Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2521 - 2550 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2521
I've been playing around with the dd command using the conv=noerror,sync option. I was always told that sync will pad sectors generating read errors with \x00...
Jacques B.
jboucher_work
Offline Send Email
May 9, 2007
11:12 pm
2522
It is a good question, but there are some forensic reasons for using the sync option, for instance if you are backing-up or reading from a tape you will have...
Bob Kardell
bobkardell
Offline Send Email
May 10, 2007
2:40 am
2523
The reason for the "sync" option is so that your offset remains the same and the data can be intelligently interpreted, as I am sure you are aware. Your...
Sutton, Blare
blare_sutton
Offline Send Email
May 10, 2007
4:40 am
2524
On 5/9/07, Bob Kardell <bobkardell@...> wrote: <snip> ... Thanks for that info Bob. My only concern with your method is that with the dd option | to md5...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
2:08 am
2525
On 5/10/07, Sutton, Blare <bsutton@...> wrote: However, you may be interested to note that dcfldd has an inbuilt ... Interesting. I was not aware of...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
2:14 am
2526
"Jacques B." <jjrboucher@...> wrote: But my original question was does it really pad read errors along the way to...
Eamonn Saunders
eamonns
Offline Send Email
May 11, 2007
9:15 am
2527
... That is correct. And if you are zero filling due to read errors, you are also hashing those zeros that you write. But we are talking best evidence rules...
Sutton, Blare
blare_sutton
Offline Send Email
May 11, 2007
12:43 pm
2528
... A. No. No data is added to the original file. The hash is computed based on the exact duplicate, and on a pad used to fill the final block after the ...
Stevens R. Miller
bobhey2000
Offline Send Email
May 11, 2007
3:53 pm
2529
Thanks Blare for that excellent explanation! Very good, detailed info. And thank you Stevens for your feedback. Of course I was playing Devil's advocate and...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
4:09 pm
2530
It's good for all of us here to play the advocate for both sides. No telling what a judge will permit or how well your (or the other side's) lawyer will...
Stevens R. Miller
bobhey2000
Offline Send Email
May 11, 2007
8:08 pm
2531
... My involvement has been on the criminal side. I've only had to testify a few times (most times I'm not required either because of a guilty plea,...
Jacques B.
jboucher_work
Offline Send Email
May 11, 2007
11:25 pm
2532
... Agreed! That is why I have always advised _against_ the detailed, meticulous, paramilitary-style logging forms that police departments routinely use....
Stevens R. Miller
bobhey2000
Offline Send Email
May 12, 2007
12:40 am
2533
... Add a bottle of Captain Morgan's Spiced Rum and we can debate it all night :-) Jacques B....
Jacques B.
jboucher_work
Offline Send Email
May 12, 2007
6:06 am
2534
Hello All, I am selling a Logicube Forensic MD 5 with hard case. I purchased the unit a little over a year ago and have only used it 6 times. I had the same...
dr_kac@...
dr_kac
Offline Send Email
May 15, 2007
3:30 pm
2535
Hello All, I am selling a Logicube Forensic MD 5 with hard case. I purchased the unit a little over a year ago and have only used it 6 times. I had the same...
dr_kac@...
dr_kac
Offline Send Email
May 15, 2007
3:32 pm
2536
I am working with a drive image in EnCase (6.5 Enterprise). I am just starting to learn EnCase so bear with me. The image I am working with is 40gb and is...
mingthemercil
Offline Send Email
May 16, 2007
6:18 pm
2537
... Well, if you want to get the deleted files on the drive, use TCT/Autopsy then. If you want help in using Encase, report it as a bug to the software vendor...
Harry Duncan
usr.src.linux@...
Send Email
May 16, 2007
7:22 pm
2538
... I don't have EnCase in front of me, but I suspect the case is that you are filtering for deleted files, not deleted and overwritten (which may be what...
Jacques B.
jboucher_work
Offline Send Email
May 17, 2007
1:45 am
2539
... Forgot to mention, the other issue is if you have the home plate on the entire case. If not, you will only see files for the directory in which you are...
Jacques B.
jboucher_work
Offline Send Email
May 17, 2007
12:25 pm
2540
Did you run "Recover Folders" across the partition? Blare Sutton Senior Manager e  bsutton@...   |   t  +61 3 9653 6241   |   m  0417 252 739...
Sutton, Blare
blare_sutton
Offline Send Email
May 23, 2007
10:31 pm
2541
While this is a *nix forensics list, not an EnCase forensics list (EnCase has it's own list), the variances you noted are variances in the approaches the two...
Sterne, Charles D
simply_persi...
Offline Send Email
May 24, 2007
2:01 pm
2542
Hi All I appreciate that this may be bread and butter to most on this list, but if you don't know you don't know :) How do I go about viewing compound file...
Stuart Bird
e_tective
Offline Send Email
Jun 1, 2007
2:27 pm
2543
Hi Stu, Take a look at libpst http://alioth.debian.org/projects/libpst/ and http://mbx2mbox.sourceforge.net/ Regards, Jon. ... From: Stuart Bird...
Echo6
echo6_uk
Offline Send Email
Jun 1, 2007
4:54 pm
2544
Anyone else read this article? Comments? http://www.cio.com/article/print/114550 =============================================== "How Online Criminals Make...
Linux User
julio_hormel
Offline Send Email
Jun 2, 2007
7:30 am
2545
... From the snippet you've posted: 1) His dictionary definition of forensics is incorrect / incomplete. 2) His view on the usefulness of digital forensics is...
Enda Cronnolly
endacronnolly
Offline Send Email
Jun 2, 2007
2:30 pm
2546
yes, several people posted comments on the original web page that it was poorly written. aside from that, has anybody here encountered these problems? I knew...
Linux User
julio_hormel
Offline Send Email
Jun 2, 2007
6:26 pm
2547
This sort of thinking is perpetual in magazines aimed at senior corporate officers. The line about "hobby level" is especially telling. He's just playing to...
Stevens R. Miller
bobhey2000
Offline Send Email
Jun 2, 2007
6:40 pm
2548
Digital Investigation: The International Journal of Digital Forensics & Incident Response The Journal of Digital Investigation is a widely referenced...
nikkel@...
Send Email
Jun 5, 2007
1:13 pm
2549
Hi I am currently working on an image of a 20 Gb /root partition (/dev/sda2). I then used foremost to look for video files of interest and found a number of...
Stuart Bird
e_tective
Offline Send Email
Jun 12, 2007
4:53 pm
2550
Hi Stu, ... What strings are you looking for? What grep terms? How are you looking for the file? Was the file allocated or unallocated? ... Nothing at all?...
Barry J. Grundy
grundy_b
Offline Send Email
Jun 12, 2007
6:52 pm
Messages 2521 - 2550 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help