Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2555 - 2585 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2555
When doing forensics on a Linux Operating System, is there a way to determine if/when a thumb drive had ever been inserted?...
mrafterv
Offline Send Email
Jul 12, 2007
9:40 pm
2556
When doing forensics on a Linux Operating System, is there a way to determine if a file had been FTP'd to another location?...
mrafterv
Offline Send Email
Jul 12, 2007
9:41 pm
2557
Have you looked for obvious clues like the .bash_history file or other shell history files? Or, if you have a specific alternate location that you suspect,...
Michael Snyder
msnyder@...
Send Email
Jul 12, 2007
9:52 pm
2558
Please excuse my complete ignorance. I am doing research for my boss on this issue and am essentially the middle man here. Where will he find the .bash and...
Matt Rafter
mrafterv
Offline Send Email
Jul 12, 2007
11:17 pm
2559
... He might be better off with a different middle-man then since this is pretty basic shell stuff. as far as your original question, there will be no...
Brendan Murray
bp_murray
Offline Send Email
Jul 12, 2007
11:33 pm
2560
... ever! no, but sometimes you can see it in the logs... also in /swap sometimes if your lucky as for when, usually that gets lost fairly quickly Richard...
Richard Reynolds
richardreyno...
Offline Send Email
Jul 13, 2007
4:57 am
2561
Looking at the log files you might be able to determine there was a USB device inserted, or that an 'sd' device was mounted. Realistically, if you're asking...
swinginscott
Offline Send Email
Jul 13, 2007
11:26 am
2562
All, I've been given a tape that I know nothing about (Tape Drive, logical format, etc). What tool(s) would you recommend for tape drive recovery and analysis?...
swinginscott
Offline Send Email
Jul 17, 2007
11:55 am
2563
... I think I'd pop the tape in the drive, and use dd to create a disk image of the tape. Let's face it, reading from tapes is slow and annoying. :) Then,...
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jul 17, 2007
5:13 pm
2564
... tar would be more traditional for grabbing info from tape, but not sure where you stand forensically in terms of having a hash of the media afterwards. A...
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 18, 2007
6:46 am
2566
Hi James, Since I've never on tapes and DD, I can't say for sure what you get, but you can MD5 the individual files that you take off the tape with tar. -Enda....
Enda Cronnolly
endacronnolly
Offline Send Email
Jul 18, 2007
12:12 pm
2567
... Enda, I've had difficulty getting Irix to read a DDS tape created under Linux with tar. And, that's just getting different versions of tar to read one...
Mark W. Jeanmougin
JSinfonia
Offline Send Email
Jul 18, 2007
6:42 pm
2568
Just wanted to add two quick points to this very worthwhile discussion: 1. _Please_ be sure the write-protect tab is in the "locked" position before you put...
Stevens R. Miller
bobhey2000
Offline Send Email
Jul 18, 2007
6:50 pm
2569
While we're in the mode of quick points, and to further add an exclamation point to Stevens' comment that "tape sucks", there is a distinct possibility that a...
Steve Fowler
sfowler@...
Send Email
Jul 18, 2007
8:40 pm
2570
That crossed my mind, too, Steve. dd is great for imaging disks, but I think you could be stymied asking it to "image" a tape, for just the reason you...
Stevens R. Miller
bobhey2000
Offline Send Email
Jul 18, 2007
9:30 pm
2571
Forensic acquisition and analysis of magnetic tapes ...
Brendan Murray
bp_murray
Offline Send Email
Jul 18, 2007
11:25 pm
2572
... I put multiple images on tapes for backups all the time i.e tar cjvf - somedir | dd of=/dev/nrmt0 bs=100k tar cjvf - someotherdir | dd of=/dev/nrmt0...
Brendan Murray
bp_murray
Offline Send Email
Jul 18, 2007
11:28 pm
2573
Thanks for pointing out my error, Brendan -- mental rust accumulation is hard for me to avoid when it comes to tapes! The error was using "EOF" when the...
Steve Fowler
sfowler@...
Send Email
Jul 19, 2007
12:02 am
2574
... I tend to use EOT for end of tape because believe it or not I would first think of EOD as end of deck. But End-of-data EOD or End-of-tape EOT are clear...
Brendan Murray
bp_murray
Offline Send Email
Jul 19, 2007
1:05 am
2575
There is an updated version of that same paper here: http://digitalforensics.ch/nikkel05.pdf Kind Regards, Bruce...
nikkel@...
Send Email
Jul 19, 2007
6:51 am
2576
Thank you all for the responses, they were quite informative. This was my first experience trying to recover from tapes at all. I learned a lot. In the end,...
swinginscott
Offline Send Email
Jul 19, 2007
1:51 pm
2577
Has any one had a problem with dd and split using ubntu 6...
depshlomo
Offline Send Email
Jul 21, 2007
10:32 am
2578
I've used the combination several times in the past few months. What kinds of problems are you seeing?...
Logan Browne
loganbrowne
Offline Send Email
Jul 21, 2007
3:09 pm
2579
Ladies and Gents, Apologies for the cross post. A new version of the Law Enforcement and Forensic Examiner's Introduction to Linux, A Beginner's Guide is now...
Barry J. Grundy
grundy_b
Offline Send Email
Oct 22, 2007
3:42 pm
2580
Has anyone filled up a foremost conf file with signatures for carving that they would be willing to share? -- Ave caesar! Morituri te salutamus [Non-text...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 30, 2007
12:50 pm
2581
... I'd be interested in that as well. Someone recently mentioned to me that on a particular image file that Foremost carved out 80 some images whereas EnCase...
Jacques B.
jboucher_work
Offline Send Email
Oct 30, 2007
4:17 pm
2582
Michael, sorry i don't have Foremost conf's any longer but maybe i could point you at Photorec from cgsecurity.org It's name belies how much it can carve, not...
kern
kern.uk@...
Send Email
Oct 31, 2007
6:53 am
2583
Thanks Kern. I've bookmarked it and forwarded it to some of my peers. I'd like to see a head to head test between EnCase, FTK, foremost, scalpel, and photorec...
Jacques B.
jboucher_work
Offline Send Email
Oct 31, 2007
10:37 am
2584
Jacques Photorecs are built in thankfully, and added to by the author and helpers on a semi regular basis. To add confs for yourself, you may have to tinker...
kern
kern.uk@...
Send Email
Oct 31, 2007
4:27 pm
2585
... Thanks Kern. I'll check out their mailing list. Jacques...
Jacques B.
jboucher_work
Offline Send Email
Oct 31, 2007
8:36 pm
Messages 2555 - 2585 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help