Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2369 - 2399 of 3158   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2369
Here, here. While there may not yet be a generally recognized and accepted "CPA" equivalent certification standard or training process for 'computer ...
Sterne, Charles D
simply_persi...
Offline Send Email
Nov 1, 2006
3:46 pm
2370
Ok here goes my politically incorrect statement as usual and realistic approach based on personal experience. Sometimes we get so caught up in a laboratory,...
Ernest Baca
dborderman
Offline Send Email
Nov 1, 2006
6:07 pm
2371
... Avoiding the 'to cert or not to cert' question and focusing on what to get, I'd recommend SANS (www.sans.org) and their certs. They have a continued focus...
Jeff Bryner
jbryner1
Offline Send Email
Nov 1, 2006
11:58 pm
2372
... Do they offer a platinum version? ;) farmerdude...
farmerduderl
Offline Send Email
Nov 7, 2006
3:37 am
2373
... Yeah, to me it is a said statement that there used to be only one version; do the practical + pass the test(s) or don't get the cert. Now there's an option...
Jeff Bryner
jbryner1
Offline Send Email
Nov 7, 2006
5:57 pm
2374
... That is the way many people felt when they made the change. I learned more from the practical than anything else. K Murphy...
maillist
maillist@...
Send Email
Nov 8, 2006
12:00 am
2375
My question is: if a suspect uses Linux and burns a .iso image to a CD-ROM using a utility such as k3b, is there any way to forensically trace the burned...
dobbscenter
Offline Send Email
Nov 9, 2006
12:56 am
2376
... It is sometimes possible to find remnants of the ISO creation process in deleted file space, including contents of the files that were included in the ISO...
Dave Dittrich
dadittrich
Offline Send Email
Nov 9, 2006
1:23 am
2377
Here is my two cents, This has always been a concern of mine, Which Cert. to invest your money into that is recognized by both corp. and LE and gov.. In the...
Harvey Rothenberg
forensic28sa
Offline Send Email
Nov 9, 2006
5:50 pm
2378
... I remember seeing a show on that. The military had done it I believe. It was a 5 1/4" floppy at the time. The guy cut it up in pieces as the military...
Jacques B.
jboucher_work
Offline Send Email
Nov 10, 2006
3:15 am
2379
I have seen the same doco. From memory they used Anadisk http://www.forensics-intl.com/anadisk.html on the spliced disk. I am pretty sure it contained some...
rclaybigpond.net.au
dodgertron
Offline Send Email
Nov 10, 2006
4:28 am
2380
I attended training for IACIS in 1994 and we dui the cut up diskette deal. We were each given a diskette that had been cut in large chunks. As I remember the...
Clayton Hoskinson
cfexaminer1
Offline Send Email
Nov 10, 2006
12:49 pm
2381
Here are some information in french that were post on the site zataz.com in 2000. The software used was effectively ...
Eric MARLIERE-ALBRECHT
eric_marlier...
Offline Send Email
Nov 11, 2006
2:01 pm
2382
... Hi Jesse, I tried it when I first heard about it on Cyberspeak. It seems to work well. I was anticipating that it would work its way into forensic...
Jacques B.
jboucher_work
Offline Send Email
Nov 14, 2006
2:36 am
2383
Hi Jessie, I had previously used it and it seemed to work well. I just tested it tonight under Linux (FC5) by running it against a folder and piping to a...
Jacques B.
jboucher_work
Offline Send Email
Nov 14, 2006
3:20 am
2384
Minor correction to my posting in "quotes"... ... Thanks, Jacques B....
Jacques B.
jboucher_work
Offline Send Email
Nov 14, 2006
3:29 am
2385
This site illustrates the use of SSDeep and a GUI front-end to find files or disk blocks that match blocks in a known sample: ...
Gary Funck
garyfunck
Offline Send Email
Nov 14, 2006
5:01 am
2386
You are exactly right that fuzzy hashing doesn't work well with small files. The limitation comes from the underlying math, so it's not something that can be...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 15, 2006
3:11 am
2387
... Thanks Jesse. That's good to know. Would you perhpaps be able to modify the application so that if a file is too small to properly fuzzy hash that it...
Jacques B.
jboucher_work
Offline Send Email
Nov 15, 2006
2:07 pm
2388
Hi All I have been tasked to examine a computer which was found to be running at the scene of an att murder. The machine is running Windows Vista RC1 beta and...
Stuart Bird
e_tective
Offline Send Email
Nov 16, 2006
8:02 pm
2389
Stuart, Since W2k3 SP1, including Vista, M$ moved access to the object \\.\PhysicalMemory from user land to kernel land. Thus dd off the Helix disk will...
Echo6
echo6_uk
Offline Send Email
Nov 16, 2006
9:25 pm
2390
Where can I get knttools or kntdd? -- Jesse...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 16, 2006
9:55 pm
2391
[I've renamed the subject line to be more descriptive.] ... [...] ... If you can successfully image the system (and process) memory, the question may still...
Gary Funck
garyfunck
Offline Send Email
Nov 16, 2006
10:57 pm
2392
Hey Jesse, I kicked an email to George M. Garner Jr, the developer for this knttools/kntdd to see if he had an open source available for the public. He...
r00t_0101
Offline Send Email
Nov 17, 2006
11:28 pm
2393
Hi list, I have taken an image of a small harddisk with using ddrescue. The disk has this layout: $#mmls image.dd DOS Partition Table Sector: 0 Units are in...
Emat
forensics@...
Send Email
Nov 19, 2006
10:22 pm
2395
... you checked to see if there is a valid boot sector there? dd if=image.dd bs=512 skip=63 count=1 | xxd | less Look for a DOS signature (OEM string should be...
Barry J. Grundy
grundy_b
Offline Send Email
Nov 20, 2006
5:07 pm
2396
We recently acquired a firefly 800 IDE bridge, described here: http://www.ncjrs.gov/pdffiles1/nij/212957.pdf We plugged it into an Adaptec Fireconnect 8300 ...
Gary Funck
garyfunck
Offline Send Email
Nov 28, 2006
4:42 am
2397
Here ya go: http://www.linux1394.org/ ... ________________________________________________________________________ 1. Linux + firefly 800/IDE => working? ...
Sterne, Charles D
simply_persi...
Offline Send Email
Nov 28, 2006
3:31 pm
2398
... Thanks, I plugged "+firefly site:linux1394.org" into Google and this turned up: http://www.linux1394.org/view_device.php?id=688 Class: Storage...
Gary Funck
garyfunck
Offline Send Email
Nov 28, 2006
4:10 pm
2399
Stuart, I sincerely hope you capture and convict the guilty party. As a criminal defense attorney, though, I have to wonder if there is anything akin to the ...
Stevens R. Miller
bobhey2000
Offline Send Email
Nov 28, 2006
6:19 pm
Messages 2369 - 2399 of 3158   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help