Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2485 - 2534 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2485
A common situation I encounter is a file, especially an email inbox file, that is zeroed out during a disk overflow crash. I use Thunderbird, so the mailboxes...
Jon Roland
jon_roland
Offline Send Email
Apr 2, 2007
12:18 pm
2487
Hello, Not really sure if anyone can help me here or not. Or maybe point me in the right spot. I have a few question, but first I will explain why I'm...
beautycr75
Offline Send Email
Apr 6, 2007
3:20 am
2499
I will be out of the office starting 04/09/2007 and will not return until 04/18/2007. From 04/09 until 04/12, If it is urgent please call Ninfa Altadonna, my ...
Raymond_Smith@...
raysmith46
Offline Send Email
Apr 10, 2007
5:04 am
2502
... That is totally dependant on the resolution fo the image. If it's a 1 megapixel image, then it will get fuzzy fairly quickly vs a 8 megapixel image. When...
Jacques B.
jboucher_work
Offline Send Email
Apr 16, 2007
1:20 pm
2503
... I would suggest that Jacques has overlooked a middle ground: you can have a forensic analyst make and hold an image copy of the drive. Also have that ...
Stevens R. Miller
bobhey2000
Offline Send Email
Apr 16, 2007
3:41 pm
2504
... Good point. For that matter you yourself could run data recovery tools against a copy/the image if you wished. But ultimately if it's going to court it...
Jacques B.
jboucher_work
Offline Send Email
Apr 16, 2007
4:46 pm
2507
Hello, And thank all of you for your replys. Yes, it could be the only thing we have. So, is there any way I can look to see if it's just still on there....
beautycr75
Offline Send Email
Apr 18, 2007
10:35 pm
2508
... Regards to looking at it without messing anything up, that can be done by booting the computer with a forensically sound live CD (this being a Linux system...
Jacques B.
jboucher_work
Offline Send Email
Apr 18, 2007
11:57 pm
2509
I thought that this would be the correct group to learn what software OR written procedures are being used to be the overall structure for a department. I know...
forensic28sa
Offline Send Email
Apr 20, 2007
3:39 pm
2511
Greetings All, I have a case where it is suspected that a highly skilled individual was given a WinXP laptop system acquired from a deceased user's effects,...
Steve Fowler
sfowler@...
Send Email
Apr 27, 2007
1:54 am
2512
... Two areas that you can look at to help you determine if date/time manipulation took place would be the Windows events logs (.evt files) and the Windows...
Jacques B.
jboucher_work
Offline Send Email
Apr 27, 2007
8:52 am
2513
... Look for evidence of windows re-activation, as the most effective way to remove evidence is to trash the drive and the most effective way of covering that...
Enda Cronnolly
endacronnolly
Offline Send Email
Apr 27, 2007
9:39 am
2514
If history files can be scrounged up from active or unallocated space, it might also be interesting to see if there are places where history dates are way out...
Steve Burgess
diarmiud
Offline Send Email
Apr 27, 2007
3:23 pm
2515
The below was found on another board. I believe it may be what you are looking for. Test before relying on the validity of the information as the UserAssist...
Rob Jones
moltisanti15601
Offline Send Email
Apr 27, 2007
5:31 pm
2516
... Neat. Didn't know that one. I tested it quickly and it seems to only change when you make a change to the date/time. I was double clicking on the time...
Jacques B.
jboucher_work
Offline Send Email
Apr 27, 2007
6:46 pm
2517
Steve, I'm not sure I've got a grasp exactly of the problem, so I can't really offer any solution. That being said, if it's thought that this user only ...
Scott Pugmire
swinginscott
Offline Send Email
Apr 27, 2007
9:24 pm
2521
I've been playing around with the dd command using the conv=noerror,sync option. I was always told that sync will pad sectors generating read errors with \x00...
Jacques B.
jboucher_work
Offline Send Email
May 9, 2007
11:12 pm
2522
It is a good question, but there are some forensic reasons for using the sync option, for instance if you are backing-up or reading from a tape you will have...
Bob Kardell
bobkardell
Offline Send Email
May 10, 2007
2:40 am
2523
The reason for the "sync" option is so that your offset remains the same and the data can be intelligently interpreted, as I am sure you are aware. Your...
Sutton, Blare
blare_sutton
Offline Send Email
May 10, 2007
4:40 am
2524
On 5/9/07, Bob Kardell <bobkardell@...> wrote: <snip> ... Thanks for that info Bob. My only concern with your method is that with the dd option | to md5...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
2:08 am
2525
On 5/10/07, Sutton, Blare <bsutton@...> wrote: However, you may be interested to note that dcfldd has an inbuilt ... Interesting. I was not aware of...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
2:14 am
2526
"Jacques B." <jjrboucher@...> wrote: But my original question was does it really pad read errors along the way to...
Eamonn Saunders
eamonns
Offline Send Email
May 11, 2007
9:15 am
2527
... That is correct. And if you are zero filling due to read errors, you are also hashing those zeros that you write. But we are talking best evidence rules...
Sutton, Blare
blare_sutton
Offline Send Email
May 11, 2007
12:43 pm
2528
... A. No. No data is added to the original file. The hash is computed based on the exact duplicate, and on a pad used to fill the final block after the ...
Stevens R. Miller
bobhey2000
Offline Send Email
May 11, 2007
3:53 pm
2529
Thanks Blare for that excellent explanation! Very good, detailed info. And thank you Stevens for your feedback. Of course I was playing Devil's advocate and...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
4:09 pm
2530
It's good for all of us here to play the advocate for both sides. No telling what a judge will permit or how well your (or the other side's) lawyer will...
Stevens R. Miller
bobhey2000
Offline Send Email
May 11, 2007
8:08 pm
2531
... My involvement has been on the criminal side. I've only had to testify a few times (most times I'm not required either because of a guilty plea,...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
11:25 pm
2532
... Agreed! That is why I have always advised _against_ the detailed, meticulous, paramilitary-style logging forms that police departments routinely use....
Stevens R. Miller
bobhey2000
Offline Send Email
May 12, 2007
12:40 am
2533
... Add a bottle of Captain Morgan's Spiced Rum and we can debate it all night :-) Jacques B....
Jacques B.
jboucher_work
Offline Send Email
May 12, 2007
6:06 am
2534
Hello All, I am selling a Logicube Forensic MD 5 with hard case. I purchased the unit a little over a year ago and have only used it 6 times. I had the same...
dr_kac@...
dr_kac
Offline Send Email
May 15, 2007
3:30 pm
Messages 2485 - 2534 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help