Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2542 - 2573 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2542
Hi All I appreciate that this may be bread and butter to most on this list, but if you don't know you don't know :) How do I go about viewing compound file...
Stuart Bird
e_tective
Offline Send Email
Jun 1, 2007
2:27 pm
2543
Hi Stu, Take a look at libpst http://alioth.debian.org/projects/libpst/ and http://mbx2mbox.sourceforge.net/ Regards, Jon. ... From: Stuart Bird...
Echo6
echo6_uk
Offline Send Email
Jun 1, 2007
4:54 pm
2544
Anyone else read this article? Comments? http://www.cio.com/article/print/114550 =============================================== "How Online Criminals Make...
Linux User
julio_hormel
Offline Send Email
Jun 2, 2007
7:30 am
2545
... From the snippet you've posted: 1) His dictionary definition of forensics is incorrect / incomplete. 2) His view on the usefulness of digital forensics is...
Enda Cronnolly
endacronnolly
Offline Send Email
Jun 2, 2007
2:30 pm
2546
yes, several people posted comments on the original web page that it was poorly written. aside from that, has anybody here encountered these problems? I knew...
Linux User
julio_hormel
Offline Send Email
Jun 2, 2007
6:26 pm
2547
This sort of thinking is perpetual in magazines aimed at senior corporate officers. The line about "hobby level" is especially telling. He's just playing to...
Stevens R. Miller
bobhey2000
Offline Send Email
Jun 2, 2007
6:40 pm
2548
Digital Investigation: The International Journal of Digital Forensics & Incident Response The Journal of Digital Investigation is a widely referenced...
nikkel@...
Send Email
Jun 5, 2007
1:13 pm
2549
Hi I am currently working on an image of a 20 Gb /root partition (/dev/sda2). I then used foremost to look for video files of interest and found a number of...
Stuart Bird
e_tective
Offline Send Email
Jun 12, 2007
4:53 pm
2550
Hi Stu, ... What strings are you looking for? What grep terms? How are you looking for the file? Was the file allocated or unallocated? ... Nothing at all?...
Barry J. Grundy
grundy_b
Offline Send Email
Jun 12, 2007
6:52 pm
2551
Hi Barry Thanks for the response. ... I won't expand on what I had done as you were correct in that the file name is arbitrary and therefore I was effectively...
Stuart Bird
e_tective
Offline Send Email
Jun 13, 2007
10:50 am
2552
Stu, Grep, Strings, XXD etc are only going to show you ascii representations of a binary file (the mpeg). I'm not sure what exactly your search strings were, ...
swinginscott
Offline Send Email
Jun 13, 2007
6:53 pm
2553
Stu, Sorry I'm a bit late to the party (I sent my first response before I saw this one). With your below commentary you've answered some of the questions I had...
swinginscott
Offline Send Email
Jun 13, 2007
7:26 pm
2555
When doing forensics on a Linux Operating System, is there a way to determine if/when a thumb drive had ever been inserted?...
mrafterv
Online Now Send Email
Jul 12, 2007
9:40 pm
2556
When doing forensics on a Linux Operating System, is there a way to determine if a file had been FTP'd to another location?...
mrafterv
Online Now Send Email
Jul 12, 2007
9:41 pm
2557
Have you looked for obvious clues like the .bash_history file or other shell history files? Or, if you have a specific alternate location that you suspect,...
Michael Snyder
msnyder@...
Send Email
Jul 12, 2007
9:52 pm
2558
Please excuse my complete ignorance. I am doing research for my boss on this issue and am essentially the middle man here. Where will he find the .bash and...
Matt Rafter
mrafterv
Online Now Send Email
Jul 12, 2007
11:17 pm
2559
... He might be better off with a different middle-man then since this is pretty basic shell stuff. as far as your original question, there will be no...
Brendan Murray
bp_murray
Offline Send Email
Jul 12, 2007
11:33 pm
2560
... ever! no, but sometimes you can see it in the logs... also in /swap sometimes if your lucky as for when, usually that gets lost fairly quickly Richard...
Richard Reynolds
richardreyno...
Offline Send Email
Jul 13, 2007
4:57 am
2561
Looking at the log files you might be able to determine there was a USB device inserted, or that an 'sd' device was mounted. Realistically, if you're asking...
swinginscott
Offline Send Email
Jul 13, 2007
11:26 am
2562
All, I've been given a tape that I know nothing about (Tape Drive, logical format, etc). What tool(s) would you recommend for tape drive recovery and analysis?...
swinginscott
Offline Send Email
Jul 17, 2007
11:55 am
2563
... I think I'd pop the tape in the drive, and use dd to create a disk image of the tape. Let's face it, reading from tapes is slow and annoying. :) Then,...
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jul 17, 2007
5:13 pm
2564
... tar would be more traditional for grabbing info from tape, but not sure where you stand forensically in terms of having a hash of the media afterwards. A...
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 18, 2007
6:46 am
2566
Hi James, Since I've never on tapes and DD, I can't say for sure what you get, but you can MD5 the individual files that you take off the tape with tar. -Enda....
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 18, 2007
12:12 pm
2567
... Enda, I've had difficulty getting Irix to read a DDS tape created under Linux with tar. And, that's just getting different versions of tar to read one...
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jul 18, 2007
6:42 pm
2568
Just wanted to add two quick points to this very worthwhile discussion: 1. _Please_ be sure the write-protect tab is in the "locked" position before you put...
Stevens R. Miller
bobhey2000
Offline Send Email
Jul 18, 2007
6:50 pm
2569
While we're in the mode of quick points, and to further add an exclamation point to Stevens' comment that "tape sucks", there is a distinct possibility that a...
Steve Fowler
sfowler@...
Send Email
Jul 18, 2007
8:40 pm
2570
That crossed my mind, too, Steve. dd is great for imaging disks, but I think you could be stymied asking it to "image" a tape, for just the reason you...
Stevens R. Miller
bobhey2000
Offline Send Email
Jul 18, 2007
9:30 pm
2571
Forensic acquisition and analysis of magnetic tapes ...
Brendan Murray
bp_murray
Offline Send Email
Jul 18, 2007
11:25 pm
2572
... I put multiple images on tapes for backups all the time i.e tar cjvf - somedir | dd of=/dev/nrmt0 bs=100k tar cjvf - someotherdir | dd of=/dev/nrmt0...
Brendan Murray
bp_murray
Offline Send Email
Jul 18, 2007
11:28 pm
2573
Thanks for pointing out my error, Brendan -- mental rust accumulation is hard for me to avoid when it comes to tapes! The error was using "EOF" when the...
Steve Fowler
sfowler@...
Send Email
Jul 19, 2007
12:02 am
Messages 2542 - 2573 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help