this list ... I've been experimenting with IDE drives plugged into an inexpensive firewire/usb2...
Gary Funck
garyfunck
Offline Send Email
Oct 16, 2005
9:38 pm
1795
... Sounds like a Windows question, not a linux question. My experience is that so long as you don't have a mounted filesystem, you can plug and unplug to your...
The Dog's Bollix
ISXPRO
Offline Send Email
Oct 17, 2005
12:22 am
1796
Gary, We have used the FireFly for quite some fime with multiple products and multiple operating systems. We are quite happy with it. It is a windows...
securityfocus
securityfocus@...
Send Email
Oct 17, 2005
2:55 am
1797 neharai2005@...
neharai2005
Offline Send Email
Oct 17, 2005
9:47 am
1799
Gary, USB/1394 to ATA Bridges: If you're in read-write mode, you definitely should think about unmounting any active file system before unhooking it from your...
Sterne, Charles D
simply_persi...
Offline Send Email
Oct 17, 2005
1:56 pm
1800
... I've used the tableau firewire/usb write blocker (they call it the firewire800 IDE bridge) to great effect. ... Since this is a linux group; it's worth...
Jeff Bryner
jbryner1
Offline Send Email
Oct 17, 2005
4:46 pm
1801
I dont know whether this was mentioned but you can scan for device names of recognized USB devices by grabbing the rescan-scsi-bus.sh script(google), running...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 18, 2005
7:34 pm
1802
For those of you in the /proc mindset you can also tell where it's at by issuing cat /proc/partitions before and after the device is connected. Jeff....
Jeff Bryner
jbryner1
Offline Send Email
Oct 18, 2005
7:49 pm
1803
I'd appreciate some advice. We have an image of a Sparc disk from a RAID1 (mirror) configuration with VTOC partitions. fdisk -l and mmls both give the same...
l1st3r@...
Send Email
Oct 21, 2005
8:13 pm
1804
... You need to tell the tools where the file system starts using the '- o' argument. So, you can run the tools on the disk image and supply the partition...
Brian Carrier
bdcarrier
Offline Send Email
Oct 22, 2005
3:09 pm
Messages 1773 - 1804 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help