Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Hear how Yahoo! Groups has changed the lives of others. Take me there.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2060 - 2100 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2060
Hi All, I know that I have seemed to have dropped off the face of the earth. I have been going through some personal as well as work transitions. I am glad to...
Ernie Baca
dborderman
Offline Send Email
Apr 10, 2006
1:37 pm
2061
Also, you must be willing to keep the project confidential, even the concept. I will probably be preapring a NDA for those participating in the project. The...
Ernie Baca
dborderman
Offline Send Email
Apr 10, 2006
1:46 pm
2064
(courtesy of http://digg.com) http://linuxhelp.blogspot.com/2006/04/linux-distributions-birds-eye-view.htm l There are umpteen GNU/Linux distributions and then...
Gary Funck
garyfunck
Offline Send Email
Apr 15, 2006
5:03 pm
2065
Hey, Anyone know of a way to mount SCO filesystems in linux? Typically a disk in a SCO system has a single partition which is broken into divisions much the...
Harry Duncan
usr.src.linux@...
Send Email
Apr 15, 2006
10:15 pm
2066
I just want to thank you for the response for my need for help with the New and Improved Penguin Sleuth Kit project. I have selected my testers and I should...
Ernie Baca
dborderman
Offline Send Email
Apr 17, 2006
3:26 pm
2068
Hi, Vinetto is a small forensics tool to examine Thumbs.db files. It is a command line python script that works on Linux, Mac OS X and Cygwin(win32). Last...
Michel Roukine
m_roukine
Offline Send Email
Apr 18, 2006
11:51 am
2069
I just installed and used the html option on gentoo. Works great and the html output is excellent. Art Montes ... [Non-text portions of this message have been...
Art Montes
kingofmex
Offline Send Email
Apr 18, 2006
9:52 pm
2070
Background: FTimes is a system baselining and evidence collection tool. The primary purpose of FTimes is to gather and/or develop information about specified...
snortboy2112
Offline Send Email
Apr 19, 2006
11:34 am
2072
I've been made aware of a useful tool that our 'Windoze' brethren use, called PEID. A quote from their page http://peid.tk/ : "PEiD detects most common...
bC
consultmac
Offline Send Email
Apr 19, 2006
11:29 pm
2073
... Maybe chkrootkit? http://www.chkrootkit.org/...
Gary Funck
garyfunck
Offline Send Email
Apr 20, 2006
1:16 am
2074
Maybe chkrootkit will be helpful to me in the big picture! What I am really looking for at this time, and correct me if I'm wrong about chkrootkit not doing...
bC
consultmac
Offline Send Email
Apr 20, 2006
2:50 am
2075
You can use the various packers themselves on linux to determine if a file is packed. eg: #here's some non packed files: $ ls printhi.py printhi.pyc #upx...
Jeff Bryner
jbryner1
Offline Send Email
Apr 20, 2006
6:41 pm
2076
... For me, the best PE reader for linux is : http://sourceforge.net/projects/perdr/ But it may need a little change in the source to compile with gcc4. Just...
Christophe Monniez
d_fence_242
Offline Send Email
Apr 20, 2006
7:19 pm
2077
Thanks Christophe. I will give that a look. I can't tell from the quick look yet if its something that I could drive with a script and/or another program. I...
bC
consultmac
Offline Send Email
Apr 20, 2006
11:52 pm
2079
Hi I'd like to ask what pointer do you know to identify when a Win9x/ME installation took place. I'm looking at the moment at Win95 installation and I identify...
fuerst@...
helvetus2004
Offline Send Email
Apr 25, 2006
3:49 pm
2080
Even though this doesn't have anything to do with Linux Forensics.... There is a paper at this link that may help...
Christine Siedsma
packys_99
Offline Send Email
Apr 25, 2006
8:40 pm
2081
Thank you, this is intersting. Unfortunately what I did calculate did not fit to the rest. But some google hits showed the same scheme as described in this...
fuerst@...
helvetus2004
Offline Send Email
Apr 26, 2006
9:48 am
2082
Okay I figured it out and it works. I also started writting a a small java application which does this task, it's unfinished yet but already can calculate the...
fuerst@...
helvetus2004
Offline Send Email
Apr 27, 2006
7:46 am
2083
... indicators? Not a Linux solution, or even a solution for Win9x, but wininternals psinfo utility can be handy running on NT/2K/XP, ...
Gary Funck
garyfunck
Offline Send Email
Apr 27, 2006
2:29 pm
2084
I'll keep that in mind if you run Windows some day...thank you Okay, I wrote it now: WinOra - to translate Win9x and WinNT InstallDate registry keys to human...
fuerst@...
helvetus2004
Offline Send Email
Apr 28, 2006
11:33 am
2085
Has anyone tried the dmraid package (either in a forensics, or in a user/admin setting)? It is a relatively recent addition to Linux, with the best level...
Gary Funck
garyfunck
Offline Send Email
Apr 28, 2006
2:55 pm
2086
A colleague of mine has been tasked with extracting the unused filesystem space from within a Novell Filesystem. Does anyone know how to do this or which tools...
The Dog's Bollix
ISXPRO
Offline Send Email
May 3, 2006
4:23 pm
2087
... Yahoo! India Answers: Share what you know. Learn something new. Click here Send instant messages to your online friends - NOW [Non-text portions of this...
Murali
tt_muralee
Offline Send Email
May 8, 2006
2:01 pm
2088
... Check out http://www.runtime.org/captain.htm. I saw in another Linux forum as a suggested tool. It has a data recovery feature that may provide some...
Jacques B.
jboucher_work
Offline Send Email
May 9, 2006
1:32 pm
2094
Well, Many of you will notice that Linux-Forensics.com and Putercops.org are nowe one in the same. I have decided to centralize all my efforts to one site. I...
Ernie Baca
dborderman
Offline Send Email
May 30, 2006
7:26 pm
2096
As this group is a good example of practicing forensics, I'm wondering if any of you have a preference for imaging devices. I've found that imaging a drive...
Ronald L. Chichester
ron@...
Send Email
Jun 6, 2006
7:32 pm
2097
... Well, at my current job, the Standard Operating Procedure is to: 1. extract the source drive 2. put it in a drive carrier (Like an IDE "cold swap" tray) 3....
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jun 6, 2006
11:01 pm
2098
I missed this earlier, but in re-reading some of the list messages I noticed it and couldn't resist responding. Your assumption that there is "essentially no...
Steve Gibson
sw_gibson
Offline Send Email
Jun 7, 2006
1:02 pm
2099
... I did some work for a firm that used one of those (not sure if it was the same make/model, of course, but they had a hand-held imager). What a ...
Stevens R. Miller
bobhey2000
Offline Send Email
Jun 7, 2006
1:33 pm
2100
... Sorry to be unclear. My "appliance" was just a PC with Linux and a custom script. :) It worked great! ... Good point. I've got a Canon 20D which has a...
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jun 7, 2006
3:01 pm
Messages 2060 - 2100 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help