Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2579 - 2609 of 3158   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2579
Ladies and Gents, Apologies for the cross post. A new version of the Law Enforcement and Forensic Examiner's Introduction to Linux, A Beginner's Guide is now...
Barry J. Grundy
grundy_b
Offline Send Email
Oct 22, 2007
3:42 pm
2580
Has anyone filled up a foremost conf file with signatures for carving that they would be willing to share? -- Ave caesar! Morituri te salutamus [Non-text...
Michael Harrington
chimpinlinux
Offline Send Email
Oct 30, 2007
12:50 pm
2581
... I'd be interested in that as well. Someone recently mentioned to me that on a particular image file that Foremost carved out 80 some images whereas EnCase...
Jacques B.
jboucher_work
Offline Send Email
Oct 30, 2007
4:17 pm
2582
Michael, sorry i don't have Foremost conf's any longer but maybe i could point you at Photorec from cgsecurity.org It's name belies how much it can carve, not...
kern
kern.uk@...
Send Email
Oct 31, 2007
6:53 am
2583
Thanks Kern. I've bookmarked it and forwarded it to some of my peers. I'd like to see a head to head test between EnCase, FTK, foremost, scalpel, and photorec...
Jacques B.
jboucher_work
Offline Send Email
Oct 31, 2007
10:37 am
2584
Jacques Photorecs are built in thankfully, and added to by the author and helpers on a semi regular basis. To add confs for yourself, you may have to tinker...
kern
kern.uk@...
Send Email
Oct 31, 2007
4:27 pm
2585
... Thanks Kern. I'll check out their mailing list. Jacques...
Jacques B.
jboucher_work
Offline Send Email
Oct 31, 2007
8:36 pm
2586
Hi, What file formats are you looking for that aren't supported by Foremost out of the box? -- Jesse...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 2, 2007
4:18 am
2587
... The specific situation we had was a data recovery one for a student and it was a PPT file. That one was not included in the conf file. Not sure if there...
Jacques B.
jboucher_work
Offline Send Email
Nov 2, 2007
10:10 am
2588
The latest version of Foremost, released just a few days ago, has a built-in OLE mode that should recover Word, Excel, and Powerpoint files. Check out...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 4, 2007
1:59 pm
2589
... Thanks Jesse. Good to know. I was under the impression that scalpel had taken over for foremost. But clearly that is not the case. And you being one of...
Jacques B.
jboucher_work
Offline Send Email
Nov 4, 2007
2:38 pm
2590
... Yes they are! I can't speak for the Scalpel team, but Foremost is still being actively developed. -- Jesse...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 4, 2007
3:04 pm
2591
... By the way I see that you will also be at the St. Louis conference in January. Looking forward to another great conference. Enjoyed last year's. This...
Jacques B.
jboucher_work
Offline Send Email
Nov 4, 2007
3:17 pm
2592
... Hmmm...I had the same impression as Jacques. I wonder where we got that from? I had thought scalpel was a replacement for foremost and I can't for the...
Barry J. Grundy
grundy_b
Offline Send Email
Nov 5, 2007
10:02 pm
2593
Good afternoon, While reading up on Foremost and Scalpel I deduced that Foremost was no longer supported and that Scalpel had replaced it. If you read...
David Kovar
dkovar
Online Now Send Email
Nov 5, 2007
10:19 pm
2594
... Whether it has or it hasn't, if foremost has nothing to offer over scalpel feature wise, it would be great if the two teams merged. Of course, if there is...
Harry Duncan
usr.src.linux@...
Send Email
Nov 5, 2007
10:38 pm
2595
Hi, Can you help me, listing/detailing the problems that can affect the capability of Foremost and Scalpel to carve a file from a dd image ? I´m studying this...
Tony Rodrigues
fotografo_to...
Offline Send Email
Nov 6, 2007
1:18 pm
2596
Anyone know where I can download George M. Garner's Forensics Acquisition Utilities that allows you to use dd.exe to capture Physical Memory? I believe it is...
Aaron Coles
computer_exp...
Offline Send Email
Nov 6, 2007
9:49 pm
2597
... It's part of the Helix distribution at http://www.e-fense.com/helix/. I've used it to acquire physical memory on several occasions. There's a link to...
Brian Eckman
forensiccerdo
Offline Send Email
Nov 6, 2007
10:18 pm
2599
http://www.gmgsystemsinc.com/fau/ Best Regards....
Barış HIZIR
bhizir
Offline Send Email
Nov 12, 2007
8:40 am
2600
The Computer Forensics Analysis & Training Center (CFATC) is a 501c3 Nonprofit Organization created to provide professional workforce development in the high...
Nancy White
dfgi114
Offline Send Email
Nov 12, 2007
9:45 pm
2601
Scalpel is a complete rewrite of Foremost version 0.69. It uses some innovative techniques to make the carving of generic headers and footers much faster under...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 14, 2007
12:41 pm
2602
... Makes perfect sense. I can see the advantage of Foremost in those instances. No doubt it comes with a performance hit. But like everything else there is...
Jacques B.
jboucher_work
Offline Send Email
Nov 14, 2007
12:48 pm
2603
Hi, Thank you very much,, and now i am doing a assignment that consists of forensic tool kits.. and its uses.. i dont know how to do that.. and i have to...
pavan kumar
pavanvovveti
Offline Send Email
Nov 15, 2007
4:49 pm
2604
hi all, this is pavan vovveti, pursuing my masters in forensic computing after my graduation in biomedical engg.. i am new to this field.. now i am doing my...
pavan kumar
pavanvovveti
Offline Send Email
Nov 15, 2007
4:55 pm
2605
Hey, guys, Any help on this ? I got no answer by now ... I appreciate any help. Even a link to some page where to find/study the topic. Thanks, Tony Rodrigues,...
Tony Rodrigues
fotografo_to...
Offline Send Email
Nov 16, 2007
4:11 pm
2606
... Try using google and find out how foremost works. The limitations are pretty damn obvious then. Have you read the foremost readme file? Harry....
Harry Duncan
usr.src.linux@...
Send Email
Nov 16, 2007
5:02 pm
2607
... As Harry pointed out, there's lots of info just a google away. Search for DFTT and CFTT for (Digital/Computer Forensics Tool Testing) to get an idea of...
Barry J. Grundy
grundy_b
Offline Send Email
Nov 16, 2007
5:24 pm
2608
Two words: File fragmentation ... -- Jesse...
Jesse Kornblum
jessekornblum
Online Now Send Email
Nov 17, 2007
11:42 am
2609
... For ease of use you can download the latest Helix Forensics Live CD from http://www.e-fense.com/helix/. And it has a great documentation too ...
Tedi Heriyanto
tedi_heriyanto
Offline Send Email
Nov 20, 2007
2:51 pm
Messages 2579 - 2609 of 3158   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help