Search the web
Sign In
New User? Sign Up
linux_forensics
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 2739 - 2768 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Messages: Simplify | Expand   (Group by Topic) Author Sort by Date ^
2739
Would using a bootloader other than GRUB help with the error problem? On 3/12/08, Alfred Tims <timsal-1@...<timsal-1%40linuxmail.org>> wrote: Hi, Try doing a...
sbeyeforhire
Offline Send Email
Apr 1, 2008
8:36 am
2740
What did you use to burn the CD? Depending on what program you use the ISO can get a little mangled, and provide you with the generic disc read error you're...
swinginscott
Offline Send Email
Apr 1, 2008
10:33 am
2741
... Using a tool to do something beyond what the original author anticipated does not make it automatically null and void. If you do proper testing using...
Jacques B.
jboucher_work
Offline Send Email
Apr 1, 2008
11:45 am
2742
... Mr Rogers also said in that same song the the qualified examiner must know when to walk away and know when to run. I'd suggest "run" for this case. The...
Enda Cronnolly
endacronnolly
Offline Send Email
Apr 1, 2008
12:36 pm
2743
... I have to disagree. If your agency has a validation unit, then they would take care of validating a live distro that they would create. If not, the person...
Jacques B.
jboucher_work
Offline Send Email
Apr 1, 2008
4:26 pm
2744
I just gave it a test (wine-0.9.46 on FC6 so not latest and greatest version of Wine or Fedora) and it failed. I could fire it up and view a folder. However...
Jacques B.
jboucher_work
Offline Send Email
Apr 1, 2008
5:01 pm
2745
Hi, Jacques, Yes, you are correct. I made things sound worse than they are. It is possible that you could spend the time with the court and the other side's...
Simson Garfinkel
simsongarfinkel
Offline Send Email
Apr 2, 2008
12:49 am
2746
... Disclaimer: I'm new to the list/group, don't do forensics, and have not tested exactly what you're wanting to do [1]. However, I have done something...
Robby Workman
robw810
Offline Send Email
Apr 2, 2008
12:49 am
2747
I am looking for help building Pasco, the index.dat parser by Foundstone. I am having trouble building under FC8 with the following make errors: gcc -o pasco...
Lehr, John
slopd4256
Offline Send Email
Apr 2, 2008
12:51 am
2748
... Thanks for the links. I was aware of Barry Grundy's linuxleo.com (Barry is a member of this list). An excellent tool to learn Linux forensics. I've used...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
1:20 am
2749
... Dear court, I'm an expert witness, except my expertese doesn't extend beyond FTK imager.... as I said, know when to walk away, and know when to run ;-) ...
Enda Cronnolly
endacronnolly
Offline Send Email
Apr 2, 2008
1:47 am
2750
John, Here's how I fixed it: Add the following #include along with the others #include <string.h> (gets rid of the implicit declaration for strcpy warning) ...
Steve Gibson
sw_gibson
Offline Send Email
Apr 2, 2008
4:56 am
2751
... Well, I'm not anywhere close to a C guru (just started learning it, in fact), but a bit of poking around shows that there were a couple ... +++ pasco.c...
Robby Workman
robw810
Offline Send Email
Apr 2, 2008
7:41 am
2752
... No, Dear court, I am an experienced forensic examiner. I have used various imaging tools over the years including FTK Imager. In this instance I used FTK...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
10:09 am
2753
... Hi Jacques, No, unfortunately time just does not allow for that sort of evaluation testing. I'm too busy trying to keep up with testing versions of stuff ...
Grundy, Barry J. (HQ-...
grundy_b
Offline Send Email
Apr 2, 2008
12:43 pm
2754
... Which directly contradicts your purpose of the exercise which you stated was to give people who were only familiar with FTK imager a linux based tool to ...
Enda Cronnolly
endacronnolly
Offline Send Email
Apr 2, 2008
1:58 pm
2755
Hi all, I got the HDD of a server on which we have a real doubt on its compromission. The system was a SUSE Linux Enterprise. For my investigation, i would...
d1g1tals1n
Offline Send Email
Apr 2, 2008
2:12 pm
2756
... Again... no. In a posting yesterday replying to you I clearly stated that had it worked, I could have created a tested/validated Linux boot CD with FTK...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
4:59 pm
2757
On Wed, Apr 2, 2008 at 8:43 AM, Grundy, Barry J. (HQ-WIM51) ... Didn't realize you were there. I was there as well both as an attendee and as a presenter. I...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
5:05 pm
2758
Steve, thank you for your help with the coding. I have built pasco without errors making the modifications you provided. I'll seek out an index.dat and parse...
Lehr, John
slopd4256
Offline Send Email
Apr 2, 2008
5:19 pm
2759
... No, I am. The exercise just appears to me be the most pointless waste of time I've witnessed in 2008, and your motives and explainations appear ...
Enda Cronnolly
endacronnolly
Offline Send Email
Apr 2, 2008
5:34 pm
2760
... Some laptops are very difficult if not near impossible to take apart to get to the drive. Some will not image properly unless in the native machine. Or...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
7:02 pm
2761
... If they were only familiar / competent with FTK imager in the first place, then they lacked the competency to take a forensic image, esp given the closed...
Harry Duncan
usr.src.linux@...
Send Email
Apr 2, 2008
7:31 pm
2762
The new PTK in alpha version has been released. PTK is the new alternative interface for Sleuth Kit. Among the features implemented in this version we...
Michele Zambelli
mizambo
Offline Send Email
Apr 2, 2008
7:49 pm
2763
... You can have a qualified forensic examiner who is proficient in a single analysis tool. That fact does not invalidate their knowledge/expertise. It...
Jacques B.
jboucher_work
Offline Send Email
Apr 2, 2008
8:48 pm
2764
... Could we kill this thread? I think Enda was saying the same thing: if you can validate the mechanism as you said above, then why not just do it? Or, if...
Dave Dittrich
dadittrich
Offline Send Email
Apr 2, 2008
11:33 pm
2765
I second Dave's emotion. Please kill this thread. Dave Dittrich <dittrich@...> wrote: > Dear court, I am an experienced forensic...
The Dog's Bollix
ISXPRO
Offline Send Email
Apr 3, 2008
10:28 am
2766
... [...] ... No idea. However, the way that I've done this is to use chroot and to point to the root of the target system. chroot /mnt/target rpm -qa --last ...
Gary Funck
garyfunck
Offline Send Email
Apr 3, 2008
2:25 pm
2767
Rather than quote parts of the interesting (and very long) thread that resulted from Jacques B.'s original query, I'll offer a few observations/opinions: - I...
Gary Funck
garyfunck
Offline Send Email
Apr 3, 2008
3:23 pm
2768
... Its actually a step backwards, state of the art is using a windows tool on a fully developed and tested windows platform, using a windows tool on a beta...
Harry Duncan
usr.src.linux@...
Send Email
Apr 3, 2008
6:45 pm
Messages 2739 - 2768 of 3157   Oldest  |  < Older  |  Newer >  |  Newest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help